Privacy Policy
Sentrel is industrial monitoring software sold to organizations, not to consumers. We hold very little personal data: enough to give you an account, keep it secure, and prove who changed what. We do not run analytics or advertising, we do not profile you, and we have never sold personal data. This policy explains the rest.
Effective 12 August 2026 · Last updated 12 August 2026
1. The two different roles we play
Almost every question about your data has a different answer depending on which of these two situations applies. It is worth two minutes.
When we decide (we are the controller)
For the small amount of personal data we hold in order to run the business, we decide why and how it is processed. That means your account details, our records of who did what inside the platform, support conversations, and anything you send us through the contact form. In UK and EU terms we are the controller. In Indian terms we are the Data Fiduciary. In Australian terms we are an APP entity. This policy governs that data, and you can exercise your rights with us directly.
When our customer decides (we are the processor)
Everything a customer puts into their workspace belongs to them. Equipment readings, device configurations, dashboards, reports, and any personal data they choose to store, we process only on their instructions. In UK and EU terms we are the processor; in Indian terms the customer is the Data Fiduciary and we act on their behalf.
2. What we collect about you
Sentrel has no self-serve signup. Accounts are created by our team at the request of the organization buying the service, so in most cases we receive your name and work email from your employer rather than from you.
| What | Specifically | Where it comes from |
|---|---|---|
| Account details | Name, work email address, password (stored only as a one-way hash, never in readable form), role and permissions, department, profile image if you add one | Your employer, or you |
| Organization details | Company name, branding settings, assigned account contact | Your employer |
| Activity records | What was changed, by whom, when, the values before and after, plus IP address and browser identifier | Automatically, as you use the platform |
| Assistant conversations | The questions you ask the built-in assistant and the answers it returns | You |
| Support requests | Tickets you raise, and the messages in them | You |
| Sales inquiries | Name, work email, company, role, country, phone if given, and your message | You, through the contact form |
| Security codes | One-time codes issued for password resets | Generated when you request a reset |
What we deliberately do not collect
- No analytics, no advertising pixels, no third-party trackers and no session recording. There is none of this anywhere in the product or on this website.
- No behavioral profiling and no scoring of individuals.
- No special category data, and we ask that you do not put health, biometric, racial, religious, political or sexual-orientation data into the platform. It is not built for it.
- No payment card details. Where a card is used, the payment provider handles it and we never see the number.
3. Why we process it, and our legal basis
The basis column matters most in the UK and EU. India, Australia and the US states use different tests, which are covered in the regional sections below.
| Purpose | UK and EU legal basis |
|---|---|
| Giving you an account and providing the service | Performance of a contract, or our legitimate interest in serving the organization that holds the contract |
| Keeping accounts secure and preventing misuse | Legitimate interests: nobody wants an unsecured industrial monitoring account |
| Keeping a tamper-evident record of changes | Legitimate interests, and legal obligation where a customer is subject to record-keeping rules such as 21 CFR Part 11 |
| Answering support requests | Performance of a contract, or legitimate interests |
| Replying to a sales inquiry you sent us | Legitimate interests: you asked us to get in touch |
| Sending service messages such as alerts and password resets | Performance of a contract |
| Meeting tax, accounting and other legal duties | Legal obligation |
Where we rely on legitimate interests we have considered whether our interest is overridden by your rights, and you can object at any time using the contact details at the end. We do not use personal data for automated decisions that produce legal effects or similarly significant effects on you. Alerts are threshold comparisons on equipment readings, not judgments about people.
4. The AI features, and what leaves the platform
Several parts of Sentrel are driven by a large language model: describing what to monitor in plain English, the dashboard assistant, and cost estimation. We want to be exact about what this involves, because "AI-powered" usually hides the answer.
- When you use one of those features, the text of your request is sent to our language-model provider, together with the field names, aggregate figures and a small sample of records needed to answer it.
- If personal data is stored in the fields being queried, that personal data can form part of what is sent.
- Requests are sent over an encrypted connection to a specialist AI inference provider acting on our instructions, which is not permitted to use your data for its own purposes or to train its models.
- Model output can be wrong. It is a starting point that you review and confirm, never something that goes live on its own.
