Privacy Policy

Privacy Policy

EFFECTIVE: 2026-05-10  //  CONTACT: [email protected]  //  sentovasecurity.com

Sentova is a cybersecurity consultancy. We assess, build, and defend the systems our clients depend on, and we run security operations on their behalf around the clock. That work puts us close to some of the most sensitive data an organisation holds, including the records that would help an attacker if they ever leaked. A firm in our line of work cannot ask others to take data protection seriously and then treat its own carelessly, so this policy is written to hold us to the same standard we set for clients.

It covers sentovasecurity.com and every service we provide, from a one-time risk assessment to fully managed monitoring. Where a section deals with the security data we handle for clients, the rules in your engagement contract come first; this policy fills in the rest.

What This Policy Covers

The policy speaks to personal data: information that identifies or relates to a person. Much of what we touch in security work is technical rather than personal, such as configuration files or firewall rules. But security data often contains personal elements too, like the username behind a login event or the IP address behind a connection, and those parts are covered here.

It does not cover the internal security practices we agree with each client under contract, nor the confidential findings of an assessment. Those are governed by the engagement terms and our confidentiality commitments, described further below.

The Distinction That Decides Your Rights

Whether Sentova or the client controls a given piece of data changes what you can ask of us.

For data about visitors, prospects, and the people who contact us through the site, Sentova decides the purposes and means. We are the controller, and the rules here apply to us directly.

For the security data inside a client’s environment, the client is the controller. When we monitor their network, scan for vulnerabilities, or investigate an incident, we act as a processor under their written instructions. If you are an employee or user of a client and you want data changed or removed, the client is the right place to start, and we support their response.

Information You Give Us Directly

When you use the enquiry form, request an assessment, or email us, we receive what you choose to send: your name, work email, phone number, company, role, and the details you share about your environment and concerns. A short note of caution that fits our field in particular: please do not send specific vulnerability details, network diagrams, or live credentials through the public contact form. Tell us you have a concern and we will move the technical detail onto a secure channel.

Information Collected Automatically

Our website records ordinary technical data as you use it: IP address and rough location, browser and device type, pages viewed, and how you arrived. We use it to operate the site, keep it secure, and understand which content is useful. On a security firm’s own site this data also feeds our own monitoring, so we may retain certain access logs longer than a typical marketing site would, for the purpose of detecting and investigating abuse.

Client Security Data We Access and Monitor

This is the part unique to security work, and it carries the highest sensitivity, so it gets the most detail.

Logs, Telemetry, and Monitoring Data

Running a security operations service means ingesting and analysing large volumes of log and event data from a client’s systems. This data routinely contains personal elements such as usernames, IP and device identifiers, authentication events, file and resource access, email metadata, and records of user activity. We process it to detect threats, investigate alerts, and report on the client’s security posture.

Vulnerability and Penetration Testing Findings

When we test a client’s defences, the output is a map of their weaknesses. It may reference systems, accounts, and occasionally the personal data we were able to reach during a controlled test. These findings are treated as among the most confidential material we hold, because in the wrong hands they are a set of directions for an attacker.

Incident and Breach Data

During an incident we may examine compromised systems, attacker activity, and the data involved, which can include the personal data of a client’s customers or staff. We handle this only to investigate, contain, and remediate the event, and to help the client meet any duty to notify regulators or affected people.

Security Awareness and Phishing Simulation Data

Where a client asks us to run awareness training or simulated phishing, we process data about how their employees responded, such as who opened a test message or entered details into a controlled page. This is used to measure and improve the client’s resilience, not to single out or penalise individuals, and the client directs how results are used.

How We Treat Confidential Security Information

Everything in the section above is the client’s, not ours. We access only what a task requires, under the least privilege needed to do it. We do not reuse a client’s security data for any other client, we do not publish or share findings outside the agreed scope, and we return or destroy the material at the end of the engagement on the contracted timeline. Knowledge of a client’s vulnerabilities stays with the small team assigned to that account. Where we describe our work publicly, we do so in general terms that cannot be traced to a client without their written agreement.

Why We Process Personal Data

Each category of data has a defined use. Enquiry details let us respond and scope work. Contact information supports project communication and, with consent, occasional security updates. Site and log data keep our own infrastructure safe. Client security data exists to deliver the protective service the client engaged us for: detection, investigation, testing, response, and reporting. We also process data where the law requires it or where we must defend our rights. For much of our security monitoring, the lawful basis is the legitimate interest in keeping systems and people safe, which we balance against individual rights.

Automated and AI-Driven Security Analysis

Security at scale is not possible by hand, so we use automated and AI-assisted tools to detect threats, triage alerts by severity, score risk continuously, and flag policy drift. These tools analyse personal elements within log data, such as user and device behaviour, to tell normal activity apart from an attack.

