Privacy Policy
Last Updated: March 17, 2026
1. Introduction
Reasoning Services LLC ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services.
This policy complies with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Data Controller Information
The data controller responsible for your personal data is:
- Company Name: Reasoning Services LLC
- Location: United States
- Email: privacy@reasoning.services
3. Information We Collect
3.1 Information You Provide
- Contact Forms: Name, email address, subject, and message content when you submit our contact form
- Account Information: If you create an account, we collect username, email, and password
- Communications: Information you provide when you contact us for support
3.2 Automatically Collected Information
- Technical Data: IP address (hashed for privacy), browser type, device type, operating system
- Usage Data: Pages visited, time spent on pages, click patterns, referring URLs
- Error Information: Technical errors and performance data (see Error Tracking section below)
4. Error Tracking and Monitoring (Sentry)
We use Sentry, a third-party error tracking service provided by Functional Software, Inc., to monitor and improve the performance and reliability of our website.
4.1 What Sentry Collects
Sentry automatically collects the following information when errors occur:
- Error Details: Error messages, stack traces, and technical debugging information
- Device Information: Browser type, version, operating system, device type
- Session Information: Hashed IP addresses, user interactions leading to errors, page URLs
- Performance Data: Page load times, API response times, resource loading performance
4.2 PII Protection Measures
We have implemented enhanced privacy protections for Sentry data:
- IP Address Hashing: Your IP address is immediately hashed and cannot be reversed to identify you
- PII Scrubbing: Passwords, credit cards, API keys, and other sensitive data are automatically removed
- Cookie Filtering: Authentication cookies and session tokens are scrubbed from error reports
- Form Data Filtering: Input values from forms are removed to prevent accidental PII collection
- URL Sanitization: Query parameters containing sensitive data are removed from URLs
4.3 Data Processor Agreement
Sentry acts as a data processor on our behalf under the Sentry Data Processing Agreement (DPA) version 5.1.0, which includes Standard Contractual Clauses (SCCs) approved by the European Commission for international data transfers.
4.4 Data Retention
- Error Events: Retained for 90 days, then automatically deleted
- Performance Data: Retained for 90 days, then automatically deleted
- Session Replays: We do not currently enable session replay functionality
4.5 Data Location
Sentry processes data in the United States. Data transfers from the EU to the US are protected by:
- Standard Contractual Clauses (SCCs) - Module 2 (Controller to Processor)
- EU-US Data Privacy Framework certification
- Technical and organizational security measures as required by GDPR Article 32
4.6 Legal Basis for Processing
We process error tracking data based on our legitimate interest (GDPR Article 6(1)(f)) in maintaining a secure, reliable, and high-performing website. Our legitimate interest assessment demonstrates that:
- Error tracking is necessary for website security and functionality
- Enhanced PII protection measures minimize privacy impact
- Benefits to users (reliable service) outweigh minimal privacy intrusion
- Users reasonably expect websites to monitor and fix technical issues
5. How We Use Your Information
- Service Delivery: To provide and maintain our services
- Communication: To respond to your inquiries and requests
- Error Resolution: To identify, diagnose, and fix technical issues
- Security: To detect and prevent fraud, abuse, and security threats
- Performance: To monitor and improve website performance and user experience
- Legal Compliance: To comply with applicable laws and regulations
6. Data Sharing and Disclosure
6.1 Third-Party Service Providers
We share data with the following service providers who process data on our behalf:
- Sentry (Functional Software, Inc.): Error tracking and performance monitoring
- Upstash: Distributed rate limiting (only processes hashed IP addresses)
- Email Service Provider: Amazon SES for transactional email delivery
All service providers are contractually bound to protect your data and process it only for the purposes we specify.
6.2 Legal Requirements
We may disclose your information if required by law or in response to valid requests by public authorities (e.g., court orders, subpoenas).
6.3 Business Transfers
If we are involved in a merger, acquisition, or asset sale, your personal data may be transferred. We will provide notice before your data is transferred and becomes subject to a different privacy policy.
7. Your Rights Under GDPR
If you are located in the European Economic Area (EEA), you have the following data protection rights:
- Right to Access: Request a copy of your personal data we hold
- Right to Rectification: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data ("right to be forgotten")
- Right to Restriction: Request limitation of processing of your data
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent where processing is based on consent
- Right to Lodge a Complaint: File a complaint with your local data protection authority
7.1 Exercising Your Rights
To exercise any of these rights, please:
- Email us at: privacy@reasoning.services
- For Sentry data: Submit a request at https://sentry.io/privacy/
We will respond to your request within 30 days as required by GDPR Article 12.
8. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption: Data in transit is protected using TLS/SSL encryption
- Access Controls: Limited access to personal data on a need-to-know basis
- Rate Limiting: Protection against brute-force attacks and abuse
- XSS Protection: Input sanitization to prevent cross-site scripting attacks
- PII Filtering: Automated removal of sensitive data from error reports
- Secure Authentication: Constant-time comparison for API key validation
- Regular Security Audits: Ongoing monitoring and security assessments
9. Data Retention
- Contact Form Submissions: Retained until the inquiry is resolved, then deleted within 30 days
- Error Tracking Data: 90 days, then automatically deleted by Sentry
- Account Data: Retained while your account is active, deleted within 30 days after account closure
- Rate Limiting Data: Hashed IP addresses retained for 24 hours for security purposes
10. Cookies and Tracking Technologies
We use cookies and similar tracking technologies. For detailed information, please see our Cookie Policy.
11. Children's Privacy
Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal data, please contact us and we will delete such information.
12. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States. We ensure appropriate safeguards are in place:
- Standard Contractual Clauses approved by the European Commission
- EU-US Data Privacy Framework certification (for US-based processors)
- Additional security measures as required by GDPR Chapter V
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last Updated" date at the top
- Sending you an email notification (if you have provided your email address)
You are advised to review this Privacy Policy periodically for any changes.
14. Contact Information
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
- Email: privacy@reasoning.services
- Support: support@reasoning.services
14.1 Supervisory Authority
If you are located in the EEA, you have the right to lodge a complaint with your local data protection supervisory authority. For a list of supervisory authorities, visit: https://edpb.europa.eu/about-edpb/board/members_en