Privacy Notice

This notice explains how SAIHM handles personal data about you in two situations: when SAIHM contacts you as a business prospect, and when you subscribe to the SAIHM blog. It is written to satisfy the transparency duties in GDPR Articles 13 and 14, UK GDPR, PECR, CAN-SPAM, and CASL.

Effective 2026-09-02. This notice covers contact data (outreach and newsletter). Two related things are documented elsewhere: the encrypted memory data that users store in the SAIHM protocol is covered on the Trust Center, where it stays encrypted end to end and the operator only ever handles ciphertext; and billing data is handled by our payment processors — Stripe worldwide, and Paystack for card and M-PESA in Africa — both named in the sub-processor list.

On this page

Who we are

For the outreach and newsletter activities described here, the data controller is the SAIHM Project, operating the website at saihm.net.

Privacy contact
ops@saihm.coti.global (subject line privacy)
Postal address
5753 Highway 85 N, #1983, Crestview, FL 32536, USA

The privacy contact above is the route for every request on this page, and handles all of them. GDPR Art. 37(1) reserves the statutory Data Protection Officer role for public authorities and for controllers whose core activities involve large-scale systematic monitoring or large-scale special-category processing; SAIHM’s outreach and newsletter sit outside all three categories.

The short version

  • If SAIHM emails you about your work, we use business contact details (your name, role, work email, employer) obtained from public professional sources. That is the entire set — business identity and business contact — and special-category data (GDPR Art. 9), health and patient data included, is excluded from it by design.
  • Our legal basis for that outreach is legitimate interest in offering a relevant business product to the right person — and you can tell us to stop at any time, for any reason or none, and we stop immediately.
  • If you subscribe to the blog, that is based on your consent, which you can withdraw with one click in any email.
  • Your data stays with SAIHM and the processors named in Who we share it with, is used only to contact you about SAIHM, and this page runs cookie-free.

How we get your details, and why

1. Business outreach (if we contacted you).

  • Where the data comes from (GDPR Art. 14): we collect business-contact details from publicly available professional sources — your employer’s own website, public business directories, and professional-network profiles — where a business email address is published in connection with your professional role.
  • Why: to introduce a business product (secure, erasable memory infrastructure for AI systems) to organizations for whom it is relevant, and to the person whose role would evaluate it.
  • Legal basis: legitimate interest (GDPR Art. 6(1)(f) / UK GDPR). Our legitimate interest is direct business-to-business marketing of a relevant product (GDPR Recital 47). We have carried out a balancing assessment: we contact you only in a professional capacity, use the minimum business data, keep special-category data out of it entirely, and give you an immediate, unconditional way to opt out — so on that balance your interests, rights and freedoms remain protected, which is what Art. 6(1)(f) requires.

2. Blog newsletter (if you subscribed).

  • Where the data comes from: directly from you, when you enter your email and tick the consent box at /subscribe.
  • Legal basis: your consent (GDPR Art. 6(1)(a); PECR; CASL). You may withdraw it at any time and we stop on withdrawal; processing carried out before that point remains lawful (GDPR Art. 7(3)).

Separately, when you follow a SAIHM outreach link through t.saihm.coti.global, a privacy-minimal, cookieless redirector records truncated, non-identifying measurement data under legitimate interest — described in full on the Trust Center.

What we collect

Business outreach:

Identity & role
Name, job title / business role
Business contact
Work email address, employer / organization
Context
Jurisdiction, and whether your business email was conspicuously published; business-fit signals about your organization (non-personal)
Interaction
Whether we have contacted you, and your opt-out / suppression status

Newsletter: email address, consent timestamp, and the IP address and browser string captured at the moment of consent (kept only to demonstrate valid consent).

The two lists above are exhaustive. They are the complete set of personal data we hold for each purpose. Special-category data (GDPR Art. 9), including health and patient data, is excluded from that set by design.

Who we share it with

  • Email delivery: outbound email is dispatched through Amazon Web Services (SES), acting as our data processor, with EU Standard Contractual Clauses in place. Delivery infrastructure is in the United States. To obtain a copy of these safeguards, email ops@saihm.coti.global with subject privacy.
  • And that is the whole list: SES is the only third party that receives your contact details. Everything else stays inside SAIHM, on a private internal system. Your personal data is never sold, rented, or traded, and it reaches no advertising network or data broker.

How long we keep it

Active conversation
Kept while a business opportunity is open.
Dormant or closed
A record that goes nowhere is anonymized or deleted — by default, anonymized 90 days after a conversation closes, and an untouched prospect purged after 12 months.
Opted out
A single suppression entry, and nothing else. That entry is the mechanism that makes your opt-out permanent.
Newsletter
Consent records retained for 7 years after you unsubscribe (statutory limitation), then deleted.

Your rights

Wherever the GDPR or UK GDPR applies to you, you have the right to:

  • Object to direct marketing — this is absolute (GDPR Art. 21(2)–(3)). Tell us to stop and we stop, immediately, for any reason or none. Every outreach email also carries a one-click opt-out.
  • Access the personal data we hold about you, and rectify anything inaccurate.
  • Erase your data (“right to be forgotten”) and restrict our processing of it.
  • Withdraw consent for the newsletter at any time (one-click unsubscribe, or ask us).
  • Data portability, where the processing is based on consent.

How to exercise any of these: email ops@saihm.coti.global with subject privacy (for erasure, use subject erasure and include the email address concerned). We respond within one month, as GDPR Art. 12(3) requires, and your first request is free.

By jurisdiction

EU & UK
GDPR / UK GDPR as above. For marketing email, PECR’s consent rule is treated as applying to individual subscribers; we contact corporate business addresses on the legitimate-interest basis, with opt-out. Where a member state requires prior consent for business email (for example Germany), we send only once that consent is in place.
United States
CAN-SPAM: our emails identify who we are, carry a valid postal address, describe their subject accurately in the header and subject line, and honor opt-out requests within 10 business days.
Canada
CASL: consent is the precondition for every send — express, or implied where you have conspicuously published your business email, the publication carries no refusal of such messages, and the message relates to your role. Opt-out is honored within 10 business days.

Automated decisions

Selecting which organizations to approach, and drafting the messages, is assisted by software, using business-fit signals about the organization rather than an assessment of you as an individual. This work is carried out under human oversight: it is operated by people who can review, change, pause, or stop it, and who remain responsible for what is sent.

GDPR Article 22 restricts decisions that produce legal or similarly significant effects on you. What is decided here is narrower than that threshold: whether one introductory email goes to a work address. It rests on business-fit signals about your organization rather than on an assessment of you as an individual, and it leaves every right, entitlement, and access to a service exactly where it was. The single outcome is whether you receive one introduction; your data builds no advertising or behavioral profile.

Your absolute right to object to direct marketing (GDPR Art. 21(2)–(3)) applies however the message was produced, and is honored immediately — see Your rights.

Complaints

If you are in the EU or UK, you have the right to complain to a data-protection supervisory authority — in the UK, the Information Commissioner’s Office (ico.org.uk); in the EU, your national authority. We would appreciate the chance to resolve your concern first — please contact us at ops@saihm.coti.global.

Changes to this notice

If we change how we handle personal data, we update this page and its effective date. Material changes affecting people we have already contacted or who have subscribed will be communicated directly where required.

Effective 2026-09-02.