The fine print, written to be read
Privacy Policy
Effective: 2026-08-11 · Version 1.1 · Questions or requests: sherpa@contextsherpa.com
The short version, honestly: we collect what you give us to do the work you asked for, and nothing sneaky. Your material never trains AI models, is never sold, and is never shown to another user. It lives in the EU at rest, with two named exceptions we list below. Ask and we export everything; ask and we delete it. That's the policy — here it is in full.
1 · Who is responsible
The data controller is Ron Sircar, sole proprietor (India), operating as Sherpa. On incorporation of Oni Private Limited (operating as Sherpa), the company becomes controller — same commitments, notified on this page. Contact: sherpa@contextsherpa.com — a postal address is provided on request.
2 · What we collect, and why
| What | When | Why (and lawful basis) |
|---|---|---|
| Name, email, LinkedIn | you sign up or write to us | to deliver what you asked for and reply (pre-contract steps / contract) |
| Your CV | you choose to upload it | to ground your Briefing or Read in your actual record (consent — skippable, withdrawable) |
| Your professional context: domains, geographies, pursuits, goals | you tell us | to make the work contextual instead of generic (pre-contract steps / contract) |
| Documents you send (tenders, RFPs) | you send them | to prepare the specific work you requested (contract; you warrant they're yours to share) |
| Your reactions and corrections | you reply or react | so the next artifact is sharper than the last (legitimate interest — the product's core promise) |
| Consent records | each agreement you tick | to prove what you agreed to, versioned (legal obligation) |
| Minimal technical data | you visit the site | security, and privacy-preserving cookieless page counts we collect ourselves — which page, which event, and the name of the site you came from. No cookies, no advertising, no cross-site tracking, and nothing that identifies you (legitimate interest) |
We do not collect data about children (18+ service), and we never buy data about you.
3 · What we never do
Never train AI models on your material. Never sell it. Never disclose one user's material to another. Never place your data in cross-user aggregates without your separate, revocable opt-in under our documented anonymisation standard. Never use dark-pattern consent — every optional box starts unticked.
4 · Who touches your data
The published sub-processor register on our Trust page is the complete list: model providers (reachable only under no-training terms with short or zero retention), database and storage, email delivery, and analytics/observability. Substantive outputs are prepared and delivered by our automated systems; the founder reviews the outbound stream as a standing routine, and that access is logged. AI model providers process content transiently to produce your work; they do not retain it beyond their stated short abuse-windows and never train on it.
5 · Where your data lives
EU at rest (Frankfurt), with two named exceptions: our email delivery processor processes mail in the US (45-day retention, under Standard Contractual Clauses), and model inference runs on provider infrastructure under the no-training terms above. Transfers from the EU/UK to India (where the operator is established) rest on the European Commission's Standard Contractual Clauses, and on the UK Addendum for UK transfers. India has no adequacy decision, so we also complete a transfer impact assessment for that route; it is available on request.
6 · How long we keep it
Your content: until you delete it — it's yours, we're holding it for you. Email at the delivery processor: 45 days. Model providers: transient (0–30 days abuse-retention class). Consent and audit records: as long as law requires. Waitlist entries: until launch or your removal request, whichever comes first.
7 · Your rights, without the run-around
Ask sherpa@contextsherpa.com and we will: export everything we hold on you, in a usable format; correct what's wrong; delete what identifies you (only consented, anonymised aggregates that identify no one survive — stated plainly); withdraw any consent, prospectively, with one email; unsubscribe from anything with one click. Honoured within 30 days, usually much faster. GDPR/UK-GDPR users may complain to their supervisory authority; India DPDP users may escalate to the grievance channel above and then the Data Protection Board.
8 · If something goes wrong
If a breach affects your data, we tell you promptly and plainly — what happened, what it touched, what we're doing — and notify authorities within the windows the law sets (72 hours under GDPR where applicable). No burying it in a status page.
9 · Changes
Material changes are emailed before they take effect and versioned here. The version you agreed to is preserved verbatim in our records — we can always show you exactly what you accepted.
v1.0 self-drafted 2026-08-11 against the ratified privacy-notice fact sheet; counsel review commissioned and owed, including appointment of an EU/UK representative. v1.1 (2026-08-31): §4 updated to reflect automated delivery — outputs are prepared and sent by our systems, with the founder reviewing the outbound stream as a standing routine. Changes on counsel's advice will be versioned and dated here.