Sentivaro privacy and cookies policy
Version: 1.1
Date of publication: July 30, 2026
Valid from: July 30, 2026
1. Administrator and contact
The administrator of personal data related to the public part of the website, user accounts, correspondence and security of the Service is Dawid Balcer, who runs the Sentivaro project as a natural person not running a business, correspondence address: ul. Jana Brzechwy 8, 60-195 Poznań, Poland, e-mail: contact@sentivaro.com.
The policy applies to the domains sentivaro.com, sentivaro.pl, sentivaro.eu and the application operating in these domains and their subdomains.
In matters relating to the data of campaign participants, the primary contact is the organization that commissioned the campaign. In this respect, the organization is the controller and Sentivaro acts as the processor.
2. The most important rules
- Sentivaro is only for authorized cybersecurity awareness activities.
- We do not sell data and do not use it for behavioral advertising.
- We do not use advertising cookies or marketing analytics.
- We do not save participants' passwords, MFA codes or content entered in simulated forms.
- We process campaign data only at the documented request of the organization, subject to legal obligations.
- We use data minimization, retention limitation and access control.
3. Roles in processing
3.1. Sentivaro as administrator
Sentivaro is the data controller of:
- visitors to a public website;
- account users;
- people representing organizations;
- people contacting the project;
- contained in the security logs of your own Service;
- related to the acceptance of documents and pursuing claims.
3.2. Sentivaro as processor
With regard to campaign participant data:
- the administrator is the organization commissioning the campaign;
- Sentivaro processes data on behalf of the organization on the basis of an entrustment agreement;
- the data source is the organization, not the participant;
- the legal basis of the campaign is determined by the organization;
- the organization is responsible for the information obligation, labor law, balancing test and DPIA, if required.
Sentivaro helps the organization realize people's rights and obligations related to security, but does not use campaign data for its own marketing purposes or to create independent participant profiles.
4. Data processed by Sentivaro as the administrator
| Process | Data categories | Purpose | Base | Retention |
|---|---|---|---|---|
| Public page | IP address or its abbreviated form, request time and address, response code, User-Agent, security events | website delivery, security and diagnostics | art. 6 section 1 letter f GDPR - security and proper operation of the Service | usually up to 90 days, shorter if the data is not needed |
| Registration and account | name and surname, work email, Organization, role, account ID, password hash, settings | creation and maintenance of an account, execution of the contract | art. 6 section 1 letter b GDPR | for the duration of use, generally up to 30 days after closing; copies in accordance with the backup cycle, no longer than 90 days |
| Organization Verification | Organization's data, representative's data, domain, statements, approval history | preventing abuse and unauthorized campaigns | art. 6 section 1 letter b and letter f GDPR | the duration of the contract, and then until the limitation period for claims expires or shorter if no further storage is necessary |
| Login and audit | time, account ID, event, result, device data to the extent necessary | account protection, fraud detection, accountability | art. 6 section 1 letter f GDPR | usually up to 180 days; longer only for a specific incident |
| Acceptance of documents | user, Organization, document version, time, source of approval | demonstration of contract terms and accountability | art. 6 section 1 letter b and f GDPR | duration of the contract and the period necessary to defend against claims |
| Contact and support | name, e-mail, content of correspondence, case details | replying and handling the report | art. 6 section 1 letter f GDPR or letter b, when the contact concerns a contract | generally up to 12 months from the closure of the case; longer for claims or incident |
| Legal obligations | data requested by the competent authority or required by law | fulfillment of legal obligation | art. 6 section 1 letter c GDPR | in accordance with the relevant duty |
Providing account data is voluntary, but necessary to create it. You can view public content without providing your name or email address.
5. Campaign data
Depending on the configuration, the organization may recommend processing:
- name and surname;
- business e-mail address;
- department, team or training category;
- participant ID created by the organization;
- the technical fact of delivery of the message;
- opening, if the organization consciously enables this function;
- clicks on a controlled link;
- news reports;
- viewing or completing educational material;
- marking technical errors and corrections;
- limited technical data if necessary for the safety or reliability of the result.
Sentivaro should not receive special category data, judgment data, private email addresses, identification numbers, financial data or health information.
The default retention period for detailed Campaign Data is 90 days, but the Organization may select a shorter period. After that period, the data is deleted or irreversibly aggregated. Data temporarily remaining in rotating backups is excluded from ordinary use and disappears when the relevant backup is overwritten in the technical backup cycle.
