Last Revised: April 3, 2023
Welcome to www.sentra.io and its subdomains (the “Website”), a website of Sentra Inc. and its affiliates and subsidiaries (“Sentra”, “Company”, “our”, “we” or “us”). This Privacy Policy (the “Privacy Policy”) is intended to describe our practices regarding the information we may collect from you (“You” or “User”) when you use our Website and/or our online Security Posture Management platform (the “Solution”) the manners in which we may use such information, and the choices and rights available to you.
YOUR CONSENT
BY ACCESSING THE WEBSITE AND/OR THE SOLUTION, YOU AGREE TO THE TERMS AND CONDITIONS SET FORTH IN THIS PRIVACY POLICY, INCLUDING TO THE COLLECTION AND PROCESSING OF YOUR PERSONAL INFORMATION (AS DEFINED BELOW) IN THE EVENT YOU DECIDE TO PROVIDE US WITH SUCH. IF YOU DISAGREE TO ANY TERM PROVIDED HEREIN, YOU MAY NOT ACCESS OR USE THE WEBSITE AND/OR THE SOLUTION.
Please note: you are not obligated by law to provide us with any Personal Information. You hereby acknowledge and agree that you are providing us with Personal Information at your own free will. You hereby agree that we may collect and use such Personal Information pursuant to this Privacy Policy and any applicable laws and regulations.
TO THE EXTENT THAT YOU PROVIDE US WITH ANY PERSONAL INFORMATION RELATED TO ANY THIRD PARTY OR ANY OTHER PERSON OR ENTITY WHICH IS NOT YOU, INCLUDING INFORMATION RELATED TO ANY OF YOUR PERSONNEL, COLLEAGUES, OR CUSTOMERS, YOU ARE SOLELY RESPONSIBLE TO RECEIVE AND HEREBY REPRESENT THAT YOU HAVE AND UNDERTAKE THAT YOU SHALL HAVE AT ALL TIMES, MAINTAINED AND RECEIVED, THE CONSENT, AUTHORITY, PERMISSION, AND APPROVAL OF SUCH PERSONS AND PROVIDED THEM WITH SUFFICIENT DISCLOSURES, TO ALLOW US TO ACCESS, STORE, COLLECT, ANALYZE AND PROCESS SUCH PERSONAL INFORMATION AS DETAILED HEREIN.
SCOPE AND APPLICABILITY
This Privacy Policy applies only to the information we collect in connection with your use of the Website and/or information we may receive or process in connection with your access or use of Solution made available by Sentra to your organization or otherwise when you receive services from us, such as support services with respect to such use or access of the Solution.
WHAT INFORMATION DO WE COLLECT FROM OUR USERS?
Non-personal Information: Non-personal Information is unidentified and non-identifiable information pertaining to Users, which may be made available to us, or collected automatically via their use of the Website and/or Solution. Such Non-personal Information does not enable us to identify the person from whom it was collected, and mainly consists of technical and aggregated usage information which is not linked to an identifiable individual, such as the operation system and browser, browser version, duration of usage of the Website, User's 'click-stream' activity, keyboard language, etc.
Personal Information: Personal Information is information that pertains or relates to a specific individual, where such individual is identified or may be identified with reasonable efforts or together with additional information, we have access to.
Personal Information does not include information that has been anonymized or aggregated; provided that such information can no longer be used to identify a specific natural person. Personal Information that is collected by us may include the following types of information: name, email address, IP address, device identifier, organization identifiers, position and other personal information provided or otherwise made available to us in connection with or as part of: (i) filling out of registration forms available on the Website; and (ii) use of the Solution and/or Sentra’s services; and (iii) engagement with our support services. In addition, the Personal Information we may collect also includes Candidates’ Information (as defined below).
We do not collect any Personal Information from you or related to you without your approval or pursuant to the approvals provided to us by your organization (including on your behalf), which is obtained, inter alia, through your active acceptance of this Privacy Policy. We may also have access to personal information as part of the data which is made available to us by our customers as part of our customers’ use of our services, who have assured us they have the right to do so. Our access and use of any such data may also be subject to an applicable data processing agreement between us and our customer, and in the event of a conflict between such data processing agreement and this Privacy Policy, such agreement shall prevail.
More specifically we collect and use the following categories and types of Personal Information in the following respective circumstances:
Personal Information you provide us actively and voluntarily when you use or interact with our Website and/or Solution: This category refers to any information, data or content you actively and voluntarily create or provide through the Website such as (i) contact information such as full name, email address, company and any other information you actively input through our Website’s and/or Solution’s online forms and text fields and in your access to the Solution and as part of your correspondence with us through various channels of communication, including when you address our support services, register for an account with us or when you update your account details; (ii) the contents of your interaction with our customer support or sales teams which may include text/video/audio recordings and transcripts of such communications.
