PRIVACY POLICY Effective date: 22 September 2026 · Last updated: 22 September 2026 1. Who is responsible The controller, owner of personal records and operator of SENRIKO is Individual Entrepreneur Izotov Aleksandr Olegovich (“SENRIKO”, “Operator”, “we”, “us” or “our”), TIN 23006199301704. The full registered address and other public provider details appear in the Legal Notice (https://senriko.com/legal/notice) at https://senriko.com/legal/notice. Privacy requests may be submitted through https://senriko.com/contact or to help@senriko.com. Further registration and contact details appear in the Legal Notice (https://senriko.com/legal/notice). Where SENRIKO processes personal data contained in a Customer’s monitoring configuration, evidence or connected systems solely on the Customer’s instructions, the Customer is the controller and SENRIKO is the processor under the DPA. Where SENRIKO determines its own purposes - for example, Account administration, billing metadata, public-Site analytics, security, legal compliance and service-level aggregate metrics - SENRIKO acts as an independent controller. 2. Scope This Policy applies to senriko.com, its English and Russian versions, the Account area, public tools, administration pages, support and legal correspondence, notifications and the SENRIKO website-monitoring Service. It does not control the independent privacy practices of monitored Sites, CRMs, mail systems, Google properties, Paddle or other third parties. Their own notices apply to processing they determine independently. Some information is required to provide the requested Service. Without a valid email, credentials/session data and essential security records, SENRIKO cannot create or secure an Account. Without Site configuration and authority information, it cannot perform monitoring; without necessary billing details supplied to Paddle, a paid Subscription cannot be completed. Optional marketing, research, testimonial and analytics choices are not required for the core Service. The Service is intended primarily for businesses, agencies and website owners and is not intended for persons under 18. 3. Data subjects Personal data may relate to: - Account holders, Workspace owners and authorised team members; - alert recipients added by a Customer; - visitors to public SENRIKO pages and users of free tools; - people who contact SENRIKO, request support, submit a complaint or seek a refund; - owners, staff and service providers of monitored Sites; - people whose information is incidentally visible in a screenshot, URL, autoresponder subject or monitored page; - buyers and billing contacts whose payment is handled by Paddle; - authorised SENRIKO personnel and contractors. 4. Information we process 4.1 Account and access data Email address; password hash, never the plain password; language; time zone; Account and Workspace status; creation, verification, sign-in, reset and modification times; user role; security settings; and support state. 4.2 Session, device and security data Session-token hash; expiry and use time; browser/user-agent; IP address in limited technical logs; HMAC-derived or hashed IP values in evidence records; URLs, response status and selected request headers; rate-limit entries; login and administrator audit events. Cookies and authorisation headers are redacted from application logs where technically possible. 4.3 Workspace, Plan and usage data Workspace name and identifier; Plan, limits, status and time zone; configuration; monitoring token; feature use; check count; execution cost; limit consumption; subscription state; and account-level notices. 4.4 Site and monitoring data Domains, URLs, redirects, labels, domain-control method and code, detected revenue paths, pages under watch, check type and frequency, selectors, accepted baselines, alert rules, authority confirmation and CRM-filter state. Results may include response codes and timing, SSL/DNS/RDAP information, page titles and canonicals, analytics tags, resources, JavaScript/browser errors, form behaviour, crawl URLs, detected changes, findings, incidents, evidence, Health Scores and reports. Raw HTML and request bodies are not ordinarily retained after processing. 4.5 Form-check and autoresponder data Synthetic field values configured by the Customer; steps, status and response; hidden marker delivery; observed analytics/advertising signals; a PNG screenshot of the visible viewport when needed as evidence; and autoresponder sender, subject truncated to 200 characters, time and associated check. Autoresponder bodies are discarded immediately. 4.6 Alerts and communications Encrypted alert-recipient email; recipient verification; severity and delivery settings; alert content; provider message identifier; delivery result and error; support, complaint, privacy and refund messages; name, email, company, website, language and message supplied through the Contact form. 4.7 Customer-connected Google Analytics data After Customer authorisation, SENRIKO may receive the GA4 property identifier, name, time zone, access/quota state and aggregated daily conversion-event and session counts, sometimes grouped by device or channel. SENRIKO does not request individual visitor identifiers or event-level profiles for this feature. 4.8 Public-Site and free-tool data Cookie choice; page and referrer; browser, device and approximate region; form-success event without the form fields; technical logs; a submitted URL; check time, test location, detected consent tool and sanitised network observations. For abuse prevention, Consent Matrix may retain an HMAC value derived from IP for up to seven days without storing the plain IP in its application database. 