Version 4.1 · Last updated: 20 May 2026 · Effective: 15 June 2026
This policy explains how SentinelForge Security, Inc. ("SentinelForge", "we", "us") handles personal data collected through our website (sentinelforge.example) and in our role as a service provider.
Data controller for website & marketing data: SentinelForge Security, Inc., 1201 Third Avenue, Suite 2200, Seattle, WA 98101, USA.
UK / EU representative: SentinelForge Security UK Ltd., 2 Portman Square, Marylebone, London W1H 6BG, United Kingdom. Contact: gdpr@sentinelforge.example.
Data Protection Officer (voluntary): Priya Nandakumar, reachable at dpo@sentinelforge.example.
Note on our two roles. For website visitors and prospects we act as a data controller. When we deliver an engagement and process personal data on behalf of a Client (see section 12), we act as a data processor — the Client is the controller and the applicable rules are set out in the DPA.
We do not use personal data for automated decision-making with legal or similarly significant effects. We do not sell personal data.
| Purpose | Legal basis |
|---|---|
| Responding to your inquiry | Legitimate interests (business communication) |
| Performing an engagement contract | Contract (or legitimate interests for the pre-contract phase) |
| Marketing emails to prospects | Consent |
| Marketing to existing business clients (soft opt-in) | Legitimate interests |
| Recruiting | Legitimate interests, or consent for talent-pool retention |
| Security telemetry, fraud prevention | Legitimate interests |
| Legal, tax, audit records | Legal obligation |
We share personal data with:
We do not sell personal data and do not share it for cross-context behavioral advertising.
We are based in the United States. Personal data collected through the website is processed in the US. For transfers of EEA, UK, or Swiss personal data to the US or other third countries, we rely on:
| Data category | Retention |
|---|---|
| Website analytics (aggregate) | 13 months |
| Server logs | 30 days |
| Security telemetry | 90 days |
| Sales / scoping communications | 36 months from last interaction |
| Engagement records (invoices, SOWs) | 7 years (tax / regulatory) |
| Engagement working data | 90 days after Deliverable acceptance, then deletion |
| Candidate CV and interview notes | 12 months from decision; longer only with consent |
We operate an ISO/IEC 27001 certified information security management system with SOC 2 Type II attestation. Controls include:
Where applicable law grants them, you have rights to access, correct, delete, restrict, port, and object to processing of your personal data, and to withdraw consent. Requests: email privacy@sentinelforge.example. We verify identity before responding and reply within 30 days (extendable to 60 for complex requests).
EEA/UK residents may complain to their local supervisory authority. For the UK: the Information Commissioner's Office (ico.org.uk).
Residents of California, Colorado, Connecticut, Utah, Virginia, and other US states with comprehensive privacy laws have rights to know, access, correct, delete, port, opt out of "sale" and "sharing" for targeted advertising, and — for sensitive information — limit its use.
We do not sell personal data and do not process personal data for targeted advertising. We do not process the categories of sensitive personal information that trigger the CPRA opt-out.
Requests: privacy@sentinelforge.example. Authorized-agent submissions must include a signed permission from the consumer.
Our services are directed at business users. We do not knowingly collect personal data from anyone under 18.
When we perform security testing, we may process personal data contained in Client systems (accounts, log entries, records exposed by vulnerabilities). We act only on documented instructions from the Client and only for engagement purposes.
The rules governing this processing are in our Data Processing Addendum, which every applicable Client executes with us. Individuals whose personal data is processed this way should contact the Client (the controller) to exercise their rights.
We update this policy when our practices change. Material changes are communicated to registered accounts and clients by email at least 14 days before taking effect and are logged in a public change history.
Privacy: privacy@sentinelforge.example
Data Protection Officer: dpo@sentinelforge.example
UK/EU representative: gdpr@sentinelforge.example