Terms of use of Sentivaro
Version: 1.0
Date of publication: July 30, 2026
Valid from: July 30, 2026
1. Operator and contact
- The operator of Sentivaro is Dawid Balcer, who runs the free Sentivaro project as a natural person not running a business, correspondence address: ul. Jana Brzechwy 8, 60-195 Poznań, Poland, e-mail: contact@sentivaro.com, hereinafter referred to as the "Operator".
- The Regulations define the rules for using the Sentivaro website and application available in the domains sentivaro.com, sentivaro.pl, sentivaro.eu and their subdomains, hereinafter referred to as the "Service".
- The Service is intended solely for professional, authorized use by organizations to build cybersecurity awareness, conduct controlled simulations and educational activities.
- The Operator does not provide legal, auditing or certification services. Use of the Service does not constitute compliance or certification with ISO/IEC 27001, NIS2, DORA, GDPR or any other requirement.
2. Definitions
- "Organization" - a legal person, organizational unit or natural person acting as part of their professional activity that has been verified and uses the Service.
- "User" - an adult natural person using the account on their own behalf or on behalf of the Organization.
- “Participant” – a person participating in an authorized cybersecurity awareness campaign.
- “Campaign” - A controlled simulation of a message or other cyber threat scenario, combined with measurement of a limited set of events and possible educational material.
- "Campaign Data" - Participants' data and events processed by the Operator at the documented request of the Organization.
- "DPA" - data processing agreement constituting a separate document and part of the agreement with the Organization.
- "Acceptable Use Policy" - a document specifying acceptable and prohibited ways of using the Service.
3. Terms of use
- The User must be of legal age and able to conclude a contract.
- The User acting on behalf of the Organization declares that he is entitled to:
- creating an Organization account;
- acceptance of the Regulations, DPA and Acceptable Use Policy;
- transfer of Participants' data;
- Campaign orders within the approved scope.
- The operator confirms the business e-mail address. A DNS entry, a qualified signature, or a paper power of attorney are not typically required. In case of increased risk, the Operator may ask for additional confirmation from the person responsible for security or another authorized person.
- To use the Service, a current browser, Internet access, an active e-mail address and necessary cookies and security mechanisms are required.
- The user is responsible for the accuracy and validity of the information provided.
4. Account
- One person cannot share his/her account with other people.
- The User is obliged to use a strong, unique password, protect login data and immediately notify the Operator of suspected account takeover.
- The organization assigns roles to users according to the principle of least privilege.
- The Operator may temporarily block the account when:
- there is suspicion of an unauthorized Campaign;
- the account or Organization has not been verified;
- there is a security threat;
- the Regulations, DPA or Acceptable Use Policy have been violated;
- it is necessary to protect Participants or third parties.
- The User may unsubscribe from the Service at any time and request closure of the account. Data is deleted in accordance with the Privacy Policy and DPA.
5. Organization Verification
- Transferring Campaign Data and launching a Campaign requires prior verification of the Organization.
- Basic verification includes:
- confirmation of your business e-mail address;
- indication of full data of the Organization;
- indication of the User's functions and emergency contact;
- declaration of authorization;
- DPA acceptance.
- The campaign may be directed to addresses in the domain consistent with the User's business address. Adding another domain requires slight additional confirmation, e.g. by a person using a business mailbox in this domain or manual assessment by the Operator. DNS entry is not required.
- The Operator may refuse activation without providing details if disclosing the details could weaken the abuse prevention mechanisms.
6. Campaigns
- The Campaign may only include persons in an approved relationship with the Organization and addresses covered by its authorization.
- Organize yourself:
- establishes the purpose and legal basis of the Campaign;
- defines the group of Participants;
- fulfills information obligations;
- conducts a balance test or DPIA if necessary;
- establishes the rules for using the results;
- is responsible for the compliance of the Campaign with labor law and internal regulations.
