YOUR DATA
Privacy policy
Last updated: 22.06.2025
Introduction
Welcome to Sentivio! This Privacy Policy explains how Sentivio (“we”, “us”, or “our”) collects, uses, and protects your personal data when you use our website and services (the “Service”). Sentivio provides stock market sentiment reports and dashboards. We are committed to safeguarding the privacy of our users in the United States, European Union, and worldwide.
Sentivio is currently developed and operated by a sole developer based in Poland, with plans to incorporate as Sentivio sp. z o.o. (a Polish limited liability company). For the purposes of data protection laws (such as the EU General Data Protection Regulation or “GDPR”), Sentivio acts as the Data Controller of your personal data. This means we determine how and why your personal data is processed. We do not currently have a dedicated Data Protection Officer given our small size, but you can contact the developer directly with any privacy questions (see Contact Us below).
By using Sentivio, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Service. We may update this Policy from time to time (see Changes to This Policy below).
Note: Sentivio is intended for users aged 18 and older. We do not knowingly collect personal information from anyone under 18. If you are under 18, please do not use the Service or provide any information. If we learn that we have collected information from a child under 18, we will delete it. If you believe a minor has provided us personal data, contact us so we can take appropriate action.
Information We Collect
We aim to collect only the data that is truly needed to operate and improve Sentivio. This section describes what personal information we collect and how we collect it.
- Information You Provide to Us:
- Account/Profile Data: When you sign up or log in using your Google account (via Firebase Authentication), we receive certain information from Google. This includes your name or display name, email address, and a unique user ID (Firebase UID) associated with your profile. We store this profile information to create and manage your user account on Sentivio.
- Subscription and Payment Data: If you choose to subscribe to a paid plan, we will record your subscription plan details (e.g., plan level, status, start and end dates). Payment processing is handled by Stripe, so we do not collect or store your full credit card numbers or billing details. (Stripe may collect your payment information directly; see Third-Party Service Providers below.) We may store a Stripe customer ID or subscription ID linked to your account, as well as basic transaction details (like payment amount and date) to manage your subscription and fulfill our financial records obligations.
- Communications: If you contact us directly (for example, via email or a contact form), we will collect the information you provide in your message (such as your name, email address, and the content of your inquiry). We use this information to respond to you and assist with your request.
- Information We Collect Automatically:
When you use Sentivio or interact with our API, we automatically collect certain technical information to help us run and secure our Service. This Log Data may include:
- Usage Logs: We record details of the requests you make to our servers, such as the date and time of access, the specific API endpoint or webpage requested, the HTTP method used (e.g., GET, POST), and your response status (success or error code).
- IP Address: We collect your Internet Protocol (IP) address as part of each request. IP addresses can indicate the general region or city from which you access the Service. We use IP addresses for purposes like detecting and preventing abuse (for example, blocking malicious traffic or rate-limiting excessive requests) and for troubleshooting network issues.
- Device and Browser Information: We collect information about the device and browser you use to access Sentivio. This includes your browser type and version, operating system, and user agent string. This data helps us ensure our Service is compatible with users’ systems and aids us in diagnosing technical problems.
- Firebase UID (in logs): If you are logged in while using the Service, our logs may include your Firebase user ID along with your requests. This helps us associate log entries with user accounts when necessary (for example, to investigate a specific user’s issue or to enforce rate limits per user). If you are not logged in, no user identifier is associated with the log entry aside from the IP and device info.
- Cookies and Similar Technologies: When you visit our website, we may use “cookies” or similar tracking technologies to remember your preferences and authenticate your session. Cookies are small text files stored on your browser. For example, once you log in, a cookie (or an equivalent token stored by Firebase) might be used to keep you logged in as you navigate the site. We do not use any third-party analytics or advertising cookies. We only use essential cookies necessary for security and to provide core functionality (such as keeping you logged in). See Cookies & Tracking below for more details on our use of cookies and how you can control them.
We do not collect any sensitive personal data about you such as your race, ethnicity, political opinions, religious beliefs, health information, or biometric data. We also do not intentionally collect any data about your exact geolocation (other than the general location that might be derived from your IP address) or any data about your social media contacts, etc. Our goal is to keep data collection minimal and relevant to providing the Service.
If you choose not to provide certain personal data (for example, if you do not allow us to collect your email by logging in, or if you refuse to provide payment information for a subscription), you may not be able to use the full functionality of Sentivio. For instance, you cannot use our personalized features or access paid reports without creating an account and providing the necessary information.
