Legal
GDPR & Data Processing
Last updated: 1 August 2026
Our role
Purple IT s.r.l. (Perugia, Italy — VAT IT01881930661) provides Sentinely.
- For the personal data contained in the DMARC aggregate reports routed to the service, and everything derived from them, we act as data processor. The customer is the controller.
- For account data, billing, this website and our own communications, we are the controller.
DMARC aggregate reports contain the IP addresses of the servers that sent email using a customer's domain. These can be personal data belonging to third parties, and we treat them as such.
Data Processing Agreement
A Data Processing Agreement (DPA) compliant with art. 28 GDPR is available to all customers. Request it at info@sentinely.eu. It covers the subject matter and duration of the processing, the categories of data and of data subjects, our obligations of confidentiality and security, the rules on sub-processors, assistance with data subject requests, breach notification, and what happens to the data when the contract ends.
Sub-processors of the service
Each of these receives only what its purpose requires:
| Sub-processor | Purpose | Data received | Location |
|---|---|---|---|
| Aruba S.p.A. | Hosting of the application and database | All service data at rest | Italy (EU) |
| Clerk | Authentication and identity | Email, name, session identifiers | USA (DPF / SCC) |
| Amazon Web Services (SES) | Delivery of all email | Recipient addresses, content of digests and alerts | EU (eu-west-1) |
| Stripe | Payments | Billing and payment data | EU / USA (DPF / SCC) |
| PayPal | Payments | Billing and payment data | EU / USA (DPF / SCC) |
| Anthropic | AI-written commentary in digests, where the plan includes it | Domain analysis data needed for the comment | USA (DPF / SCC) |
| Cloudflare | DNS, report-delivery verification, website delivery | Request metadata | EU / global network |
We notify customers before adding or replacing a sub-processor, so that they can object.
Website analytics and advertising
The services used on sentinely.eu for statistics and advertising — Google Analytics, Matomo and the Meta Pixel — concern visitors to the website, not customer data, and run only with consent. They are described in the Cookie Policy. None of them is used inside the application at app.sentinely.eu, which loads no third-party tracking script at all.
Data residency
Account data and report data are processed and stored in the European Union. Transfers outside the EU occur only through the sub-processors marked above, under the EU-U.S. Data Privacy Framework or standard contractual clauses.
Security
Access to production data is restricted and authenticated. Data is encrypted in transit. Backups are taken automatically and restore procedures are documented. Administrative access to a customer's data for support purposes is technically restricted to read-only and recorded in an immutable audit log. Details are provided in the DPA.
Retention and deletion
Report data is retained for the period of the customer's plan and then purged automatically. On termination, customer data is deleted according to the terms of the DPA. Permanent deletion of a domain and all its data can be requested at any time and is irreversible.
Contact
Data protection enquiries: info@sentinely.eu.