Privacy Policy

Pursuant to Art. 13-14 of EU Regulation 2016/679 (GDPR)  ·  Version 1.0 — August 2026

This document describes how Airgrid S.r.l. processes the personal data of users who access and use the Sentinel platform, available at sentinel.airgrid.eu.

1. Data Controller

Airgrid S.r.l.
VAT IT02598290306
E-mail: privacy@airgrid.eu

2. Data processed and purposes

2.1 Registration and access

At registration we collect: first name, last name, tax code, e-mail address and password (hashed with bcrypt). Processing is necessary for contract performance (Art. 6 §1(b) GDPR) and compliance with applicable legal obligations.

2.2 Scan data

Target URLs submitted by the user and vulnerability scan results are stored in the database for the period covered by the active plan:

PlanScan retention
Free1 day
Web Sec PRO5 days
Web Sec RED30 days

Processing is necessary for the performance of the contract (Art. 6 §1(b) GDPR).

2.3 Activity log (audit log)

All significant actions (login, scan start, report download, account changes) are logged with username, IP address and timestamp. Legal basis: legitimate interest in IT security and legal traceability (Art. 6 §1(f) GDPR). Logs are retained for 12 months.

2.4 Payments

Payments are handled by Stripe Inc. (San Francisco, CA, USA) through its PCI-DSS certified infrastructure. Airgrid does not process or store credit card data. Stripe acts as a data processor pursuant to Art. 28 GDPR. For more information: stripe.com/privacy.

2.5 Technical browsing data

The web server automatically logs the IP address, user-agent and requested URLs in nginx logs. These data are used solely for operational security and are retained for 30 days. Legal basis: legitimate interest (Art. 6 §1(f) GDPR).

3. Cookies and similar technologies

Sentinel uses only strictly necessary technical cookies:

CookiePurposeDuration
sessionAuthenticated session management (Flask)8 hours
Stripe cookiesSecure payment flow management (checkout only)Session

No profiling, tracking or marketing cookies are used. No third-party analytics systems are present.

4. International transfers

Data is processed on servers located in the European Union (OVH, France). Transfer of data to Stripe (USA) takes place on the basis of Standard Contractual Clauses approved by the European Commission (Art. 46 GDPR).

5. Data subject rights

Under Arts. 15-22 GDPR, the user has the right to:

To exercise your rights, send a request to privacy@airgrid.eu. You also have the right to lodge a complaint with the competent supervisory authority in your EU member state.

6. Security of processing

We implement appropriate technical and organisational measures to protect personal data: TLS encryption in transit, bcrypt password hashing, mandatory two-factor authentication, data access limited to authorised personnel, complete activity audit log.

7. Updates

This policy may be updated. Material changes will be communicated by e-mail to registered users. The current version is always available on this page.