Privacy Policy

SelinAI LLC Effective Date: September 23, 2026 Last Updated: September 23, 2026


1. Introduction & Scope

SelinAI LLC ("SelinAI," "we," "us," or "our") is a limited liability company organized under the laws of the State of Iowa, with its principal place of business in Windsor Heights, Iowa. SelinAI designs and delivers custom artificial intelligence and software applications for business clients.

This Privacy Policy describes how SelinAI collects, uses, discloses, and protects personal information in connection with:

  • Our business development and client relationship activities;
  • The delivery of our services under client contracts and statements of work; and
  • Any web properties, portals, or communications we operate.

B2B Context. SelinAI's services are provided exclusively to business clients ("Clients"). In our primary operating model, Clients are independent data controllers responsible for the personal data they collect from their own customers, employees, and end users. When Clients submit personal data into applications SelinAI builds or operates on their behalf, SelinAI acts as a data processor — processing that data only as instructed by the Client. This Policy addresses both our role as a controller (for our own business operations) and our role as a processor (for Client-submitted data).

This Policy applies to all individuals whose personal information we process as a controller, including Client representatives, prospective clients, vendors, and other business contacts. It does not override the terms of any Data Processing Agreement (DPA) entered into with a Client, which will govern our processor obligations in full.


2. Information We Collect

2.1 Contact & Account Data

When you or your organization engages with SelinAI — whether as a prospective client, active client, vendor, or partner — we may collect:

  • Full name, job title, and professional role
  • Business email address and phone number
  • Company name, business address, and industry
  • Account credentials (where applicable) for any portal or platform we operate
  • Communications history (emails, meeting notes, messages)

2.2 Project & Contract Data

In the course of delivering our services, we collect and process:

  • Statements of work, contracts, and related agreements
  • Project specifications, requirements, and documentation
  • Deliverables, source code, and technical outputs
  • Correspondence and records related to the engagement

2.3 Usage Data

When you interact with our web properties, portals, or applications, we may automatically collect:

  • IP address and approximate geographic location (city/region level)
  • Browser type and version, operating system, and device type
  • Pages visited, features accessed, and actions taken
  • Timestamps and session duration
  • Referral URLs

Usage data is collected primarily for security monitoring, system performance, and aggregate product improvement purposes.

2.4 Client-Submitted Data

Clients may configure and use SelinAI-built applications to process personal data belonging to their own customers, employees, or other third parties ("Client-Submitted Data"). With respect to Client-Submitted Data:

  • SelinAI acts as a data processor, not a data controller.
  • We process Client-Submitted Data solely on the documented instructions of the Client, as set forth in the applicable service agreement and DPA.
  • We do not use Client-Submitted Data to train general-purpose AI or machine learning models for SelinAI's own commercial benefit unless the Client expressly authorizes that use in a signed written agreement.
  • Clients are responsible for ensuring they have lawful bases to submit such data to SelinAI.
  • This Policy does not govern the Client's collection or use of their end-user data; Clients' own privacy policies apply to their data subjects.

If you are a data subject whose information has been submitted into a SelinAI-built application by a Client, please direct your privacy inquiries to that Client directly.

2.5 Payment Data

When billing is applicable, payment transactions are processed by third-party payment processors (such as Stripe or similar services). SelinAI does not receive, store, or process full payment card numbers, CVV codes, or bank account credentials. We may retain billing records such as invoice amounts, transaction IDs, and payment confirmations as required for our financial and legal obligations.


3. How We Use Information

SelinAI uses the personal information we collect as a controller for the following purposes:

Purpose Description
Service Delivery To perform our contractual obligations, execute projects, and deliver applications and related services
Billing & Account Management To issue invoices, process payments (via third-party processors), and manage Client accounts
Business Communications To respond to inquiries, send project updates, and communicate about our services
Security & Fraud Prevention To monitor for unauthorized access, detect security incidents, and protect the integrity of our systems
Legal Compliance To comply with applicable laws, respond to legal process, and fulfill recordkeeping obligations
Product Improvement To analyze aggregated and anonymized usage trends to improve our offerings — we do not use identifiable personal data for this purpose
Business Development To evaluate and pursue prospective engagements with potential Clients and partners

We do not use personal information to serve behavioral advertising, and we do not sell personal information to third parties.


