Sentyra Legal

Privacy Policy

This Privacy Policy explains how Sentyra collects, uses, shares, and protects personal data when you use our website and platform. As a compliance company, we aim to hold ourselves to the standards we help our customers meet. This policy is drafted to align with India's Digital Personal Data Protection Act, 2023 and the EU/UK General Data Protection Regulation.

Status: Effective · Effective date: 2026-07-22 · Provider: Sentyra Works, Delhi, India

Factual update: 2026-10-06 · Sections 6 and 7 updated: our servers, database, authentication and evidence files moved to AWS Asia Pacific (Mumbai); Supabase and Vercel are now former sub-processors. The legal terms are unchanged since the review above.

1. Introduction & scope

This policy applies to personal data we handle as a data fiduciary/controller in the operation of the Sentyra platform and website — for example account, billing, and usage data of our customers and their users, and data of website visitors.

Where we process personal data on behalf of a customer to provide the Service (for example evidence and content in a customer’s compliance workspace), we act as a data processor and that processing is governed by our agreement with the customer, including any Data Processing Agreement. In that role the customer is the data fiduciary/controller and is responsible for the notices and lawful grounds for that data.

2. Who we are

The data fiduciary/controller responsible for personal data described in this policy is Sentyra Works, located in Delhi, India. You can reach us regarding privacy at privacy@sentyra.in.

3. Data we collect

Data you provide

  • Account data: name, work email, organisation name, and role.
  • Authentication data: credentials managed through our identity provider (passwords are not stored by us in readable form).
  • Billing and business contact data where applicable.
  • Support and communications: messages you send us and their contents.

Data we collect automatically

  • Usage and log data: actions taken in the platform, timestamps, and audit-trail entries used to secure and operate the Service.
  • Device and connection data: IP address, browser type, and similar technical information.
  • Cookies and similar technologies strictly necessary to authenticate sessions and keep the Service secure (see the Cookies section).

Integration and evidence metadata

When a customer connects a third-party system, we process the configuration and the evidence returned by that system on the customer’s instruction. This may incidentally contain personal data (for example a user email in an access-review export). We handle such data as a processor for the customer, not for our own purposes.

4. How we use data

  • to provide, maintain, and secure the Service and your account;
  • to authenticate users and enforce access controls and tenant isolation;
  • to provide support and respond to your requests;
  • to maintain audit trails and the integrity of evidence and decision records;
  • to send service and administrative communications;
  • to improve reliability, safety, and performance of the Service in aggregate;
  • to comply with legal obligations and to establish, exercise, or defend legal claims.

We do not sell personal data. We do not use customer content to train general-purpose models for unrelated purposes.

6. Sharing & sub-processors

We share personal data only as needed to operate the Service and as described here:

  • Infrastructure sub-processors we currently use: Amazon Web Services in the Asia Pacific (Mumbai) region (compute hosting, the managed database, authentication, uploaded evidence file storage, and transactional email through Amazon SES), Sentry (application error monitoring), and Hostinger (hosting of our own e-mail addresses, including privacy@sentyra.in, where you may write to us). We impose data-protection obligations on them by contract.
  • Former sub-processors, disclosed until their data is gone: Supabase provided our database, authentication and file storage until 5 October 2026; a copy of that database remains in its Sydney, Australia project until it is deleted, scheduled by 20 October 2026. Vercel hosted our website until 6 October 2026; it no longer receives customer traffic and the account is pending deletion. Resend delivered our transactional email until 7 October 2026; it receives no new mail and its credentials are being retired.
  • AI sub-processor: Amazon Web Services, through its Amazon Bedrock service, which we use to analyse compliance evidence documents you upload, to draft questionnaire answers, and to generate remediation guidance. This processing runs through the AWS India region. The content is processed by AWS within Bedrock, and AWS states that Bedrock does not use customer inputs or outputs to train models. We do not use it for any other purpose. Until 18 August 2026 this processing was performed by DeepSeek in the People's Republic of China; that arrangement has ended.
  • Professional advisers and authorities: where required to comply with law, enforce our terms, or protect rights and safety.
  • Business transfers: in connection with a merger, acquisition, or asset sale, subject to this policy.

This list reflects our sub-processors as of the date on this page. We will update it when we add or remove a sub-processor.

7. International transfers

Where a sub-processor processes personal data outside India, we use appropriate safeguards: contractual data-protection terms with each provider and, where the provider offers them, standard contractual clauses that extend to India as an exporter jurisdiction.