- Sentivaro does not save real passwords, MFA codes or the contents of simulated form fields. The Organization cannot modify the Service to obtain them.
- The organization should use the results primarily in an educational, proportionate and sensitive manner that takes into account the possibility of technical errors.
- The result of the Campaign cannot constitute the only basis for an automatic decision producing legal effects or having a similarly significant impact on the Participant.
- Detailed restrictions are set out in the Acceptable Use Policy.
7. Personal data
- The rules for processing Users' data are described in the Privacy Policy.
- With respect to Campaign Data, the Organization is the controller and the Operator acts as a processor under the DPA.
- The Organization undertakes to provide only data that is adequate and necessary for the Campaign.
- The User may not transfer special categories of data, data regarding judgments and violations of law, or private contact details via the Service without prior written agreement with the Operator and proof of legal basis.
8. Free of charge and availability
- In the basic model, the Service is provided free of charge.
- Voluntary contribution to the maintenance of the project, if available, is not a condition for obtaining access, does not guarantee mutual benefit and does not give priority in service.
- The Operator develops the Service on its own and does not guarantee:
- uninterrupted availability;
- suitability for the specific purpose of the Organization;
- compliance of the Organization with a standard or regulation;
- the delivery of each message, as it also depends on email systems and security filters.
- The Operator may carry out maintenance work, change functions or terminate the provision of the Service, providing sufficient notice in advance, whenever possible.
- In the event of termination of the Service, the Operator will enable the Organization to download available data or delete it, unless safety, law or an urgent incident require other action.
9. Responsibility
- Each Organization is responsible for the legality of the commissioned Campaign, the scope of Participants, the content of the materials used and the method of using the results.
- The Operator is responsible for its own actions under the terms of mandatory law.
- To the fullest extent permitted by law, the Operator is not responsible for:
- User's actions inconsistent with the Regulations;
- personnel and organizational decisions made based on the results;
- failure to deliver messages by external systems;
- consequences of providing incorrect data;
- interruptions resulting from supplier failures or force majeure.
- The provisions of the Regulations do not exclude liability that cannot be excluded by law, in particular liability for intentional action.
10. Intellectual property
- The rights to the Service, its code, markings and materials belong to the Operator or relevant licensors.
- The Organization retains the rights to the materials it provides and grants the Operator a non-exclusive authorization to use them technically, limited to the time and purpose of the Campaign.
- The Organization declares that it has the rights to the names, signs, graphics and content used in the Campaign.
- Materials from third parties may be used only after obtaining the appropriate right or to the extent expressly permitted by law.
11. Reporting problems and complaints
- Problems, complaints and suspected abuse can be reported to contact@sentivaro.com.
- The report should include a description of the case, the ID of the Organization or Campaign, if available, and the expected method of resolution.
- The Operator will respond within a reasonable time, generally no later than 14 days. In complex cases, the deadline may be extended, of which the applicant will be informed.
- Suspected security breaches should be marked with the word "SECURITY" in the message title.
12. Duration and ending
- The contract is concluded upon acceptance of the Regulations and creation of an account.
- The contract is concluded for an indefinite period and may be terminated at any time by closing the account.
- The Operator may terminate the contract with immediate effect in the event of a serious breach of security rules, an unauthorized Campaign or an attempt to use the Service for actual phishing.
- Termination of the contract does not affect obligations related to the deletion or return of data or provisions that by their nature apply after its termination.
13. Changes
- The Operator may change the Regulations due to a change in function, law, security measures or operating model.
- Users will be informed about significant changes before they enter into force.
- If the change affects the rights or obligations of the Organization, the Operator may require repeated acceptance. Lack of acceptance allows you to stop using the Service.
14. Applicable law
- Polish law applies to the Regulations, taking into account mandatory provisions applicable to a given User.
- The parties should first attempt to resolve the dispute amicably.
15. Related documents
The following are integral to the use of the Service:
- Privacy policy;
- Data processing agreement;
- Fair use policy;
- current list of further processors.