4.9 Payment and subscription metadata Paddle processes complete payment-card details. SENRIKO may receive the buyer/account email, name or business details, country, Plan, amount, currency, tax status, payment and subscription state, Paddle customer/transaction/subscription identifiers, invoice/receipt reference, and refund, dispute or chargeback status. SENRIKO does not receive or store complete card numbers or card security codes. 4.10 Share links and free text Public incident-link token hash, expiry, selected display settings, revocation and access counts/times; and text a user enters when closing an incident, ignoring a finding, rejecting a path, providing feedback or describing a missed issue. 5. Information we ask users not to provide Do not place real passwords, complete payment details, identity documents, secret keys, medical/biometric information, children’s data, special-category data or unnecessary third-party information in test fields, URLs, Site names, comments, screenshots or support messages. SENRIKO does not intentionally collect autoresponder bodies, Customer CRM contents, individual visitor identifiers from Customer GA4, domain-owner contact fields from RDAP/WHOIS, session replay or heatmaps. 6. Sources We obtain data directly from users; automatically from browsers and SENRIKO systems; from monitored public Sites and configured destinations; from Google after Customer authorisation; from Paddle about transactions and subscriptions; from email and infrastructure providers; from public DNS/RDAP systems; and from a Customer acting as controller. 7. Purposes and legal bases Purpose | Main data | Legal basis where applicable Create, verify and administer Accounts and Workspaces | Account, session, settings | Contract performance and pre-contract steps; legal duties where applicable Provide monitoring, evidence, reports and alerts | Sites, configuration, results, screenshots, GA4 aggregates | Contract performance; documented Customer instructions; legitimate interests in reliable delivery Run synthetic form checks | Synthetic values, result and evidence | Customer instruction after authority verification; Customer supplies its own lawful basis for target-system processing Process payments and subscriptions | Transaction and subscription metadata | Contract performance; legal/accounting duties; fraud-prevention interests Answer inquiries, support, refunds and complaints | Contact details, messages, diagnostics | Pre-contract steps; contract performance; legal duties; legitimate interests in support and claims Secure the Service and prevent abuse | IP/HMAC/hashed IP, browser, logs, audit and blocked domains | Legitimate interests and legal duties to protect users, systems and rights Measure public-Site use | Consent record, GA4 events/cookies | Consent where required; a lawful legitimate-interest basis only where local law allows analytics without consent Improve reliability and capacity | Aggregate/de-identified usage, error and performance data | Legitimate interests in quality, security and product development Maintain legal evidence | Terms acceptance, consent, billing, complaints and relevant logs | Contract performance, legal obligations and legitimate interests in establishing, exercising or defending claims Optional marketing, research or testimonial | Only data described next to the optional control | Consent Creating an Account is acceptance of the Terms and acknowledgement of this Policy, not consent to every processing operation. Separate consent is requested only where consent is genuinely the applicable basis and is not bundled with the Service. Where consent applies, it must be freely given, specific, informed and recorded through an unambiguous action. It can be withdrawn as easily as it was given. Withdrawal does not affect earlier lawful processing or processing supported by another basis. 8. Website monitoring and synthetic submissions Most checks read publicly available technical information. Deep Audit follows robots.txt; a recurring check of a page expressly configured by an authorised Customer may operate independently where lawful. A form check can submit a real synthetic lead to a Customer-controlled Site and may trigger downstream processing. It requires domain/authority verification and identifiable test markers. The Customer must have authority, use fictional values, inform appropriate personnel, configure filters and choose a proportionate frequency. SENRIKO does not control how the target Site or its vendors subsequently process a correctly submitted test. 9. Recipients and service providers Personal data is disclosed only as needed for the stated purpose, a documented Customer instruction, a legal obligation or a protected corporate transaction. - Hetzner Online GmbH: application, database, files and backups; current core hosting in Nuremberg, Germany. - Resend / Plus Five Five, Inc.: transactional email, verification/reset links, alerts, reports and selected messages; United States and provider infrastructure. - ImprovMX Incorporated: inbound forwarding of mail sent to senriko.com addresses; France and United States as described by the provider. - Google and relevant affiliates: public-Site GA4 after consent; Customer-authorised Analytics Admin/Data APIs; Operator Gmail mailbox used for correspondence; global infrastructure. - Cloudflare, Inc.: Turnstile and related anti-abuse/security data only where enabled; global network. - Paddle: authorised reseller/Merchant of Record and independent controller for checkout, payment, tax, fraud, receipt, refund and chargeback processing. The applicable entity is shown at checkout. - DNS/RDAP/WHOIS registries and operators: technical domain and DNS queries; SENRIKO does not intentionally collect registrant contact fields. - Monitored Sites and Customer systems: SENRIKO source IP, User-Agent, monitoring header, synthetic identity and test markers as directed by the Customer. - Professional advisers, courts, regulators and authorities: minimum information needed for a valid demand, compliance, rights protection or dispute. - Successor or transaction parties: limited due-diligence and transfer information subject to confidentiality and continued protection. Current subprocessors and role distinctions appear on the Subprocessors page (https://senriko.com/legal/subprocessors). We do not sell personal data or disclose it to advertisers for payment. 