Legal
Privacy Policy
Last updated: 1 August 2026
This Privacy Policy explains how Purple IT s.r.l. processes personal data when you visit sentinely.eu, contact us, or use the Sentinely service at app.sentinely.eu.
Data controller: Purple IT s.r.l., Perugia (PG), Italy — VAT IT01881930661 — info@sentinely.eu.
Two different roles, and it matters which one applies
- For the website, our marketing, and your account data, we are the data controller: we decide why and how those data are processed.
- For the DMARC reports you route to the service and everything derived from them, we act as data processor on your behalf: you remain the controller of that data. The terms of that processing are in our Data Processing Agreement.
What we process, and why
When you visit the website. Technical data needed to serve the pages (IP address, browser, pages viewed) and, only if you consent, analytics and marketing cookies. See the Cookie Policy. Legal basis: our legitimate interest in a working, secure site (art. 6(1)(f)) and your consent for anything beyond that (art. 6(1)(a)).
When you contact us. The details you send us, to answer you. Legal basis: art. 6(1)(b) and (f).
When you use the service. Account data (name, email address, preferences, language, authentication identifiers), billing data, and audit records of significant actions. Legal basis: performance of the contract (art. 6(1)(b)) and our legal obligations (art. 6(1)(c)).
The DMARC reports themselves. Aggregate reports contain the IP addresses of the servers that sent email using your domain — which can be personal data of third parties. We process them only to produce the analysis, score, alerts and digests you asked for, as your processor, and never for our own purposes. Legal basis: your instructions as controller, under the DPA.
AI-generated commentary. If enabled for your plan, the digest may include a written comment produced by Anthropic. Only the domain data needed for that comment is sent. This is stated explicitly because it is the question customers ask most often.
Who else sees the data
We use a limited set of sub-processors, each for a specific purpose. The current list, with what each one receives, is published on our GDPR & DPA page.
Where the data is
Account data and report data are processed and stored in the European Union, on infrastructure operated by Aruba S.p.A. in Italy, with email delivery in the AWS eu-west-1 region.
Some sub-processors and the optional analytics and marketing services may transfer data to the United States, under the EU-U.S. Data Privacy Framework or standard contractual clauses. Where this applies it is stated in the sub-processor list and in the Cookie Policy.
How long we keep it
- Account data: for as long as your account exists, then removed or anonymised.
- DMARC reports and derived data: according to the retention period of your plan, after which they are purged automatically.
- Cookie consent records: 24 months (see the Cookie Policy).
- Billing records: for the period required by Italian tax law.
Your rights
You may request access, rectification, erasure, restriction and portability of your personal data, and object to processing based on legitimate interest. Where processing is based on consent, you may withdraw it at any time, without affecting what was done before.
Write to info@sentinely.eu. You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (garanteprivacy.it).
If your request concerns data inside DMARC reports processed on behalf of a customer, we will refer you to that customer, who is the controller for those data.
Changes
We publish the date of the last update at the top of this page. Substantial changes affecting cookies also trigger a new consent request.