Privacy Policy
Last updated: 2026-07-10
This policy explains how [Company legal name] handles personal data when you visit sentinelpanda.com, use the SentinelPanda product, or contact us. Records that our customers upload into their own workspaces (about their staff, vendors, and auditors) are processed strictly on the customer's instructions under our Data Processing Addendum — their own privacy notice governs that data.
1. Who we are
[Company legal name] ("we", "us") operates SentinelPanda. Registered office: [Registered address]. Privacy questions go to [privacy@yourdomain]; EU/UK data subjects can reach our Data Protection Officer at [dpo@yourdomain].
2. What we collect
- From you directly: name, work email, company, role, and the text of demo / contact / signup messages. From paying customers we also receive billing details and the addresses of invited users.
- Observed automatically: IP address, requested URL, response code, and a short request identifier — logged by our hosting and edge platform for debugging, abuse defence, and security. Cloudflare Web Analytics provides site traffic stats and does not set tracking cookies or retain IPs.
- Inside the product: records customers store about their controls, evidence, assessments, vendors, and engagements. We process this as a processor under the DPA.
3. Why we use it (legal bases under GDPR Article 6)
- Run the product and deliver your subscription — contract (Art. 6(1)(b)).
- Respond to demo and contact enquiries — pre-contractual steps / legitimate interest (Art. 6(1)(b) / (f)).
- Service comms (account, billing, security, incidents) — contract and legal obligation (Art. 6(1)(b) / (c)).
- Opt-in marketing — consent (Art. 6(1)(a)); withdraw any time via the unsubscribe link.
- Detect fraud and abuse, protect the platform — legitimate interest (Art. 6(1)(f)).
- Tax, accounting, statutory record-keeping — legal obligation (Art. 6(1)(c)).
4. What we do not do
We do not sell or rent personal data. We do not use customer content to train AI models. We do not share data with ad networks. Our business model is paid subscriptions, not surveillance.
5. Sharing and international transfers
We share personal data with the sub-processors who host or operate parts of the platform (cloud infrastructure, edge network, transactional email, error reporting, payment processor) and with our own auditors and counsel under confidentiality. The current sub-processor list is part of the DPA.
We are established in [Country of establishment]. Where personal data leaves the EEA or UK, we rely on the Standard Contractual Clauses and the UK addendum, supplemented by encryption in transit and at rest.
6. Retention
Marketing enquiries: [retention period] from last contact. Account data: kept while the account is active, then deleted or anonymised within [retention period] of closure (subject to legal hold). Application logs: rolling [retention period]. Security and audit logs: [retention period]. Customer content is returned or deleted on the customer's instruction at the end of the term.
7. Your rights
Under the EU/UK GDPR and similar laws (e.g. California CCPA/CPRA), you may ask us to give you a copy of your personal data, correct it, delete it, restrict or object to a particular use, port it to another service, or withdraw consent where we relied on it. Email [privacy@yourdomain]; we respond inside the timeframes set by applicable law (one month under GDPR, 45 days under CCPA) and may verify your identity first.
If you are an end user of a SentinelPanda customer, exercise these rights with that customer directly — they are the controller of that data. You may also complain to your local supervisory authority (in the EU, the authority where you live, work, or where the issue occurred; in the UK, the Information Commissioner's Office).
8. Security, children, cookies
Security. Role-based access, encryption in transit and at rest for credentials and customer content, an append-only admin audit log, mandatory MFA for staff, and a documented incident response programme.
Children. The product is for businesses; we do not knowingly collect data from anyone under 16. Contact [privacy@yourdomain] if you believe we have.
Cookies. We store two localStorage entries (your theme and your cookie-banner choice). No tracking cookies. EU/UK visitors see a banner; the "Cookie settings" footer link reopens it at any time.
9. Changes
We update this policy occasionally. Material changes will be announced by email or by a prominent notice on the site at least 30 days before they take effect. The "last updated" date at the top identifies the current version.