5. Who inside your organization can see your activity
Two features let one person see another person's activity. Both are disclosed here because you should not discover them by accident.
- Administrator access to assistant conversations
- An administrator in your organization can be granted the ability to view, continue or delete the assistant conversations of members of that organization. This is a decision your employer makes, not us. Sales-side conversations are excluded.
- Support access to your account
- With authorization, a support operator can work inside a customer workspace to diagnose a problem. Every action taken this way is written to the audit trail and attributed to the operator, not to you.
8. Where your data is processed
Sentrel is operated from India and uses providers based in more than one country, so your data may be processed in India, the United States and the European Union.
Where personal data leaves the UK or the European Economic Area, we rely on the UK International Data Transfer Addendum or the European Commission's Standard Contractual Clauses, together with an assessment of the destination country. Where personal data about Australian individuals is disclosed overseas, we take reasonable steps under Australian Privacy Principle 8 to ensure it is handled consistently with the Australian Privacy Principles. Indian personal data is handled under the Digital Personal Data Protection Act, 2023.
Ask us at info@sentrel.io for a copy of the safeguards for any specific transfer.
9. How long we keep it
| What | Kept for |
|---|---|
| Account details | While the account is active, then 30 days after the workspace closes |
| Activity and audit records | For the life of the workspace. These are append-only by design, so an entry cannot be edited or removed without breaking the record. If you need one erased we will explain exactly what that does to the chain. |
| Assistant conversations | Until you or an administrator delete them |
| Support tickets | While the account is active, then as needed for legal claims |
| Sales inquiries | While there is a live conversation, and up to 24 months afterwards |
| Data inside a workspace | As the customer directs. They control it, and deletion is their call |
10. How we protect it
Passwords are stored only as one-way hashes. Traffic is encrypted in transit. Access inside a workspace is governed by roles and per-module permissions, workspaces are isolated from one another, and every change is written to a tamper-evident record. The Security page sets out the controls in full, including what we have not done yet.
No system is perfectly secure. If a breach is likely to result in a risk to your rights we will notify the relevant regulator and, where required, you, within the timeframes the law sets: 72 hours to the ICO or an EU authority, as soon as practicable to the Indian authority under the DPDP Act, and as soon as practicable under the Australian Notifiable Data Breaches scheme.
11. Your rights, wherever you are
Whichever country's law applies to you, we will honor the following. Regional detail follows in sections 12 to 15.
- Access
- Get a copy of the personal data we hold about you.
- Correction
- Have inaccurate or incomplete data fixed.
- Deletion
- Have data erased, subject to records we must keep by law or to defend a claim.
- Objection and restriction
- Object to processing based on legitimate interests, or ask us to pause it while a dispute is resolved.
- Portability
- Receive your data in a structured, machine-readable format.
- Withdraw consent
- Where we rely on consent, withdraw it at any time, without affecting what was done before.
- Complain
- Raise it with your data protection authority. We would rather you came to us first, but it is your right either way.
Write to info@sentrel.io. We reply within the period the applicable law sets and, at the latest, within 30 days. There is no charge unless a request is manifestly unfounded or excessive, and we will say so before doing anything. We may need to verify your identity, and we will ask for no more than is necessary to do that.
12. United Kingdom and European Union
This section applies if you are in the UK or the EEA. It supplements the rest of the policy under the UK GDPR and the Data Protection Act 2018, and under the EU GDPR.
- Our legal bases are set out in section 3. We do not rely on consent for the core service, so there is nothing to withdraw in order to keep using it.
- You have the rights in Articles 15 to 22: access, rectification, erasure, restriction, portability, and objection, including an absolute right to object to direct marketing.
- We carry out no automated decision-making producing legal or similarly significant effects, so Article 22 does not bite.
- You can complain to the Information Commissioner's Office at ico.org.uk, or to the supervisory authority in your EU member state. You can also seek a judicial remedy.
13. United States
This section applies if you are a resident of a US state with a comprehensive privacy law, including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota and Maryland.