Personal Information we automatically obtain when you use or interact with our Website and/or Solution: This category refers to any information we obtain through the Website and/or Solution and which is derived, learned, or detected as a result of your access to and/or interaction with the Website, such as: (i) Technical information with respect to the devices and software you use to access our Website and/or Solution such as operating system, browser type, and version, type of end-user device, device ID, etc.; (ii) Usability information with respect to your use of the Website and/or Solution and your engagement, such as clickstream, event and log data, page visits, and different segmentation we apply when we consider your engagement with our Website and/or Solution; (iii) Impression and attribution information which mainly includes information concerning your navigations from and to our Website and/or Solution, such as http referrals, IP address, advertiser ID.
We perform such automatic collection through (i) the use of cookies, web beacons, and similar technologies; and (ii) unique identifiers you provided us with, such as email, ID number, full name or other unique identifiers that generally only identify a computer, device, browser or application.
Keep in mind - Most mobile devices, operating systems and browsers, allow their user to control or disable the use of certain collectible information including location services, by any application, in the device's settings menu.
Personal information collected from other sources: We may collect personal information concerning you, from third parties who have assured us that they have obtained your consent for such provision of information (including without limitation our customers). We may also have access to personal information as part of the data made available to us as part of providing our services to our customers.
For the avoidance of doubt, any Non-Personal Information connected or linked to any Personal Information shall be deemed as Personal Information as long as such connection or linkage exists.
We do not collect any Personal Information from you or related to you without your approval, which is obtained, through various means, including through your acceptance of this Privacy Policy.
WHY DO WE COLLECT INFORMATION ON OUR USERS?
We may use the information that we collect and receive about you for the following purposes:
LAWFUL GROUNDS FOR COLLECTING INFORMATION ON OUR USERS
We collect and process your information for the purposes described in this policy, based at least on one of the following legal grounds:
WHERE DO WE STORE USER’S PERSONAL INFORMATION?
Information regarding the Users will be maintained, processed, and stored by us and our authorized affiliates and service providers in the EU, US, and in Israel, and as necessary, in secured cloud storage, provided by our third-party service provider.
While the data protection laws in the above jurisdictions may be different from the laws of your residence or location, please know that we, our affiliates, and our service providers that store or process your Personal Information on our behalf are each committed to keeping it protected and secured, pursuant to this Privacy Policy and industry standards, regardless of any lesser legal requirements that may apply in their jurisdiction.
You hereby accept the place of storage and the transfer of information as described above.
WHO DO WE SHARE USER INFORMATION WITH AND WHY?
We keep the information processed by us in strict confidence and we may only share information with third parties (or otherwise allow them access to it) in very limited circumstances and for very specific purposes, as described below:
Specifically, each of our Service Providers which store or process your Personal Information either: (i) assured us that they provide adequate safeguards to protect your rights to privacy including where applicable, by undertaking to comply with the EU Standard Contractual Clauses; (ii) where applicable, hold and process such information on our behalf in jurisdictions which have been determined to ensure adequate level protection by the EU Commission; (iii) perform such processing pursuant to your consent and acceptance of their privacy policy as further detailed in this Privacy Policy.
For avoidance of doubt, we may share anonymized/de-identified information with any other third party, at our sole discretion.
YOUR RIGHTS
If you are a visitor of our Website and to the extent that the law applicable to you grants you such rights, you may provide us with certain requests with respect to your Personal Information that is stored in our systems. You may also ask for our confirmation as to whether or not we process your Personal Information. In some jurisdictions, you may request to exercise rights concerning your Personal Information as follows:
Right of access. You may have a right to know what information we hold about you and, in some cases, to have the information communicated to you. We reserve the right to ask for reasonable evidence to verify your identity before we provide you with any information.
Right to correct Personal Information. We endeavor to keep the information that we hold about you accurate and up to date. Should you realize that any of the information that we hold about you is incorrect, please let us know and we will use our best efforts to correct it as soon as we can.
Data deletion. In some circumstances and under certain laws and regulations, you may have a right to request that some portions of the Personal Information that we hold about you be deleted or otherwise anonymized/de-identified.
Data portability. In some circumstances and under certain laws and regulations, you may have the right to request that the data that you have provided to us be provided to you, so you can transfer or port it elsewhere.