How We Use Your Information
We use the collected information for the following purposes, and we ensure that such use is compatible with the reasons you provided it to us or we collected it (as described above):
- To Provide and Maintain the Service: We process your personal data so that you can use Sentivio’s features. For example, we use your Firebase UID and email to create and maintain your user account, so you can log in with your Google account. Your subscription plan information is used to determine which features you can access and to enforce any usage limits or quotas associated with your plan. Essentially, we use your data to operate the Service and deliver the functionality you expect (such as generating stock sentiment reports and dashboards tailored to your account).
- Authentication and Security: Your login information (via Firebase) allows us to authenticate you and secure your account. We use cookies or similar tokens to keep you logged in during a session and to prevent unauthorized access to your account. We also use log and device information (like IP addresses and user agents) to protect the security of the Service, user accounts, and our infrastructure. This includes detecting suspicious or malicious activity (for example, to identify if a single IP is making a huge number of requests, which might indicate a bot or attacker) and preventing abuse of our APIs.
- Service Performance and Improvement: We analyze usage logs and performance data to understand how the Service is used and to find ways to improve it. For example, log data can help us debug errors, measure response times, and optimize our backend performance. It can also inform us if certain features are heavily used (or not used), guiding future improvements. Importantly, we use aggregated or anonymized data whenever feasible for analytics, and we do not use personal data for any intrusive profiling. Our goal is to continuously make Sentivio faster, more reliable, and more useful, using the minimal data necessary.
- Customer Support and Communications: If you reach out to us with questions, feedback, or support requests, we will use your contact information and communication history to respond to you. We may also send you administrative emails when necessary, such as notifications about important changes to the Service, privacy policy updates, or information about your account or subscription (for example, confirmation of a successful payment or notice of an upcoming subscription renewal). We do not send marketing or promotional emails unrelated to the Service unless you explicitly opt-in to such communications (and as of now, we have no separate marketing newsletter).
- Manage Subscriptions and Payments: We use your profile and Stripe transaction information to manage billing and subscriptions. For instance, we might send a notice if your subscription is about to expire or if there’s an issue with a payment. We keep track of who our paying customers are (by email/UID and plan) so that paid features can be enabled and billing issues resolved. Payment data is handled securely by Stripe, but we maintain records of payments for accounting, auditing, and tax compliance (e.g., to generate purchase receipts and comply with financial regulations).
- Legal Compliance and Protection: In certain cases, we may need to process and retain personal information to comply with legal obligations or to protect our rights. For example, we could use data to comply with a valid legal request (such as a court order), to enforce our Terms of Service or other agreements, or to detect and prevent fraud or security issues. We may also use data to establish or exercise our legal rights or defend against legal claims. This kind of processing will occur only when necessary and in accordance with applicable laws.
We will not use your personal data for purposes that are not compatible with the above, unless we obtain your consent or have a legal obligation to do so. In particular, we do not sell your personal information to any third parties, and we do not use your data to profile you for advertising or marketing purposes. Sentivio’s use of data is strictly limited to running our Service and serving our users.
Legal Bases for Processing (GDPR)
If you are located in the European Economic Area (EEA) or another jurisdiction with similar data protection rules, we must inform you of the legal grounds on which we process your personal data under the GDPR (General Data Protection Regulation). We rely on the following legal bases:
- Performance of a Contract: Most of our data processing is justified by the fact that it is necessary to provide the Service that you request. When you create an account, use Sentivio, or subscribe to a plan, you enter into a contractual relationship with us (even if the service is free). We need to process your data (like your login credentials, account info, and subscription details) to fulfill our obligations under that contract – for example, to authenticate you, deliver content, and provide the features you are entitled to. If you purchase a paid subscription, processing your payment information and enabling your premium access is also necessary for performing our contract with you. Without this information, we cannot provide you with the Service.
- Legitimate Interests: We also process certain data as necessary for our legitimate interests, provided those are not overridden by your data protection rights. We have a legitimate interest in keeping our Service secure, preventing fraud/abuse, and improving our product’s performance and usability. For example, collecting and analyzing usage logs, IP addresses, and device info helps us detect misuse and optimize our Service. We consider these processing activities to have a minimal impact on your privacy (especially since they often involve aggregated data and are not used to profile or market to you). We always balance our interests against your rights and will not rely on this basis if we determine your privacy interests outweigh ours.
- Legal Obligation: In some cases, we must process certain personal data to comply with a legal obligation. For instance, as a business, we may need to retain transaction records (which could include personal identifiers like your email or Stripe customer ID) for accounting and tax purposes, or to comply with financial regulations and audit requirements. If we are required by law enforcement or a court order to disclose data, processing your data for that purpose would also fall under legal obligation. We will only do so when strictly necessary and in accordance with applicable laws.