We are direct about what this means. These systems raise alerts and prioritise them; a human analyst reviews anything that leads to a consequential action, such as isolating an account or escalating an incident. They are not used to make standalone decisions that produce legal effects on an individual. If you are a user of a client and an automated security action affected you, the client controls that environment, so raise it with them and we will assist. We do not use one client’s data to train models for another.

Sharing and Disclosure

We do not sell personal data. Beyond the subprocessors listed below, disclosure is limited to defined cases. We disclose data when the law, a regulator, or a court requires it. We disclose it to investigate or respond to a security incident, which can include sharing technical indicators of an attack, stripped of unnecessary personal detail, with threat-intelligence communities or law enforcement. We disclose it to defend our legal rights or protect people from harm. And in a sale or merger, records would transfer to a buyer bound by protections no weaker than these, with notice to you.

Subprocessors and Security Platforms

Our service is delivered through specialised platforms and a few operational tools. Your data may sit with or pass through:

  • Security platforms we deploy and operate, including CrowdStrike, Palo Alto Networks, Fortinet, Splunk, SentinelOne, and Microsoft Defender
  • Log aggregation, threat-intelligence, and analysis services used to run monitoring
  • Hosting, email, and scheduling tools we use to run the firm and communicate with you

Each provider operates under its own privacy and security terms. Given our field, we hold subprocessors to a high bar and bind them to use shared data only for the agreed task.

How Long We Keep Data

Retention depends on the data. Contact and enquiry records are kept for up to two years after your last interaction, then removed. Security logs and monitoring data are retained for the period set in the client contract and any applicable regulation, which for some frameworks runs to a year or more, because investigating an intrusion often depends on historical records. Incident and forensic data may be held under legal hold while a matter is open. When a deletion would undermine an active investigation or a legal duty, we keep the minimum necessary and remove the rest. De-identified statistics may be kept without a fixed end date.

How We Protect Data

We apply strong technical and organisational safeguards, as you would expect from a security firm, and we will describe them plainly rather than dress them up. Data is encrypted in transit and at rest. Access follows least privilege and is logged and reviewed. Staff are vetted and trained, multi-factor authentication is required for our systems, and we test our own defences the way we test a client’s. Engagements run with strict separation between client environments.

Even so, no system is beyond compromise, and a security company claiming perfect safety would be the least trustworthy of all. We reduce risk; we do not pretend to eliminate it. Protect your side too, and tell us immediately if you suspect a problem on a system we operate with you.

If a Breach Happens

We hold ourselves to the duty we help clients meet. If a security incident affects personal data we control, we will investigate without delay, contain it, and notify affected people and the relevant authorities within the timeframes the law requires. Where an incident touches data we process for a client, the client is the controller and leads notification, and we provide the technical facts and support they need to comply. We will not stay silent to protect our reputation.

Cookies

Our site uses a small set of cookies: strictly necessary ones that run security and forms, analytics cookies that show how the pages perform in anonymised form, and preference cookies that remember simple settings. Your browser can block or delete them, and where consent is legally required for non-essential cookies, we ask first.

Your Rights

You can ask to access the data we hold on you, get a copy, correct it, delete it, restrict or object to its use, or withdraw consent. Email [email protected] to start, and we will verify your identity before acting. One honest limit specific to our work: where data sits in security logs or incident records, we may be unable to delete it on request, because retaining it can be necessary to defend systems or required by law. We will explain when that applies rather than refuse without reason.

EEA, UK, and Switzerland

We process personal data on a lawful basis: consent, a contract, a legal obligation, or a legitimate interest such as protecting systems, weighed against your rights. Consent, where relied on, can be withdrawn at any time without affecting earlier processing. You may also complain to your national data protection authority.

California

Under the CCPA and CPRA you can request the categories and pieces of personal information we collected, ask for access, deletion, or correction, and opt out of any sale or sharing. We do not sell personal data, and exercising your rights will not get you treated differently. Security log retention may limit deletion as noted above.

International Transfers

Sentova and some providers operate across borders, the United States included, where privacy law may differ from your own. For international transfers we apply recognised safeguards such as Standard Contractual Clauses or rely on an adequacy decision. Using the site means you understand this can occur.

Children

This service is for organisations and is not directed to anyone under 16. We do not knowingly collect children’s data and will delete it if we discover we have. A parent or guardian with a concern can write to [email protected].

Links to Other Sites

Our pages may link to platforms, advisories, or resources we do not operate. This policy ends at our boundary. Once you follow a link elsewhere, that site’s own policy applies, so review it before sharing anything.

Updates to This Policy

We revise this policy as our services and the law change. The current version sits on this page with its effective date, and we make a reasonable effort to flag significant changes. Continuing to use the site after an update means the new version applies to you.

Contact

For any privacy question, request, or complaint, reach us directly. For sensitive security matters, ask us for a secure channel before sending detail.