Skip to content

Privacy Policy

How CRA Sentinel collects, uses, stores and protects personal data, and the rights you have over it under the EU General Data Protection Regulation. Written from what the system actually does.

Effective date
2026-09-03
Provider
Enete Ebube Basil · 3534461-2 · VAT FI35344612
Business address
Taitoniekantie 9 R, 40740 Jyväskylä, Finland

1Who is responsible for your data

The controller of the personal data described in this policy is Enete Ebube Basil, Business ID 3534461-2, VAT number FI35344612, business address Taitoniekantie 9 R, 40740 Jyväskylä, Finland.

For any question about this policy, or to exercise a right described in section 8, contact [email protected].

We are the controller for the data we hold to run the service itself: account and organisation data, billing data, security records, and the messages you send us.

The content you upload — your products, versions, software bills of materials and the decisions your team records — is data your organisation controls. We hold and process it on your behalf, only to provide the service to you as described in section 4, and we do not use it for our own purposes. If your organisation requires a separate data processing agreement, contact [email protected] and we will discuss what you need.

2What this policy covers

The public CRA Sentinel website and the CRA Sentinel application supplied to business customers under the Terms of Service.

CRA Sentinel is business software. We do not knowingly collect personal data from consumers or from children, and the service is not directed at them.

3What we collect

  • Account data. The email address used to create an account, the organisation it belongs to, the role held within that organisation, and a cryptographic hash of the password. Passwords are never stored in a form from which they can be recovered.
  • Organisation data. The organisation name and the contact details you record for regulatory reporting purposes.
  • Session and security records. Session identifiers held in a cookie, and a security log of relevant events such as sign-in, sign-out, password change, API key issuance and billing actions. Each entry holds a timestamp, the event name, the user and organisation it concerns, and a short description. It deliberately holds no credential material.
  • Product and version metadata. The products and supported versions you record, and the details you attach to them.
  • Software bills of materials. The SBOM documents you upload, and the component inventory derived from them. These describe your software rather than people, but may contain personal data where you choose to include it.
  • Vulnerability, triage and reporting records. Findings, the triage decisions your team makes and their revisions, reporting cases, deadlines, and the append-only evidence history. These records attribute decisions to the account that made them, deliberately: a record of who decided what, and when, is the purpose of the product.
  • Billing data. Subscription status, the identifiers linking your organisation to its customer and subscription at our payment provider, and invoice references synchronised from it. Card details are handled entirely by the payment provider and are never received or stored by us.
  • Transactional email records. The messages we send you, and their delivery status as reported by our email provider.
  • Messages you send us. If you email our contact address, the message and the address it came from.

The application does not record your IP address or your browser user agent. Our infrastructure and content-delivery providers may record such data in their own operational and security logs, governed by their own terms and retention practices rather than by ours.

The public CRA Sentinel website sets no cookies, runs no analytics or advertising scripts, and does not track visitors.

4Why we use it, and on what legal basis

  • To provide the service — creating and maintaining accounts, monitoring the components you record, running the triage and reporting workflow, keeping the evidence history, and sending the transactional messages the service depends on. Legal basis: performance of a contract, GDPR Article 6(1)(b). Without this data the service cannot be delivered at all.
  • To take payment — managing subscriptions, invoicing and handling billing disputes. Legal basis: performance of a contract, Article 6(1)(b); and compliance with a legal obligation for accounting records, Article 6(1)(c).
  • To keep the service secure — detecting and investigating abuse, protecting accounts and maintaining the security log. Legal basis: our legitimate interests in operating a secure service, Article 6(1)(f). We consider this proportionate because the data involved is limited to account identifiers and event descriptions, and the alternative is being unable to investigate a compromise of a customer account.
  • To answer your enquiries — responding to messages you send us. Legal basis: performance of a contract where you are a customer, otherwise our legitimate interest in answering the people who contact us, Article 6(1)(f).

We do not use your data to train machine learning models, we do not sell it, and we do not share it for advertising.

5Who processes it on our behalf

We use a small number of service providers. Each processes data only to provide its service to us: application hosting; a managed database and private object storage; DNS, TLS and content delivery; transactional email delivery; and payment processing. The payment provider acts as an independent controller for payment data under its own privacy policy.

The providers we currently use for those functions are:

  • Render — application hosting.
  • Supabase — managed database and private object storage.
  • Cloudflare — DNS, TLS and content delivery for our websites, and forwarding for our contact address.
  • Resend — delivery of transactional email.
  • Stripe — payment processing and subscription management.

If this list changes we will update this policy. For questions about a specific provider, contact [email protected].

We may also disclose data where required by law, or where necessary to establish, exercise or defend legal claims.

6Where your data is held

As currently configured, the application runs in Germany and the database and object storage are hosted in Ireland, both within the European Economic Area.

Some providers operate globally and may process limited data, such as network metadata or payment information, outside the EEA.

Where that happens, the transfer is governed by the safeguards in that provider’s own terms and privacy documentation. If you need to know how a particular provider handles transfers for your organisation, contact [email protected] and we will tell you what we know and point you to the provider’s own terms.

7How long we keep it

  • While your account is active. Account data, customer content and evidence records are retained for as long as your organisation holds an account.
  • After a deletion request. Deletion is scheduled with a 90-day grace period, during which the request can be reversed. This exists so that an accidental or disputed deletion does not destroy compliance records your organisation may still need. This period is set in the application configuration.
  • After cancellation. Ending a subscription does not delete anything. Records remain readable and exportable.

For everything else — billing and accounting records, security log entries and transactional email records — we keep personal data only for as long as it is necessary for the purposes described in section 4, and for any longer period that accounting, tax or other applicable law requires. If you want to know how long we hold a particular category of data, contact [email protected].

8Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you, and receive a copy of it;
  • have inaccurate data corrected;
  • have data erased, where we have no overriding obligation or legitimate ground to keep it;
  • restrict or object to processing carried out on the basis of our legitimate interests;
  • receive data you provided in a structured, commonly used, machine-readable format, and have it transmitted to another controller; and
  • withdraw consent at any time, where processing is based on consent.

To exercise any of these, contact [email protected]. We will respond within one month and will tell you if we need longer because the request is complex.

If you are a member of a customer organisation, note that the evidence history attributes decisions to the account that made them, and that attribution is part of the integrity of the record. Where we cannot erase such a record without destroying its evidential value, or where the customer organisation has its own basis for retaining it, we will explain why and tell you what we can do instead.

You may also lodge a complaint with a supervisory authority. In Finland this is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto, tietosuoja.fi). You may also complain to the authority in your own country of residence or work.

9How we protect it

Passwords are hashed with Argon2. Sessions use signed, HTTP-only cookies, marked Secure outside development, with cross-site request forgery protection on state-changing requests. Traffic is encrypted in transit. Every record belongs to exactly one organisation and every request is authorised against it. Uploaded documents are held in private object storage that is not publicly addressable. Evidence entries are append-only and hash-chained, so alteration is detectable. Inbound provider webhooks are signature verified. Backups are taken, and their restoration is verified rather than assumed.

No system is perfectly secure. These measures reduce risk. They are not a certification, and they are not a guarantee that a security incident cannot occur.

10Changes to this policy

We may update this policy as the service changes. The effective date above records the current version. Where a change materially affects your rights, we will notify account holders by email before it takes effect.

This policy describes how the service is built and operated. It is a statement of practice, not a claim to hold any certification, and describing our practices here is not an assertion that every requirement of data-protection law has been independently verified.