Privacy Policy

Last updated: July 17, 2026

Who this covers

This policy covers the Sentasity marketing website and the Sentasity product: the portal you sign in to. Sentasity is a business-to-business AWS cost-optimization platform, and our audience is businesses in the United States. It explains, in plain English, what data we touch and what happens to it.

Information we collect

We collect two kinds of information, and we keep them separate in our heads and in our systems.

On the marketing site. When you fill in a contact or inquiry form, we collect what you type: your name, work email, company, and message. Our servers also keep standard request logs (IP address, browser, timestamps) the way any web server does. We do not run analytics or advertising scripts on the site, so there is no cross-site tracking of your visit.
In the product. To sign you in, we hold account identifiers such as your email address. To do the actual work, we read the AWS cost data, resource-configuration metadata, and security-posture findings that your read-only role produces. We do not read your application data, your code, the contents of your secrets, or your customers' data: the same limit we publish on our trust center.

How we use information

We use what we collect to:

  • respond to your inquiries and sell you the product;
  • operate the scans and produce your cost, commitment, and security reports;
  • generate executive summaries, which run on AWS Bedrock inside AWS;
  • monitor, debug, and improve the service; and
  • protect the site from spam and abuse.

We do not sell personal information, and we do not use it for third-party advertising.

Cookies and similar technologies

The site uses only strictly-necessary cookies: session and authentication cookies for signed-in users, and the cookie Cloudflare Turnstile sets to tell humans from bots on our public forms. We do not use analytics, advertising, or cross-site tracking cookies, which is why you won't see a cookie consent banner. There is nothing to consent to beyond the cookies that make sign-in and spam protection work.

Where data lives and who processes it

Your data is stored in AWS, in United States regions. Executive summaries are generated using AWS Bedrock.

We share data only with the subprocessors below, each used for one purpose:

SubprocessorWhat it does
Amazon Web ServicesAll infrastructure, data storage, and Bedrock model inference for report generation
VercelWeb application and website hosting
SentryError monitoring (technical diagnostics, not your cost data)
Zoho CRMContact and sales inquiries you submit through our forms
CloudflareBot protection (Turnstile) on public forms

We update this list before we add a subprocessor, so it is always current.

How we share information

We share data only with the subprocessors above, to run the service, and when we are required to by law. We do not sell data, and we do not share it with advertisers or data brokers. If you are an MSP customer, tenant isolation keeps your private discounts and margins invisible to your sub-customers: the same boundary we describe on the trust center.

Security

Your data is encrypted in transit with TLS and at rest with AWS-managed encryption. Access is scoped by a strict tenant hierarchy, and the exact read-only role we ask for (and its limits) is published in full on our trust center. We'd rather show you the mechanics than ask you to take our word for it.

Data retention and deletion

We keep your stored scan data only while your account is active. If you close your account or ask us to delete your data, we remove it within 60 days: a window that covers our encrypted backups rotating out, not just the live database. You can also end all access immediately at any time by deleting the CloudFormation stack; that role is the only path into your account, so removing it closes the door at once.

Breach notification

If a security incident affects your data, we will notify you within 72 hours of confirming it, with what we know at the time and what we are doing about it. We keep the incident-notification commitment on our trust center identical to this one.

Your choices and rights

You can ask us what personal data we hold about you, ask us to correct it, or ask us to delete it. Email the address in the contact section below and we will handle it. We keep this practical rather than citing specific statutes: tell us what you need and we'll do it.

Audience and international transfers

Sentasity is based in the United States and serves United States customers, and your data is stored in United States AWS regions. The service is intended for businesses; it is not directed at consumers or at children.

A note for enterprise buyers

A Data Processing Agreement (DPA) is available to business customers on request. Ask through our contact page and we'll provide it.

Changes to this policy

When we make a material change, we update the "Last updated" date at the top of this page. Continued use of the site or product after an update means you accept the current version.

Contact us

Questions about this policy, or requests about your data, go to support@sentasity.com or through our contact form.