Sentyra Legal

Privacy Policy

This Privacy Policy explains how Sentyra collects, uses, shares, and protects personal data when you use our website and platform. As a compliance company, we aim to hold ourselves to the standards we help our customers meet. This policy is drafted to align with India's Digital Personal Data Protection Act, 2023 and the EU/UK General Data Protection Regulation.

Status: Effective · Effective date: 2026-07-22 · Provider: Sentyra Works, Delhi, India

1. Introduction & scope

This policy applies to personal data we handle as a data fiduciary/controller in the operation of the Sentyra platform and website — for example account, billing, and usage data of our customers and their users, and data of website visitors.

Where we process personal data on behalf of a customer to provide the Service (for example evidence and content in a customer’s compliance workspace), we act as a data processor and that processing is governed by our agreement with the customer, including any Data Processing Agreement. In that role the customer is the data fiduciary/controller and is responsible for the notices and lawful grounds for that data.

2. Who we are

The data fiduciary/controller responsible for personal data described in this policy is Sentyra Works, located in Delhi, India. You can reach us regarding privacy at Paras.Bakshi@Sentyra.xyz.

3. Data we collect

Data you provide

  • Account data: name, work email, organisation name, and role.
  • Authentication data: credentials managed through our identity provider (passwords are not stored by us in readable form).
  • Billing and business contact data where applicable.
  • Support and communications: messages you send us and their contents.

Data we collect automatically

  • Usage and log data: actions taken in the platform, timestamps, and audit-trail entries used to secure and operate the Service.
  • Device and connection data: IP address, browser type, and similar technical information.
  • Cookies and similar technologies strictly necessary to authenticate sessions and keep the Service secure (see the Cookies section).

Integration and evidence metadata

When a customer connects a third-party system, we process the configuration and the evidence returned by that system on the customer’s instruction. This may incidentally contain personal data (for example a user email in an access-review export). We handle such data as a processor for the customer, not for our own purposes.

4. How we use data

  • to provide, maintain, and secure the Service and your account;
  • to authenticate users and enforce access controls and tenant isolation;
  • to provide support and respond to your requests;
  • to maintain audit trails and the integrity of evidence and decision records;
  • to send service and administrative communications;
  • to improve reliability, safety, and performance of the Service in aggregate;
  • to comply with legal obligations and to establish, exercise, or defend legal claims.

We do not sell personal data. We do not use customer content to train general-purpose models for unrelated purposes.

6. Sharing & sub-processors

We share personal data only as needed to operate the Service and as described here:

  • Infrastructure sub-processors we currently use: Amazon Web Services (compute hosting), Supabase (managed database, authentication, and file storage), Vercel (frontend hosting), Sentry (application error monitoring), and Resend (transactional email delivery). We impose data-protection obligations on them by contract.
  • AI sub-processor: Amazon Web Services, through its Amazon Bedrock service, which we use to analyse compliance evidence documents you upload, to draft questionnaire answers, and to generate remediation guidance. The model is Anthropic's Claude Sonnet 4.5, run by AWS within Bedrock: the content is processed by AWS and is not sent to Anthropic, and AWS states that Bedrock does not use customer inputs or outputs to train models. We invoke it through a regional inference profile confined to AWS Australia (Asia Pacific Sydney and Melbourne), so this content is processed in Australia and not in India. We do not use it for any other purpose. Until 18 August 2026 this processing was performed by DeepSeek in the People's Republic of China; that arrangement has ended. AWS offers no India-pinned route for this model, so this processing stays in Australia for now — see section 7 for why.
  • Professional advisers and authorities: where required to comply with law, enforce our terms, or protect rights and safety.
  • Business transfers: in connection with a merger, acquisition, or asset sale, subject to this policy.

This list reflects our sub-processors as of the date on this page. We will update it when we add or remove a sub-processor.

7. International transfers

We process and store personal data in countries other than your own, including where our sub-processors operate. Where we transfer personal data across borders we use appropriate safeguards — for example the standard contractual clauses incorporated into our data processing agreement with Supabase, which extend to India as an exporter jurisdiction.

Where your data is today. Sentyra is in early access. Our application servers and database currently run in AWS Asia Pacific (Sydney), ap-southeast-2 — not in India. Evidence content submitted for AI review is processed by Amazon Bedrock in AWS Australia(Sydney/Melbourne) — also not in India (section 6). Until 18 August 2026 that content was sent to DeepSeek and processed in the People's Republic of China; that arrangement has ended. We state this plainly rather than describe our intended setup as though it were already in place.