Where your data is today. Sentyra is in early access. Since 6 October 2026 our application servers, database, authentication and uploaded evidence files run in AWS Asia Pacific (Mumbai), ap-south-1. Evidence content submitted for AI review is processed by Amazon Bedrock through the AWS India region(section 6). Transactional email is sent through Amazon SES in the same Mumbai region since 7 October 2026. Two services still run outside India — not in India: application error monitoring (Sentry), which receives only the data needed for that function, and the hosting of our own e-mail addresses (Hostinger), which holds what you write to us at privacy@sentyra.in and our other role addresses. Until 5 October 2026 our database, authentication and file storage ran on Supabase in AWS Asia Pacific (Sydney), ap-southeast-2; a copy of that database remains there until it is deleted, scheduled by 20 October 2026. Until 18 August 2026 AI review content was sent to DeepSeek and processed in the People's Republic of China; that arrangement has ended. We state this plainly rather than describe our intended setup as though it were already in place.

Where it is going. Before general availability the Service moves to a separate production environment, also in AWS Asia Pacific (Mumbai), ap-south-1, with its own database, keys and authentication. That is the production setup described in our data processing agreement. Transactional email moves to Amazon SES in the same region at that point, and we will review error monitoring so that it, too, stays in India. Once that is done, your account, the database, authentication, the audit trail, the stored evidence files and the AI review described below all stay in India.

AI review runs in India. Evidence content you submit for AI review is processed by Amazon Bedrock through the AWS India region. AWS states that Bedrock does not use customer inputs or outputs to train models, and we do not use the content for any other purpose.

As at the date of this page, the Central Government has not notified any country under section 16 of the Digital Personal Data Protection Act, 2023 as one to which personal data may not be transferred. Should a restriction be notified that affects any transfer described here, we will change the arrangement to comply. Further details are available on request at privacy@sentyra.in.

8. Data retention

We retain personal data for as long as needed to provide the Service and for the purposes described in this policy, and thereafter only as required to comply with legal obligations, resolve disputes, and enforce agreements. Account data is retained for the life of the account and then deleted or anonymised within 3 years after closure, subject to legal holds. Audit-trail records may be retained longer where required for security and accountability.

9. Security

We apply technical and organisational measures designed to protect personal data. Current measures include:

  • row-level security (RLS) in our database to enforce strict tenant isolation between customer organisations;
  • encryption in transit (TLS) and encryption at rest for sensitive credentials, protected by a dedicated encryption key (SENTYRA_CREDENTIAL_KEY);
  • Ed25519 digital signatures and SHA-256 hashing of evidence artifacts so their integrity can be independently verified, with hash-chained decision traces;
  • authentication via a managed identity provider with short-lived sessions and role-based access controls;
  • least-privilege access for personnel and audit logging of privileged actions.

A note on certifications. The measures above describe controls we operate. Sentyra does not currently hold, and this policy does not claim, any third-party certification or attestation (such as SOC 2 or ISO 27001) unless and until we publish such a report in writing. No security measure is perfectly secure, and we cannot guarantee absolute security.

10. Your rights

Subject to applicable law and verification of your identity, you have rights over your personal data. Under the DPDP Act, as a Data Principal you may:

  • access a summary of the personal data we process about you and the processing activities;
  • seek correction, completion, updating, or erasure of your personal data;
  • nominate another individual to exercise your rights in the event of death or incapacity;
  • readily withdraw consent where processing is based on consent;
  • have your grievances addressed through our grievance redressal mechanism (below).

Under the GDPR, where it applies, you may additionally have rights to object to or restrict processing, to data portability, and to lodge a complaint with your supervisory authority.

To exercise any right, contact privacy@sentyra.in. There is no self-service online portal for these requests yet — email is the current mechanism, and requests are logged and tracked internally against a service-level target once received. If you are a user within a customer’s workspace, we may direct your request to that customer, who acts as the fiduciary/controller for that data.

11. Grievance redressal

If you have a concern or complaint about how we handle personal data, you may contact our grievance officer / data protection contact:

Grievance Officer: Paras Bakshi, Founder and CEO

Email: privacy@sentyra.in

Address: Delhi, India

We will acknowledge and address grievances within the timeframes required by applicable law. If you remain unsatisfied, you may escalate to the Data Protection Board of India or your relevant supervisory authority.

12. Children's data

The Service is intended for business use and is not directed to children. We do not knowingly collect personal data of children without the consent of a parent or lawful guardian as required by the DPDP Act and other applicable law. If you believe a child’s data has been provided to us, contact us so we can address it.

13. Cookies

We use cookies and similar technologies that are strictly necessary to operate the Service — principally to authenticate sessions and protect against fraud and abuse. Where we use any non-essential cookies, we will obtain consent as required by applicable law and provide controls to manage them.

14. Changes to this policy

We may update this policy from time to time. We will post the updated version with a new effective date and, for material changes, provide additional notice as required by law. Your continued use of the Service after changes take effect indicates acceptance of the updated policy where permitted.

15. Contact

For any privacy question, contact privacy@sentyra.in, or write to Sentyra Works, Delhi, India.