Privacy notice
Last updated 2 October 2026
Who we are
Decisive Condition Ltd ("we") operates Selvatai, a business-development CRM. For personal data about our own account holders we are the data controller. For the customer, company and stakeholder data our users enter, we act as a data processor on behalf of the customer organisation, which is the controller of that data.
Decisive Condition Ltd, company number 17170647.
Registered office: 167-169 Great Portland Street, London, United Kingdom, W1W 5PF.
Privacy contact: privacy@decisivecondition.com
We have not appointed a Data Protection Officer, as the law does not require one for the processing we carry out. Questions about how we handle personal data go to the privacy contact above.
What we process
- Account data — your name, email address, role and organisation. Used to authenticate you and provide the service.
- CRM content you enter — customers, companies, stakeholders (including their names, email addresses and phone numbers), engagements, notes, pipeline and uploaded documents.
- Usage & diagnostics — operational logs (pseudonymous user and organisation identifiers), records of AI features used, plus optional product analytics and error reporting that run only where enabled and, for analytics cookies, only after you consent.
Why, and on what legal basis
- To provide the service (contract) — authentication, storing and displaying your CRM data, AI-assisted features you invoke.
- Legitimate interests — securing the service, keeping operational logs, and processing customers' stakeholder data to deliver the product to that customer.
- Consent — optional analytics cookies, which never load until you opt in and can be withdrawn at any time in Settings → Privacy & data.
We do not make decisions about you with legal or similarly significant effects by automated means alone. AI features produce drafts and summaries for a person to review.
Sub-processors
We use the following providers. Some are located outside the UK; where so, transfers rely on the UK's adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework) or on Standard Contractual Clauses with the UK Addendum, as stated against each provider.
-
Neon (Databricks, Inc.) — Managed PostgreSQL database — the primary data store.
UK (aws-eu-west-2, London).
Data: All CRM data: stakeholders, projects, documents, user accounts
Transfer basis: Data is stored in aws-eu-west-2 (London). The contracting party is Databricks, Inc. (US), parent of Neon, LLC, under the Databricks Master Cloud Services Agreement; the DPA is incorporated rather than separately signed. Databricks, Inc. is certified under the EU-US Data Privacy Framework, its UK Extension and the Swiss-US DPF, with Neon, LLC named as a covered entity — confirmed against the Data Privacy Framework register on 2026-08-23; due for recertification 2027-08-10. -
Fly.io — Application hosting and the encrypted document volume.
London (lhr).
Data: All data in transit, plus uploaded documents at rest
Transfer basis: Data is stored and processed in the UK (lhr). Fly.io is US-established (Chicago, Illinois), so the arrangement is a restricted transfer: it is covered by Standard Contractual Clauses executed 2026-08-22, under which Fly.io acts as processor. Fly.io retains data for 90 days following termination. -
Clerk — Authentication and organisation membership.
United States.
Data: Email address, name, authentication events
Transfer basis: UK/EU Standard Contractual Clauses -
Upstash (Redis, provisioned via Fly.io) — Shared rate-limit counters across application workers.
London (lhr), provisioned via Fly.io.
Data: A rate-limit key only — the signed-in user id, or, for requests made before signing in, an irreversible hash of the client IP address. The IP itself is never sent. No CRM content. Counters expire automatically with the rate-limit window.
Transfer basis: Processed in the UK and not replicated outside it. Instance selvatai-ratelimit is primary in lhr with no read regions configured, verified against `fly redis list` on 2026-08-13. Covered by the Fly.io data-processing addendum executed 2026-08-22, Fly being the contracting party for this Fly-managed instance.
Falls back to per-process in-memory counting when unset, in which case no data leaves the application. -
PostHog — Product analytics, only after consent is given.
EU host by default (eu.i.posthog.com).
Data: A pseudonymous user identifier and plan/role attributes. Email addresses are deliberately not sent.
Transfer basis: Processed in the EEA under the default host -
Sentry — Error reporting and diagnostics.
United States.
Data: Stack traces and request metadata; no direct identifiers are sent deliberately
Transfer basis: UK/EU Standard Contractual Clauses
The following are used only if your organisation configures them. They are listed so the choice is visible before it is made; they receive nothing unless selected.
AI features run only on the provider and the credentials your organisation's administrator saves in Settings. We do not supply an AI account of our own, so until one is set up no AI provider receives anything.
-
Anthropic — AI features you invoke: email drafting, document Q&A, project insights.
United States.
Data: The text of documents and records included in the request
Transfer basis: Your organisation's own agreement with Anthropic — the account its API key belongs to — and Anthropic's data processing terms
Pre-selected in Settings, but used only once your organisation saves its own Anthropic API key. Requests are made on that key and billed to your organisation's Anthropic account. -
OpenAI — AI features you invoke, where an organisation chooses OpenAI (the models behind ChatGPT) as its provider.
United States.
Data: The text of documents and records included in the request
Transfer basis: Your organisation's own agreement with OpenAI — the account its API key belongs to — and OpenAI's data processing terms
Requests are made on your organisation's own OpenAI API key and billed to that account. -
Amazon Web Services (Bedrock) — AI features, where an organisation chooses AWS as its provider.
The AWS region that organisation selects.
Data: The text of documents and records included in the request
Transfer basis: Determined by the selected region; eu-west-2 keeps processing in the UK -
Microsoft Azure OpenAI — AI features, where an organisation chooses Azure as its provider.
The Azure region that organisation selects.
Data: The text of documents and records included in the request
Transfer basis: Determined by the selected deployment -
Self-hosted or third-party OpenAI-compatible endpoint — AI features, where an organisation supplies its own endpoint.
Wherever that organisation hosts it — including on-premises.
Data: The text of documents and records included in the request
Transfer basis: Determined by that organisation
Selected by organisations that require inference inside their own boundary.
This list is generated from the system's own configuration and is also available as machine-readable JSON at /api/subprocessors.
How long we keep it
- Account and CRM data — for as long as your organisation's account is active. When a record, an account or a whole organisation is deleted, the data is removed from the live database and uploaded files are deleted from storage at the same time.
- Records of AI features used — 365 days, then deleted automatically. These record which feature was used and when; they do not contain the text sent to the AI provider.
- Records of questions asked through a connected AI assistant — 365 days, then deleted automatically.
- Uploaded files no longer attached to any record — deleted automatically after 7 days.
- Error reports — no longer than 90 days. Product analytics (only if you consented) — no longer than 12 months.
Deleted data can persist for a short period in our database provider's point-in-time recovery history until that history rolls over, and with our hosting provider for up to 90 days after our contract with them ends.
Your rights
Subject to applicable law, you can request access to, correction of, export of, or deletion of your personal data, object to or restrict certain processing, and withdraw consent. To exercise these rights contact privacy@decisivecondition.com. We respond within one month. Account holders can also export or delete organisation data themselves from Settings → Privacy & data.
If your data was entered by one of our customers — for example, you are a contact in their CRM — that customer is the controller, and requests are best directed to them. If you contact us instead, we will pass your request on and help them answer it.
You also have the right to complain to the Information Commissioner's Office (ico.org.uk).
Cookies
We use essential cookies required to sign you in and run the app. Optional analytics cookies load only if you accept them; you can change your choice at any time in Settings → Privacy & data.
Changes to this notice
When this notice changes we update the date at the top. Material changes — including a new sub-processor — are notified to customer organisations in advance, as set out in our data processing agreement.