- Consent: Generally, we do not rely on consent as a legal basis for processing your personal data, because our processing is covered by the bases above (contract, legitimate interests, or legal obligations). However, if we ever need to collect or use your data in a way that requires consent (for example, if we wanted to send marketing emails, or use cookies beyond what is strictly necessary), we will ask for your consent and honor your choices. You have the right to withdraw your consent at any time if we have obtained it – for instance, you can opt out of marketing communications if you had subscribed to them (though again, we currently do not send such communications by default).
If you have any questions about the legal bases for processing or need more clarification, feel free to contact us. We want to ensure you understand why we collect and use your data under data protection law.
How We Share Your Information
We do not sell your personal information to anyone. We also do not share your data with third parties for their own independent marketing or advertising purposes. However, we do need to share some information with certain trusted third parties in order to run Sentivio, process payments, or comply with the law. The categories of recipients with whom we may share data are:
- Service Providers / Data Processors: We use a few third-party services to host our application, store data, authenticate users, and process payments. These third parties process data on our behalf and are contractually obligated to protect it and use it only for the purposes we specify. The primary services we use are:
- Firebase (Google Cloud): Sentivio is built on Google’s Firebase platform, which provides our authentication system (Google login), database, and hosting infrastructure. This means that personal data such as your user profile (UID, email, name) and usage logs are stored on Firebase/Google Cloud servers. Google acts as our data processor for these services. We have agreements in place (including a Data Processing Addendum) to ensure that Google handles this data in compliance with GDPR and other applicable laws. Google will not use your data for any purpose except to provide the services we request (for example, storing it and making it available to us in our application). For more information, you can review the Google Privacy Policy which covers Firebase services.
- Stripe (Payment Processor): We use Stripe to handle all credit card payments and subscription billing. When you enter payment information, it is transmitted directly to Stripe over an encrypted connection; we do not see or store your sensitive payment card details on our servers. Stripe processes your payment and gives us a confirmation (so we know if a payment succeeded, and we can activate your subscription). Stripe may store your card information and billing details securely to facilitate payment processing and compliance with financial laws. Stripe acts as a “service provider” (under CCPA terms) or “processor” (under GDPR) for us in this context. We have a data processing agreement with Stripe as well. Stripe will only use your information for processing payments and related purposes (like fraud prevention). For more details, please see Stripe’s own privacy policy: Stripe Privacy Policy.
- Other Vendors: Apart from Firebase and Stripe, we currently do not use additional third-party analytics or advertising services. We do not use Google Analytics or any social media plugins that would share your data. In the future, if we engage other trusted vendors (for example, a service to send emails or a cloud backup service), we will update this policy accordingly and ensure any such vendor is bound by strict privacy and security obligations.
- Business Transfers: If Sentivio (or the planned Sentivio sp. z o.o. company) is involved in a merger, acquisition, investment, financing, or sale of all or a portion of its assets, your data may be transferred to the new owner or partner as part of that transaction. We would only do this if the recipients commit to respect your personal data in a manner consistent with this Privacy Policy. You would be notified (for example, via a prominent notice on our site or an email) of any change in ownership or uses of your personal information, as well as any choices you may have regarding your personal information in that event.
- Legal Compliance and Safety: We may disclose personal information to courts, law enforcement agencies, government authorities, or other third parties when we believe it’s required to:
- Comply with applicable laws, regulations, legal processes, or enforceable governmental requests (such as a subpoena or court order).
- Enforce our Terms of Service or other agreements, investigate potential violations, or protect the security and integrity of our Service.
- Protect the rights, property, or safety of Sentivio, our users, or the public, as required or permitted by law.
- Detect or resolve fraud or security concerns (for example, we might share limited information with an anti-fraud service or with law enforcement if we detect fraudulent activity).
In all cases of data sharing, we only share the minimum amount of information necessary for the purpose. When we share data with service providers, they cannot legally or contractually use it for anything besides providing services to us (and ultimately to you). We do not allow our service providers to use your personal data for their own marketing or other purposes.
Aside from the situations above, we will not disclose your personal data to anyone else unless we have your consent to do so. If we ever want or need to share your information for any new purpose, we will notify you and obtain consent as required by law.
International Data Transfers
Sentivio is based in Poland (within the European Union), but we serve users around the world, including in the United States and other countries. Your information may be transferred or stored across international borders in the course of providing our Service. Specifically:
- Within the EU: If you are an EU/EEA user, know that your data is primarily stored on servers located in the region appropriate to our Firebase hosting. We aim to use EU-based servers when possible. However, some of our service providers (like Stripe or certain Firebase services) might process data in other countries (for example, the United States).
