Privacy Policy
Last updated: 2026-09-05
1. Introduction
This Privacy Policy explains how Denis Sota, operating as SentriKat ("we", "us", or "the Data Controller"), collects, uses, stores, and protects personal data in connection with the SentriKat website (sentrikat.com), the SentriKat customer portal, and the SentriKat software product.
This policy is designed to comply with the Swiss Federal Act on Data Protection (nDSG / FADP). Where we process personal data of individuals located in the European Economic Area (EEA), the EU General Data Protection Regulation (GDPR) also applies pursuant to its extraterritorial scope (Art. 3(2) GDPR).
SentriKat is offered in two deployment modes, and what reaches us is different for each. On-premises installations run entirely on your own infrastructure; the data we receive is limited to the license and knowledge-base telemetry described in Section 3, never your vulnerability data, inventory, or scan results. Cloud (SaaS) deployments are different in kind, not degree: the portal and platform we operate are the service, so operating them necessarily involves processing the data you put into them, as a processor acting on your instructions, governed by our Data Processing Agreement.
2. Data Controller
The data controller responsible for processing your personal data is:
Denis Sota
Via Lucomagno 97, 6715 Dongio, Switzerland
Email: [email protected]
3. What Personal Data We Collect and Why
We only collect personal data that is necessary for the purposes described below.
| Data | Source | Purpose | Legal Basis |
|---|---|---|---|
| Name, email, company name | Customer at purchase | Contract fulfillment, license delivery | Contract performance (nDSG Art. 6(3); GDPR Art. 6(1)(b)) |
| Payment data (card details, billing address) | Stripe checkout | Payment processing | Contract performance (nDSG Art. 6(3); GDPR Art. 6(1)(b)) |
| License key, software version, agent/asset count | SentriKat installation (heartbeat) | License validation | Contract performance (nDSG Art. 6(3); GDPR Art. 6(1)(b)) |
| IP address, HTTP user-agent | Automatic on connection (server logs) | Security, abuse prevention, rate limiting | Overriding legitimate interest (nDSG Art. 6(3); GDPR Art. 6(1)(f)) |
| Hostname, operating system info | SentriKat installation (at activation) | License binding, support diagnostics | Contract performance (nDSG Art. 6(3); GDPR Art. 6(1)(b)) |
| KB-state telemetry: dataset row counts, sync cursors and status, bundle version, and internal quality-check status/timestamp (counters, versions and timestamps only, never content) | SentriKat installation (heartbeat) | Detect an installation falling behind on data, or a shared quality regression across several installations | Overriding legitimate interest (nDSG Art. 6(3); GDPR Art. 6(1)(f)) |
| CPE mapping contributions (standardized vendor/product name patterns, an installation identifier, a confidence score) | PRO installations (KB Sync, opt-out) | Community knowledge base for improved vulnerability matching | Overriding legitimate interest (nDSG Art. 6(3); GDPR Art. 6(1)(f)) |
| Unidentified-software reports: vendor name, product name, an aggregate install count, and whether that name has ever been linked to a security advisory (yes/no). No version, hostname, or tenant data | SentriKat installation (any edition, opt-out) | Crowd-sourced identification of software our matching engine cannot yet resolve, curated by us before being shared back to every user | Overriding legitimate interest (nDSG Art. 6(3); GDPR Art. 6(1)(f)) |
| Email address (newsletter) | Voluntary signup | Marketing communications | Consent (nDSG Art. 6(6); GDPR Art. 6(1)(a)) |
4. What We Do NOT Collect
This section describes the on-premises deployment, where SentriKat runs entirely on the customer's own infrastructure. It does not describe the Cloud (SaaS) deployment, where the platform itself processes the operational data a customer puts into it as part of providing the service, governed by our Data Processing Agreement.
- We do NOT collect or process any data from an on-premises SentriKat installation beyond the data listed in Section 3 above (license heartbeat, KB-state telemetry, activation metadata, and the two knowledge-base signals described below).
- We do NOT have access to vulnerability data, user accounts, LDAP/SSO data, agent data, configuration, or any other data stored in an on-premises SentriKat instance.
- Customer operational data (vulnerability scans, full software inventories, alerts) never leaves the customer's infrastructure. The one exception is the anonymized, per-item signals described below, sent only for software our engine could not otherwise identify or map, never a customer's full inventory.
License heartbeat: The SentriKat
instance sends a periodic heartbeat (approximately every 24 hours) to
our license server (license.sentrikat.com) containing: the license key, installation ID, the SentriKat
version installed, the number of active agents/assets, and
KB-state telemetry (dataset row counts, sync status, bundle
version, and internal quality-check status, all counters,
versions or timestamps, never content). Hostname and OS
information are additionally sent, once, at activation only.
The connecting IP address and HTTP user-agent are recorded in
connection logs for 90 days. No personal data of end-users is
transmitted.
KB Sync (mapping contributions, PRO): PRO installations may push locally discovered CPE vendor/product mapping patterns to the central knowledge base. These contributions contain only standardized software identifiers (e.g., "apache" → "http_server"), the contributing installation's own identifier (the same one used for license activation, not a name, email or company), and a confidence score. No vulnerability data, scan results, or customer infrastructure details are included. Contributions are published to other users once 3 or more independent installations confirm the same mapping; this can be disabled from the installation's settings.
