Skip to content
Sentrize is an AWS Advanced Tier Partner

Privacy Policy

How Sentrize collects, uses, and protects your information.

Last updated: August 2026

1. Who we are and what this policy covers

Sentrize designs, builds, and operates custom software and cloud platforms for startups, SaaS companies, and enterprises, with offices in Sydney, London, and Singapore. This policy explains how we handle personal data when you visit www.sentrize.com, contact us about a project, or work with us as a client.

It covers three situations, and our role differs in each:

  • Website visitors and prospects. When you browse our site, submit the contact form, or exchange emails with our team, Sentrize decides how and why that data is used — we act as the data controller.
  • Client business contacts. When we work with your organization, we hold contact details of your team members (names, work emails, roles) to deliver and administer the engagement. Here too we are the controller.
  • Client project data. When we build, migrate, or operate systems that contain your end users' or employees' personal data, we handle that data only on your documented instructions. For that data, you are the controller and Sentrize is a data processor, and the terms of our data processing agreement (DPA) with you apply, not this policy.

2. Information we collect

You provide it directly: name, work email, company, the service you're interested in, budget range, and anything you include in a message to us; contact details exchanged during an engagement; billing details needed to invoice your organization.

We collect it automatically: IP address, browser and device type, pages visited, referring page, and similar technical logs generated when you use our website. We use this to keep the site running, secure, and improving.

Client project data: whatever data your systems contain when we host, operate, or work on them. We do not use this data for our own purposes, and we access it only to the extent your instructions and the engagement require.

We do not intentionally collect special-category (sensitive) data through this website, and we ask that you not include it in contact-form messages.

3. How we use personal data, and our legal bases

Where GDPR or similar laws apply, we rely on the following legal bases:

  • Responding to inquiries and scoping projects — our legitimate interest in running our business, and steps taken at your request before entering a contract.
  • Delivering services and managing engagements — performance of a contract with you or your organization.
  • Invoicing, accounting, tax, and legal compliance — compliance with legal obligations.
  • Securing our systems and preventing abuse — our legitimate interest in protecting our infrastructure and our clients'.
  • Occasional updates about our services — legitimate interest for existing business contacts, or consent where the law requires it. You can opt out at any time.

We do not sell personal data, and we do not use it for automated decision-making that produces legal or similarly significant effects.

4. Cookies and analytics

Our website uses a small number of cookies and similar technologies: strictly necessary cookies that make the site work, and analytics that help us understand how the site is used so we can improve it. Analytics data is aggregated wherever practical. You can control cookies through your browser settings; where the law requires consent for non-essential cookies, we ask for it before setting them.

5. Sharing and subprocessors

We share personal data only where needed to run our business:

  • Cloud infrastructure providers — primarily Amazon Web Services (AWS), which hosts our website and much of the infrastructure we manage.
  • Business software providers — email, CRM, ticketing, accounting, and communication tools we use to operate.
  • Professional advisers — auditors, insurers, accountants, and lawyers, under confidentiality obligations.
  • Authorities — where the law requires it, or to protect our rights or the safety of others.

Every processor acting on our behalf is bound by a written agreement requiring confidentiality and appropriate security. For client project data processed under a DPA, we maintain a list of approved subprocessors and notify clients of changes as the DPA provides. Enterprise clients can request the current subprocessor list at privacy@sentrize.com.

6. International transfers

We are a globally distributed team with offices in Australia, the United Kingdom, and Singapore, so personal data may be transferred between these regions and to our subprocessors' locations. Where data protected by GDPR or UK GDPR leaves the EEA or UK, we rely on adequacy decisions where available and otherwise on the European Commission's Standard Contractual Clauses (and the UK Addendum or IDTA), together with supplementary technical measures such as encryption. For client project data, data-residency requirements can be fixed contractually — many of our clients pin workloads to specific AWS regions.

7. How we protect your data

Security is our discipline, not an afterthought. Sentrize is certified to ISO 27001 and audited annually against SOC 2 Type II for security, availability, and confidentiality. In practice that means: least-privilege, role-based access with MFA; encryption in transit and at rest; infrastructure defined as code and changes going through review; continuous monitoring and logging; documented incident response; and background-checked personnel bound by confidentiality. Access to client data is restricted to the engineers assigned to your engagement. If a breach affects your personal data, we will notify you and any relevant regulator as the law requires.

8. How long we keep data

We keep personal data only as long as needed for the purpose it was collected: inquiry data for as long as the conversation is live and a reasonable period after; client contact and contract data for the engagement plus the period required for legal, tax, and audit obligations; website logs for a short rolling window. Client project data is retained and deleted according to your instructions and the DPA — typically returned or deleted when the engagement ends, subject to any legally required backups, which expire on their own schedule.

9. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent where processing is based on consent. These rights exist under GDPR and UK GDPR, and similar rights apply under the Australian Privacy Act, Singapore's PDPA, and various other laws.

To exercise any of them, email privacy@sentrize.com. We will respond within one month (or the shorter period your local law requires) and may ask you to verify your identity first. If we hold your data as a processor for one of our clients, we will refer your request to them and support their response. You also have the right to complain to your data protection authority, though we'd appreciate the chance to resolve your concern first.

10. Children

Our website and services are aimed at businesses and are not directed at children. We do not knowingly collect personal data from anyone under 16; if you believe we have, contact privacy@sentrize.com and we will delete it.

11. Changes to this policy

We may update this policy as our services, subprocessors, or the law change. We will post the revised version here with an updated "Last updated" date, and for material changes we will make the update prominent or notify active clients directly.

12. Contact

Questions, requests, or concerns about privacy: privacy@sentrize.com. You can also write to any of our offices — Sydney, London, or Singapore — listed on our contact page.