- Outside the EU: If you are outside of Europe, your data will likely be transferred to and stored in the EU (because that’s where our base of operations is) and also in the United States (because Stripe is a U.S.-based company, and Google’s infrastructure spans global regions including the U.S.). Similarly, data may be accessed by our developer in Poland or any future team members in Poland or potentially other countries in the course of operating the Service.
Regardless of where your data is processed, we protect your information under the same privacy standards described in this Policy. When we transfer personal data out of the European Economic Area or United Kingdom, we ensure a level of protection equivalent to that under EU law. We take one or more of the following precautions for international transfers:
- Adequacy Decisions: If the data is sent to a country that the European Commission has recognized as providing an adequate level of data protection, we rely on that decision (for example, transfers to countries under the EU-U.S. Data Privacy Framework or other adequacy frameworks, once applicable). Both Stripe and Google have implemented measures to comply with EU data transfer requirements (Stripe, for instance, has certified under the EU-U.S. Data Privacy Framework and also offers Standard Contractual Clauses for data transfers).
- Standard Contractual Clauses (SCCs): We incorporate the European Commission’s approved Standard Contractual Clauses into our agreements with service providers like Stripe and Google to contractually require that your personal data receives an equivalent level of protection even if stored or processed in the U.S. or another country outside the EU. These clauses impose data protection obligations on the recipient and give you enforceable rights.
- Other Safeguards: We also ensure that our service providers maintain robust security and privacy practices (such as encryption and access controls) that align with EU requirements. In some cases, we may ask for your explicit consent for the transfer if no other legal transfer mechanism is available (though this is unlikely given the mechanisms above).
By using Sentivio, you understand that your personal data may be transferred to our servers and third-party partners in various countries, including the United States and Poland. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and applicable law. If you have questions about international data transfers or need more specifics on the safeguards we use, please contact us (see Contact Us section below).
Cookies & Tracking Technologies
In this section, we explain how we use cookies and similar technologies, as well as how we handle “Do Not Track” signals and other preferences.
Cookies: Cookies are small text files that websites store on your device to save information. When you use Sentivio, we (or our service providers) may place a few essential cookies in your browser for the following purposes:
- Authentication and Session Management: When you log into Sentivio, a cookie or secure token is set to keep you logged in as you navigate between pages. This saves you from having to re-enter your credentials on every page. It also helps us identify your account in order to deliver account-specific features (like your saved settings or subscription access).
- Preference Storage: We might use cookies to remember certain preferences (for example, if the application has UI settings like theme or language preferences, which currently it might not, but in future it could). This enhances your experience by recalling your choices without you having to set them each time.
- Security: Cookies (or similar technologies like local storage) can be used to implement security features, such as protecting access to certain areas of the site or helping detect unusual account behavior. For instance, a cookie might help prevent cross-site request forgery (CSRF) attacks by storing a token that the site checks.
Importantly, we do not use any advertising, marketing, or third-party analytics cookies on Sentivio. This means we are not tracking your browsing across other sites, nor are we feeding data to third-party marketing platforms. All cookies we use are first-party (set by sentivio.com) or come from our trusted processors (e.g., Firebase) strictly to provide the Service’s core functions.
Your Choices for Cookies: Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies or notify you when a cookie is being placed. Be aware that if you disable or delete cookies required for login or security, some features of Sentivio may not function properly. For example, you may not be able to stay logged in, or some pages might not display correctly. If you prefer not to have any tracking at all, you could use private browsing mode or configure your browser to block cookies, but you will need to log in fresh each time you use the Service.
At this time, because our cookies are all essential or strictly functional, we do not present a cookie consent banner. In the future if we introduce any non-essential cookies, we will implement appropriate consent mechanisms as required by law.
Log Files and Analytics: As described in Information We Collect, our servers automatically generate logs of usage activity. These logs record details like IP address, timestamps, and API endpoints accessed. We treat these logs confidentially; only our developer (and any future authorized team members) can view them, and they are used solely for the purposes outlined (troubleshooting, security monitoring, etc.). We do not use third-party analytics services like Google Analytics. Instead, any analysis of how users use Sentivio is done in-house on the aggregated log data. We do not tie log data to individual identities beyond what is necessary for service operation (for example, linking logs to a user ID for debugging or abuse investigation).