Notice at collection
| Category under the CCPA | Do we collect it? | Why |
|---|---|---|
| Identifiers such as name, email, account ID, IP address | Yes | To provide and secure the service |
| Customer records such as employer and job role | Yes | To provide the service |
| Commercial information | Limited, from sales inquiries | To respond to you |
| Internet activity within our own service | Yes, as audit records | Security and record-keeping |
| Professional or employment information | Yes | To provide the service |
| Geolocation, biometric, sensitive personal information | No | Not collected |
| Inferences or profiles about you | No | Not created |
Sale, sharing and targeted advertising
We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not process it for targeted advertising or profiling in furtherance of decisions producing legal or similarly significant effects. That is true of every state law listed above, and it has always been true. We do not knowingly sell or share the personal information of anyone under 16.
Because we do not sell or share, there is nothing for a Global Privacy Control signal to opt you out of. We honor one anyway if we receive it.
Your rights
- Know what we collect, use and disclose, and get a copy in a portable form.
- Delete personal information we hold, subject to the exceptions the statutes allow.
- Correct inaccurate personal information.
- Opt out of sale, sharing and targeted advertising. Not applicable to us, but available if that ever changes.
- Limit the use of sensitive personal information. Not applicable, since we do not collect it.
- Not be discriminated against for exercising any of these. We will not deny service, change prices or degrade quality.
- Appeal a refused request. Where your state gives you that right we will respond within the statutory window and, if we still refuse, tell you how to contact your Attorney General.
Send requests to info@sentrel.io. We respond within 45 days and may extend once where the law permits. An authorized agent may act for you with written permission that we can verify. California residents may also request the disclosure described in the Shine the Light law, though we make no such disclosures.
14. India
This section applies if you are in India. It supplements the rest of the policy under the Digital Personal Data Protection Act, 2023, and under the Information Technology Act, 2000 with the SPDI Rules, 2011.
- Where we act as Data Fiduciary we process your personal data for the lawful purposes set out in section 3, and only for as long as the purpose needs it.
- Where a customer decides the purpose, they are the Data Fiduciary and we process on their behalf.
- As a Data Principal you may ask for a summary of the personal data we process and what we do with it, ask for correction, completion, updating or erasure, nominate someone to exercise your rights if you die or become incapacitated, and use the grievance route below.
- You also have a duty under the Act not to impersonate someone else or file a false or frivolous complaint.
- We do not process the personal data of children for tracking, behavioral monitoring or targeted advertising. We do none of those things for anyone.
- We follow reasonable security practices and procedures for sensitive personal data under the SPDI Rules. The Security page describes them.
Grievance redressal
Send a grievance to info@sentrel.io with "Grievance" in the subject line. We acknowledge within 48 hours and respond within 30 days. If you are not satisfied you may complain to the Data Protection Board of India.
15. Australia
This section applies if you are in Australia. It supplements the rest of the policy under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
- We collect personal information only where it is reasonably necessary for our functions, and by lawful and fair means (APP 3).
- Most personal information reaches us from your employer rather than from you. This policy is the notice required by APP 5.
- We use and disclose personal information only for the purpose it was collected for, or a directly related purpose you would reasonably expect (APP 6).
- We do not use or disclose personal information for direct marketing without a clear opt-out, and we never do so where the information came to us as a processor for a customer (APP 7).
- Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles (APP 8). Section 8 lists where processing happens.
- You may ask for access to, and correction of, the personal information we hold (APP 12 and 13). We respond within 30 days.
- We do not adopt or use government-related identifiers as our own (APP 9), and we do not offer anonymous dealing where an account is required, because we cannot secure an account we cannot identify (APP 2).
Complaints and data breaches
Complain to info@sentrel.io and we will respond within 30 days. If you are not satisfied you may take it to the Office of the Australian Information Commissioner at oaic.gov.au. Where an eligible data breach is likely to cause serious harm we will notify you and the OAIC under the Notifiable Data Breaches scheme.
16. Children
Sentrel is a workplace tool sold to organizations and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child's data has reached us, write to info@sentrel.io and we will delete it.
17. Changes to this policy
When we change this policy we update the date at the top. If a change materially affects your rights we will give at least 30 days' notice by email to account holders, or by a notice in the product, before it takes effect.
18. Contact us
Questions, rights requests and complaints all go to info@sentrel.io. A person reads it.
- Provider
- LuminaTech
- Registered office
- India
- Privacy and grievances
- info@sentrel.io
- Security reports
- info@sentrel.io