1.1. The controller of personal data processed in connection with the website sentiteasy.com and the service SentItEasy (the "Service") is the operator of sentiteasy.com (the "Controller", "we"). Contact for all privacy matters: admin@sentiteasy.com or the Messages function of the Service. We have not appointed a data protection officer, as this is not required by Article 37 of Regulation (EU) 2016/679 (GDPR) in our circumstances.
1.2. This Privacy Policy forms part of the Terms and Conditions. Capitalised terms have the meaning given in the Terms and Conditions.
2.1. As controller we process the data of our Customers and website visitors described in section 3 for our own purposes (providing the Service, security, billing, statistics and communication).
2.2. As processor we process, on behalf of our Customers, the personal data of third parties that Customers enter into the Service (for example names of contact persons, drivers, sole traders, vehicle numbers and addresses appearing in declarations, saved contacts and library files). In respect of that data the Customer is the controller; the processing terms are set out in clause 6.4 of the Terms and Conditions.
| Data | Purpose | Legal basis (GDPR) | Retention |
|---|---|---|---|
| Account data: e-mail address, first and last name, telephone, individual/company status, company name, registration number and address, contact person; password (stored only as a one-way hash); optional two-factor secret; confirmation and session tokens; time of acceptance of the Terms. | Registration, authentication, performance of the agreement, security, support. | Art. 6(1)(b) contract; Art. 6(1)(f) legitimate interest in security. | While the Account exists; deleted when you delete the Account. |
| Sign-up source: the website, medium and campaign tag (for example from a link in our e-mail) under which you reached the sign-up. | Measuring which of our communications lead to registrations. | Art. 6(1)(f) legitimate interest in understanding our reach. | While the Account exists. |
| Declaration content and library: carrier, sender and recipient names, VAT numbers and addresses, vehicle and trailer numbers, document, route and goods data, saved contacts, generated XML files and folders. | Providing the Service: generating, storing and re-using your files. | Art. 6(1)(b) contract (as processor for third-party data). | Until you delete it or delete the Account. |
| Usage records: type of action (generated or saved), document type, carrier/sender/recipient names and countries, time; recently used goods codes; number of Declarations used. | Operating the Service, applying the Free Allowance, showing you statistics, preventing abuse. | Art. 6(1)(b) and (f). | While the Account exists. |
| Messages and notifications exchanged with us, and questions submitted through the public question form or chat widget (question text and, if given, e-mail address). | Answering and keeping a record of support communication. | Art. 6(1)(b) and (f). | Account messages: while the Account exists. Public questions: until answered and then for as long as needed to maintain the answer, but no longer than 24 months. |
| Subscription and payment data: Stripe customer identifier, subscription status and renewal date; invoices and payment records. Card numbers are processed only by Stripe and never reach our systems. | Billing, accounting, tax compliance. | Art. 6(1)(b); Art. 6(1)(c) legal obligation (accounting law). | Accounting records for the period required by law; other data while the Account exists. |
| Security records: failed and successful login attempts (e-mail address), registration and reset requests (IP address), password-reset tokens (stored only as a hash; valid 60 minutes, or 24 hours for new administrators). | Protection against unauthorised access and abuse. | Art. 6(1)(f) legitimate interest in security. | Deleted automatically after 30 days. |
| Administrator action log (which administrator did what, when and from which IP address). | Accountability and security of administrator access. | Art. 6(1)(f). | 24 months. |
| Website statistics for public pages (home page, blog, terms): page, language, referring site or campaign tag, and a pseudonymous visitor identifier derived with a daily-changing key from IP address and browser data. Neither the IP address nor the browser data is stored; no cookies are used. | Understanding how the website is used. | Art. 6(1)(f). | 400 days. |
| Server logs of our web server (IP address, time, requested address, browser identification). | Operation, security, error analysis. | Art. 6(1)(f). | Rotated automatically; kept for a limited period of up to 30 days. |
| Business contacts (prospects): company name, publicly available business e-mail address and telephone number, country and notes about our communication with the company. | Offering the Service to undertakings in the freight and forwarding sector (direct marketing to businesses). | Art. 6(1)(f) legitimate interest. The source is the company's public website or public registers. You may object at any time (section 9) and we will delete the data and not contact you again. | Until objection, or deletion after 24 months without any response or business relationship. |
3.2. Providing account data is necessary to conclude and perform the agreement; without it we cannot provide the Service.
