Data protection and GDPR
Last updated: 23 September 2026
Clear responsibilities matter before data is shared. This policy explains how website privacy differs from processing customer data in SENTR, and what must be agreed for an evaluation or production deployment.
1. Responsibility and scope
SENTR TECHNOLOGIES LTD
Registered in England and Wales. Company number 17476717.
Contact ian@sentr.io for data protection enquiries. This is our privacy contact; it is not a representation that a statutory Data Protection Officer has been appointed.
Our approach is to identify the purpose and lawful ground for processing, limit information to what that purpose needs, keep it accurate, control access and retention, and support applicable individual rights. The relevant framework includes the UK GDPR and Data Protection Act 2018, as amended, and the EU GDPR where applicable.
This public policy explains responsibilities and the review process. It does not certify compliance, replace an agreed Data Processing Agreement (DPA), or establish that a particular deployment meets every customer or regulatory requirement.
2. Website and business-contact information
SENTR TECHNOLOGIES LTD is the controller for the website and enquiry activities described in our Privacy policy. That notice covers the information we collect, sources, purposes and legal grounds, AI conversations, CRM follow-up, scheduling, enrichment, providers, international transfers and retention.
Enquiries and requested follow-up do not subscribe you to marketing. Optional website analytics requires your choice, which you can change through “Privacy choices” in the footer. Our Cookie policy identifies browser storage and its duration.
Public forms and chat are for business enquiries. Do not upload production fraud records, identity documents, payment-card details, credentials or sensitive customer information. Contact us to agree the appropriate channel and processing terms first.
3. Customer platform data and GDPR roles
A customer determines why it uses fraud-event information and how its decisions affect people. Where SENTR processes personal data on that customer’s documented instructions, the arrangement is a controller–processor relationship. If the customer itself acts as a processor, the necessary authorisation and subprocessor terms must be established. Roles depend on the actual processing and are recorded in the agreement.
Before providing data, the customer needs a lawful basis, appropriate notices, authority to disclose it and a defined scope. Decisions about required impact assessments, human review, challenges to decisions and any use of sensitive or criminal-offence information must be addressed for the intended use. Neither a fraud-prevention purpose nor a free evaluation removes those requirements.
Qualified Shadow Mode evaluates alongside the customer’s existing operation without changing its production decisions. It can still involve personal data, so evaluation scope, permitted fields, access and deletion arrangements must be agreed before transfer.
4. Data Processing Agreement
Request a DPA and the relevant processing schedules through Security review or ian@sentr.io before sharing customer personal data. The customer agreement must identify:
- The parties, purpose, duration, data categories and people concerned.
- Documented instructions, confidentiality, security measures and authorised subprocessors.
- Help with rights requests, incident response and required impact assessments.
- Retention, return or deletion, international-transfer safeguards, and audit arrangements.
The executed agreement governs the deployment. Visiting this page or booking a meeting does not execute a DPA, authorise a data transfer or accept a customer service contract.
5. Security, retention and transfers
Website controls include HTTPS, server-side credentials, validation, request limits and duplicate-submission protection. The website retention schedule includes review of inactive enquiries after 12 months. That review is a manual operating responsibility, not a claim of automatic CRM deletion.
Platform hosting, authorised access, encryption, logging, backup handling, retention and deletion need to match the agreed deployment. Review the Security and data page and request supporting evidence for controls material to your assessment. Confirm certification status, scope and supporting documents during that review.
The public website uses different providers from the customer platform. The website provider list covers Netlify, HubSpot, OpenAI and Google services. It is not a complete platform subprocessor schedule. Website providers may process information outside the UK or EEA; EU platform hosting alone does not establish that all processing stays in the EU.
Customer schedules should identify each relevant provider, its purpose, processing location and applicable transfer arrangements. Data retention and backup expiry must be specified for the agreed service; no universal retention period for every customer dataset is promised here.
6. Rights, concerns and incidents
For website information, email ian@sentr.io to request access, correction, erasure, restriction or portability where applicable, or to object or withdraw consent. We normally respond without undue delay and within one calendar month, subject to applicable extensions and exceptions explained in our Privacy policy.
If your request concerns a decision by a SENTR customer, contact that organisation using its privacy notice. It determines the relevant decision and normally handles the request as controller. If you contact us, describe the organisation and issue without sending sensitive records so we can help identify the correct route.
Report a suspected data exposure to ian@sentr.io promptly with a non-sensitive description. Do not send exposed credentials or exploit the issue further. Incident handling and notification duties depend on the roles, facts, applicable law and customer agreement.
You may raise concerns with the UK Information Commissioner’s Office or another competent supervisory authority. Where EU GDPR applies, this includes the authority where you habitually live, work or believe an infringement occurred.