Privacy Policy

Last updated: July 15, 2026

Centive AI, Inc. ("Centive," "we," "us") provides an AI-powered customer success platform (the "Service") and operates centive.ai. This policy explains how we handle personal information. It covers visitors to our websites, people who sign up for or use the Service, and, in a distinct way described below, the customers and contacts of our business customers whose information is processed through the Service.

1. Two Roles: Controller and Processor

As a controller, we decide how to handle information about our own users and site visitors: account details, sign-in records, billing, support conversations, and marketing preferences. Most of this policy covers that.

As a processor, we handle personal data inside Customer Data: the CRM records, contact details, product-usage events, and communications that our business customers connect to the Service so that Aria, our AI agent, can evaluate their accounts and communicate with their customers on their behalf. For that data, our customer is the controller, we process it only on their instructions and under our agreement with them, and questions or requests about it should go to the business you have the relationship with. If we receive such a request directly, we will refer it to the relevant customer and assist as required.

2. Information We Collect as a Controller

You provide it

  • Account and profile: name, work email, company name, role, and the setup details you enter (such as team size and the CRM you use).

  • Authentication: sign-in email address; if you use Google or Microsoft sign-in, the identifiers those providers share. Magic sign-in links are single-use and expire.

  • Billing: handled by our payment providers; we do not store full card numbers.

  • Communications: support requests, feedback, and waitlist or marketing sign-ups.

Collected automatically

  • IP address, browser and device information, and log data such as sign-in times and pages viewed;

  • Product telemetry about how the Service is used (features opened, actions approved or rejected), used to operate and improve the Service;

  • Cookies and similar technologies for session management and analytics, controllable through your browser.

3. Customer Data We Process on Our Customers' Behalf

When a business connects its systems to the Service, we process the data needed for the Service to work, which can include: contact names, email addresses, roles, and account records from their CRM; product-usage events they send us; documents they upload (such as product guides and brand-voice materials); the content of communications Aria drafts, sends, and receives on their behalf; and transcripts of chat or avatar conversations between Aria and their customers. We use Customer Data solely to provide the Service to that customer, we do not sell it, and we do not use it to train models for other customers except in aggregated, de-identified form for service operation and improvement where our agreements permit.

4. How We Use Information

  • To provide, secure, and operate the Service, including authentication and fraud prevention;

  • To send transactional messages (sign-in links, service notices, billing) and, with your consent or as permitted by law, product updates you can opt out of at any time;

  • To respond to inquiries and provide support;

  • To understand usage and improve the Service;

  • To comply with law and enforce our terms.

Where the GDPR or similar laws apply to information we control, we rely on: performance of a contract (providing the Service), legitimate interests (security, improvement, business communications), consent (where required, such as some marketing), and legal obligations.

5. How We Share Information

We do not sell or rent personal information. We share it only with:

  • Service providers (subprocessors) that help us run the Service, such as cloud hosting and database infrastructure, email delivery, AI model providers, CRM integration services, conversational avatar services, analytics, and payment processing. They are bound by contract to process data only for us. A current list of subprocessors is available on request at privacy@centive.ai;

  • Authorities or parties where required by law, legal process, or to protect rights and safety;

  • A successor in a merger, acquisition, or asset sale, with notice where required.

6. International Transfers

We are based in the United States and process data there and in the locations of our service providers. Where we transfer personal data from regions with transfer restrictions (such as the EEA or UK), we use appropriate safeguards such as standard contractual clauses.

7. Security

We use administrative, technical, and organizational safeguards appropriate to the data we handle, including encryption in transit, access controls, and audit logging, and we are engaged in independent security compliance programs. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Retention

We keep controller data for as long as your account is active or as needed for the purposes above, then delete or de-identify it in the ordinary course of our systems. Customer Data is retained according to our agreement with the relevant customer and deleted or returned on termination as that agreement provides. Some records may be retained longer where the law requires (for example, billing records).

9. Your Rights

Depending on where you live, you may have rights to access, correct, delete, or export your personal information, to object to or restrict processing, and to withdraw consent. You can also unsubscribe from marketing at any time via the link in any marketing email. To exercise rights over data we control, email privacy@centive.ai; we will verify your request and respond as the law requires. If your information reached us through a business using the Service, contact that business, and we will support their response. You will not be discriminated against for exercising your rights, and where local law provides, you may also lodge a complaint with your supervisory authority.

10. Children

The Service is for business use and is not directed to anyone under 18. We do not knowingly collect information from children; if you believe we have, contact us and we will delete it.

11. Changes to This Policy

We may update this policy from time to time. We will post the updated version here with a new date, and for material changes we will provide additional notice such as email or in-product notice.

12. Contact

Centive AI, Inc.
2261 Market Street STE 86586
San Francisco, CA 94114, United States
Email: privacy@centive.ai