Unidentified-software reports (any edition): when the matching engine cannot resolve a piece of software to a known identity, an installation may report it for human curation: the vendor name, the product name, an aggregate install count, and whether that name has ever been linked to a security advisory. No version, hostname, tenant, or other Customer Data is included, and a curator reviews an identity before it is ever shared back to other users. This can be disabled from the installation's settings.
5. Third-Party Data Processors
We use the following third-party service providers to process personal data on our behalf. The complete, actively maintained list, kept current under Art. 28 GDPR, is at /subprocessors; the table below covers the ones relevant to the website and on-premises license server described in this policy.
| Processor | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| Hetzner Online GmbH (DE) | Cloud infrastructure, virtual servers hosting the Cloud platform, license server, and website | Heartbeat data, IP address | hetzner.com/privacy |
| Cloudflare, Inc. (US) | DNS, CDN, DDoS protection, and Turnstile (bot protection for forms) | IP address, browser fingerprint (on pages with forms only) | cloudflare.com/privacy |
| Resend, Inc. (US) | Transactional email (confirmations, license delivery, newsletter) | Name, email address, email content | resend.com/privacy |
| Stripe, Inc. (US) | Payment processing (activated when billing is enabled for your account) | Billing data (name, email, payment method, billing address) | stripe.com/privacy |
6. International Data Transfers
SentriKat is operated from Switzerland. The European Commission has recognized Switzerland as providing an adequate level of data protection (adequacy decision pursuant to Art. 45 GDPR). Data transfers between Switzerland and the EEA do not require additional safeguards.
- Stripe: Stripe, Inc. is based in the United States and is certified under the EU-US Data Privacy Framework and the Swiss-US Data Privacy Framework, providing an adequate level of data protection.
- Cloudflare: Cloudflare, Inc. is based in the United States and is certified under the EU-US Data Privacy Framework and the Swiss-US Data Privacy Framework.
- Hetzner: All data processed by Hetzner is stored in German data centers within the European Union. No transfer outside the EEA/Switzerland occurs.
- Resend: Resend, Inc. is based in the United States and is certified under the EU-US Data Privacy Framework, providing an adequate level of data protection.
7. Data Retention
We retain personal data only for as long as necessary for the purposes described in this policy:
- Customer and billing data: Retained for the duration of the license relationship plus 10 years, as required by Swiss statutory retention obligations for invoices and commercial records (OR Art. 958f).
- Connection logs (IP address, user-agent) from license heartbeats and activations: 90 days rolling retention, then automatically deleted. Raw web-server access logs for sentrikat.com are separately managed by host-level log rotation, 30 days.
- Activation metadata (hostname, OS info, IP, user-agent, KB-state telemetry): Retained while the activation is active. Deleted immediately when the activation is deactivated, whether by the customer or by us freeing the seat on their request; the seat-history record itself (that an activation existed, when) is kept for the duration of the license relationship for billing and support continuity.
- KB mapping contributions: Retained indefinitely as part of the community knowledge base. Contributions are identified only by the contributing installation's own identifier, never by name, email, or company.
- Newsletter subscription data: Retained until you unsubscribe or withdraw consent.
8. Your Rights
8.1 Under Swiss nDSG
Under the Swiss Federal Act on Data Protection (nDSG), you have the following rights:
- Right of access (Art. 25 nDSG), obtain information about whether and how we process your data
- Right to data portability (Art. 28 nDSG), receive your data in a commonly used electronic format
- Right to rectification, correct inaccurate or incomplete data
- Right to erasure, request deletion of your data where processing is no longer justified
- Right to object, object to processing in certain circumstances
- Right to withdraw consent, where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing
8.2 Under EU GDPR
If you are located in the European Economic Area, the GDPR grants you additional rights (Art. 15–22), including the right to restriction of processing (Art. 18 GDPR) and the right to lodge a complaint with your local supervisory authority.
8.3 How to Exercise Your Rights
To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days of receiving your request.
8.4 Right to Lodge a Complaint
You have the right to lodge a complaint with the competent supervisory authority. For Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC / EDÖB). If you are located in the EEA, you may also lodge a complaint with your local data protection authority.
9. Security Measures
We implement appropriate technical and organizational measures to protect your personal data, including:
- TLS encryption for all connections to sentrikat.com and license.sentrikat.com
- Encryption at rest for the licensing and portal database (AES-256, LUKS/dm-crypt volume), and for its off-site backups before they leave our infrastructure
- Access control, access to personal data is limited to the Data Controller only
- Secure payment processing, payment data is handled entirely by Stripe and never stored on our servers
11. Children's Privacy
Our services are intended for business use and are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us immediately at [email protected] and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will post the revised policy on this page and update the "Last updated" date. For material changes, we will notify affected customers by email. We encourage you to review this page periodically.
13. Contact
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
Denis Sota
Via Lucomagno 97, 6715 Dongio, Switzerland
Email: [email protected]