Where it is going. Before general availability our application servers, database, authentication and uploaded evidence files move to AWS Asia Pacific (Mumbai), ap-south-1. That is the production setup described in our data processing agreement. Once that move is done, the AI review call described below is issued from those Indian servers and is the only border crossing left: your account, the database, authentication, the audit trail and the stored evidence files all stay in India, and what leaves is the content of a specific file at the moment you ask for it to be reviewed.

AI review will stay outside India, and here is why. We had said we would move AI processing to a model hosted in India. We have since established that AWS provides no India-pinned route for the model we use: every Bedrock model requires an inference profile, and the only profile covering Mumbai for Claude Sonnet 4.5 may process in any AWS region. The available alternatives were a materially weaker model, or dedicated capacity at a fixed cost out of proportion to early-access usage. We chose to keep the stronger model in a named, disclosed region — AWS Australia — rather than route your content unpredictably or degrade the review quality you are paying for. We will move it to India if and when AWS offers an India-pinned route, and we will say so here.

As at the date of this page, the Central Government has not notified any country under section 16 of the Digital Personal Data Protection Act, 2023 as one to which personal data may not be transferred. Should a restriction be notified that affects any transfer described here, we will change the arrangement to comply. Further details are available on request at Paras.Bakshi@Sentyra.xyz.

8. Data retention

We retain personal data for as long as needed to provide the Service and for the purposes described in this policy, and thereafter only as required to comply with legal obligations, resolve disputes, and enforce agreements. Account data is retained for the life of the account and then deleted or anonymised within 3 years after closure, subject to legal holds. Audit-trail records may be retained longer where required for security and accountability.

9. Security

We apply technical and organisational measures designed to protect personal data. Current measures include:

  • row-level security (RLS) in our database to enforce strict tenant isolation between customer organisations;
  • encryption in transit (TLS) and encryption at rest for sensitive credentials, protected by a dedicated encryption key (SENTYRA_CREDENTIAL_KEY);
  • Ed25519 digital signatures and SHA-256 hashing of evidence artifacts so their integrity can be independently verified, with hash-chained decision traces;
  • authentication via a managed identity provider with short-lived sessions and role-based access controls;
  • least-privilege access for personnel and audit logging of privileged actions.

A note on certifications. The measures above describe controls we operate. Sentyra does not currently hold, and this policy does not claim, any third-party certification or attestation (such as SOC 2 or ISO 27001) unless and until we publish such a report in writing. No security measure is perfectly secure, and we cannot guarantee absolute security.

10. Your rights

Subject to applicable law and verification of your identity, you have rights over your personal data. Under the DPDP Act, as a Data Principal you may:

  • access a summary of the personal data we process about you and the processing activities;
  • seek correction, completion, updating, or erasure of your personal data;
  • nominate another individual to exercise your rights in the event of death or incapacity;
  • readily withdraw consent where processing is based on consent;
  • have your grievances addressed through our grievance redressal mechanism (below).

Under the GDPR, where it applies, you may additionally have rights to object to or restrict processing, to data portability, and to lodge a complaint with your supervisory authority.

To exercise any right, contact Paras.Bakshi@Sentyra.xyz. There is no self-service online portal for these requests yet — email is the current mechanism, and requests are logged and tracked internally against a service-level target once received. If you are a user within a customer’s workspace, we may direct your request to that customer, who acts as the fiduciary/controller for that data.

11. Grievance redressal

If you have a concern or complaint about how we handle personal data, you may contact our grievance officer / data protection contact:

Grievance Officer: Paras Bakshi, Founder and CEO

Email: Paras.Bakshi@Sentyra.xyz

Address: Delhi, India

We will acknowledge and address grievances within the timeframes required by applicable law. If you remain unsatisfied, you may escalate to the Data Protection Board of India or your relevant supervisory authority.

12. Children's data

The Service is intended for business use and is not directed to children. We do not knowingly collect personal data of children without the consent of a parent or lawful guardian as required by the DPDP Act and other applicable law. If you believe a child’s data has been provided to us, contact us so we can address it.

13. Cookies

We use cookies and similar technologies that are strictly necessary to operate the Service — principally to authenticate sessions and protect against fraud and abuse. Where we use any non-essential cookies, we will obtain consent as required by applicable law and provide controls to manage them.

14. Changes to this policy

We may update this policy from time to time. We will post the updated version with a new effective date and, for material changes, provide additional notice as required by law. Your continued use of the Service after changes take effect indicates acceptance of the updated policy where permitted.

15. Contact

For any privacy question, contact Paras.Bakshi@Sentyra.xyz, or write to Sentyra Works, Delhi, India.