“Do Not Track” Signals: “Do Not Track” (DNT) is a setting in some web browsers that allows you to signal websites that you do not want to be tracked across different sites. Currently, there is no standard interpretation or enforcement of DNT signals across websites. Given that Sentivio does not engage in cross-site tracking or targeted advertising, we do not use data in a way that would be affected by DNT. In other words, whether or not you have DNT enabled, we are not tracking your browsing behavior outside of our own site, and we only use your data as described in this policy. As such, we currently do not respond to DNT signals differently; we simply limit our data usage for all users by default. If a standardized approach to DNT is established in the future, we will revisit this and update our practices accordingly.
Global Privacy Control: Similar to DNT, Global Privacy Control (GPC) is a proposed browser signal that can communicate a user’s privacy preferences (specifically related to CCPA/CPRA opt-out of sale/sharing). We do not “sell” or “share” personal information for behavioral advertising (see California Privacy Rights below), so GPC signals have no effect on data practices that we don’t engage in. Nonetheless, if we detect a GPC signal from a California resident’s browser, we will treat it as an opt-out request for sale/sharing of data (even though we don’t perform those activities in the first place, the confirmation won’t harm).
In summary, our use of cookies and logs is minimal and purely for running Sentivio effectively. We respect your privacy choices to the extent applicable, but since we avoid non-essential tracking, our site behaves the same for all users – prioritizing privacy by design.
Data Retention
We retain personal data only for as long as it is necessary to fulfill the purposes described in this Privacy Policy, or as required by law. The length of time we keep information varies depending on the type of data and the purpose for which we collected it:
- Account Information: If you have a Sentivio account, we will keep your profile data (such as your email, name, and account UID) for as long as your account is active so that we can provide you the Service. If you choose to delete your account or if we close your account due to inactivity or other reasons, we will remove or anonymize your personal data from our active databases. (At the moment, account deletion is not self-service via the app, but you can request deletion—see Your Rights below—and we will handle it manually.) We may retain your email or UID in a suppression list if needed to honor opt-outs or to prevent fraud (for example, to ensure a former user’s email is not re-registered maliciously), but we will not use it for other purposes after deletion.
- Usage Logs: Our server and API logs, which include IP addresses and activity information, are typically retained for a limited period. We generally keep log data for a short period, e.g. 30–90 days unless we need to retain it longer to investigate a specific incident (such as a security breach or an abuse report). After that, log entries are deleted or aggregated. We might retain aggregated, non-identifiable statistics about Service usage (for example, total number of requests per month) for a longer period to track growth and performance, but those statistics will not contain personal data.
- Subscription and Transaction Records: We retain records of your subscriptions and payments as long as you are a subscriber and for a certain period after. This is both to manage your ongoing subscription and because we may have legal obligations to keep financial records. For example, under Polish accounting and tax laws, we might need to keep invoices or payment records for 5 years (or whatever duration local law requires) from the end of the financial year in which the transaction occurred. These records may include personal data such as your name, email, Stripe customer ID, and the subscription details, but we will only use them for bookkeeping, audits, and handling any disputes/refunds. After the required retention period passes, we will securely delete or anonymize these records.
- Communication Data: If you contacted us via email or support channels, we may retain those communications for a period of time to ensure we have a history of support interactions (this can help in providing you better service if you contact us multiple times). Typically, we might keep support emails for up to a couple of years, unless you request deletion sooner. In any case, we will not use those communications for purposes other than addressing your inquiry and improving our support processes.
- Backup Copies: Please note that even after data is deleted from our primary systems, it may persist for a short time in routine backups. We maintain backups for disaster recovery and business continuity purposes. Backup data is encrypted and secured; it is only accessed if needed for restoration. We have processes to delete or overwrite old backups, so backup retention is time-limited. If we restore data from a backup, we will re-delete any data that had previously been deleted from the live system, to the extent feasible.
After the retention periods above expire, or once we have no ongoing legitimate need to process your information, we will either delete your personal data or anonymize it (so it can no longer be associated with you). If deletion or anonymization is not immediately possible (for example, because the data is stored in archived backups), we will securely store and isolate the data from any further use until deletion is possible.
Data Security
We take the security of your personal data very seriously. We implement appropriate technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. Here are some of the security practices we follow:
- Encryption: The Sentivio website and API use HTTPS (TLS encryption) for all data in transit. This means that any data transferred between your device and our servers (including your login credentials and any data you view or download) is encrypted and cannot be easily intercepted by third parties. Additionally, our database and storage (through Firebase/Google Cloud) encrypts data at rest. In simple terms, your data is protected both when it’s moving and when it’s stored.
