1. Scope
This Privacy Notice applies when you visit the Substrate marketing site, communicate with us, submit or discuss a closed-beta application, participate in a managed founder or organizational beta, or otherwise interact with a service that links to this notice (collectively, the “Services”).
“Substrate,” “we,” “us,” and “our” refer to Sightline Technologies Inc.. This notice does not cover third-party products, websites, or services that have their own privacy notices. A beta agreement, order form, data processing addendum, or other written agreement may supplement this notice. If those terms conflict, the applicable signed agreement controls for that engagement.
2. Our role
For marketing-site visits, direct communications, beta applications, and our administration of a beta relationship, we generally decide why and how the relevant personal data is handled.
When an organization authorizes Substrate to process organizational source data on its behalf, the organization generally determines the relevant purposes and scope, and we process that data to provide the agreed service. The organization is responsible for its instructions, permissions, notices, and lawful basis for making that data available. Precise legal labels vary by jurisdiction and are addressed in the applicable customer agreement.
In a managed founder beta, the participant and our team define the approved sources and operating boundary. The agreement for that beta should identify the parties’ respective responsibilities for connected data and any other individuals represented in it.
3. Data we collect
Depending on how you interact with the Services, we may handle:
- Contact and professional data, such as name, work email, employer, role, and information included in a message or meeting request.
- Beta application and relationship data, such as your use case, company context, source availability, evaluation needs, onboarding notes, support history, and decisions about beta participation.
- Account and access data, if account functionality is enabled, such as login identifiers, authentication events, permissions, and workspace or engagement associations.
- Website and device data, such as pages viewed, page-entry and page-exit events, approximate timestamps, browser or device information, referring information, and network metadata ordinarily transmitted in a web request.
- Communications data, including emails, meeting notes, feedback, requests, and records needed to manage a founder-led beta relationship.
- Authorized source and application data, described below, when a beta participant deliberately connects or provides it.
Please do not send credentials, private keys, authentication tokens, or sensitive datasets through ordinary email or a beta application. We will identify an approved transfer method if data is needed for an evaluation.
4. Data in the adaptive application
Substrate is designed to transform authorized signals into qualified, source-aware context. Depending on the beta configuration, application data may include information about people, organizations, roles, communications, meetings, commitments, preferences, projects, products, accounts, support matters, and changes over time.
The adaptive application may create and maintain several kinds of records:
- Source records and references used to establish where information came from, subject to the agreed ingestion and storage design.
- Canonical entity records that associate authorized information with a person, organization, project, product, or other durable entity.
- Qualified memory that can distinguish observed facts, explicit directions, hypotheses, uncertainty, conflict, current context, and superseded or historical context.
- Derived context and outputs, such as summaries, retrieved context, suggested preparation, or a managed founder briefing.
- Corrections, review records, and provenance used to inspect, challenge, update, or trace application context.
- Operational records such as processing status, errors, configuration, access events, and quality-review notes.
Derived context is probabilistic and may be incomplete or wrong. It should not be treated as psychological fact, a complete profile, or independent authority to make decisions about a person. Substrate does not turn memory into permission to act. Beta participants remain responsible for reviewing outputs and using them lawfully and appropriately.
5. Sources of data
We may receive data:
- directly from you when you browse, apply, email us, schedule a meeting, provide feedback, or participate in a beta;
- from your organization and its authorized administrators or users;
- from third-party services or data sources deliberately connected to an approved beta, which may include communications, calendar, CRM, support, documents, work systems, or product-usage sources where supported;
- from service providers that help us operate the website and beta; and
- from the Services themselves through events, derived context, corrections, and operational records.
Source availability varies by deployment. A reference to a potential source category does not mean every connector is generally available or that we collect it from every participant.
6. How we use data
We use personal data as reasonably necessary to:
- operate, secure, troubleshoot, and improve the website and Services;
- review beta applications and manage prospective and current relationships;
- configure and deliver the authorized beta, including ingestion, entity resolution, memory qualification, bounded retrieval, briefings, and other agreed outputs;
- maintain provenance, enable review and correction, and evaluate memory quality;
- provide support and send operational or relationship communications;
- understand website usage and the effectiveness of our content;
- protect users, organizations, the Services, and our rights; prevent misuse; and comply with law;
- enforce agreements and establish, exercise, or defend legal claims; and
- perform another purpose disclosed when data is collected or authorized by the relevant organization or individual.
