Airgrid S.r.l.
VAT IT02598290306
E-mail: privacy@airgrid.eu
At registration we collect: first name, last name, tax code, e-mail address and password (hashed with bcrypt). Processing is necessary for contract performance (Art. 6 §1(b) GDPR) and compliance with applicable legal obligations.
Target URLs submitted by the user and vulnerability scan results are stored in the database for the period covered by the active plan:
| Plan | Scan retention |
|---|---|
| Free | 1 day |
| Web Sec PRO | 5 days |
| Web Sec RED | 30 days |
Processing is necessary for the performance of the contract (Art. 6 §1(b) GDPR).
All significant actions (login, scan start, report download, account changes) are logged with username, IP address and timestamp. Legal basis: legitimate interest in IT security and legal traceability (Art. 6 §1(f) GDPR). Logs are retained for 12 months.
Payments are handled by Stripe Inc. (San Francisco, CA, USA) through its PCI-DSS certified infrastructure. Airgrid does not process or store credit card data. Stripe acts as a data processor pursuant to Art. 28 GDPR. For more information: stripe.com/privacy.
The web server automatically logs the IP address, user-agent and requested URLs in nginx logs. These data are used solely for operational security and are retained for 30 days. Legal basis: legitimate interest (Art. 6 §1(f) GDPR).
Sentinel uses only strictly necessary technical cookies:
| Cookie | Purpose | Duration |
|---|---|---|
session | Authenticated session management (Flask) | 8 hours |
| Stripe cookies | Secure payment flow management (checkout only) | Session |
No profiling, tracking or marketing cookies are used. No third-party analytics systems are present.
Data is processed on servers located in the European Union (OVH, France). Transfer of data to Stripe (USA) takes place on the basis of Standard Contractual Clauses approved by the European Commission (Art. 46 GDPR).
Under Arts. 15-22 GDPR, the user has the right to:
To exercise your rights, send a request to privacy@airgrid.eu. You also have the right to lodge a complaint with the competent supervisory authority in your EU member state.
We implement appropriate technical and organisational measures to protect personal data: TLS encryption in transit, bcrypt password hashing, mandatory two-factor authentication, data access limited to authorised personnel, complete activity audit log.
This policy may be updated. Material changes will be communicated by e-mail to registered users. The current version is always available on this page.