- Access Controls: Access to personal data is strictly limited. As a solo-developed service, only the developer/administrator has direct access to user data, and this access is protected by strong authentication (e.g., strong passwords and two-factor authentication where available). In the event our team grows, we will ensure that any personnel or contractors with access to personal data are bound by confidentiality obligations and have been trained on proper data handling. Each service provider we use (Google, Stripe) also employs industry-standard access controls on their systems.
- Secure Development Practices: We develop and update Sentivio with security in mind. This includes practices like regular software updates, using secure coding techniques to prevent common vulnerabilities (such as SQL injection, XSS, etc.), and routine testing/monitoring for potential security issues. We use Firebase’s built-in security features (like security rules for database access) to ensure that user data can only be accessed by authorized requests.
- Monitoring and Auditing: We monitor our systems for suspicious activity and have logging in place for security-relevant events. If any unusual behavior is detected (such as repeated failed logins or unexpected spikes in usage), we investigate promptly. We also keep our server software and dependencies up to date with the latest security patches to minimize risks.
- Stripe Security: For payment processing, we rely on Stripe, which is a PCI-DSS Level 1 compliant payment processor (the highest level of payment data security). Your payment details are handled by Stripe’s secure infrastructure. We never transmit or store your full credit card information on our systems, as all payment forms are hosted by or iFramed from Stripe in a secure manner. (We only receive tokens or references that indicate a payment was made.)
- Incident Response: Despite all efforts, no method of transmission over the internet or electronic storage is 100% secure. In the unlikely event of a data breach or security incident that affects your personal data, we will act promptly to contain the issue and mitigate any harm. We will also notify you and the appropriate authorities as required by law. For example, under GDPR we would inform the relevant supervisory authority (and if necessary, you as well) within 72 hours of becoming aware of a significant personal data breach. Similarly, we would adhere to any applicable breach notification laws in the US (such as state laws requiring notice to affected individuals).
We also encourage you to take steps to protect your own account and data. Never share your account’s login credentials (your Google account details) with others, and use a strong, unique password for your Google account. Keep your devices secure and updated. If you suspect any unauthorized access to your Sentivio account or experience any security issues, please notify us immediately so we can help secure your account.
In summary, we strive to use industry best practices to keep your data safe. However, if you have specific questions about security or if you need to report a vulnerability, you can reach out to us via the contact information below.
Your Rights and Choices
Depending on your jurisdiction, you have certain rights regarding your personal data. Sentivio is committed to honoring these rights and providing you with appropriate control over your information. This section outlines the data protection rights available to you, especially if you are in the European Union (GDPR) or in California (CCPA/CPRA), and how you can exercise them.
Rights Under GDPR (for EU/EEA Users)
If you are located in the European Union, European Economic Area, or a comparable jurisdiction, you have the following rights under the GDPR and local data protection laws:
- Right to Access: You have the right to request a copy of the personal data we hold about you, and to obtain information about how we process it. This is sometimes called a “Data Subject Access Request.” We will provide you with a copy of your data in a commonly used format (unless doing so adversely affects the rights of others, or your request is unfounded or excessive).
- Right to Rectification: If any of your personal data is inaccurate or incomplete, you have the right to ask us to correct or update it. For example, if you believe we have an incorrect email address or if your name is misspelled in our records, you can request a correction. We strive to keep your data accurate and will make corrections as soon as possible.
- Right to Erasure (Right to be Forgotten): You have the right to request the deletion of your personal data in certain circumstances. You can request that we erase your data, for example, if it’s no longer needed for the purposes we collected it, or if you withdraw consent (in cases where we rely on consent) and have no other legal ground for processing. Note that this right is not absolute – sometimes we may have legal obligations or compelling legitimate interests to retain some data (e.g. financial records that must be kept for auditing, or logs needed for security). However, we will honor deletion requests to the fullest extent required by law. If you want to delete your Sentivio account and associated data, please contact us (since there is no in-app delete button yet) and we will process your request. Deletion of your data will be permanent (aside from possible retention in backups for a short time, from which it will be erased in due course).
- Right to Restrict Processing: You have the right to ask us to limit the processing of your data in certain cases. For instance, if you contest the accuracy of your data, you can request we restrict processing until we verify and correct it. Or if you object to processing based on our legitimate interests, you can request restriction while we assess whether our interests override yours. When processing is restricted, we will store your data but not use it (except, for example, to establish legal claims or with your consent).
- Right to Data Portability: You have the right to obtain your personal data in a structured, commonly used, machine-readable format and to have that data transmitted to another controller, where technically feasible. This typically applies to data you provided to us and that we process by automated means based on your consent or on a contract. In practical terms, should you request it, we can export certain account data (like your profile info and perhaps any data you’ve inputted into Sentivio, if applicable) in a standard format so that you could import it into another service.
