Privacy Policy
Protecting your personal data is important to us. We process your data exclusively on the basis of the statutory provisions (GDPR, Austrian Data Protection Act (DSG), Austrian Telecommunications Act (TKG 2021)). This policy informs you about the nature, scope and purpose of processing on the website and platform sentrivo.org / sentrivo.at.
1. Controller
Gerhard Kienbauer
Riedauerstraße 4, 4753 Taiskirchen im Innkreis, Austria
Email: team@sentrivo.at
2. Roles for business customers
Sentrivo is a platform for businesses. When a company registers its employees on the platform, the company is the controller within the meaning of Art. 4(7) GDPR for the data of its employees. Sentrivo processes this data as a processor (Art. 28 GDPR) on the basis of a data processing agreement that forms part of the terms of use. For visits to the public website and the registration of the company administrator, Sentrivo itself is the controller.
3. What data we process
3.1 Visiting the website (server logs)
When you access the website, our hosting provider automatically processes: IP address, date and time, page accessed, browser type and operating system, referrer URL. This data serves the technical provision, stability and security of the website (legal basis: Art. 6(1)(f) GDPR – legitimate interest). Retention period: server log files are deleted after 30 days.
3.2 Registration and user account
During registration we process: name, email address, password (exclusively as a cryptographic hash), company name, role (administrator/employee), preferred language and assignment to the company. Purpose: provision of the user account and performance of the contract of use (Art. 6(1)(b) GDPR).
3.3 Training data
When you use the platform we process: completed modules, quiz results, points earned (XP), level, badges and timestamps of completions. Purpose: evidence of training, progress display and evaluations for the company administrator (Art. 6(1)(b) GDPR or, for employees: legitimate interest of the employer in demonstrable security awareness pursuant to Art. 6(1)(f) GDPR in conjunction with statutory duties of care, e.g. NIS2 legislation).
Note for employees: Your employer (company administrator) can view your training progress and quiz results. Sentrivo does not evaluate this data for purposes other than documenting training.
3.4 Invitations
When an administrator invites employees, we store the invited email address and an invitation token until the invitation is accepted or for a maximum of 30 days.
3.5 Contact
If you contact us by email or via the contact form on our website, your details (name, email address, optionally company and phone number, subject and message) are stored to process the enquiry and for follow-up questions (Art. 6(1)(b) or (f) GDPR). Enquiries via the contact form are stored in our database (Supabase, see section 5) and forwarded to us by email. To protect against misuse (spam), we store a non-reversible hash of your IP address for 30 days. We delete the enquiry itself no later than 12 months after it has been dealt with, unless statutory retention obligations or a contractual relationship prevent this.
4. Cookies and local storage
The website uses no tracking or marketing cookies and no analytics tools. For sign-in, a session token is stored in your browser's local storage (localStorage). It is technically necessary to keep you signed in and is deleted when you sign out. Your language preference is also stored locally. No consent is required for this pursuant to § 165(3) TKG 2021.
5. Recipients and processors
- Website hosting: IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. Server location: Germany (EU). Data processing agreement pursuant to Art. 28 GDPR concluded via the IONOS customer centre. Details: ionos.de/terms-gtc/datenschutzerklaerung
- Database and authentication: Supabase Inc., 970 Toa Payoh North #07-04, Singapore 318992. Data is stored on servers in Ireland (EU). A data processing agreement pursuant to Art. 28 GDPR is in place with Supabase; the EU standard contractual clauses apply to any access from third countries. Details: supabase.com/privacy
- Email delivery (confirmations, invitations): Sendinblue GmbH (Brevo), Köpenicker Straße 126, 10179 Berlin, Germany. Server location EU. Data processing agreement pursuant to Art. 28 GDPR: brevo.com/legal/termsofuse/#dpa
Data is not passed on to other third parties unless we are legally obliged to do so.
6. Retention period
Account data and training data are stored for the duration of the contract of use and deleted within 30 days after its end or upon instruction of the business customer, unless statutory retention obligations prevent this. At the company's request, training records can be retained longer for documentation towards authorities or auditors.
7. Data security
Transmission is exclusively encrypted (TLS). Passwords are stored only as hashes. Access to data is restricted by role-based access rules (row level security) so that each company can only see its own data.
8. Your rights
You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). Please contact team@sentrivo.at. Employees of a business customer should primarily contact their employer as controller; we support the employer in responding.
If you believe that the processing of your data violates data protection law, you may lodge a complaint with the supervisory authority. In Austria this is the Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna. You may also contact the supervisory authority of your own EU member state.
9. Changes
We reserve the right to amend this privacy policy if the legal situation or our processing changes. The current version is available at sentrivo.org/privacy (German: sentrivo.at/datenschutz).