Skip to main content
SentryOT
  • Solutions
  • Product
  • Platform
  • Our Mission
  • About Us
  • Latest News

Features

  • Asset InventoryA live map of every asset, down to firmware
  • Real Time MonitoringContinuous detection across every OT asset
  • Incident InvestigationFull context on every event, from alert to physical impact
  • Operational ImpactCyber events understood in operational terms
  • Case ManagementFrom alerts to one defensible case

Services

  • Data Sources EnablementEvery OS, ICS, and network source, switched on.
  • Data Retention & ContinuityRedundancy and retention for uninterrupted collection.
  • Infrastructure CalibrationPlatform mapped to your process and infrastructure.
Request a Demo

Privacy Policy

This notice explains what happens to personal data in connection with the www.sentryot.com website. It is short because the website itself collects very little: it sets no cookies on its public pages unless you agree to analytics, and it asks before it sets any. (The /admin area, which only SentryOT staff can reach, sets strictly necessary first-party cookies for signing in and for editor preferences; the Cookie Policy describes them.) What you type into the contact form reaches us as an e-mail and is not stored on the website; section 3 sets that out.

This notice covers the website. Processing that reaches us by other routes — commercial correspondence, recruitment, the wider group’s own activities — is governed by our internal records, and you can ask us about any of it at the address in section 1.

1. Who is responsible

1.1 The controller of any personal data processed in connection with this website is ENEVO CYBERSEC SRL, a Romanian legal entity with headquarters in Bucharest, Barbu Vacarescu Str., no. 301-311, Romania, registered with the Trade Register Office under no. J40/4752/2013 and having VAT Code RO 31491048 (“Enevo Cybersec”).

1.2 For any question about this notice or about your personal data, write to office@sentryot.com or call +40 371 017 242.

2. What this website collects

2.1 You do not need an account, a registration or to give us anything about yourself in order to read this website. There is no newsletter, no file upload, no user profile and no automated decision-making of any kind. What the site does receive without being given it — the technical records any web server keeps, and the data described in the sections below — is set out here rather than glossed over.

2.2 The website sets no cookies and no device identifiers on its public pages unless you accept analytics on the banner shown on your first visit. If you accept, we measure which pages are read, where visitors click, how far they scroll and the path taken from one page to the next, we work out from your IP address the approximate part of the world the visit came from, and we record the visit so that it can be replayed afterwards — with every input field masked, so nothing you type is recorded. If you decline, none of those analytics data are created or recorded. The one thing stored either way is the record of your own answer — a single local-storage entry holding “granted” or “denied” and the date, no identifier, never sent anywhere. It expires after about six months, and can be changed or withdrawn at any time under Analytics at the foot of every page. The supplier, the cookie names, their lifetime and the deletion that follows a withdrawal are set out in the Cookie Policy, section 5.

2.3 The website uses no advertising technology, no tag manager and no cross-site tracking, and it does not build profiles for marketing or share visit data with advertising networks or data brokers. Fonts, images and scripts are served from our own domain rather than from external content networks, so loading a page does not disclose your IP address to a content network; PostHog is addressed through our own domain as well, so your browser opens no connection to the supplier — though the request our own server forwards does carry your IP address, as section 4.1 explains. The single exception is the spam check on the contact page, which your browser fetches from Cloudflare’s domain: section 2.5 describes it.

2.4 The infrastructure that serves this website keeps the ordinary technical records any web server does — the request, the time, the address it came from — because it cannot operate or be defended without them. They are normally kept for 30 days, and longer only where a particular record is needed to investigate a security incident. They are not used to build any profile of you. Ask us at the address in section 1 if you need detail about them.

2.5 The spam check on the contact form. The contact page is protected against automated abuse by a check supplied by Cloudflare, which runs on that page only. It stores nothing on your device and never sees what you type; it sends Cloudflare a small set of technical signals — your IP address, a fingerprint of your browser’s encrypted connection, the identifier your browser sends to describe itself, and the key identifying our widget with the address of the page. The check uses no cookie and no other storage on your device that would require your consent. Separately, for the personal data involved in running it, the lawful basis is our legitimate interest in protecting the contact form against automated abuse, Art. 6(1)(f) GDPR. You can object, and you can write to office@sentryot.com instead of using the form. Section 4.3 names the supplier and the transfer arrangements, and Cookie Policy section 5.3 sets the whole of it out.

3. The contact form

3.1 When you submit the form in the Contact section, the details you enter — your name, your work e-mail address, your telephone number, the type of enquiry and what you write — are transmitted to us as an e-mail so that we can read and answer it.

3.2 Where it is kept. This website keeps no copy: there is no submissions database behind the form, and the message is not written to any log. It is transmitted by Amazon Web Services (section 4.2) and it then lives where any e-mail to us lives — in our business mail system, in the mailbox of whoever answers you, in that system’s backups, and in the correspondence that follows. We would rather say that plainly than claim the message exists in only one place.

3.3 Why we may do this. Which ground applies depends on who is asking, and for a form that asks for a work e-mail address that distinction matters. Where you contact us on your own behalf about a contract between you and us, we process your details to take steps at your request before entering into it, Art. 6(1)(b) GDPR. Where you contact us for the organisation you work for — which is the ordinary case here, and where any contract would be between that organisation and us rather than with you personally — we rely on our legitimate interest in receiving, assessing and answering business enquiries, Art. 6(1)(f) GDPR. The same legitimate interest covers any other enquiry. We use the details only to respond to you and to carry that discussion forward: not for marketing lists, not for profiling, and never passed to anyone for their own purposes.