- Right to Object: You have the right to object to our processing of your personal data when that processing is based on legitimate interests (or on the performance of a task in the public interest/exercise of official authority). If you object, we will evaluate your request and will stop or limit processing unless we have compelling legitimate grounds that override your interests or if we need to continue processing for the establishment or defense of legal claims. You also have the absolute right to object to any processing of your data for direct marketing purposes – however, note that Sentivio does not engage in direct marketing with your data.
- Right to Withdraw Consent: In the rare cases where we rely on your consent to process personal data, you have the right to withdraw that consent at any time. Withdrawing consent will not affect the lawfulness of processing based on consent before its withdrawal. If in the future we ask for consent (for example, to send an optional newsletter), you can opt out later by unsubscribing or contacting us.
- Right to Lodge a Complaint: If you believe we have infringed your data protection rights or failed to comply with GDPR, you have the right to lodge a complaint with a supervisory data protection authority. You may do this in the EU member state where you reside, work, or where the alleged infringement occurred. For example, in Poland (where we are based), the supervisory authority is the President of the Personal Data Protection Office (UODO). Contact information for local authorities can be found here. We would, however, appreciate the chance to address your concerns directly before you approach a regulator – so please feel free to contact us with any issue, and we will do our best to resolve it.
California Privacy Rights (CCPA/CPRA)
If you are a resident of California, you are protected by the California Consumer Privacy Act (CCPA) of 2018, as amended by the California Privacy Rights Act (CPRA) of 2020. These laws provide California consumers with specific rights regarding their personal information. Below is a summary of those rights and how you can exercise them:
- Right to Know (Access): You have the right to request that we disclose what personal information we have collected about you over the past 12 months, including the categories of personal information, the categories of sources of that information, the business or commercial purpose for collecting it, the categories of third parties with whom we share the information, and specific pieces of personal information we hold about you. (Much of that information is already provided in this Privacy Policy.) Upon a verifiable request, we will provide a report of the personal information we have about you in a readily usable format, generally covering the 12 months preceding your request.
- Right to Delete: You have the right to request that we delete personal information we collected from you and retained, subject to certain exceptions. Once we receive and confirm a verifiable deletion request, we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies. Note that we may deny deletion requests if retaining the information is necessary for us or our service providers to complete a transaction you requested, to detect security incidents or protect against malicious activity, to comply with a legal obligation, or other reasons allowed by the CCPA. We will inform you of any such exceptions that apply. In practice, this right is very similar to the GDPR right to erasure – California residents can contact us to have their Sentivio account and data deleted.
- Right to Correct: Under the CPRA amendments, California residents have the right to request correction of any inaccurate personal information we hold about them. If you become aware that any information is incorrect, please contact us with details of the inaccuracy, and upon verifying your identity, we will correct it (taking into account the nature of the information and the purposes of processing).
- Right to Opt-Out of Sale or Sharing: You have the right to opt-out of the “sale” of your personal information or the “sharing” of your personal information for cross-context behavioral advertising. However, Sentivio does not sell personal information to third parties for monetary value or any other consideration. We also do not share your personal information for targeted advertising purposes. In the last 12 months, we have not sold any personal information of our users, nor shared it for behavioral advertising. Because we do not engage in these practices, we do not display a “Do Not Sell or Share My Personal Information” link—there is nothing to opt out of. Rest assured that your data is not being sold or monetized in that way. If our practices change, we will update this policy and provide appropriate opt-out mechanisms.
- Right to Limit Use of Sensitive Personal Information: The CPRA introduced rights relating to “Sensitive Personal Information” (SPI). Examples of SPI include Social Security numbers, financial account info, precise geolocation, race/ethnicity, health data, etc. We do not collect or process sensitive personal information beyond what is necessary for providing the service (aside from perhaps a login identifier or IP, which are not considered SPI under CPRA, and any payment card info which we do not directly handle). Since we do not collect sensitive data beyond what is necessary for providing the service, there is no use of sensitive data to limit. If that changes, California users would have the right to direct us to limit the use/disclosure of their sensitive data to only what is necessary for providing the service.
- Right of No Retaliation (Non-Discrimination): We will not discriminate against you for exercising any of your CCPA rights. This means that if you choose to exercise your rights (such as requesting deletion or opting out of sale), we will not deny you our services, charge you different prices, or provide you a lower quality of service just because you exercised your rights. The only scenario where service might be affected is if your request inherently prevents us from providing it (for example, if you ask us to delete all your data, we cannot provide your account services afterward—but that’s a natural consequence, not a retaliatory action). We do not offer financial incentives in exchange for your data, so non-discrimination in that context is not applicable.
