SiteSentinel

Privacy Policy

Effective date: 2026-06-27. Version: 2026-06-27.

1. Controller

The controller of personal data processed in connection with SiteSentinel is Maksym Stanowski, an individual conducting unregistered activity under Polish law, maksym1stanowski@gmail.com, Polska. Privacy contact: prywatnosc@sitesentinel.pl.

2. Scope

This policy covers data processed in connection with sitesentinel.pl, accounts, organizations, website monitoring, reports, incidents, payments, invoicing, contact, support, service security and marketing communication after separate consent.

3. Data categories

  • name
  • email address
  • company or organization name
  • position and organization role
  • account and authentication data
  • session and login information
  • IP address
  • device and browser data
  • language and theme settings
  • monitored website URLs
  • monitoring configuration
  • check results
  • incident history
  • comments and recommendations
  • report data
  • billing and invoice data
  • payment history
  • contact and support request content
  • security logs
  • accepted document versions and consent records

Special categories of data should not be provided through SiteSentinel unless expressly agreed and properly secured.

4. Purposes and legal bases

  • account creation and contract performance - Article 6(1)(b) GDPR
  • organization, monitoring, report and incident handling - Article 6(1)(b) GDPR
  • payments and subscription management - Article 6(1)(b) GDPR
  • tax and accounting duties - Article 6(1)(c) GDPR
  • pre-contract questions and requests - Article 6(1)(b) GDPR
  • other contact handling - Article 6(1)(f) GDPR
  • service protection, abuse prevention, error detection and claims - Article 6(1)(f) GDPR
  • marketing, campaign and conversion measurement through Meta Pixel - consent, Article 6(1)(a) GDPR and electronic communication rules
  • optional analytics - consent where required

5. Required data

Required data is necessary to create an account, conclude a contract or handle a request. Missing required data may prevent the relevant action. Marketing data is voluntary.

6. Recipients

Data may be shared with or entrusted to hosting and infrastructure providers, database providers, Redis or queue providers, Stripe, Resend, file storage and backup providers, error monitoring providers when enabled, Google in connection with analytics and Meta Platforms Ireland Limited after marketing consent, accounting, legal advisors and authorities entitled by law. The current list is available on the Subprocessors page.

7. Transfers outside the EEA

If a provider processes data outside the EEA, the controller uses an appropriate legal mechanism, especially an adequacy decision or standard contractual clauses. Transfers must reflect actual vendor locations and legal bases.

8. Retention

  • account data - while using the service and then as needed for settlement and claims
  • contract data - for contract duration and limitation periods
  • accounting documents - for the period required by law
  • monitoring results - according to plan retention
  • security logs - according to internal retention policy
  • contact data - until the matter ends and then as needed for claims
  • marketing data - until consent withdrawal or effective objection
  • consent records - as long as needed to prove validity
  • deleted account data - until mandatory retention ends, then deleted or anonymized

9. User rights

  • access
  • copy
  • rectification
  • erasure
  • restriction
  • portability
  • objection
  • consent withdrawal
  • complaint to a supervisory authority

Consent withdrawal does not affect earlier lawful processing.

10. Automated decisions

SiteSentinel does not make solely automated decisions producing legal effects. Automated scan results and priorities are technical and may require human verification.

11. Monitored websites

Users should add only websites they are authorized to monitor and are responsible for legal compliance of configurations and data. The service must not be used to obtain data from non-public areas without a proper basis.

12. Security

Technical and organizational measures include access control, secure sessions, encrypted transmission, permission validation, request limits and scanner safeguards. Details are available on the Security page.

13. Cookies and browser storage

Information about cookies, localStorage and similar technologies is available in the Cookie Policy.

14. Changes

This policy may change due to law, service, vendor or processing scope changes. Material changes are communicated in the panel or through an available contact channel.

SiteSentinelSiteSentinel

Monitoring, technical audits and reports for the websites you manage.

© 2026 SiteSentinel. All rights reserved.

SecurityPrivacyTermsCookiesCookie settingsContactStatusApp