Privacy Policy
Last updated: 9 July 2026 ยท Includes our cookie policy (section 8)
1. Who we are
Sentryscan Limited (company number 17321496) ("SentryScan") is the data controller for the personal data described in this policy. We are registered in England and Wales; our registered office is International House, 51 Borough High Street, London SE1 1NB. Contact: info@sentryscan.services.
This policy covers our website, customer dashboard and managed scanning service. Our service is aimed at businesses, but much of the information we handle (names, work emails, and the contents of security reports) is or can be personal data, so we treat it accordingly under UK data protection law (UK GDPR and the Data Protection Act 2018).
2. What we collect
- Account and order details โ your name, work email address, company name, password (stored only as a secure hash), the plan you choose, and the scope of systems you ask us to scan.
- Authorisation records โ when you confirm you are authorised to have systems tested, we keep the confirmation wording, the scope at that time, your name and company, and technical metadata (IP address, browser user-agent). We keep this as legal evidence of the engagement's lawful basis.
- Payment data โ payments are processed by Stripe. We receive and store order amounts, invoice status and Stripe reference identifiers. We never see or store your full card details.
- Scan results and reports โ the findings our scans produce about the systems you authorised, and the reports we deliver to you.
- Technical and security logs โ IP addresses and timestamps for actions such as sign-in attempts (used for rate limiting and abuse prevention), and a log of the emails we send you (for deliverability auditing).
- Correspondence โ emails and enquiries you send us.
3. Why we use it (lawful bases)
- To provide the service (performance of a contract): running scans you order, delivering reports, operating your dashboard, taking payment, and sending service emails such as order confirmations, report notifications, password resets and renewal or payment-failure notices.
- To keep the service secure (legitimate interests): rate limiting, abuse and fraud prevention, and security logging.
- To meet legal obligations: keeping financial and tax records, and keeping authorisation records that evidence scanning was lawfully commissioned.
- Marketing: we do not send marketing emails unless you have agreed to receive them, and you can opt out at any time.
4. Scan data is sensitive โ how we protect it
Your scan reports describe weaknesses in your infrastructure, and your scope describes what you own. We treat both as confidential security information, not ordinary account data.
- Reports are stored outside the web-accessible area of our server under randomised filenames, and can only be downloaded through your authenticated dashboard by the account that owns them.
- All traffic to the site and dashboard is encrypted in transit (HTTPS, with HSTS).
- Access to stored reports and scan data is restricted to the people who need it to operate the service.
- We never use your scan results for marketing, never share them with other customers, and never sell them.
5. Who we share data with
| Recipient | What | Why |
|---|---|---|
| Stripe Payments Europe / Stripe Inc. | Payment and billing details | Card payment processing and subscription billing (see Stripe's own privacy policy) |
| Our web hosting provider | All service data (they host our server) | Hosting the website, dashboard and database |
| Our email (SMTP) provider | Email address and message content of service emails | Delivering order, report and account emails |
| Authorities or legal recipients | What the law requires | Only where we are legally obliged, or to establish or defend legal claims |
We do not sell personal data, and we do not share it with advertisers or data brokers.
6. International transfers
We are UK-based and store service data in our hosting provider's data centres. Stripe may process payment data outside the UK (including in the United States); those transfers are covered by Stripe's safeguards, including the UK International Data Transfer Addendum / standard contractual clauses.
7. How long we keep it
- Account data โ while your account is active, and for a reasonable period afterwards in case you return or a dispute arises.
- Financial records (orders, invoices, payments) โ at least 6 years, as required for UK tax and accounting purposes.
- Authorisation records โ for as long as we may need to evidence that scanning was lawfully commissioned (normally at least 6 years).
- Reports and scan results โ while your account is active so you can access your history; deleted on verified request or account closure, subject to the retention above.
- Security logs (sign-in attempts, rate limiting) โ short-term only, typically no more than 12 months.
8. Cookies
We keep cookies to the minimum needed to run the service, which is why you don't see a cookie consent banner โ we only set cookies that are strictly necessary:
| Cookie | Purpose | Lifetime |
|---|---|---|
| Session cookie (PHP session) | Keeps you signed in to your dashboard and protects forms against cross-site request forgery (CSRF) | Deleted when your browser session ends |
- We use no analytics, advertising or tracking cookies, and no third-party scripts on our pages.
- If you pay for a plan, checkout happens on Stripe's own pages, and Stripe sets its own cookies there (fraud prevention and payment processing) under Stripe's cookie policy.
- You can block or delete cookies in your browser settings, but you won't be able to stay signed in to the dashboard without the session cookie.
9. Your rights
Under UK data protection law you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have data erased, where retention is no longer justified;
- restrict or object to processing based on legitimate interests;
- receive a portable copy of data you provided to us; and
- withdraw consent, where processing is based on consent.
To exercise any of these, email info@sentryscan.services. We may need to verify your identity first. You also have the right to complain to the Information Commissioner's Office (ico.org.uk), though we'd appreciate the chance to resolve any concern with you directly first.
10. Security
We protect data with HTTPS everywhere (including HSTS), hashed passwords, rate limiting on authentication, CSRF protection, restricted report storage as described in section 4, and security headers on all pages. No system is perfectly secure โ if we become aware of a breach affecting your personal data, we will notify you and the ICO as required by law.
11. Changes to this policy
If we make material changes we will update this page and, where the change significantly affects you, notify you by email. The "Last updated" date at the top shows the current version.
12. Contact
Privacy questions or requests: info@sentryscan.services.