sentivaro
Resilience assessmentEmployee training
Why Sentivaro
Phishing without secretsMake good decisionsRead between the linesVerify through another channelProtect the processWhen everything looks rightThe final decisionConnect the eventsKeep exceptions under controlVerify the evidenceContain the impact
ContactHelp Centre
Sign in
Product
Resilience assessmentEmployee training
Why Sentivaro
Knowledge
Phishing without secretsMake good decisionsRead between the linesVerify through another channelProtect the processWhen everything looks rightThe final decisionConnect the eventsKeep exceptions under controlVerify the evidenceContain the impact
ContactSign in

Sentivaro · Legal documents

Privacy Policy

Version 1.1

Sentivaro privacy and cookies policy

Version: 1.1

Date of publication: July 30, 2026

Valid from: July 30, 2026

1. Administrator and contact

The administrator of personal data related to the public part of the website, user accounts, correspondence and security of the Service is Dawid Balcer, who runs the Sentivaro project as a natural person not running a business, correspondence address: ul. Jana Brzechwy 8, 60-195 Poznań, Poland, e-mail: contact@sentivaro.com.

The policy applies to the domains sentivaro.com, sentivaro.pl, sentivaro.eu and the application operating in these domains and their subdomains.

In matters relating to the data of campaign participants, the primary contact is the organization that commissioned the campaign. In this respect, the organization is the controller and Sentivaro acts as the processor.

2. The most important rules

  • Sentivaro is only for authorized cybersecurity awareness activities.
  • We do not sell data and do not use it for behavioral advertising.
  • We do not use advertising cookies or marketing analytics.
  • We do not save participants' passwords, MFA codes or content entered in simulated forms.
  • We process campaign data only at the documented request of the organization, subject to legal obligations.
  • We use data minimization, retention limitation and access control.

3. Roles in processing

3.1. Sentivaro as administrator

Sentivaro is the data controller of:

  • visitors to a public website;
  • account users;
  • people representing organizations;
  • people contacting the project;
  • contained in the security logs of your own Service;
  • related to the acceptance of documents and pursuing claims.

3.2. Sentivaro as processor

With regard to campaign participant data:

  • the administrator is the organization commissioning the campaign;
  • Sentivaro processes data on behalf of the organization on the basis of an entrustment agreement;
  • the data source is the organization, not the participant;
  • the legal basis of the campaign is determined by the organization;
  • the organization is responsible for the information obligation, labor law, balancing test and DPIA, if required.

Sentivaro helps the organization realize people's rights and obligations related to security, but does not use campaign data for its own marketing purposes or to create independent participant profiles.

4. Data processed by Sentivaro as the administrator

ProcessData categoriesPurposeBaseRetention
Public pageIP address or its abbreviated form, request time and address, response code, User-Agent, security eventswebsite delivery, security and diagnosticsart. 6 section 1 letter f GDPR - security and proper operation of the Serviceusually up to 90 days, shorter if the data is not needed
Registration and accountname and surname, work email, Organization, role, account ID, password hash, settingscreation and maintenance of an account, execution of the contractart. 6 section 1 letter b GDPRfor the duration of use, generally up to 30 days after closing; copies in accordance with the backup cycle, no longer than 90 days
Organization VerificationOrganization's data, representative's data, domain, statements, approval historypreventing abuse and unauthorized campaignsart. 6 section 1 letter b and letter f GDPRthe duration of the contract, and then until the limitation period for claims expires or shorter if no further storage is necessary
Login and audittime, account ID, event, result, device data to the extent necessaryaccount protection, fraud detection, accountabilityart. 6 section 1 letter f GDPRusually up to 180 days; longer only for a specific incident
Acceptance of documentsuser, Organization, document version, time, source of approvaldemonstration of contract terms and accountabilityart. 6 section 1 letter b and f GDPRduration of the contract and the period necessary to defend against claims
Contact and supportname, e-mail, content of correspondence, case detailsreplying and handling the reportart. 6 section 1 letter f GDPR or letter b, when the contact concerns a contractgenerally up to 12 months from the closure of the case; longer for claims or incident
Legal obligationsdata requested by the competent authority or required by lawfulfillment of legal obligationart. 6 section 1 letter c GDPRin accordance with the relevant duty

Providing account data is voluntary, but necessary to create it. You can view public content without providing your name or email address.

5. Campaign data

Depending on the configuration, the organization may recommend processing:

  • name and surname;
  • business e-mail address;
  • department, team or training category;
  • participant ID created by the organization;
  • the technical fact of delivery of the message;
  • opening, if the organization consciously enables this function;
  • clicks on a controlled link;
  • news reports;
  • viewing or completing educational material;
  • marking technical errors and corrections;
  • limited technical data if necessary for the safety or reliability of the result.

Sentivaro should not receive special category data, judgment data, private email addresses, identification numbers, financial data or health information.