If you wish to exercise any of these rights, contact us at: info@sentra.io. When handling these requests, we may ask for additional information to confirm your identity and your request. Please note, upon request to delete your Personal Information, we may retain such data in whole or in part to comply with any applicable rule or regulation and/or response or defend against legal proceedings versus us or our affiliates.
Please Note: Sentra is merely acting as a processor of certain personal information on behalf of its customers (pursuant to the agreement entered between Sentra and the customer, including data processing agreement). As such, if you are using our Solution and related services on behalf of your organization, you should contact your organization in order to enforce any of the rights listed above.
To find out whether these rights apply to you and on any other privacy-related matter, you can contact your local data protection authority if you have concerns regarding your rights under local law.
USING COOKIES AND OTHER TRACKING TECHNOLOGIES
When you access or use the Website, we may use industry-wide monitoring and tracking technologies such as "cookies" or “pixel tags” (or similar technologies), which store certain information on your computer ("Local Storage"), and which will allow us to enable automatic activation of certain features and make your service experience much more convenient and effortless. The Local Storage is created per session and may be deleted by you, or you may configure your browser to not accept any such local storage items.
For example, these technologies enable us to: (i) provide you with the Website and/or Solution, (ii) keep track of our users’ preferences and authenticated sessions, (iii) secure our Website by detecting abnormal behaviors, (iv) identify technical issues and improve the overall performance of the Website and/or Solution, and (v) deliver targeted advertisements that are more tailored to their audience and track ad performance (For more information about this practice, click here: http://www.aboutads.info/choices/).
Such tracking technologies may include Pixel tags (also commonly known as web beacons), transparent images, iFrames, cookies, or Java script placed on our Website and/or Solution or our advertisements and emails, that are used to understand how you interact with the Website and/or Solution, with such advertisements and emails. To learn more about our use of Cookies and other tracking technologies, please see our Cookie Policy. It is important to note that some of these tracking technologies are provided to us by our Services Providers who collect and process personal information in the scope of the services that they provide us.
Please note – in certain cases such Services Providers may collect and process personal information, in a scope that is broader than the scope of collection and processing required for the purposes set forth above. This means that sometimes these Services Providers have access to more of your personal information than we do. In such cases, all such excess collections and processing are performed pursuant to and under a direct contractual relationship you have with such Service Providers, as detailed below, and any rights you may have with respect to such information, collected by such Services Providers, shall be governed by such contractual relationship. Otherwise, the terms of this Privacy Policy shall fully apply.
We may also use Google and Facebook functionality of re-marketing tracking cookies and pixel-based retargeting. This means that if you provide your consent to Google or Facebook, (the “Social Ad Platforms”) to be provided with personalized commercial offers, you may be served with ads based on your use of the Website, outside of the Website, and across the internet. In such an event the Social Ad Platforms, will place cookies or pixels on your web browser and use such technologies to serve you ads based on past visits to our Website.
Please visit the Social Ad Platforms’ individual privacy policy to find out how they use such information:
Google: https://policies.google.com/technologies/ads
Facebook: https://www.facebook.com/about/privacy/
If you wish to opt-out of such re-targeting and tracking functionality of the Social Ad Platforms, you may do so at the following links:
Google: https://adssettings.google.co.il/authenticated
Facebook: https://www.facebook.com/settings/?tab=ads
In addition, if you wish not to receive ads from us based on your use of the Website, please send us an e-mail to info@sentra.io and we will respond within a reasonable timeframe and in accordance with applicable laws.
By accepting this Privacy Policy and using the Website and/or Solution you hereby consent that the following third-party Services Providers shall collect and process your personal information in accordance with their respective privacy policy to which you hereby agree:
Google analytics: https://policies.google.com/technologies/partner-sites
Okta: https://www.okta.com/privacy-policy/
Learn more about your choices and how to opt-out of tracking technologies: In order to delete or block any tracking technologies, please refer to the “Help” area on your internet browser for further instructions, or You may also opt out of third-party tracking technologies by following the instructions provided by each third-party service provider in its privacy policy listed above or visiting www.youronlinechoices.eu or http://www.aboutads.info/choices/. Please note however that deleting any of our tracking technologies or disabling future tracking technologies may prevent you from accessing certain areas or features of our Website, or may otherwise adversely affect your user experience. Please also note that we do not respond to the ‘Do Not Track’ setting on your browser as the protocol and form for such setting has not yet been generally accepted.
DIRECT MARKETING
You hereby agree that we may use your contact details provided during the filling of a registration form on the Website for the purpose of informing you regarding our products and services which may interest you, and to send to you other marketing material. You may withdraw your consent via sending us written notice by email to the following address: info@sentra.io or by pressing the “Unsubscribe” button in the mail.
