Privacy Policy

Last updated: September 2026

This is a convenience translation of the German original (sentrivo.at/datenschutz). In case of discrepancies, the German version prevails.

Protecting your personal data is important to us. We process your data exclusively on the basis of the statutory provisions (GDPR, Austrian Data Protection Act (DSG), Austrian Telecommunications Act (TKG 2021)). This policy informs you about the nature, scope and purpose of processing on the website and platform sentrivo.org / sentrivo.at.

1. Controller

Gerhard Kienbauer
Riedauerstraße 4, 4753 Taiskirchen im Innkreis, Austria
Email: team@sentrivo.at

2. Roles for business customers

Sentrivo is a platform for businesses. When a company registers its employees on the platform, the company is the controller within the meaning of Art. 4(7) GDPR for the data of its employees. Sentrivo processes this data as a processor (Art. 28 GDPR) on the basis of a data processing agreement that forms part of the terms of use. For visits to the public website and the registration of the company administrator, Sentrivo itself is the controller.

3. What data we process

3.1 Visiting the website (server logs)

When you access the website, our hosting provider automatically processes: IP address, date and time, page accessed, browser type and operating system, referrer URL. This data serves the technical provision, stability and security of the website (legal basis: Art. 6(1)(f) GDPR – legitimate interest). Retention period: server log files are deleted after 30 days.

3.2 Registration and user account

During registration we process: name, email address, password (exclusively as a cryptographic hash), company name, role (administrator/employee), preferred language and assignment to the company. Purpose: provision of the user account and performance of the contract of use (Art. 6(1)(b) GDPR).

3.3 Training data

When you use the platform we process: completed modules, quiz results, points earned (XP), level, badges and timestamps of completions. Purpose: evidence of training, progress display and evaluations for the company administrator (Art. 6(1)(b) GDPR or, for employees: legitimate interest of the employer in demonstrable security awareness pursuant to Art. 6(1)(f) GDPR in conjunction with statutory duties of care, e.g. NIS2 legislation).

Note for employees: Your employer (company administrator) can view your training progress and quiz results. Sentrivo does not evaluate this data for purposes other than documenting training.

3.4 Invitations

When an administrator invites employees, we store the invited email address and an invitation token until the invitation is accepted or for a maximum of 30 days.

3.5 Contact

If you contact us by email or via the contact form on our website, your details (name, email address, optionally company and phone number, subject and message) are stored to process the enquiry and for follow-up questions (Art. 6(1)(b) or (f) GDPR). Enquiries via the contact form are stored in our database (Supabase, see section 5) and forwarded to us by email. To protect against misuse (spam), we store a non-reversible hash of your IP address for 30 days. We delete the enquiry itself no later than 12 months after it has been dealt with, unless statutory retention obligations or a contractual relationship prevent this.

4. Cookies and local storage

The website uses no tracking or marketing cookies and no analytics tools. For sign-in, a session token is stored in your browser's local storage (localStorage). It is technically necessary to keep you signed in and is deleted when you sign out. Your language preference is also stored locally. No consent is required for this pursuant to § 165(3) TKG 2021.

5. Recipients and processors

Data is not passed on to other third parties unless we are legally obliged to do so.

6. Retention period

Account data and training data are stored for the duration of the contract of use and deleted within 30 days after its end or upon instruction of the business customer, unless statutory retention obligations prevent this. At the company's request, training records can be retained longer for documentation towards authorities or auditors.

7. Data security

Transmission is exclusively encrypted (TLS). Passwords are stored only as hashes. Access to data is restricted by role-based access rules (row level security) so that each company can only see its own data.

8. Your rights

You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). Please contact team@sentrivo.at. Employees of a business customer should primarily contact their employer as controller; we support the employer in responding.

If you believe that the processing of your data violates data protection law, you may lodge a complaint with the supervisory authority. In Austria this is the Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna. You may also contact the supervisory authority of your own EU member state.

9. Changes

We reserve the right to amend this privacy policy if the legal situation or our processing changes. The current version is available at sentrivo.org/privacy (German: sentrivo.at/datenschutz).