We do not use organizational source data to expand a different customer’s memory. Any use of beta data to improve generalized systems, models, or evaluation methods must follow the applicable agreement and approved data boundary; this point must be stated expressly in beta contracting.
7. Legal bases
Where applicable law requires a legal basis, we rely on the basis appropriate to the activity: performance of a contract or steps requested before entering one; our legitimate interests in operating, securing, evaluating, and improving the Services and managing business relationships; consent where requested; and compliance with legal obligations or protection of legal rights.
If we rely on legitimate interests, we consider the purpose, necessity, and potential effect on individuals. If we rely on consent, it may be withdrawn for future processing, although withdrawal does not affect prior lawful processing.
9. Marketing-site analytics
The current site code can initialize PostHog only when a public PostHog key and host are configured. When enabled, it records page views and page-leave events. The current configuration disables session recording and automatic interaction capture, uses memory-only persistence in the browser, and creates person profiles only for identified users. The marketing site does not currently identify ordinary visitors through application code.
Memory-only persistence means the current browser configuration does not ask PostHog to retain its analytics identifier in a cookie or local storage across sessions. PostHog and network infrastructure may still process technical data ordinarily included in requests. Analytics requests are routed through a first-party path on this domain rather than sent directly to the provider.
10. Retention
We retain data only for as long as reasonably necessary for the purposes in this notice, the applicable beta or customer agreement, legal obligations, dispute resolution, security, and enforcement. Retention depends on the data category, source configuration, relationship status, legal requirements, and whether the data is held on behalf of an organization.
Closed-beta application records are retained for up to 24 months after an application is decided, then deleted or irreversibly anonymized. Authorized memory content is retained for the life of the account and deleted within 30 days of a verified deletion request or account termination, except where a longer period is required by law. Operational and security logs are retained for up to 12 months. Aggregated, de-identified analytics that cannot be linked to an individual may be retained indefinitely.
Deletion from active systems may not immediately remove data from security, continuity, or disaster-recovery backups. We isolate or allow backup copies to expire according to applicable procedures and agreements, unless preservation is legally required.
11. Security
We use administrative, technical, and organizational measures intended to protect data in light of its nature and the current beta boundary. No service or transmission method can be guaranteed completely secure. Product design goals such as source-aware memory, bounded retrieval, and scope separation are not certifications or guarantees of security, privacy, or compliance.
If you believe you have found a vulnerability, do not include personal data or exploit a system beyond what is necessary to demonstrate the issue. Report it to security@trysubstrate.co. We will acknowledge a good-faith report and will not pursue action against research that follows this notice.
12. Your choices and privacy rights
Depending on your location and applicable law, you may have rights to request access, correction, deletion, restriction, portability, or objection; to withdraw consent; or to appeal a decision. You may also have a right to complain to a relevant privacy regulator. These rights can be limited or subject to verification and exceptions.
If data was provided by or is controlled by your organization, please submit your request to that organization first. We will assist it as required by the applicable agreement and law. For data we control directly, contact us using Section 16. We may request information needed to verify identity, authority, and the data involved.
You may decline optional marketing messages using the method provided in the message. We may still send service, security, legal, or relationship messages that are not promotional.
13. International data transfers
We and our providers may process data in countries other than the country in which it was collected. Those countries may have different data-protection laws. Where required, we use an applicable transfer mechanism and supplementary measures appropriate to the transfer, including the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum where they apply.
14. Children
The Services are designed for business and professional use, not for children. You must be at least 18 years of age to use the Services. We do not knowingly collect personal data from children or invite them to apply for or participate in the closed beta. If you believe a child has provided data to us, contact us and we will delete it.
15. Changes to this notice
We may update this notice as the website, beta, providers, or legal requirements change. We will post the revised notice and update the “Last updated” date. If required, we will provide additional notice or request consent before a material change takes effect.
16. Contact us
Questions or requests concerning this notice may be directed to privacy@trysubstrate.co.
Sightline Technologies Inc.
Security reports: security@trysubstrate.co
Legal notices: legal@trysubstrate.co