Satia
Delaware DOPPA & DPDPA Compliance

Privacy Policy

Transparency, compliance with Delaware DOPPA & DPDPA, and sovereignty over your corporate data.

Last updated: September 8, 2026

At SATIA LLC (8 The Green, Suite B, Dover, Delaware, United States, 19901; hereinafter, 'Satia', 'we', 'us', or 'our'), we understand the critical importance of corporate confidentiality. This Privacy Policy transparently describes how we collect, process, store, and safeguard personal and corporate data in strict compliance with the Delaware Online Privacy and Protection Act (DOPPA - 6 Del. C. § 1205C) and the Delaware Personal Data Privacy Act (DPDPA - 6 Del. C. § 12D-101 et seq.). By accessing or using Satia, you acknowledge the data practices described herein.

1. Privacy Roles: Controller vs. Processor

Under applicable data protection laws (including the Delaware DPDPA and European GDPR), legal obligations depend on our role in data processing:

  • Satia as Data Controller: We act as a Data Controller regarding account information for our direct business customers (e.g., administrator name, corporate email, customer billing info, Wallet transaction records, and technical support interactions).
  • Satia as Data Processor / Service Provider: When our business customers use our platform to interact with their own end-users or consumers (e.g., WhatsApp chats, voice calls with phone agents, Dynamic ERP records, or knowledge base files uploaded to Satia Docs), our customer acts as the Data Controller and Satia acts strictly as a Data Processor under the customer's instructions. Such processing is governed by our formal Data Processing Addendum (DPA) .

2. Information & Categories of Data Collected (DOPPA)

To provide our AI Operating System services, we collect the following categories of Personally Identifiable Information (PII) and business records:

  • Direct Identifiers: Name, corporate email address, business telephone number, and secure authentication credentials managed via Supabase Auth.
  • Commercial & Billing Data: Transaction history, Wallet top-up logs, corporate entity details, and channel subscription records. We do not store complete credit card numbers; card transactions are processed by PCI-DSS Level 1 payment gateways.
  • Structured Business Data (Dynamic ERP V3): Custom entity schemas, attributes, relational links, and customer/catalog records configured within the tenant's dynamic tables.
  • Knowledge Documentation (Satia Docs): Markdown documents, PDF files, and multimedia assets uploaded for Retrieval-Augmented Generation (RAG) contextual grounding.
  • Communications & Audio/Voice Data: Message transcripts from connected channels (WhatsApp, Instagram, WebChat), audio recordings or transcripts of voice agent calls, and session metadata.
  • Internet & Network Activity: IP address, browser type, device identifiers, system audit logs, and UI telemetry.

3. Purposes of Data Processing

We process collected data strictly for the following legitimate commercial purposes:

  • To operate, maintain, and optimize business workflows and autonomous automation pipelines.
  • To provide semantic grounding (RAG) to autonomous agents to ensure accurate responses and prevent hallucinations.
  • To execute scheduled cron tasks, background operations, and web navigation tasks (Browser Agents).
  • To synchronize and route messages across integrated channels (Meta Cloud API, telephony carriers).
  • To manage atomic Wallet usage balances and consumption billing at the database engine level.
  • To ensure multi-tenant security isolation, fraud prevention, and human-in-the-loop (HITL) support.

Zero Sale Commitment:

SATIA LLC DOES NOT sell or rent corporate or personal customer data to any third parties or data brokers, nor do we share it for cross-context behavioral advertising.

4. Multi-tenant Isolation & Deterministic Security (RLS)

Satia's technical architecture is engineered around the principle of deterministic tenant isolation:

  • PostgreSQL Row Level Security (RLS): Every database table storing customer data (RAG docs, ERP rows, chat transcripts, configs) operates with mandatory RLS policies. Every database query cryptographically verifies the user JWT token and strictly isolates data access to the verified tenant identifier (tenant_id / sub_user_id).
  • Encryption in Transit & at Rest: All data transmitted between the customer, Satia, and subprocessors is protected using TLS 1.3 encryption. All stored data at rest is encrypted using industry-standard AES-256 encryption.

5. Data Subprocessors & AI Model APIs

To provide AI capabilities, telecommunications, and cloud infrastructure, we share specific categories of data with vetted subprocessors under strict data protection agreements:

  • Cloud Infrastructure & Database: Supabase Inc. / Amazon Web Services (AWS) for hosting, authentication, and PostgreSQL databases with RLS.
  • Foundational AI Model APIs: Google LLC (Gemini API) and OpenAI LLC (OpenAI API) for reasoning, computer vision analysis, and vector embeddings.
  • Messaging Channel Integration: Meta Platforms Inc. (WhatsApp Cloud API, Instagram Graph API) for commercial messaging synchronization.
  • Telephony Carriers: SIP/VoIP carrier providers for executing inbound and outbound calls with human voice agents.

