Privacy Policy
Last updated · August 14, 2026
This policy explains what TruSend (“we”) collects when you use trusend.ai and the TruSend platform, why we collect it, and the choices you have. We keep it short on purpose — if anything is unclear, ask us at privacy@trusend.ai.
Who is responsible
The controller is Vlas Dmitrenko PR TruSend, Sole proprietorship (preduzetnik) registered in the Republic of Serbia (registration number 68677424, PIB 115837343), with its seat at Bulevar Vudroa Vilsona 8v, Beograd. Full identification is on the company details page. We have not appointed a data protection officer — we are not required to under Serbia’s Law on Personal Data Protection — so privacy requests go straight to a person who can act on them, at privacy@trusend.ai.
Two roles, two kinds of data
TruSend is operated from the Republic of Serbia. For data about you as our customer — your account, workspace settings, billing — we are the data controller. For your customers’ conversations flowing through your workspace, we are a processor acting on your instructions: that data is yours, we handle it only to provide the service. If you are subject to the GDPR or the Serbian Law on Personal Data Protection, we will sign a data processing agreement with you — ask at privacy@trusend.ai.
What we collect
- Account data — name, email, workspace name, and the settings you configure.
- Conversation data — messages, attachments and metadata processed through your connected channels, used to operate the inbox and ground AI answers in your knowledge base.
- Usage data — product analytics (pages, features, approximate region) used to improve the service.
- Billing data — handled by Paddle, our merchant of record. We never see or store full card numbers.
- Messages you send us — email, the chat on this site, and the address you leave for launch updates, used to answer you and to send what you asked for.
Why we are allowed to process it
- To perform our contract with you — account data, workspace configuration, operating the service, billing.
- Our legitimate interests — keeping the service secure, preventing abuse, and understanding which features get used, balanced against your interests and never to profile you.
- Your consent — launch-update emails, and anything stored in your browser that is not strictly necessary. You can withdraw consent at any time, which does not affect processing that already happened.
- Legal obligation — invoices and accounting records we are required to keep.
What we do not do
- We do not sell personal data — yours or your customers’.
- We do not use your customers’ conversations to train models shared with other TruSend customers.
- We do not keep data we no longer need: deleted workspaces are purged from production systems within 30 days.
How long we keep it
- Workspace and conversation data — for as long as your workspace exists; purged from production systems within 30 days of deletion, and from encrypted backups as those backups age out.
- Account data — deleted with the workspace, except what we must retain for accounting.
- Invoices and accounting records — for the retention period Serbian tax and accounting law imposes.
- Launch-update emails — until you unsubscribe or ask us to delete them.
AI processing and PII redaction
AI replies are produced by large language model providers acting as our subprocessors, bound by data-processing agreements. TruSend’s safety pipeline can redact common PII patterns — emails, phone numbers, card numbers, IP addresses — before content reaches a model, and that switch is yours to control per workspace. The AI answers support questions and hands off to a human; it makes no decision that produces a legal effect for anyone, and we do not use it to profile people.
Subprocessors
We use a short list of subprocessors: cloud infrastructure hosting, LLM providers for AI replies, and Paddle for payments. The current list is available on request at privacy@trusend.ai.
Where data is stored and who touches it
We are established in the Republic of Serbia and operate the service from there. Workspace and conversation data is stored with cloud infrastructure providers we engage as subprocessors, and the AI replies are generated by large language model providers — so personal data crosses borders. The current subprocessor list, naming each provider and where it processes, is available at privacy@trusend.ai and we send it before you sign anything.
There is no European Commission adequacy decision for Serbia, and some of the countries in that chain do not have one either. Where the GDPR applies to data reaching us we rely on the European Commission’s Standard Contractual Clauses together with a transfer impact assessment, and for onward flows we rely on the instruments Serbia’s Law on Personal Data Protection provides. A copy of the clauses that apply to you comes with our data processing agreement.
Cookies and browser storage
This site runs no advertising network and no third-party analytics. What it does store in your browser, and how to control it, is listed on the Cookie Policy page.
Your rights
You can access, export, correct or delete your data at any time — from the workspace where possible, or by emailing us. We handle personal data in line with Serbia’s Law on Personal Data Protection and, where it applies to you, the EU GDPR. If you have statutory privacy rights, we honor access, rectification, erasure, restriction, portability and objection requests within the statutory deadlines — 30 days in Serbia and one month under the GDPR, extendable where the law allows and we tell you why.
If you think we got it wrong, tell us first — we would rather fix it. You can also complain to a supervisory authority: in Serbia, the Commissioner for Information of Public Importance and Personal Data Protection; in the EEA, the authority where you live or work.
Changes
If this policy changes in a way that matters, we will email workspace owners before the change takes effect — not after.