3.4 How long. Where your enquiry leads to an engagement, we keep the relevant correspondence with the contractual records, for the period our legal, tax and accounting obligations require. Where it does not lead to one, we keep the correspondence for up to 24 months after the last substantive exchange, because a purchase in this field is discussed over many months and an enquiry is often picked up again; after that it is deleted, unless there is a legal reason to keep it longer. You can ask us at any time how long we still hold a particular enquiry. You can ask us to delete it sooner: we will consider the request under the GDPR, act on it where the Regulation requires, and tell you plainly if there is a legal reason we have to keep it — for example while a claim is being established or defended.

3.5 You are free to send us only as much as you want us to have. If the online form is unavailable, you may write to us directly at office@sentryot.com.

4. Third parties

4.1 Analytics, if you have agreed to it. The analytics described in section 2.2 are provided by PostHog Inc., which acts as our processor: it handles the data on our instructions, for the purposes we have set and for no purpose of its own. The data is held on PostHog’s European infrastructure in Frankfurt. It includes your IP address, which reaches PostHog on the request our server forwards and is used to establish an approximate location — a country and a region, not an address; both it and the location derived from it are kept for as long as the events are. The lawful basis is your consent, Art. 6(1)(a) GDPR, and withdrawing it is as straightforward as giving it — Analytics at the foot of every page — after which the cookies and local storage entries it placed are deleted from your device. We keep the events for up to twelve months and the session recordings for up to thirty days. PostHog Inc. is a company established in the United States; the arrangements governing any transfer of this data outside the European Economic Area are the European Commission’s Standard Contractual Clauses, incorporated in our data processing agreement with PostHog Inc., a copy of which is available on request.

4.2 The mail service that carries the contact form. The e-mail described in section 3 is transmitted by Amazon Web Services through its Simple Email Service, which acts as our processor for that transmission and for no purpose of its own. It is sent from infrastructure in Amazon’s Frankfurt region, inside the European Economic Area. Amazon’s data processing terms, including the European Commission’s Standard Contractual Clauses for any transfer outside the European Economic Area, form part of our agreement with Amazon and apply to this processing automatically. Amazon processes the message in order to provide the transmission service — which includes the automated security, anti-abuse and deliverability handling any mail system performs — and does not use it for advertising or profiling.

4.3 The spam check that protects the contact form. The check described in section 2.5 is Cloudflare Turnstile, provided by Cloudflare, Inc. For the check itself Cloudflare acts as our processor, on our instructions. It is also, on its own account, a controller of the same signals for the narrow purpose of improving how its bot detection works — that is Cloudflare’s own arrangement, set out in its Turnstile Privacy Addendum, and not something we direct. The signals are the ones listed in section 2.5, and the contents of the form are not among them. Cloudflare does not pass those signals back to us. Its verification response tells us whether the check succeeded, together with standard verification metadata such as the time of the challenge and the hostname it ran on; our server reads only the success flag and any error code. The fingerprint and the other signals behind the verdict are never disclosed to us. We do not use Turnstile’s optional ephemeral device identifiers. Our own infrastructure separately records your IP address as part of the ordinary request logs described in section 2.4 — that is our processing, not Turnstile’s, and the two should not be confused. Cloudflare does not publish a retention period for the signals it holds. Cloudflare, Inc. is established in the United States; the arrangements governing any transfer outside the European Economic Area are the European Commission’s Standard Contractual Clauses, incorporated in Cloudflare’s data processing addendum, which forms part of our agreement with Cloudflare. The lawful basis for our own use of the check is Art. 6(1)(f) GDPR, our legitimate interest in preventing automated abuse of the form; because that is not consent, you have the right to object under section 5, and you can always write to us at office@sentryot.com instead.

4.4 The links to our LinkedIn and YouTube pages are ordinary links, not embedded plug-ins: they transmit nothing to those networks until you choose to follow them.

4.5 We do not sell personal data and we do not share it with advertising networks or data brokers.

5. Your rights

5.1 Under the General Data Protection Regulation (EU) 2016/679 you have the right to ask us for access to your personal data and for its rectification; and, in the circumstances the Regulation sets out for each, the right to erasure, the right to restrict processing, the right to object, and the right to data portability — portability applying to data you provided where the processing is automated and rests on your consent or on a contract. Where processing rests on your consent, you may withdraw it at any time. Not every right applies to every kind of processing, and we will tell you plainly which one applies if you ask.

5.2 To exercise any of these rights, write to office@sentryot.com. We will respond within the time limits the Regulation sets.

5.3 One of those rights does not require writing to us at all: the consent described in section 2.2 can be withdrawn directly on the website, under Analytics at the foot of every page, in the same single step that gave it. Withdrawal takes effect immediately and deletes from your device the cookies and local storage entries that were set under it. Withdrawing does not affect processing already carried out while the consent stood.

5.4 You also have the right to lodge a complaint with the Romanian supervisory authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP), www.dataprotection.ro, or with the supervisory authority of your place of residence.

6. Changes to this notice

6.1 This notice is updated whenever our practices change. The version in force is always the one published on this page.

SentryOT

Real-time OT defense for critical energy infrastructure.

Product

  • Solutions
  • Product
  • Platform

Company

  • Our Mission
  • About Us
  • Latest News

Contact

  • +40 371 017 242
  • office@sentryot.com

Social

LinkedIn (opens in a new tab)YouTube (opens in a new tab)
Website Terms of UsePrivacy PolicyCookie Policy

© 2026 SentryOT. All rights reserved.