4.1. We use one cookie, named "session", which is strictly necessary: it keeps you signed in, remembers your language and protects forms against forgery (CSRF). It is flagged HttpOnly, SameSite=Lax and, on the live site, Secure. A signed-in session ends after 20 minutes of inactivity. Because it is strictly necessary, no consent is required (Art. 5(3) of Directive 2002/58/EC).
4.2. We do not use advertising, tracking or analytics cookies, and we do not use third-party tracking scripts. Fonts and scripts are served from our own server.
5.1. We share personal data only with the following categories of recipients, to the extent necessary: (a) hosting and infrastructure providers that operate our servers and backups; (b) an e-mail delivery provider used to send confirmation, password-reset, invitation and security e-mails; (c) Stripe (Stripe Payments Europe, Ltd. and affiliates), which processes subscription payments and acts as an independent controller for payment and fraud-prevention data; (d) public authorities, courts and professional advisers where required by law or to establish, exercise or defend legal claims.
5.2. OpenStreetMap. On the SENT100 and SENT200 pages, the optional location map and the address-to-coordinates search load map tiles and search results from OpenStreetMap services (OpenStreetMap Foundation). When you use them, your browser contacts those servers directly, which therefore receive your IP address and, for the search, the address you entered.
5.3. We do not sell personal data and we do not use it for advertising profiling.
6.1. Where a recipient is located outside the EEA (for example Stripe's affiliates in the United States), the transfer is based on an adequacy decision of the European Commission (including the EU–US Data Privacy Framework for certified recipients) or on standard contractual clauses under Article 46 GDPR, together with supplementary measures where necessary.
7.1. We do not make decisions based solely on automated processing that produce legal or similarly significant effects. The statistics in your Account are shown to you for information only.
8.1. We apply technical and organisational measures appropriate to the risk, including encrypted connections (HTTPS), one-way hashing of passwords, optional two-factor authentication, protection against cross-site request forgery, automatic session expiry, rate limiting and temporary lock-out after repeated failed sign-ins, role-based access, a log of administrator actions, regular backups held for a limited period, and monitoring of availability. In the event of a personal data breach we will notify the supervisory authority and affected persons where and as required by Articles 33 and 34 GDPR.
9.1. Subject to the conditions of the GDPR you have the right: to access your data (Art. 15); to rectify it (Art. 16) – you can edit your profile yourself; to erasure (Art. 17) – you can delete your Account yourself under My profile; to restrict processing (Art. 18); to data portability (Art. 20) – you can download your data as a JSON file under My profile; to object to processing based on legitimate interests, including direct marketing, at any time (Art. 21); and to withdraw consent where processing is based on consent, without affecting earlier processing.
9.2. To exercise a right that you cannot exercise yourself, write to admin@sentiteasy.com. We respond within one month, which may be extended by up to two further months for complex requests, and we may need to verify your identity. Where you are a Customer's end contact whose data a Customer entered, please also contact that Customer, who is the controller of that data.
9.3. You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or of the alleged infringement. In Latvia the authority is the Data State Inspectorate (Datu valsts inspekcija), Elijas iela 17, Riga, LV-1050, www.dvi.gov.lv.
10.1. Account data, Customer Data and usage records are deleted immediately from the live system when you delete your Account. Copies in backups are overwritten within 14 days. Other retention periods are stated in section 3. We may delete Accounts that have been inactive for 24 months after notice as set out in the Terms.
11.1. The Service is intended for businesses and is not directed to persons under 18; we do not knowingly collect their data.
12.1. We may update this Privacy Policy. The "Last updated" date shows the current version; material changes are notified to Customers by e-mail or in the Service.