Exercising Your California Rights: To make any of the requests described above (access/know, delete, correct, etc.), please contact us using the information in the Contact Us section. Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information (or an authorized representative). This may include verifying control of the email associated with your account or other identifying details. We will respond to your request as required by CCPA, generally within 45 days (with an extension of 45 additional days if reasonably necessary, in which case we will let you know the reason for delay). If we cannot fulfill your request, we will explain the reasons (for example, inability to verify your identity, or the request falling under an exemption).
Authorized Agent: California residents can designate an authorized agent to make requests on their behalf. If you send an agent to exercise your rights, we will take steps to verify that the agent is properly authorized (for instance, we might request a signed authorization or proof of power of attorney, and we will still need to verify the identity of the person who is the subject of the data).
Shine the Light Law: Separately from CCPA, California’s “Shine the Light” law (Civil Code § 1798.83) allows residents to request certain information about what personal information is shared with third parties for their direct marketing purposes. Sentivio does not disclose personal information to third parties for their direct marketing purposes. Therefore, we do not have any such information to provide under Shine the Light. If you have questions about this, you can still reach out to us and we will provide any relevant details.
Additional Notes for Other Jurisdictions
While GDPR (EU) and CCPA (California) are the primary privacy laws we adhere to, we strive to respect privacy rights for all our users. If you are located in a region with similar laws (for example, other US states with privacy laws, or countries like Canada, Australia, etc.), you likely have rights to access or delete your data as well. We will do our best to accommodate any reasonable requests, regardless of residency, in line with the rights outlined above.
For example, residents of certain U.S. states (such as Virginia, Colorado, etc.) have rights similar to CCPA (access, delete, etc.). While it’s not explicitly listed for each state here, you can contact us to exercise any applicable rights and we will honor them as required. Similarly, if you’re in a country with data protection laws (like Brazil’s LGPD, Canada’s PIPEDA, etc.), you may contact us to exercise your rights under those laws.
How to Exercise Your Rights (All Users)
To make any privacy-related request (access, correction, deletion, etc.), please reach out to us via email at contact@sentivio.com (or see Contact Us below for additional contact options). Please clearly describe your request—what right you want to exercise and what data it concerns. We may need to verify your identity to ensure we do not give your data to someone else. Usually, verification will involve confirming control of your account email or other information we have on file. We will respond to your request within a reasonable timeframe, and in any event within the timeframes required by applicable law. There is no fee for making such requests, though if a request is manifestly unfounded or excessive (e.g., repetitive) we may charge a reasonable fee or refuse to act on it (as permitted by GDPR).
We value your privacy rights and will do our best to fulfill your requests and address any concerns. If you have any questions about your rights or how to exercise them, please let us know.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. When we make changes, we will modify the “Effective Date” at the top of this Policy to indicate when the revisions came into effect. For significant changes, we may also provide a more prominent notice of the update – for example, by posting a notification on our website or by emailing you (if you have provided an email address and not opted out of such notifications).
What constitutes a significant change? Examples include: if we start collecting new types of personal data not previously collected, if we begin using data for a new purpose that isn’t covered by this current Policy, if we begin sharing data with new types of third parties, or if we need to comply with a major change in law that affects your rights. In such cases, we will make sure you are informed and, if required by law, obtain your consent or give you an opportunity to review the changes before they apply to you.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. It’s important that you understand our current practices and your rights. If you continue to use Sentivio after any changes to this Policy, it will signify your acceptance of the updated terms (to the extent permitted by law). Of course, if you do not agree with the changes, you always have the choice to stop using our Service and/or exercise your rights (such as requesting deletion of your data).
For any prior version of this Privacy Policy, you may contact us to obtain a copy if needed. We maintain an archive of changes for record-keeping.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the way we handle your personal data, please do not hesitate to contact us. We are here to help and address any issues you might have.
Contact Information:
- Email: contact@sentivio.com
We will respond to your inquiries as soon as possible, typically within a few business days. If you are contacting us to exercise your data protection rights, please include sufficient information for us to verify your identity (such as the email associated with your account) and to understand the scope of your request.
Language: You can contact us in English or Polish. We will do our best to communicate in your preferred language or find appropriate resources to do so.
If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, you may also contact your local data protection authority (for EU users) or the relevant privacy regulatory body in your jurisdiction for further assistance.
Thank you for trusting Sentivio. We value your privacy and are committed to protecting it.
If you do not agree with any part of this Privacy Policy, please do not use Sentivio.