The default retention period for detailed Campaign Data is 90 days, but the Organization may select a shorter period. After that period, the data is deleted or irreversibly aggregated. Data temporarily remaining in rotating backups is excluded from ordinary use and disappears when the relevant backup is overwritten in the technical backup cycle.

6. Legitimate interests

If the basis is Art. 6 section 1 letter f GDPR, we pursue the following interests:

  • maintaining a safe and efficient Service;
  • protection of accounts and data against unauthorized access;
  • detecting abuse and unauthorized campaigns;
  • ensuring accountability of administrative activities;
  • handling correspondence;
  • determining, investigating and defending against claims.

An organization's legitimate interest in a campaign is identified and documented by that organization. This may include ensuring information security and assessing the effectiveness of the awareness program, provided that the requirements of necessity, proportionality and respect for the rights of participants are met.

7. Statistics, evaluation and decisions

Sentivaro calculates statistics and can assign events to technical categories. We do not make automatic decisions on our own behalf that produce legal effects or similarly significantly affect a person.

The organization should:

  • prefer aggregated results;
  • take into account the possibility of operation of mail filters and scanners;
  • enable verification or correction of the result;
  • use the results educationally;
  • do not base personnel decisions solely on the automatic Sentivaro result.

8. Recipients and further sub-processors

Data may be received by:

  • persons authorized by the Operator, only to the extent necessary for maintenance and safety;
  • hosting, email, DNS/CDN, backup and security providers listed in the current list at `/subprocessors`;
  • advisors obliged to confidentiality;
  • public authorities, if the basis for disclosure is law.

The current list of suppliers along with their location and function is part of the processing information. Sentivaro does not sell data.

9. Transfers outside the EEA

The core Campaign Data infrastructure should be located in the European Economic Area.

If the supplier causes data to be transferred outside the EEA, we will use the appropriate legal mechanism, in particular an adequacy decision or standard contractual clauses together with a transfer assessment, if required.

Please confirm the actual locations of all vendors prior to publication. Current information can be found on the /subprocessors page.

10. Cookies and browser memory

We only use technologies necessary for:

  • maintaining the session;
  • login;
  • form protection;
  • remembering security and privacy settings;
  • load balancing, if applicable.

We do not use advertising, remarketing or marketing analytics cookies. Disabling essential mechanisms may prevent login or security from working properly.

Mechanism table:

NameSupplierPurposeTime
application session cookieSentivarosession, sign-in and CSRF protectionuntil the browser session is closed
sentivaro_cookie_notice_v1 in localStorageSentivaroremembering that the cookie notice was dismisseduntil website data is removed in the browser

11. External materials and websites

Regular links to YouTube, BuyCoffee or other sites do not transmit data to them prior to clicking, beyond the standard download of the link element from the Sentivaro server.

If external material is embedded, it should be locked until the user consciously activates it. Once launched, the third-party operator's policies apply.

12. Rights of persons

Depending on the basis and circumstances, a person may have the right to:

  • access to data and receiving a copy thereof;
  • corrections;
  • deletion;
  • processing restrictions;
  • data transfer when the conditions of Art. 20 GDPR;
  • object to processing based on legitimate interest;
  • withdraw consent if a specific process was based on it, without affecting previous compliance;
  • submit a complaint to the President of the Personal Data Protection Office: https://uodo.gov.pl/.

Requests for data for which Sentivaro is the controller can be directed to contact@sentivaro.com.

With respect to Campaign Data, the primary contact is the organization running the campaign. If the participant contacts Sentivaro, we will forward the request to the appropriate organization and assist it in fulfilling its obligation.

13. Information obligation regarding the campaign

We receive participant data from the organization. The organization is responsible for providing the participant with the information required by Art. 13 or 14 of the GDPR, depending on the method of obtaining the data.

The information may describe a program of periodic cybersecurity awareness activities without disclosing the date of the specific campaign, if such solution is legal, transparent and does not defeat the purpose of the test.

14. Security

We use risk-appropriate measures, including:

  • HTTPS;
  • secure password hashing;
  • role control and separation of the Organization;
  • confirming your business email address and limiting your campaigns to associated domains;
  • random, time-limited tokens;
  • administrative activity logs;
  • limitation of retention;
  • incident handling mechanisms;

No system guarantees absolute security. In the event of a breach, we act in accordance with the GDPR and agreements with Organizations.

15. Children

The Service is not intended for children or for conducting Campaigns towards them without prior individual legal and organizational agreement. Only adults can create accounts.

16. Policy changes

The policy may be updated as the law, functions, suppliers or operating model change. Significant changes will be communicated to users. The current version is published with a number and effective date.

17. Contact

Privacy Questions: contact@sentivaro.com.

© 2026 SentivaroTermsPrivacy PolicyDPAAcceptable use