SYSOISYSOI Run it on your event

Privacy

How SYSOI handles personal data

Effective 2026-07-20. This page is our operative subprocessor disclosure and a plain-language summary of what SYSOI actually does with personal data, written from the system itself. A comprehensive counsel-reviewed policy is in progress and will replace this summary; the facts below will not get less honest in the process.

Who we are

SYSOI (sysoi.ai) is an event-lifecycle intelligence platform operated by Sandbox Group LLC. Privacy contact: brian@sysoi.ai.

Two roles, two situations

Event data: your event organizer is the controller. SYSOI is business software. When an event organizer connects their registration platform, CRM, or spreadsheets to SYSOI, we process attendee and contact data on that organizer's behalf and instructions. If you attended an event run on SYSOI, the organizer is your point of contact for privacy requests, and we give them built-in tooling to honor those requests (see Your rights).

This website and direct business contacts: SYSOI is the controller. For visitors to sysoi.ai and people we contact about SYSOI itself, we are responsible for the data described below.

What the product processes

For each customer workspace, SYSOI builds one consolidated record per event contact from the sources the customer connects: registration platforms, CRMs, marketing tools, and uploaded lists. That record typically holds name, work email, phone, company, title, event registrations and attendance, session activity, meetings, and email engagement.

Enrichment from public professional sources. At the customer's direction, SYSOI can enrich a business contact from publicly available professional-profile information (for example a public LinkedIn profile located via web search), adding fields like industry, seniority, and company size. This data does not come from you directly; this page is our notice of that practice, and you can object via your event organizer or by contacting us.

AI analysis. SYSOI uses Anthropic's Claude models to score engagement, summarize activity, and draft content for the customer. The reasoning behind every score is stored so it can be reviewed by a human, and outputs prioritize sales follow-up rather than producing legal or similarly significant automated decisions.

Consent and opt-out are enforced in the machinery, not just policy. A contact marked as having declined marketing is hard-blocked from every SYSOI-sent marketing email. Every campaign email carries a working unsubscribe link and one-click (RFC 8058) unsubscribe headers. Spam complaints opt the address out automatically. Unsubscribes are also kept on a separate suppression list so a re-imported spreadsheet cannot quietly re-subscribe anyone. Nothing sends without a human pressing Activate.

What this website collects

Our own analytics are first-party and server-side: we log page views without any analytics cookies or client-side trackers of our own, we never store your raw IP address (visitor counts use a salted hash that rotates daily), and we look up the visiting network with IPinfo to learn the company it belongs to, never the person.

Two Google services do load on our marketing pages: the Google Ads conversion tag and Google Fonts. Both involve requests to Google, which Google may process per its own policies. This privacy page itself carries no ad tag.

Your rights

SYSOI ships data-subject tooling in the product: access (a full view of what a workspace holds about a contact), export (a machine-readable copy), and erasure. Erasure removes the contact and every linked engagement, session, score, and attribution, and records a suppression entry so a later re-sync from the original source does not recreate the person. Two honest limits: data already handed off to a customer's own CRM is the customer's copy to erase, and we cannot un-generate free-text content that mentioned a name before erasure.

If your data reached SYSOI through an event, direct your request to the event organizer (the controller); they can execute it in the product. For anything else, or if you cannot reach the organizer, email brian@sysoi.ai and we will route it.

Subprocessors

These vendors process data as part of running SYSOI. This list is kept in lockstep with our internal vendor register.

  • Render · application hosting · runs the SYSOI application and its background jobs.
  • Neon · Postgres database · stores all workspace data at rest.
  • Clerk · authentication · user login identity, sessions, and organization membership.
  • Nango · connector vault · holds the OAuth tokens for tools customers connect; SYSOI stores only a connection reference.
  • Anthropic · AI inference · processes content sent for scoring, summaries, and drafting.
  • Resend · email delivery · recipient addresses and message content for digests and campaigns.
  • GitHub · source control and CI · code only, no customer workspace data.
  • OpenAI · embeddings for our own internal content library · no customer workspace data.
  • Zernio · social publishing · post content and platform account references for customers who publish socially.
  • Apify and ForgeScrape (Forge Intelligence LLC) · enrichment · name and company terms used to locate public professional profiles, where a customer enables enrichment.
  • Google (Custom Search, Ads tag, Fonts) · enrichment search fallback and the marketing-site services described above.
  • IPinfo · site analytics · visiting network in, company-level result out; we store no raw IPs.
  • Composio · operator tooling · the platform our founder-directed engineering sessions use to reach our own infrastructure (database, hosting, and email provider APIs); every such access is logged internally.

The tools customers connect are not our subprocessors. Registration platforms and CRMs like Cvent, RainFocus, Swoogo, Marketo, Bizzabo, Jifflenow, Mailchimp, Google Sheets, HubSpot, Salesforce, and Attio are the customer's own systems, accessed with the customer's credentials on the customer's behalf.

Retention

Workspace data is retained while the customer relationship is active and is deleted on verified erasure requests as described above. Suppression entries are retained, because honoring an opt-out or erasure requires remembering it.

Changes

We will update this page as practices or vendors change, and the counsel-reviewed policy will replace this summary when it lands. Material changes to the subprocessor list are reflected here first.

Questions: brian@sysoi.ai.