Privacy Policy
Last updated: 2026-07-30
Sentrovia ("we", "us", "our") is a corporate PM training platform. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and the choices you have. It applies to all visitors and users of Sentrovia.
1. Data we collect
- Account data: name, email address, password hash, organization, role assignments, and credentials (PMP candidate status).
- Usage data: exam attempts, scores, flashcard reviews, tutorial progress, AI assistant conversations, project records you create.
- Technical data: IP address, browser user-agent, device type, last-login timestamps, and session cookies.
- Org data: for enterprise customers, membership records, competency aggregates, and audit-log entries tied to your account.
- Payment data: billing email, plan tier, subscription state. Card details are stored by our payment processor (Stripe), not by us.
2. Lawful basis (GDPR Art. 6)
We process personal data under one of these lawful bases:
- Contract: to deliver the service you signed up for.
- Legitimate interests: to operate, secure, and improve the platform.
- Consent: for non-essential cookies and marketing communications.
- Legal obligation: tax records, audit logs, fraud prevention.
3. How we use your data
- Deliver the learning experience: exams, flashcards, AI coach, project tooling.
- Provide team-level competency reporting to your organization's admin (no individual question-level details are surfaced to organizational admins).
- Send transactional emails: verification, password reset, billing.
- Detect abuse and enforce rate limits.
4. Data retention
- Account data: retained while your account is active. When you close your account it is deactivated immediately and no longer usable; you may request permanent deletion of your personal data at any time by contacting our DPO.
- Exam attempts and flashcard reviews: retained while your account is active to support competency trending, and removed when your personal data is deleted.
- Audit logs: retention varies by sensitivity — routine activity logs for at least 90 days, security-sensitive events for up to 2 years, and administrative and compliance-relevant actions for up to 7 years.
- Backups: encrypted off-site backups are retained on a rolling schedule.
5. Who we share data with
We do not sell personal data. We share it with:
- Sub-processors: our hosting provider (Vercel), database provider (Neon / Postgres), email delivery (Resend), payment processing (Stripe), AI model providers (Anthropic and OpenAI), error monitoring (Sentry), and operational alerting (Slack). If you enable an optional messaging integration (for example WhatsApp, provided by Meta), the messages you send through it are processed by that provider as well.
- Your organization: if you signed up through an org, your org admin sees your aggregate progress and membership status.
- Legal compulsion: if required by law or to protect rights.
6. Data residency & cross-border transfers
Our primary application compute runs in a European region (London) on Vercel, and the database is hosted by Neon. We do not currently offer a per-tenant choice of data region; for the current list of processing locations for your organization, contact our DPO at the address below.
Where personal data is transferred across borders to our sub-processors, we rely on one or more of the following safeguards as appropriate to the recipient and jurisdiction:
- The EU-US Data Privacy Framework adequacy decision for DPF-certified recipients;
- Standard Contractual Clauses (SCCs) — Module 1 (controller-to-controller) or Module 2 (controller-to-processor), as applicable — for transfers to recipients not covered by an adequacy decision;
- UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs for transfers originating in the UK;
- Equivalent local mechanisms under KSA PDPL and UAE PDPL where these apply.
A current list of sub-processors and the transfer mechanism in use for each is available on request from the DPO contact below.
7. Your rights
- Access (GDPR Art. 15): request a copy of all data we hold on you.
- Rectification (Art. 16): correct inaccurate data.
- Erasure (Art. 17): request deletion of your account and data.
- Portability (Art. 20): export your data in machine-readable JSON.
- Restriction (Art. 18): ask us to stop processing certain data.
- Objection (Art. 21): object to processing based on legitimate interests.
- CCPA / CPRA: California residents have analogous rights including the right to know and the right to delete.
To exercise any of these rights, email privacy@sentrovia.com. We respond within 30 days.
8. Cookies
See our Cookie Policy for details on the cookies we use and how to control them. We do not set non-essential cookies without your consent.
9. Security
Passwords are hashed with bcrypt. Session tokens are httpOnly + SameSite=Lax + Secure-in-production. TOTP-based 2FA is available on every account. We maintain an audit log of privileged actions. Our security incident response process targets notification within 72 hours of a confirmed breach.
10. Children
Sentrovia is intended for adult learners (16+). We do not knowingly collect data from children under 16. If you believe we have, contact us and we will delete it.
11. Changes to this policy
We may update this policy. Material changes will be announced via email and in-app banner at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
12. Contact
Data controller: Sentrovia, Inc.
Email: privacy@sentrovia.com
Data Protection Officer: dpo@sentrovia.com
EU representative: contact us at the email above to be routed to our EU rep.