Skip to content
SAILIENT GROUP
Join the team
Sailient Group
Nexus Sentinel Atlas Features
Defense & Security Civil & Government Infrastructure Enterprise & Automation
Overview Publications Initiatives White Papers
Company Team Careers
Overview Blog Product Previews Press Updates
Contact
Privacy Terms Legal
← Back to Home
Legal

Privacy Policy

Draft pending legal review. This policy has been prepared to reflect the GDPR, the Austrian Data Protection Act (DSG) and the Austrian Telecommunications Act 2021 (TKG 2021) as they apply to this marketing website. Fields marked [TO BE CONFIRMED] depend on facts not yet finalized (e.g. formal incorporation); fields marked [LEGAL REVIEW REQUIRED] flag assessments that should be verified by a qualified Austrian data protection lawyer before this policy is treated as final. This page is the basis for that review, not a substitute for it.

1. Scope

This privacy policy explains how Sailient Group collects and uses personal data through this website (sailientgroup.com), including data you provide when you contact us or apply for a role with us. It does not cover our products (Nexus, Sentinel, Atlas) — see Section 8. This website is not directed at children and we do not knowingly collect data relating to children.

2. Data Controller

The data controller responsible for this website is Sailient Group. Sailient Group is currently in the process of formal incorporation; the legally responsible entity, registered address, company register number and VAT ID will be published here once incorporation is complete. Until then:

Entity name[TO BE CONFIRMED — pending incorporation]
Legal form[TO BE CONFIRMED]
Registered seatSalzburg, Austria [TO BE CONFIRMED]
Company register no.[TO BE CONFIRMED]
VAT ID[TO BE CONFIRMED]
Privacy contactinfo@sailientgroup.com
Data Protection OfficerNot currently appointed. [LEGAL REVIEW REQUIRED: whether a DPO is mandatory under Art. 37 GDPR once our processing scope, especially AI-related processing, is finalized.]

See also our Legal Notice for provider identification under § 5 ECG and § 25 MedienG.

3. Categories of Personal Data We Process

We only process the categories below in relation to this marketing website — not to any product account, since this site does not offer logins or purchases.

CategoryExamples
Identity DataFirst name, last name, job title (as provided in a form)
Contact DataEmail address, phone number (if provided), company name
Applicant DataCV/résumé, cover letter, role applied for, and any other information you choose to submit through our careers application form
Technical DataIP address, browser type and version, device type, referring page, timestamps — collected via server and CDN logs. Additionally, the IP address from which a form is submitted is stored together with that submission, for abuse prevention (see Section 6).
Financial / Transaction DataNot collected. This website does not process payments or e-commerce transactions.

4. How We Collect Personal Data

Directly from you: when you submit the contact form, apply through the careers page, or email us directly.

Automatically: our hosting and content-delivery provider (Cloudflare) generates standard technical logs (IP address, request metadata) as part of operating and securing the website. Where cookies or comparable technologies are used, see Section 7 and our Cookie Policy.

5. Legal Bases for Processing

Under Art. 6(1) GDPR, we rely on one or more of the following legal bases, depending on the purpose:

Art. 6(1)(a)Consent — e.g. optional cookies you actively accept via our consent banner
Art. 6(1)(b)Contract / pre-contractual measures — e.g. responding to a business inquiry, processing a job application
Art. 6(1)(c)Legal obligation — e.g. retention required by Austrian commercial or tax law, where applicable
Art. 6(1)(f)Legitimate interests — e.g. keeping the website secure, preventing abuse, aggregate traffic measurement. We do not rely on Art. 6(1)(f) where your interests or fundamental rights override ours.

Art. 6(1)(d) (vital interests) and Art. 6(1)(e) (public task) are not relevant to this website's processing. We do not knowingly process special categories of data under Art. 9 GDPR through this site; if a future feature required this, we would identify the applicable Art. 9(2) exception before launch. [LEGAL REVIEW REQUIRED: confirm no special-category data is incidentally captured via free-text form fields, e.g. a cover letter.]