4. Legal Basis for Processing (GDPR Article 6)

For individuals located in the European Union, the United Kingdom, or other jurisdictions requiring a lawful basis for processing, SelinAI relies on the following bases:

4.1 Contractual Necessity (Article 6(1)(b))

Processing that is necessary to perform a contract to which you or your organization is a party, or to take steps at your request prior to entering into a contract. This includes processing Contact & Account Data and Project & Contract Data to deliver our services.

4.2 Legitimate Interests (Article 6(1)(f))

Processing that is necessary for our legitimate business interests, where those interests are not overridden by your rights and interests. Our legitimate interests include:

  • Maintaining business records and managing client relationships
  • Ensuring the security and operational integrity of our systems
  • Improving our products and services (using aggregated, anonymized data)
  • Conducting business development activities with prospective clients

Where we rely on legitimate interests, we have conducted a balancing assessment to confirm that our interests do not override the rights of the individuals concerned.

4.3 Legal Obligation (Article 6(1)(c))

Processing that is necessary to comply with applicable laws, including tax laws, financial recordkeeping requirements, and responses to lawful governmental or judicial requests.

4.4 Consent (Article 6(1)(a))

Where no other lawful basis applies and where required by applicable law, we will seek your explicit consent before processing. You may withdraw consent at any time without affecting the lawfulness of prior processing. To withdraw consent, contact us at [email protected].


5. Data Sharing

SelinAI does not sell, rent, or trade personal information. We may share information with the following categories of recipients:

5.1 Service Providers

We engage trusted third-party vendors to support our operations, including:

  • Cloud hosting and infrastructure providers (e.g., AWS, Google Cloud, Microsoft Azure)
  • Payment processors (e.g., Stripe or equivalent)
  • Analytics and monitoring tools (e.g., application performance monitoring services)
  • Communication and collaboration platforms (e.g., email, project management tools)
  • Professional advisors (attorneys, accountants, and insurers bound by confidentiality obligations)

Where required by law (including GDPR Article 28), we enter into Data Processing Agreements with service providers who process personal data on our behalf.

5.2 Business Transfers

If SelinAI undergoes a merger, acquisition, asset sale, or restructuring, personal information we hold as a controller may be transferred to a successor entity. We will provide notice of any such transfer in accordance with Section 14 of this Policy.

5.3 Legal Disclosure

We may disclose personal information when we believe in good faith that disclosure is required to:

  • Comply with a legal obligation, court order, or valid governmental request
  • Enforce our agreements or protect our legal rights
  • Protect the safety of SelinAI, our Clients, or the public

We will, where legally permitted, notify affected individuals or Clients of such disclosures.

5.4 Client Direction (Processor Role)

When acting as a data processor, we share Client-Submitted Data only as expressly instructed by the Client or as required by law.


6. Data Retention

We retain personal information for as long as necessary to fulfill the purposes described in this Policy, subject to the following guidelines:

Data Category Retention Period
Contact & Account Data Duration of the business relationship plus 7 years following termination or last engagement, consistent with Iowa business recordkeeping requirements and applicable statutes of limitations
Project & Contract Data Duration of the engagement plus 7 years following project completion or contract termination
Usage Logs 90 days from collection, unless a shorter period is required by a specific security or legal hold
Payment Records As required by applicable tax and financial laws, generally 7 years
Client-Submitted Data As specified in the applicable Data Processing Agreement with the Client; absent a DPA, upon written request from the Client or within 90 days following contract termination

After the applicable retention period expires, we will securely delete or anonymize the information. In cases where deletion is not immediately practicable (e.g., backup systems), we will isolate the data from further active processing until deletion is possible.


7. Data Security

SelinAI implements technical and organizational security measures designed to protect personal information against unauthorized access, disclosure, alteration, loss, or destruction. These measures include:

  • Encryption in transit: All data transmitted between clients and our systems uses TLS (Transport Layer Security) encryption.
  • Encryption at rest: Stored personal data is encrypted using industry-standard protocols.
  • Access controls: Access to personal data is restricted to authorized personnel on a need-to-know basis, using role-based access controls and multi-factor authentication where appropriate.
  • Vendor management: We assess the security practices of third-party service providers before engagement and require appropriate contractual safeguards.
  • Monitoring & testing: We maintain logging and monitoring for anomalous activity and conduct periodic security assessments.