6. Legitimate interests
If the basis is Art. 6 section 1 letter f GDPR, we pursue the following interests:
- maintaining a safe and efficient Service;
- protection of accounts and data against unauthorized access;
- detecting abuse and unauthorized campaigns;
- ensuring accountability of administrative activities;
- handling correspondence;
- determining, investigating and defending against claims.
An organization's legitimate interest in a campaign is identified and documented by that organization. This may include ensuring information security and assessing the effectiveness of the awareness program, provided that the requirements of necessity, proportionality and respect for the rights of participants are met.
7. Statistics, evaluation and decisions
Sentivaro calculates statistics and can assign events to technical categories. We do not make automatic decisions on our own behalf that produce legal effects or similarly significantly affect a person.
The organization should:
- prefer aggregated results;
- take into account the possibility of operation of mail filters and scanners;
- enable verification or correction of the result;
- use the results educationally;
- do not base personnel decisions solely on the automatic Sentivaro result.
8. Recipients and further sub-processors
Data may be received by:
- persons authorized by the Operator, only to the extent necessary for maintenance and safety;
- hosting, email, DNS/CDN, backup and security providers listed in the current list at `/subprocessors`;
- advisors obliged to confidentiality;
- public authorities, if the basis for disclosure is law.
The current list of suppliers along with their location and function is part of the processing information. Sentivaro does not sell data.
9. Transfers outside the EEA
The core Campaign Data infrastructure should be located in the European Economic Area.
If the supplier causes data to be transferred outside the EEA, we will use the appropriate legal mechanism, in particular an adequacy decision or standard contractual clauses together with a transfer assessment, if required.
Please confirm the actual locations of all vendors prior to publication. Current information can be found on the /subprocessors page.
10. Cookies and browser memory
We only use technologies necessary for:
- maintaining the session;
- login;
- form protection;
- remembering security and privacy settings;
- load balancing, if applicable.
We do not use advertising, remarketing or marketing analytics cookies. Disabling essential mechanisms may prevent login or security from working properly.
Mechanism table:
| Name | Supplier | Purpose | Time |
|---|---|---|---|
| application session cookie | Sentivaro | session, sign-in and CSRF protection | until the browser session is closed |
sentivaro_cookie_notice_v1 in localStorage | Sentivaro | remembering that the cookie notice was dismissed | until website data is removed in the browser |
11. External materials and websites
Regular links to YouTube, BuyCoffee or other sites do not transmit data to them prior to clicking, beyond the standard download of the link element from the Sentivaro server.
If external material is embedded, it should be locked until the user consciously activates it. Once launched, the third-party operator's policies apply.
12. Rights of persons
Depending on the basis and circumstances, a person may have the right to:
- access to data and receiving a copy thereof;
- corrections;
- deletion;
- processing restrictions;
- data transfer when the conditions of Art. 20 GDPR;
- object to processing based on legitimate interest;
- withdraw consent if a specific process was based on it, without affecting previous compliance;
- submit a complaint to the President of the Personal Data Protection Office: https://uodo.gov.pl/.
Requests for data for which Sentivaro is the controller can be directed to contact@sentivaro.com.
With respect to Campaign Data, the primary contact is the organization running the campaign. If the participant contacts Sentivaro, we will forward the request to the appropriate organization and assist it in fulfilling its obligation.
13. Information obligation regarding the campaign
We receive participant data from the organization. The organization is responsible for providing the participant with the information required by Art. 13 or 14 of the GDPR, depending on the method of obtaining the data.
The information may describe a program of periodic cybersecurity awareness activities without disclosing the date of the specific campaign, if such solution is legal, transparent and does not defeat the purpose of the test.
14. Security
We use risk-appropriate measures, including:
- HTTPS;
- secure password hashing;
- role control and separation of the Organization;
- confirming your business email address and limiting your campaigns to associated domains;
- random, time-limited tokens;
- administrative activity logs;
- limitation of retention;
- incident handling mechanisms;
No system guarantees absolute security. In the event of a breach, we act in accordance with the GDPR and agreements with Organizations.
15. Children
The Service is not intended for children or for conducting Campaigns towards them without prior individual legal and organizational agreement. Only adults can create accounts.
16. Policy changes
The policy may be updated as the law, functions, suppliers or operating model change. Significant changes will be communicated to users. The current version is published with a number and effective date.
17. Contact
Privacy Questions: contact@sentivaro.com.