6. Purposes of Processing

PurposeData UsedLegal BasisRetention
Responding to a contact inquiryIdentity, Contact, Technical (IP address)Art. 6(1)(b) / (f)[TO BE CONFIRMED]
Processing a job applicationIdentity, Contact, Applicant, Technical (IP address)Art. 6(1)(b) / (f)[TO BE CONFIRMED]
Responding to a pricing or enterprise/government enquiryIdentity, Contact, Technical (IP address)Art. 6(1)(b) / (f)[TO BE CONFIRMED]
Operating and securing the website (incl. abuse/fraud prevention)TechnicalArt. 6(1)(f)[TO BE CONFIRMED]
Aggregate, privacy-preserving traffic measurement (Cloudflare Web Analytics — see Section 7)Technical (aggregated)Art. 6(1)(f) [LEGAL REVIEW REQUIRED]Controlled by Cloudflare; not linked to an identifiable visitor by us
Managing your cookie preferencesConsent state onlyArt. 6(1)(a) / (c)[TO BE CONFIRMED]

Where a purpose above lists Technical (IP address), this means the IP address you submit the form from is stored alongside your submission. We rely on Art. 6(1)(f) GDPR for this: our legitimate interest is detecting and investigating spam, automated abuse and misuse of our forms. It is not used for profiling, advertising or tracking you across sites. If you object under Art. 21 GDPR, contact us using the details in Section 3. [LEGAL REVIEW REQUIRED: confirm this balancing test and the retention period below are adequately documented before this policy is treated as final.]

A finalized retention schedule will replace the [TO BE CONFIRMED] values above once our data processing operations are formally documented (see Section 10).

7. Cookies and Similar Technologies

We use a consent banner (see Cookie Policy) that distinguishes strictly necessary technologies from optional ones, in line with § 165(3) TKG 2021 (the Austrian implementation of the ePrivacy Directive, which governs access to end-user devices — not the GDPR's consent rules directly). Strictly necessary technologies, such as storing your cookie preference itself, do not require consent because they are essential to a service you actively request. Optional technologies require your prior, informed consent.

This site loads a Cloudflare Web Analytics beacon script (served from static.cloudflareinsights.com) for aggregate traffic measurement. Per Cloudflare's own documentation this beacon is designed to operate without cookies or persistent client-side identifiers. [LEGAL REVIEW REQUIRED] whether this nonetheless constitutes "access to end-user equipment" under § 165(3) TKG 2021 requiring consent, or falls under the strictly-necessary/no-device-access exception — the marketing/statistics category in our consent banner is kept available and inactive-by-default until this is confirmed. No marketing or advertising cookies are currently in use.

8. Disclosure to Third Parties & Processors

We share personal data with third parties only where necessary for the purposes in Section 6, or where you have consented. We do not sell personal data.

Cloudflare, Inc.Hosting (Cloudflare Pages), content delivery network, DDoS/WAF protection, and key-value storage for contact and application form submissions. Acts as our processor for these functions. [LEGAL REVIEW REQUIRED: confirm a Data Processing Agreement is executed under Art. 28 GDPR.]
Additional processors[TO BE CONFIRMED — none currently engaged beyond Cloudflare for this website]

We require any processor we engage to protect personal data under a written agreement and to process it only on our documented instructions.

9. International Data Transfers

Cloudflare operates a global network, which means requests to this website may be handled at data centers outside the European Economic Area (EEA) as part of normal content delivery, even where stored data (e.g. form submissions in Cloudflare KV) is configured for EU-region storage. Where personal data is transferred to a country without an adequacy decision under Art. 45 GDPR, we rely on appropriate safeguards under Art. 46 GDPR, such as the EU Standard Contractual Clauses, as provided by our processor. [LEGAL REVIEW REQUIRED]: confirm and document, per processor, (a) which countries are involved, (b) which Art. 46 safeguard applies, and (c) whether supplementary measures are needed following the CJEU's "Schrems II" standard.

Our products (Nexus, Sentinel, Atlas) are governed by separate, product-specific terms and — once in production — are planned to be hosted with providers in Austria and Germany; this is a roadmap commitment, not a current operational fact, and will be confirmed in product-specific documentation once verified.

10. Data Retention

[RETENTION PERIOD TO BE CONFIRMED] for each purpose in Section 6. As a general principle, we retain personal data only for as long as necessary to fulfil the purpose it was collected for, including any applicable statutory retention obligations under Austrian commercial or tax law, after which it is deleted or anonymized. Job application data that does not result in an offer is deleted or anonymized within a defined period once finalized; contact inquiries are retained only as long as needed to resolve them, unless a longer period is required to establish, exercise or defend legal claims.

