Privacy Policy

Last updated 11 August 2026

This explains what we collect when you use Sendascale, why we collect it, who else sees it, and how to get it removed. It is written to be read, not to be survived.

It covers the free ChatGPT visibility report, this website, and the client portal.

1. Who is responsible

Neural Agents SA, trading as Sendascale, is the controller of the personal data described here.

Company
Neural Agents SA (Corporation (société anonyme))
Address
c/o Rudy Perez, Avenue de l'Ermitage 32, 1224 Chêne-Bougeries, Switzerland
Company number (UID)
CHE-274.397.263
Register ID
CH-660-5621025-6
Contact
rudy@sendascale.com

2. What we collect

Three groups, depending on what you do.

When you request a report
Your website address, the business details we read from that public website, the questions you choose, add or reorder, any competitor you ask us to check, your name, your email address, your phone number if you give one, and the two budget ranges you pick. Phone is optional and the report is sent without it.
The report itself
We keep what your website said, the questions we generated from it, the answers ChatGPT gave on the day and our count of who was named. It is stored against your website address, so that when we follow up we are talking about the report you actually saw. For 7 days the same website gets that stored report back rather than a fresh run, which is why two people at the same company see the same answers.
Automatically, on every visit
Your IP address, your browser and device type, and which pages you opened. The IP address is used to stop one visitor, or a script, running hundreds of reports and emptying the budget that pays for them. It is not tied to your name.
If you become a client
The account email and name you sign in with, plus the campaign data we run for you. This lives in the client portal behind a login.

3. Why we hold it, and what allows us to

Two of the reasons below run on what the law calls our legitimate interest. That is the one basis a business grants itself, so here is the balancing behind it written out rather than asserted.

Our interest is in producing the report you asked for and then offering, once, the service the report is about. What it costs you is one follow up about a thing you requested minutes earlier, sent to a business address you gave us for that purpose. Nothing sensitive is involved, nothing is sold on, and nothing is used to build a picture of you as a person rather than of your business. Somebody who has just asked an agency to analyse their website would expect to hear back from that agency, which is the test that matters, and it is why we hold that our interest does not override your rights. If you disagree, that judgement is ours and the decision is yours: object and it stops.

The same goes for the rate limiting. Recording an IP address to stop one script draining a free tool is a narrow use of a piece of data that is never attached to your name.

To produce and send your report
You asked for it. In legal terms, taking steps at your request and performing what we agreed.
To follow up once about your report
Our legitimate interest in offering the service the report is about. One follow up, and you can stop it in a click.
To keep the site working and stop abuse
Our legitimate interest in a service that stays available and is not scraped.
To measure advertising
The Meta advertising pixel on the ChatGPT ads pages. Section 7 sets out what it records, what it stores in your browser, and how to refuse it.
To run the client portal
Performing our contract with you.
To keep the records the law makes us keep
A legal obligation. Invoices and accounting records are kept whether either of us wants them kept, which is why section 8 gives them a retention period of their own.

4. What gets sent to ChatGPT, and what does not

Start with your website, because this is the part most privacy policies leave vague. When you type an address in, our server fetches that page and sends the text it finds to an AI model made by Anthropic, which writes back a description of your business and a list of questions your customers might ask before they buy. Your website is read by an AI model, and it happens before anyone here looks at anything.

The report then works by putting those buying questions to ChatGPT and reading what comes back. That means the question text, which includes your business name, your city and what you sell, goes to OpenAI. All of it comes from your own public website.

If that website carries personal details, a team page with names and email addresses being the usual case, that text goes through the same process, because it is part of the page we fetched.

Your name, your email address, your phone number and your budget answers are never sent to OpenAI or to any other AI provider. They stay in our database.

OpenAI and Anthropic both state that data sent through their business APIs is not used to train their models. We rely on that, and we do not send anything through them that we would mind seeing in public.

5. Who else processes it

We keep this list short on purpose. Every company below is one this service actually calls, and each one only gets what it needs to do its job.

Vercel (United States)
Hosts the website and runs the report.
Supabase (Europe)
The database where leads and client accounts are stored.
OpenAI (United States)
Answers the report questions. Receives the questions only, never your contact details.
Anthropic (United States)
Reads your public website to fill in the first screen, and reads ChatGPT's answers to work out which businesses were named. Receives no contact details.
Resend (United States)
Sends the report email and our replies.
Meta (Ireland and United States)
Advertising measurement, if you have allowed it. Receives that a report was requested, never your name, email or phone.
Calendly (United States)
Only if you book a call. You give it your details directly.

6. Sending data abroad

Some of those companies are in the United States, so your data goes there. Transfers are covered by the European Commission's Standard Contractual Clauses together with the Swiss addendum recognised by the Federal Data Protection and Information Commissioner, or by an equivalent safeguard where a provider offers one.

You can ask us for a copy of the safeguard that applies to any provider on that list.

7. Cookies, our own measurement, and the advertising pixel

This site sets no third-party analytics cookies and no advertising cookies until you allow them. The client portal sets one cookie that keeps you signed in, which is required for the portal to work at all and cannot be turned off separately from using it.

On the ChatGPT ads pages we do our own visit measurement, stored in our own database and shared with nobody: which pages were opened, roughly where from, what was clicked and how far the page was read. It uses a random id in your browser, never your name, and it never records what you type into a form. The exceptions are the report request itself, meaning the website address you submit for the scan and any competitor names you add to it: those stay with the visit. If you later send the form, we connect that visit to your request so we know which ad worked.

The same pages carry the Meta advertising pixel, which tells us whether an ad we paid for produced a report request. It reports the event, never who you are.

  • To refuse both in your browser: turn on Do Not Track, or use any content blocker. Neither the pixel nor our measurement loads.
  • To turn it off across Meta's own products: Facebook or Instagram settings, then Ads, then Ad preferences.
  • Nothing about the report depends on either. Refuse them and everything still works.
  • To have anything already collected removed, write to us. Section 9 covers that and we answer within 30 days.

8. How long we keep it

Report requests
24 months after your last contact with us, then deleted. Sooner if you ask.
Client accounts and campaign data
For as long as you are a client, then 12 months.
Invoices and accounting records
10 years, because Swiss law requires it.
Visit measurement
12 months, then deleted automatically.
Server logs
30 days.

9. Your rights

Under Swiss data protection law and, where it applies to you, the GDPR, you can ask us to do any of the following. Write to rudy@sendascale.com and we answer within 30 days. There is no charge and you do not have to give a reason.

  • See everything we hold about you, and get a copy of it.
  • Correct anything that is wrong.
  • Have it deleted.
  • Object to us using it, including the follow up email.
  • Get it in a portable file, or have it sent to someone else.
  • Ask us to pause using it while a dispute is sorted out.
  • Withdraw consent you gave, at any time, without it affecting what happened before.

10. If you are not happy with our answer

You can complain to the Swiss Federal Data Protection and Information Commissioner (edoeb.admin.ch). If you are in the European Union or the United Kingdom, you can complain to the supervisory authority where you live instead.

We would rather you told us first, but you are not required to.

11. Security

Data is encrypted in transit and at rest. The database is closed to the public internet and reachable only by this application. Access is limited to the people who need it to deliver the work.

No system is perfect. If a breach ever affects your data we will tell you and the regulator within the deadlines the law sets.

12. Children

This is a service sold to businesses. It is not aimed at anyone under 16 and we do not knowingly collect their data.

13. Changes

If this policy changes in a way that matters, the date at the top changes and anyone whose data we hold is told by email before the change takes effect.