← Legal

Privacy Policy - Sentaro AB

Effective date: 2 January 2026 Last updated: 19 February 2026

This Privacy Policy explains how Sentaro AB ("Sentaro", "we", "us") collects, uses, shares, and otherwise processes personal data in connection with:

  • our website sentaro.com (the "Site"),
  • our sales and marketing activities ("Corporate Operations"), and
  • our email-security SaaS and related plugin/extension (the "Service").

Quick summary

  • Website visitors / marketing contacts: Sentaro is typically the controller of personal data we collect on the Site and in Corporate Operations.
  • End users whose emails are analyzed by our Service (e.g., employees of our customers): our customer is typically the controller, and Sentaro acts as a processor on the customer's instructions.

1) Who we are (Controller details)

Controller: Sentaro AB Registered address: Birger Jarlsgatan 57, 113 56 Stockholm, Sweden Org. no.: 559350-3120 Contact: privacy@sentaro.com

If you are an end user at a customer organization and your data is processed through the Service, your organization is the primary contact for privacy questions (see Section 3).

2) Scope. when this policy applies

This policy applies where Sentaro decides why and how personal data is processed (i.e., as controller) via the Site and Corporate Operations, and in limited Service scenarios described here.

This policy does not govern personal data we process only on behalf of a customer (processor role). In those cases, the customer's privacy notice and our Data Processing Agreement (DPA) govern.

3) Notice to end users (customer employees, mailbox users)

If your employer (or another organization) uses Sentaro's Service, Sentaro may process personal data contained in or related to emails (and related telemetry) on behalf of that organization.

  • The organization is the controller and determines the purposes and legal bases.
  • Sentaro is a processor and processes data under the organization's instructions and applicable contract/DPA.
  • To exercise rights related to this processing, contact your organization first. We will assist the customer as required by law and our contract.

4) Personal data we collect

A. Data you provide to us

  • Website forms / demo requests / contact: name, business email, phone, company, job title, message content, scheduling details.
  • Account/admin setup (Service): admin identifiers, login credentials (or SSO identifiers), contact details, role/permissions.
  • Support: support tickets, recordings or transcripts if you join a recorded call (where applicable), troubleshooting files you choose to share.

B. Data we collect automatically on the Site

  • Device & usage data: IP address, approximate location (derived from IP), browser/device type, pages viewed, referrer URLs, timestamps, interaction events.
  • Cookies and similar technologies: see Section 6.

C. Data processed through the Service (customer content)

Depending on configuration, the Service may process:

  • Email content and attachments (including sender/recipient fields, subject lines, message bodies, headers, URLs, and files)
  • Email metadata and security signals (e.g., indicators of compromise, authentication results, link reputation)
  • Service telemetry (logs, feature usage, configuration state, audit trails)

Sentaro designs the Service to support cybersecurity purposes such as detection, analysis, and remediation of email threats. The exact categories depend on the customer's deployment and instructions.

D. Information from other sources

We may receive business contact information from resellers/partners, lead providers, event organizers, or public professional sources (e.g., company websites, professional networks) to support B2B sales/marketing.

5) How we use personal data (purposes and legal bases)

Where GDPR applies, we process personal data under one or more of the following legal bases:

A. Site & Corporate Operations (Sentaro as controller)

  • Provide and operate the Site (necessary cookies, security, load balancing). Legal basis: Legitimate interests; contract (where relevant)
  • Analytics & Site improvement (e.g., Google Analytics). Legal basis: Consent (where required for cookies/trackers); legitimate interests for strictly necessary measurement where permitted
  • Sales and marketing (demo requests, newsletters, retargeting/ads, events). Legal basis: Legitimate interests (B2B outreach where permitted), consent (marketing cookies/targeting), or consent where required by law
  • Customer relationship management & communications (responding to inquiries, managing contracts). Legal basis: Contract; legitimate interests
  • Security and fraud prevention (protecting our Site and systems). Legal basis: Legitimate interests; legal obligation where applicable
  • Legal compliance (accounting, tax, responding to lawful requests)

B. Service (Sentaro typically as processor)

When processing personal data within customer email environments, we act on customer instructions under the contract/DPA. Customers determine the legal basis (often legitimate interests and/or legal obligations related to security).

6) Cookies, pixels, and tracking

We use cookies and similar technologies on sentaro.com. These may include:

  • Strictly necessary cookies (Site functionality, security, consent management)
  • Analytics cookies (e.g., Google Analytics)
  • Marketing/advertising cookies (e.g., Meta/Facebook Pixel, LinkedIn Insight Tag, and similar tools)

Your choices:

  • You can manage preferences via our cookie banner/consent manager (where implemented).
  • You can also block cookies via browser settings, but some Site features may not work.

Do Not Track: Some browsers offer DNT signals; our response may vary depending on technical feasibility and legal requirements.

For more details, see our Cookie Policy.

7) How we share personal data

We may share personal data with:

  • Service providers (processors): hosting, analytics, customer support tools, CRM/marketing automation, email delivery, security monitoring, billing, and consent management.
  • Advertising/marketing partners: only where permitted and (where required) based on your consent for marketing cookies/trackers.
  • Professional advisers: auditors, law firms, accountants.
  • Business transfers: in connection with merger, acquisition, financing, or sale of assets.
  • Legal and safety: to comply with law, lawful requests, or to protect rights, safety, and security.

We may also share aggregated or de-identified data where permitted.

8) International transfers

Sentaro may process personal data outside Sweden/EEA depending on where we and our vendors operate. Where GDPR applies and data is transferred internationally, we use appropriate safeguards, such as:

  • EU Standard Contractual Clauses (SCCs) and (where relevant) supplementary measures, and/or
  • other lawful transfer mechanisms recognized under applicable law.

9) Data retention

We retain personal data only as long as necessary for the purposes described above, including for legal, accounting, and security needs.

Typical retention patterns:

  • Marketing/contact data: retained while the relationship is active and for a reasonable period thereafter, unless you object or unsubscribe.
  • Website analytics: retained according to your analytics configuration.
  • Service data (customer content): retained according to contract/DPA and customer instructions; deleted or returned upon termination where applicable, subject to limited security/legal retention.

10) Security

We use appropriate technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction. Measures may include access controls, encryption in transit, logging/monitoring, least-privilege practices, and vendor security review.

11) Your rights (GDPR/EEA)

If you are in the EEA/UK/Switzerland and Sentaro is the controller of your personal data, you may have the right to:

  • access your data
  • rectify inaccurate data
  • request deletion
  • restrict processing
  • object to processing (including direct marketing)
  • data portability (where applicable)
  • withdraw consent at any time (where processing is based on consent)

To exercise rights: email privacy@sentaro.com and describe your request. We may need to verify identity.

Complaints: You can lodge a complaint with your supervisory authority. In Sweden, this is Integritetsskyddsmyndigheten (IMY).

If Sentaro processes your data as a processor for a customer (end-user context), please contact the customer (your organization) first.

12) Children

Our Site and Service are intended for business use and not directed to children. We do not knowingly collect personal data from children.

13) Third-party links and social media

The Site may link to third-party sites or embed third-party technologies (e.g., social media pixels). Their privacy practices are governed by their own policies.

14) Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version on this page and update the "Last updated" date. If changes are material, we may provide additional notice.

15) Contact

Privacy inquiries: privacy@sentaro.com Postal address: Sentaro AB, Birger Jarlsgatan 57, 113 56 Stockholm, Sweden