Please note that the Company may also contact you with important information regarding our Website and/or Solution. For example, we may notify you (through any of the means available to us) of changes or updates to our Website and/or Solution, payment issues, service maintenance, etc. You will not be able to opt out of receiving such service messages.
MINORS
To use our Website and/or Solution, you must be over the age of eighteen (18). Therefore, we do not knowingly collect Personal Information from minors under the age of eighteen (18) and do not wish to do so. We reserve the right to request proof of age at any stage so that we can verify that minors under the age of eighteen (18) are not using the Website and/or Solution.
Without derogating from the above, certain personal information of persons under the age of eighteen (18) might be included as part of the data provided to us or made available by our customers in relation to the services, who have assured us it has the right to do so. Our access and use of any such data is as set forth in this Privacy Policy.
INFORMATION SECURITY
We take great care in implementing and maintaining the security of the Website, Solution, and Personal Information. We have implemented administrative, technical, and physical safeguards to help prevent unauthorized access, use, or disclosure of Personal Information. Your information is stored on secure servers and is not publicly available. We limit access to your information only to those employees, third-party service providers, or partners on a “need to know” basis, and strictly in order to enable us to perform the agreement between you and us or the agreement between us and your organization (in its capacity as our customer).
Despite these measures, we cannot provide absolute information security or eliminate all risks associated with Personal Information, and security breaches may happen. If you have any questions about our Personal Information security, please contact us at info@sentra.io.
DATA RETENTION
If you are a visitor of our Website, we will retain your Personal Information only for as long as necessary to achieve the purposes for collection and processing set forth above. Retention periods will be determined taking into account the type of information that is collected and the purpose for which it is collected, bearing in mind the requirements applicable to the situation and the need to destroy outdated, unused information at the earliest reasonable time. If you withdraw your consent to our processing of your Personal Information, we will delete your Personal Information from our systems (except to the extent retaining such data in whole or in part is necessary to comply with any applicable rule or regulation and/or to respond to or defend against legal proceedings brought against us or our affiliates).
Please Note: If you are using of our Solution and related services on behalf of your organization, or your Personal Information has been made available to us as part of data made available by your organization as part of using Sentra’s services, you should contact your organization in order to request the deletion of your Personal Information and/or any part thereof.
JOB CANDIDATES
We welcome all candidates (“Candidates”) to apply to any of the open positions posted on our Website, or that we otherwise publish on Facebook or LinkedIn. We may be provided with certain Personal Information which may include your full name, email address, phone number, curriculum vitae, and other information such Candidates may elect to share with us over the course of their candidacy (“Candidates Information”). We are committed to keeping Candidates’ Information private and using it solely for our internal recruitment purposes (including for identifying Candidates, evaluating their applications, making hiring and employment decisions, and contacting Candidates by phone or in writing).
Please note that Sentra may retain Candidates Information submitted to ius t even after the applied position has been filled or closed. This is done so we could: re-consider Candidates for other positions and opportunities at Sentra; use their Candidates Information as references for future applications submitted by them; and in case the Candidate is hired, for additional employment and business purposes related to their work.
If you previously submitted your Candidates Information to Sentra, and now wish to access it, update it, or have it deleted from our systems, please contact us at info@sentra.io.
UPDATES TO THIS PRIVACY POLICY
We reserve the right to change this policy at any time, so please revisit this page frequently. We will notify you regarding substantial changes to this Privacy Policy by changing the link to the Privacy Policy on the Website and/or Solution and/or by sending you an e-mail regarding such changes to the e-mail address that you provided during registration. Such substantial changes will take effect seven (7) days after such notice was provided on our Website or sent by email. Otherwise, all other changes to this Privacy Policy are effective as of the stated “Last Revised” date, and your continued use of the Website and/or Solution after the Last Revised date will constitute acceptance of, and agreement to be bound by, those changes.
GENERAL
This Privacy Policy, its interpretation, and any claims and disputes related hereto, shall be governed by the laws of the State of New York, without respect to its criminal law principles. Any and all such claims and disputes shall be brought in, and you hereby consent to them being litigated in and decided exclusively by a court of competent jurisdiction located in New York, NY.
This Privacy Policy was written in English and may be translated into other languages for your convenience. If a translated (non-English) version of this Privacy Policy conflicts in any way with the English version, the provisions of the English version shall prevail.
If you have any questions (or comments) concerning this Privacy Policy, you are welcome to send us an email at: info@sentra.io and we will make an effort to reply within a reasonable timeframe.