Privacy Notice

This notice explains how SAIHM handles personal data about you in two situations: when SAIHM contacts you as a business prospect, and when you subscribe to the SAIHM blog. It is written to satisfy the transparency duties in GDPR Articles 13 and 14, UK GDPR, PECR, CAN-SPAM, and CASL.

Effective 2026-07-19. This notice covers contact data (outreach and newsletter). It does not cover two other things, each documented elsewhere: the encrypted memory data that users store in the SAIHM protocol, covered on the Trust Center, where the operator never sees plaintext; and billing data, which is handled by our payment processors — Stripe worldwide, and Paystack for card and M-PESA in Africa — both named in the sub-processor list.

On this page

Who we are

For the outreach and newsletter activities described here, the data controller is SAIHM, operating the website at saihm.coti.global.

Privacy contact
ops@saihm.coti.global (subject line privacy)
Postal address
5753 Highway 85 N, #1983, Crestview, FL 32536, USA

A statutory Data Protection Officer is not required for this processing (it is not large-scale special-category processing, systematic large-scale monitoring, or public-authority processing under GDPR Art. 37(1)). The privacy contact above handles all requests.

The short version

  • If SAIHM emails you about your work, we use business contact details (your name, role, work email, employer) obtained from public professional sources — never special-category data, never health or patient data.
  • Our legal basis for that outreach is legitimate interest in offering a relevant business product to the right person — and you can tell us to stop at any time, immediately, with no reason needed.
  • If you subscribe to the blog, that is based on your consent, which you can withdraw with one click in any email.
  • We do not sell your data, we do not build advertising profiles, and we set no tracking cookies on this notice.

How we get your details, and why

1. Business outreach (if we contacted you).

  • Where the data comes from (GDPR Art. 14): we collect business-contact details from publicly available professional sources — your employer’s own website, public business directories, and professional-network profiles — where a business email address is published in connection with your professional role.
  • Why: to introduce a business product (secure, erasable memory infrastructure for AI systems) to organizations for whom it is relevant, and to the person whose role would evaluate it.
  • Legal basis: legitimate interest (GDPR Art. 6(1)(f) / UK GDPR). Our legitimate interest is direct business-to-business marketing of a relevant product (GDPR Recital 47). We have carried out a balancing assessment: we contact you only in a professional capacity, use the minimum business data, do not use special-category data, and give you an immediate, unconditional way to opt out — so this processing does not override your interests or rights.

2. Blog newsletter (if you subscribed).

  • Where the data comes from: directly from you, when you enter your email and tick the consent box at /subscribe.
  • Legal basis: your consent (GDPR Art. 6(1)(a); PECR; CASL). You may withdraw it at any time; withdrawing does not affect anything done beforehand.

Separately, when you follow a SAIHM outreach link through t.saihm.coti.global, a privacy-minimal, cookieless redirector records truncated, non-identifying measurement data under legitimate interest — described in full on the Trust Center.

What we collect

Business outreach:

Identity & role
Name, job title / business role
Business contact
Work email address, employer / organization
Context
Jurisdiction, and whether your business email was conspicuously published; business-fit signals about your organization (non-personal)
Interaction
Whether we have contacted you, and your opt-out / suppression status

Newsletter: email address, consent timestamp, and the IP address and browser string captured at the moment of consent (kept only to demonstrate valid consent).

We never collect, for either purpose: special-category data (GDPR Art. 9), health or patient data, or any personal data beyond what is described above.

Who we share it with

  • Email delivery: outbound email is dispatched through Amazon Web Services (SES), acting as our data processor, with EU Standard Contractual Clauses in place. Delivery infrastructure is in the United States.
  • No one else: we do not sell, rent, or trade personal data; we do not share it with advertising networks or data brokers; and our internal prospect records are held on a private, non-public system.

How long we keep it

Active conversation
Kept while a business opportunity is open.
No response / not pursued
A record that goes nowhere is anonymised or deleted (default: anonymize 90 days after a conversation is closed; purge an untouched prospect after 12 months).
Opted out
We keep the minimum needed to make sure we do not contact you again (a suppression entry), and nothing more.
Newsletter
Consent records retained for 7 years after you unsubscribe (statutory limitation), then deleted.

Your rights

Wherever the GDPR or UK GDPR applies to you, you have the right to:

  • Object to direct marketing — this is absolute (GDPR Art. 21(2)–(3)). Tell us to stop and we stop, immediately, no reason required. Every outreach email also carries a one-click opt-out.
  • Access the personal data we hold about you, and rectify anything inaccurate.
  • Erase your data (“right to be forgotten”) and restrict our processing of it.
  • Withdraw consent for the newsletter at any time (one-click unsubscribe, or ask us).
  • Data portability, where the processing is based on consent.

How to exercise any of these: email ops@saihm.coti.global with subject privacy (for erasure, use subject erasure and include the email address concerned). We respond within 30 days. There is no charge for a first request.

By jurisdiction

EU & UK
GDPR / UK GDPR as above. For marketing email, PECR’s consent rule is treated as applying to individual subscribers; we contact corporate business addresses on the legitimate-interest basis, with opt-out. Where a member state requires prior consent for business email (for example Germany), we do not send on the legitimate-interest basis.
United States
CAN-SPAM: our emails identify who we are, carry a valid postal address, are not deceptive, and honor opt-out requests within 10 business days.
Canada
CASL: we send a commercial email only where consent exists — including implied consent where you have conspicuously published your business email without a notice refusing such messages, and the message relates to your role. Otherwise we do not send. Opt-out is honored within 10 business days.

Automated decisions

We do not make decisions producing legal or similarly significant effects about you by solely automated means. We may prioritize which organizations to contact using business-fit signals, but a person decides whether and how to reach out, and this has no legal effect on you.

Complaints

If you are in the EU or UK, you have the right to complain to a data-protection supervisory authority — in the UK, the Information Commissioner’s Office (ico.org.uk); in the EU, your national authority. We would appreciate the chance to resolve your concern first — please contact us at ops@saihm.coti.global.

Changes to this notice

If we change how we handle personal data, we update this page and its effective date. Material changes affecting people we have already contacted or who have subscribed will be communicated directly where required.

Effective 2026-07-19.