Contractual Zero-Training Guarantee: Satia operates under enterprise API contracts explicitly providing that customer data, Satia Docs files, and chat transcripts ARE NOT used to train, retrain, or fine-tune third-party public foundation models. For full details, review our AI Addendum .

6. Delaware Consumer Rights (DPDPA)

Under the Delaware Personal Data Privacy Act (DPDPA - 6 Del. C. § 12D-101 et seq.) and applicable privacy laws, consumers have the following rights regarding personal data processed by Satia:

  • Right to Confirm & Access: Confirm whether Satia is processing personal data and access a copy of such personal data.
  • Right to Correct: Correct inaccuracies in personal data held about you.
  • Right to Delete: Request the definitive deletion of personal data provided by or obtained about you.
  • Right to Data Portability: Obtain a portable, readily usable copy of your personal data in a machine-readable format.
  • Right to Opt-Out: Opt out of the processing of personal data for purposes of: (a) targeted advertising, (b) sale of personal data (we do not sell data), or (c) profiling in furtherance of solely automated decisions that produce legal or similarly significant effects.

Response Timeline: We will respond to verified requests within forty-five (45) days of receipt. This period may be extended once by an additional forty-five (45) days when reasonably necessary, provided notice is sent within the initial period.

To submit a request, contact our Data Protection Officer at ginna@satia.so.

7. Appeal Process & Delaware Attorney General (DPDPA)

If Satia declines to take action regarding a consumer request under the DPDPA, you have the legal right to appeal our decision:

  • Filing an Appeal: You may submit an appeal within thirty (30) days of our decision notice by writing to ginna@satia.so with the subject line "DPDPA Privacy Appeal".
  • Appeal Determination: Satia will inform you in writing within forty-five (45) days of receipt of the appeal of any action taken or not taken, including a written explanation of the reasons for the decision.
  • Complaint to Delaware Attorney General: If your appeal is denied or unsatisfied, you have the right to file a complaint with the Delaware Department of Justice Consumer Protection Unit:

    Delaware Department of Justice - Consumer Protection Unit

    820 N. French Street, 5th Floor, Wilmington, DE 19801

    Toll-Free: (800) 220-5424 / Phone: (302) 577-8600

    Official portal: attorneygeneral.delaware.gov/fraud/cmu

8. 'Do Not Track' & Global Privacy Control Signals (DOPPA)

In compliance with Section 1205C of the Delaware Online Privacy and Protection Act (DOPPA - 6 Del. C. § 1205C) and universal opt-out provisions under the DPDPA:

  • Do Not Track (DNT) Headers: Due to the lack of an established cross-industry standard, our website does not currently alter its operational practices upon receiving generic browser DNT headers alone.
  • Global Privacy Control (GPC): Under Delaware DPDPA requirements, we recognize and process valid Global Privacy Control (GPC) opt-out preference signals sent by your browser or extension as a valid request to opt out of targeted advertising where applicable.
  • Zero Sale of Data: Satia confirms that it does not sell personal data for monetary consideration.

9. Protection of Minors Under 18 (DOPPA § 1204C)

In accordance with Delaware provisions safeguarding minors online (DOPPA - 6 Del. C. § 1204C):

  • B2B Enterprise Focus: Satia is strictly an enterprise business-to-business platform designed for individuals and companies aged 18 and older. We do not intentionally market to or knowingly collect data from children under 18.
  • Advertising Prohibitions: We adhere to Delaware prohibitions against advertising age-restricted products or services to minors.
  • Content Removal for Delaware Minors: If a Delaware resident under 18 who is a registered user has uploaded or posted content to the platform, they have the right to request removal of such content by contacting ginna@satia.so.

10. Cookies & Local Storage

Satia utilizes strictly essential first-party cookies and LocalStorage for vital functionality:

  • Authentication: Encrypted Supabase Auth session tokens verifying your credentials securely.
  • Preferences: Storing language preferences (EN/ES) and minimal UI states (collapsed sidebar, Zen layout).
  • No Third-Party Ad Trackers: We do not deploy behavioral ad tracking cookies or data broker analytics.

11. Notice of Material Changes & Effective Date

We may revise this Privacy Policy from time to time. If we introduce material changes to our data handling practices under DOPPA requirements, we will provide conspicuous notice on our platform or send an email notification to registered account administrators prior to the effective date.

The "Last updated" date at the top of this document indicates when the latest revision took effect.

12. Contact, Data Officer & Links

For questions regarding this policy, RLS architecture, DPDPA requests, or our DPA terms, contact our team:

SATIA LLC

8 The Green, Suite B, Dover, Delaware, United States, 19901

Direct Email: ginna@satia.so

Data Protection Representative for the State of Delaware.

Satia Sovereignty & Protection

SATIA LLC operates under strict privacy-by-design engineering standards. We do not monetize client data or train public models with private business records.

Contact Officer