Privacy Policy
Last updated 11 August 2026
This explains what we collect when you use Sendascale, why we collect it, who else sees it, and how to get it removed. It is written to be read, not to be survived.
It covers the free ChatGPT visibility report, this website, and the client portal.
1. Who is responsible
Neural Agents SA, trading as Sendascale, is the controller of the personal data described here.
- Company
- Neural Agents SA (Corporation (société anonyme))
- Address
- c/o Rudy Perez, Avenue de l'Ermitage 32, 1224 Chêne-Bougeries, Switzerland
- Company number (UID)
- CHE-274.397.263
- Register ID
- CH-660-5621025-6
- Contact
- rudy@sendascale.com
2. What we collect
Three groups, depending on what you do.
- When you request a report
- Your website address, the business details we read from that public website, the questions you choose, add or reorder, any competitor you ask us to check, your name, your email address, your phone number if you give one, and the two budget ranges you pick. Phone is optional and the report is sent without it.
- The report itself
- We keep what your website said, the questions we generated from it, the answers ChatGPT gave on the day and our count of who was named. It is stored against your website address, so that when we follow up we are talking about the report you actually saw. For 7 days the same website gets that stored report back rather than a fresh run, which is why two people at the same company see the same answers.
- Automatically, on every visit
- Your IP address, your browser and device type, and which pages you opened. The IP address is used to stop one visitor, or a script, running hundreds of reports and emptying the budget that pays for them. It is not tied to your name.
- If you become a client
- The account email and name you sign in with, plus the campaign data we run for you. This lives in the client portal behind a login.
3. Why we hold it, and what allows us to
Two of the reasons below run on what the law calls our legitimate interest. That is the one basis a business grants itself, so here is the balancing behind it written out rather than asserted.
Our interest is in producing the report you asked for and then offering, once, the service the report is about. What it costs you is one follow up about a thing you requested minutes earlier, sent to a business address you gave us for that purpose. Nothing sensitive is involved, nothing is sold on, and nothing is used to build a picture of you as a person rather than of your business. Somebody who has just asked an agency to analyse their website would expect to hear back from that agency, which is the test that matters, and it is why we hold that our interest does not override your rights. If you disagree, that judgement is ours and the decision is yours: object and it stops.
The same goes for the rate limiting. Recording an IP address to stop one script draining a free tool is a narrow use of a piece of data that is never attached to your name.
- To produce and send your report
- You asked for it. In legal terms, taking steps at your request and performing what we agreed.
- To follow up once about your report
- Our legitimate interest in offering the service the report is about. One follow up, and you can stop it in a click.
- To keep the site working and stop abuse
- Our legitimate interest in a service that stays available and is not scraped.
- To measure advertising
- The Meta advertising pixel on the ChatGPT ads pages. Section 7 sets out what it records, what it stores in your browser, and how to refuse it.
- To run the client portal
- Performing our contract with you.
- To keep the records the law makes us keep
- A legal obligation. Invoices and accounting records are kept whether either of us wants them kept, which is why section 8 gives them a retention period of their own.
4. What gets sent to ChatGPT, and what does not
Start with your website, because this is the part most privacy policies leave vague. When you type an address in, our server fetches that page and sends the text it finds to an AI model made by Anthropic, which writes back a description of your business and a list of questions your customers might ask before they buy. Your website is read by an AI model, and it happens before anyone here looks at anything.
The report then works by putting those buying questions to ChatGPT and reading what comes back. That means the question text, which includes your business name, your city and what you sell, goes to OpenAI. All of it comes from your own public website.
If that website carries personal details, a team page with names and email addresses being the usual case, that text goes through the same process, because it is part of the page we fetched.
Your name, your email address, your phone number and your budget answers are never sent to OpenAI or to any other AI provider. They stay in our database.
OpenAI and Anthropic both state that data sent through their business APIs is not used to train their models. We rely on that, and we do not send anything through them that we would mind seeing in public.
5. Who else processes it
We keep this list short on purpose. Every company below is one this service actually calls, and each one only gets what it needs to do its job.
- Vercel (United States)
- Hosts the website and runs the report.
- Supabase (Europe)
- The database where leads and client accounts are stored.
- OpenAI (United States)
- Answers the report questions. Receives the questions only, never your contact details.
- Anthropic (United States)
- Reads your public website to fill in the first screen, and reads ChatGPT's answers to work out which businesses were named. Receives no contact details.
- Resend (United States)
- Sends the report email and our replies.
- Meta (Ireland and United States)
- Advertising measurement, if you have allowed it. Receives that a report was requested, never your name, email or phone.
- Calendly (United States)
- Only if you book a call. You give it your details directly.
6. Sending data abroad
Some of those companies are in the United States, so your data goes there. Transfers are covered by the European Commission's Standard Contractual Clauses together with the Swiss addendum recognised by the Federal Data Protection and Information Commissioner, or by an equivalent safeguard where a provider offers one.
You can ask us for a copy of the safeguard that applies to any provider on that list.
8. How long we keep it
- Report requests
- 24 months after your last contact with us, then deleted. Sooner if you ask.
- Client accounts and campaign data
- For as long as you are a client, then 12 months.
- Invoices and accounting records
- 10 years, because Swiss law requires it.
- Visit measurement
- 12 months, then deleted automatically.
- Server logs
- 30 days.
9. Your rights
Under Swiss data protection law and, where it applies to you, the GDPR, you can ask us to do any of the following. Write to rudy@sendascale.com and we answer within 30 days. There is no charge and you do not have to give a reason.
- See everything we hold about you, and get a copy of it.
- Correct anything that is wrong.
- Have it deleted.
- Object to us using it, including the follow up email.
- Get it in a portable file, or have it sent to someone else.
- Ask us to pause using it while a dispute is sorted out.
- Withdraw consent you gave, at any time, without it affecting what happened before.
10. If you are not happy with our answer
You can complain to the Swiss Federal Data Protection and Information Commissioner (edoeb.admin.ch). If you are in the European Union or the United Kingdom, you can complain to the supervisory authority where you live instead.
We would rather you told us first, but you are not required to.
11. Security
Data is encrypted in transit and at rest. The database is closed to the public internet and reachable only by this application. Access is limited to the people who need it to deliver the work.
No system is perfect. If a breach ever affects your data we will tell you and the regulator within the deadlines the law sets.
12. Children
This is a service sold to businesses. It is not aimed at anyone under 16 and we do not knowingly collect their data.
13. Changes
If this policy changes in a way that matters, the date at the top changes and anyone whose data we hold is told by email before the change takes effect.