11. Data Security

We apply technical and organizational measures (TOMs) to protect personal data against loss, misuse and unauthorized access. Measures currently in place for this website include: TLS/HTTPS encryption in transit (HSTS enforced), a Content Security Policy and standard security headers, and Cloudflare's platform-level DDoS and web application protections. [TO BE CONFIRMED / LEGAL REVIEW REQUIRED]: formal documentation of access-control policy (e.g. role-based access, multi-factor authentication for administrative access), logging and monitoring scope, backup policy, and a written incident response procedure — these are expected to be formalized alongside incorporation and are not yet documented as TOMs in the Art. 32 GDPR sense. Should a personal data breach occur, we will notify the competent supervisory authority within 72 hours where legally required under Art. 33 GDPR, and affected individuals under Art. 34 GDPR where the risk threshold is met.

12. Automated Decision-Making & Profiling

We do not currently use automated decision-making or profiling that produces legal or similarly significant effects on you within the meaning of Art. 22 GDPR, on this website or in our recruitment process (see Section 13). If this changes, we will update this policy in advance and describe the logic involved, its significance, and the safeguards and rights that apply, including the right to obtain human intervention.

13. Use of AI in Recruitment

We do not currently use AI tools to screen, score or make decisions about job applications. Applications submitted through our careers page are stored and reviewed by our team directly; no automated system decides whether an application progresses. If we introduce AI-assisted tools into recruitment in the future, we will update this policy beforehand to describe the tool, the extent of human review, your rights under Art. 22 GDPR, and any applicable requirements under the EU AI Act and Austrian labor law (e.g. works council co-determination, where applicable). We will not claim human oversight of a process that has not actually been implemented.

14. Your Rights

Subject to the conditions set out in the GDPR, you have the right to:

  • Access the personal data we hold about you (Art. 15 GDPR)
  • Rectification of inaccurate or incomplete data (Art. 16 GDPR)
  • Erasure of your personal data, in certain circumstances (Art. 17 GDPR)
  • Restriction of processing, in certain circumstances (Art. 18 GDPR)
  • Data portability, for data you provided under consent or a contract (Art. 20 GDPR)
  • Object to processing based on our legitimate interests (Art. 21 GDPR)
  • Withdraw consent at any time, without affecting the lawfulness of prior processing (Art. 7(3) GDPR)
  • Rights related to automated decision-making, where applicable (Art. 22 GDPR — see Section 12)

Under Austrian law, § 1 DSG additionally grants a constitutional-level right to secrecy of personal data ("Grundrecht auf Datenschutz"), which underlies the rights above. To exercise any of these rights, contact info@sailientgroup.com. We may need to verify your identity before acting on a request. We aim to respond within one month, extendable by a further two months for complex requests, in which case we will inform you.

15. Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority, in particular the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, "DSB"), if you believe our processing infringes the GDPR:

AuthorityÖsterreichische Datenschutzbehörde (DSB)
AddressBarichgasse 40-42, 1030 Vienna, Austria
Websitedsb.gv.at

We would appreciate the chance to address your concern directly first — please contact us at info@sailientgroup.com before lodging a complaint, though you are not required to do so.

16. Links to Third-Party Websites

This website may link to third-party websites, including our own product sites (Nexus, Sentinel, Atlas) and platforms like GitHub, LinkedIn or X where noted. We do not control these third-party sites and are not responsible for their privacy practices. We encourage you to read the privacy policy of every website you visit.

17. Changes to This Policy

We keep this privacy policy under regular review and may update it as our processing activities, incorporation status, or applicable law changes. Material changes will be reflected in the "Last updated" date below.

18. Governing Law & Jurisdiction

This policy is governed exclusively by Austrian law. Place of jurisdiction: Salzburg, Austria. See also our Terms of Use and Legal Notice.

Last updated: August 25, 2026

Solutions

Defense Civil & Government Infrastructure Enterprise & Automation

Technology & Resources

Developer Docs API Reference Security Research White Papers Blog Secure Portal

Company

About Us Team Careers Press & News
Legal Notice Data Protection Terms of Use Cookies Compliance
SAILIENT GROUP Sovereign AI & Cyber Defense. Built in Europe.
© 2026 Sailient Group. All rights reserved.