No security system is impenetrable. In the event of a data breach that may affect your rights or interests, SelinAI will:

  • Notify affected Clients and, where legally required, relevant supervisory authorities within the timeframes required by applicable law (including within 72 hours of becoming aware for GDPR-reportable incidents);
  • Cooperate with Clients to enable their own regulatory notification obligations;
  • Take prompt remediation steps to contain and address the incident.

8. CCPA Rights (California Residents and Businesses)

This section applies to California residents and, where applicable, California-based business contacts whose personal information SelinAI processes as a controller under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA).

Categories of Personal Information Collected. In the past 12 months, SelinAI has collected the following CCPA categories of personal information from or about California individuals in a business context: Identifiers (name, email, IP address); commercial information (transaction and contract records); internet or network activity information (usage logs); and professional or employment-related information (job title, company).

Your CCPA Rights include:

  • Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purposes for collection, and the categories of third parties with whom we share information.
  • Right to Delete: You may request deletion of personal information we hold about you, subject to certain exceptions (e.g., data needed to complete a transaction, comply with a legal obligation, or maintain a contractual relationship).
  • Right to Correct: You may request correction of inaccurate personal information we hold about you.
  • Right to Opt-Out of Sale or Sharing: SelinAI does not sell or share personal information as those terms are defined under the CCPA/CPRA. No opt-out mechanism is required, but you may contact us to confirm our practices.
  • Right to Limit Use of Sensitive Personal Information: SelinAI does not use sensitive personal information beyond the purposes permitted by the CPRA without explicit consent.
  • Right to Non-Discrimination: SelinAI will not discriminate against you for exercising your CCPA rights. We will not deny services, charge different prices, or provide a different quality of service based on the exercise of these rights.

How to Submit a CCPA Request. Submit verifiable consumer requests to [email protected]. We will acknowledge your request within 10 business days and respond within 45 calendar days. If additional time is needed, we will notify you and may extend the response period by an additional 45 days.

We may need to verify your identity before fulfilling requests. For requests submitted on behalf of a business, we may require confirmation of your authority to act on the business's behalf.


9. GDPR Rights (EU and UK Data Subjects)

This section applies to individuals located in the European Union, the European Economic Area, or the United Kingdom whose personal information SelinAI processes as a data controller.

You have the following rights under the GDPR (EU Regulation 2016/679) and, where applicable, the UK GDPR:

Right Description
Right of Access (Art. 15) Request a copy of the personal data we hold about you and information about how we process it
Right to Rectification (Art. 16) Request correction of inaccurate or incomplete personal data
Right to Erasure (Art. 17) Request deletion of your personal data where it is no longer necessary for the purpose collected, where you have withdrawn consent, or where processing is unlawful — subject to applicable exemptions
Right to Restriction of Processing (Art. 18) Request that we limit processing of your data in certain circumstances (e.g., while accuracy is contested)
Right to Data Portability (Art. 20) Receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller — where processing is based on consent or contract and carried out by automated means
Right to Object (Art. 21) Object to processing based on legitimate interests or for direct marketing purposes at any time
Right Not to Be Subject to Automated Decision-Making (Art. 22) Not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects — SelinAI does not currently engage in such automated decision-making

How to Exercise Your Rights. Submit requests to [email protected]. We will respond within 30 days. In complex cases, we may extend this period by up to 60 additional days and will notify you accordingly.

Right to Lodge a Complaint. If you are located in the EU/EEA and believe we have not handled your personal data in accordance with the GDPR, you have the right to lodge a complaint with the supervisory authority in your EU member state of residence or place of work. If you are located in the United Kingdom, you may contact the Information Commissioner's Office (ICO) at https://ico.org.uk.

SelinAI's EU/EEA and UK data subjects may also contact us directly first, and we will endeavor to resolve any concerns promptly.


