Legal
Privacy policy
Last updated 17 September 2026. This policy explains what personal data ScoutSentinel Ltd collects, why, and the choices you have. It is written to be read; if anything is unclear, email privacy@scoutsentinel.com.
Who we are
ScoutSentinel Ltd ("ScoutSentinel", "we") is the controller for personal data about visitors to www.scoutsentinel.com and about the people who administer and use ScoutSentinel accounts. For data our customers place in the service (for example test identities in a Watch), the customer is the controller and we are the processor under our terms and data processing addendum.
What we collect
Website visitors
- Server logs: IP address, user agent, requested page and time, held by our hosting provider for security and kept for 30 days.
- Privacy-respecting product analytics with no cross-site tracking. We do not use advertising cookies and we honour Global Privacy Control.
- Anything you send us by email, such as a request for a journey assessment.
Account holders and users
- Name, work email, organisation, role, sign-in method and security settings (passkeys, two-factor status, sessions, API keys).
- Billing contact and invoices. Payment details are collected and stored by Stripe; we never see full card numbers.
- Product usage and audit records: what was configured, by whom and when. The audit log exists to protect your evidence and is retained under your plan.
- Support conversations.
Data in evidence
Probes capture screenshots, network archives and responses from surfaces our customers ask us to assure, using test identities the customer configures. Customers must not point Watches at real customer accounts. Known secret values are redacted before storage. We process this data only on the customer's instructions.
Why we process it
| Purpose | Legal basis |
|---|---|
| Providing the service, authentication and security | Contract; legitimate interests in keeping the service secure |
| Billing and accounting | Contract; legal obligation |
| Product analytics and improvement | Legitimate interests; you can object |
| Answering enquiries and support | Legitimate interests; contract |
| Product news by email | Consent; unsubscribe at any time |
Who we share it with
Our sub-processors are listed on the trust centre with purpose and location: Cloudflare (hosting, storage, email), PlanetScale (database), Stripe (billing), Anthropic (model inference on redacted plan and evidence summaries) and Twilio (voice probes). We do not sell personal data. We disclose data to authorities only when legally required and, where permitted, we tell the affected customer.
International transfers
You choose an EU or US storage region for your organisation. Where data leaves the UK or EU, we rely on adequacy decisions or the UK and EU standard contractual clauses with our sub-processors.
How long we keep it
Account data for the life of the account and up to 30 days after deletion, then in backups for up to 35 further days. Billing records for six years as required by law. Observations, evidence and audit records under the retention entitlement of your plan; see data retention. Website logs for 30 days.
Your rights
You can ask for access to, correction of, deletion of, or a portable copy of your personal data, and you can object to or restrict processing based on legitimate interests. Email privacy@scoutsentinel.com. We respond within one month. You can also complain to the Information Commissioner's Office (UK) or your local supervisory authority.
Security
Encryption in transit and at rest, envelope-encrypted secrets, tenant isolation with row-level security, short-lived evidence access tokens with audit rows and a responsible disclosure programme. Details are on the trust centre.
Cookies
This website sets no cookies. The application sets strictly necessary cookies for sign-in and security. We do not use third-party advertising or tracking cookies.
Changes
We will post changes here and, for material changes affecting account holders, email administrators at least 14 days before they take effect.