Privacy Policy
Valid from 28.9.2026.
The English version is a convenience translation; the Serbian text prevails.
This platform works with the customer's business mail archive. So this page states exactly what is processed, where the data lives, who reaches it and how it is deleted — no boilerplate.
Who is responsible for the data
The platform is built and maintained by Leniventus LLC. The customer (the agency or company that connected its mailbox) is responsible for the data entered into the instance — they decide whose messages enter the system and who gets written to. Leniventus processes that data on the customer's instructions, to run the platform.
What data is processed
- Email messages from the mailbox the customer connected: sender, recipients, date, subject, message body and attachment metadata (name, type, size).
- Derived data: contacts and companies recognised from addresses, conversations, classification (whether anyone replied) and commitments extracted from message text, with a verbatim quote from the source message.
- Platform account data: username, password in encrypted form (scrypt), time of last sign-in and last activity.
- Operational records: actions of the agent that imports mail, processing errors, language model usage (token counts and estimated cost).
The system collects no visit data, uses no analytics tools or ad networks, and does not profile visitors. See Cookies.
Access requests (the form on this site)
Whoever fills in the “Request access” form leaves their name, their agency's name, a work email and, optionally, a website address and a short note on what they want to automate. We also record the page language, the site the form was sent from, the version of this policy they agreed to and when. Leniventus LLC is responsible for this data.
The data is used only to answer the request and judge whether we can help. It is not used for ads, not sold and not added to any mailing list. The system sends no automatic email: a person at Leniventus replies from their own inbox.
The request is kept in the shared part of the platform, outside any customer's space, and only authorised Leniventus operators see it. It is kept for 12 months from the last contact and then deleted; if the request turns into a contract, the data follows the contract. You can ask for earlier deletion at the address in the footer.
Abuse protection works without outside services and without extra cookies: the form has a hidden field and a timing check, and the number of requests per hour is limited.
Measurement in campaign messages
When the platform sends campaign messages on the user's behalf, measurement elements may be embedded: a pixel that records opens and redirected links that record clicks (time, message address, browser technical data). The user can turn this measurement off in settings. Every message carries a visible unsubscribe link and the standard List-Unsubscribe header — unsubscribing is honoured immediately and permanently, and the address is never contacted again.
The previous paragraph concerns recipients of campaign messages. For visitors of this site the promise stands: no analytics, no tracking, only the sign-in cookie.
Where the data lives
Every customer gets their own instance — a separate space in the database and separate settings. Data is stored on the server named in the customer's contract (in the pilot: a server in Serbia, controlled by Leniventus). One customer's data is never visible to another.
Language model processing (AI)
To extract commitments and prepare drafts, the system sends parts of message text to an external language model provider. That is a material fact, so it is stated here explicitly:
- The provider is chosen per instance, in settings (MiniMax in the pilot; others are supported, including local models that send nothing outside).
- The message text needed for processing is sent, without attachments. The result (commitment + quote) is stored in the customer's instance.
- The customer may change the provider or switch this processing off — the platform then runs only its deterministic parts (import, threading, classification), sending no text outside.
Who has access
- Account users the customer created on their own instance.
- The assistant (software agent) that feeds in messages — it uses a separate key and can only send messages and start processing.
- Leniventus, only as far as maintenance and fault fixing require, under a duty of confidentiality.
How long it is kept and how it is deleted
Data is kept for the term of the contract. The customer may at any time ask for:
- an export of their data in machine-readable form,
- deletion of a single contact or message, or
- shutting the instance down — the database and settings are deleted, and backups expire within 30 days.
Requests go to the address in the footer and are carried out without delay, and within 30 days at the latest.
Rights of people whose data is in the archive
People who appear in the correspondence (contacts) may ask to see, correct or delete their data. Since the archive belongs to the customer, such a request goes to them; Leniventus provides the technical support to carry it out. If someone asked not to be written to again, the system permanently excludes them from every campaign.
Security
Access to the platform goes through password sign-in; traffic is protected by HTTPS; agent access uses separate scoped keys, so a key for one purpose does not open another. Passwords are stored only in encrypted form.
Changes
When processing changes (a different language model provider, a new channel), this text and the valid-from date at the top change with it.
Questions about data: slovic@leniventus.com (Leniventus LLC). Other documents: Privacy · Terms of use · Cookies.