10. Data Processing Agreements

SelinAI recognizes that B2B Clients subject to GDPR, CCPA, or other privacy regulations may require a formal Data Processing Agreement (DPA) to govern SelinAI's processing of personal data on their behalf.

  • Clients may request a standard DPA by contacting [email protected].
  • Our standard DPA addresses the requirements of GDPR Article 28, including processing instructions, confidentiality obligations, security measures, sub-processor controls, data subject rights assistance, breach notification, and data deletion or return at contract end.
  • For EU data transfers, our DPA incorporates the Standard Contractual Clauses issued by the European Commission (June 2021) under the appropriate module.
  • We will negotiate DPA terms in good faith to accommodate legitimate Client compliance requirements.

Where a signed DPA is in place, its terms will govern and supersede this Policy with respect to our processor activities for that Client.


11. International Data Transfers

SelinAI is headquartered in Windsor Heights, Iowa, United States. Personal information we collect may be stored and processed in the United States or other countries where our service providers operate.

If you are located in the European Union, EEA, or United Kingdom, please be aware that the United States does not have an adequacy decision covering all US data processing. When we transfer personal data from the EU/EEA or UK to the United States or other third countries that lack an adequacy determination, we rely on the following safeguards:

  • Standard Contractual Clauses (SCCs): We use the European Commission's Standard Contractual Clauses (2021 versions, Module 2: Controller-to-Processor) for transfers to our data processors, and we incorporate appropriate UK SCCs or the UK International Data Transfer Addendum for UK data.
  • EU-U.S. Data Privacy Framework: Where applicable, we may rely on adequacy decisions or framework certifications as they become available and appropriate.
  • Supplementary measures: Where required by a transfer impact assessment, we implement supplementary technical and organizational measures to protect data.

To obtain a copy of the specific safeguards applicable to your personal data transfer, contact [email protected].


12. Cookies & Tracking

SelinAI's web properties use a minimal, functionality-first approach to cookies and tracking technologies.

  • Functional/essential cookies: We use cookies that are strictly necessary for the operation of our web properties (e.g., session management, security tokens). These cookies cannot be disabled without impairing site functionality.
  • No third-party advertising trackers: SelinAI does not use third-party advertising cookies, pixel trackers, or cross-site tracking technologies on its web properties.
  • Analytics: If we use web analytics tools (e.g., to understand aggregate page traffic), we configure them to minimize personal data collection and do not link analytics data to identifiable individuals.

Where consent is required by applicable law (such as the EU ePrivacy Directive), we will request your consent before placing non-essential cookies. You may withdraw consent or manage cookie preferences at any time through your browser settings.


13. Children's Privacy

SelinAI's services are designed for and directed exclusively to businesses and their authorized representatives. We do not knowingly market to, contract with, or collect personal information from individuals under the age of 18.

If we become aware that we have inadvertently collected personal information from a person under 18, we will take prompt steps to delete that information. If you believe we have collected such information, please contact us at [email protected].


14. Changes to This Policy

SelinAI may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable law.

  • Material changes (e.g., new categories of data collected, new purposes for use, changes to data sharing practices) will be communicated by email to Client contacts of record and/or by posting a prominent notice on our website at least 30 days before the change takes effect.
  • Non-material changes (e.g., clarifications, typographical corrections, or legal updates that do not affect how we process your data) will be effective upon posting, with the "Last Updated" date revised accordingly.

We encourage you to review this Policy periodically. Your continued engagement with SelinAI after the effective date of a revised Policy constitutes acceptance of the updated terms, to the extent permitted by applicable law.


15. Contact & Data Controller Information

SelinAI LLC is the data controller for personal information processed in connection with our own business operations.

Data Controller:

SelinAI LLC Windsor Heights, Iowa, United States Website: https://selin-ai-tech.com

Privacy Inquiries: Email: [email protected]

For requests regarding your personal data rights (Sections 8 and 9), Data Processing Agreement inquiries (Section 10), or any other privacy-related questions, please contact us at the email address above. We will acknowledge your inquiry promptly and respond within the timeframe required by applicable law.


This Privacy Policy was prepared for SelinAI LLC. It is provided for informational purposes and does not constitute legal advice. SelinAI recommends consulting qualified legal counsel to ensure compliance with all applicable privacy laws.