The fine print, written to be read

Privacy Policy

Effective: 2026-08-11 · Version 1.1 · Questions or requests: sherpa@contextsherpa.com

1 · Who is responsible

The data controller is Ron Sircar, sole proprietor (India), operating as Sherpa. On incorporation of Oni Private Limited (operating as Sherpa), the company becomes controller — same commitments, notified on this page. Contact: sherpa@contextsherpa.com — a postal address is provided on request.

2 · What we collect, and why

WhatWhenWhy (and lawful basis)
Name, email, LinkedInyou sign up or write to usto deliver what you asked for and reply (pre-contract steps / contract)
Your CVyou choose to upload itto ground your Briefing or Read in your actual record (consent — skippable, withdrawable)
Your professional context: domains, geographies, pursuits, goalsyou tell usto make the work contextual instead of generic (pre-contract steps / contract)
Documents you send (tenders, RFPs)you send themto prepare the specific work you requested (contract; you warrant they're yours to share)
Your reactions and correctionsyou reply or reactso the next artifact is sharper than the last (legitimate interest — the product's core promise)
Consent recordseach agreement you tickto prove what you agreed to, versioned (legal obligation)
Minimal technical datayou visit the sitesecurity, and privacy-preserving cookieless page counts we collect ourselves — which page, which event, and the name of the site you came from. No cookies, no advertising, no cross-site tracking, and nothing that identifies you (legitimate interest)

We do not collect data about children (18+ service), and we never buy data about you.

3 · What we never do

Never train AI models on your material. Never sell it. Never disclose one user's material to another. Never place your data in cross-user aggregates without your separate, revocable opt-in under our documented anonymisation standard. Never use dark-pattern consent — every optional box starts unticked.

4 · Who touches your data

The published sub-processor register on our Trust page is the complete list: model providers (reachable only under no-training terms with short or zero retention), database and storage, email delivery, and analytics/observability. Substantive outputs are prepared and delivered by our automated systems; the founder reviews the outbound stream as a standing routine, and that access is logged. AI model providers process content transiently to produce your work; they do not retain it beyond their stated short abuse-windows and never train on it.

5 · Where your data lives

EU at rest (Frankfurt), with two named exceptions: our email delivery processor processes mail in the US (45-day retention, under Standard Contractual Clauses), and model inference runs on provider infrastructure under the no-training terms above. Transfers from the EU/UK to India (where the operator is established) rest on the European Commission's Standard Contractual Clauses, and on the UK Addendum for UK transfers. India has no adequacy decision, so we also complete a transfer impact assessment for that route; it is available on request.

6 · How long we keep it

Your content: until you delete it — it's yours, we're holding it for you. Email at the delivery processor: 45 days. Model providers: transient (0–30 days abuse-retention class). Consent and audit records: as long as law requires. Waitlist entries: until launch or your removal request, whichever comes first.

7 · Your rights, without the run-around

Ask sherpa@contextsherpa.com and we will: export everything we hold on you, in a usable format; correct what's wrong; delete what identifies you (only consented, anonymised aggregates that identify no one survive — stated plainly); withdraw any consent, prospectively, with one email; unsubscribe from anything with one click. Honoured within 30 days, usually much faster. GDPR/UK-GDPR users may complain to their supervisory authority; India DPDP users may escalate to the grievance channel above and then the Data Protection Board.

8 · If something goes wrong

If a breach affects your data, we tell you promptly and plainly — what happened, what it touched, what we're doing — and notify authorities within the windows the law sets (72 hours under GDPR where applicable). No burying it in a status page.

9 · Changes

Material changes are emailed before they take effect and versioned here. The version you agreed to is preserved verbatim in our records — we can always show you exactly what you accepted.

v1.0 self-drafted 2026-08-11 against the ratified privacy-notice fact sheet; counsel review commissioned and owed, including appointment of an EU/UK representative. v1.1 (2026-08-31): §4 updated to reflect automated delivery — outputs are prepared and sent by our systems, with the founder reviewing the outbound stream as a standing routine. Changes on counsel's advice will be versioned and dated here.