10. International transfers Core hosting is currently in Germany. Email, Google, Cloudflare, Paddle and other providers may process data in the United States and other countries. A Customer can also cause a transfer by monitoring a foreign Site, connecting a foreign analytics property or choosing a foreign alert recipient. Where transfer restrictions apply, SENRIKO uses an available lawful mechanism, which may include contract necessity, data-subject consent where valid, processor agreements, contractual safeguards such as approved standard clauses, risk assessment, encryption, data minimisation and access controls. A public policy does not replace a transfer agreement required by law. Before actively targeting a country with localisation, representative, filing or other mandatory requirements, SENRIKO will assess and implement the required controls. Availability or payment acceptance alone does not waive local law. 11. Retention SENRIKO keeps personal data only for the period needed for the stated purpose, the contract, security, legal evidence or a binding duty. The target retention schedule for the paid launch is: Information | Retention period / criterion Account, Workspace, Sites and current settings | Until deletion or termination, then removed from active systems, except minimum retained evidence Sessions | Up to 30 days; earlier on logout, password reset, deletion or security action One-time verification/reset tokens | Until use or expiry; residual technical record removed within 30 days Monitoring history, findings, incidents, audits, screenshots, autoresponder metadata and site timeline | Plan history: 7 / 30 / 90 / 365 / 730 days; automated daily cleanup; written Enterprise order may vary Downgrade excess history | Deleted after a 30-day export window announced before downgrade Consent Matrix result | 30 days; anti-abuse HMAC up to 7 days Customer GA4 aggregates | While connected and within the Plan history; connection credentials revoked on disconnect; residual configuration removed within 30 days unless needed for security Public incident link | Until expiry/revocation; related access metadata no longer than the applicable history period Subscription, usage ledger and Terms-acceptance evidence | During the contract and 3 years after termination; longer only for an active dispute, payment investigation or binding duty Optional-consent evidence | During the consent-based processing and 3 years after withdrawal/end, restricted to proof and claims Contact, support, complaint and refund correspondence | Up to 3 years after closure, shorter where no longer needed; longer for an active dispute or legal duty Technical application logs | 30 days Security logs | 180 days; incident evidence may be restricted until final resolution and applicable claim period expires Administrator audit logs | 12 months; longer for an active security/legal investigation Rate-limit data | Usually 15 minutes to 1 hour Accounting, tax and Paddle transaction records | Statutory period required by applicable accounting/tax law and payment obligations Disaster-recovery backups | 14 daily copies; deleted live data ages out within up to 14 days and is not used for ordinary access Cookies and local storage | As stated in the Cookie Policy (https://senriko.com/legal/cookies) On expiry, information is deleted, irreversibly de-identified or overwritten through the backup cycle. If a legal hold is necessary, use is restricted to that purpose and only the minimum relevant records are retained. 12. Terms acceptance and consent evidence To prove the agreement, SENRIKO may retain the accepted Terms version and language, date/time, user identifier, HMAC-derived IP value, browser/device information and Paddle transaction identifier where available. This is retained for the contract and three years after termination, longer only for an unresolved dispute, refund, chargeback, investigation or proceeding. Where optional consent is used, SENRIKO may retain the form/purpose, document version, affirmative action, date/time, pseudonymised identifier, browser information and withdrawal record. These records are personal data and are used only for accountability and claims. 13. Security Measures include, as appropriate: - HTTPS/HSTS, content-source restrictions and protective HTTP headers; - scrypt password hashing and hashing of session, one-time and public-link tokens; - encryption of alert addresses with a key separated from the database; - role-based access, restricted staff enablement and administrator audit logs; - rate limits, blocked-domain controls and server-side request-forgery protection; - isolated browser sessions and separated browser-check processes; - backup, health monitoring, patching and incident-response procedures; - vendor assessment, confidentiality obligations and processor contracts; - minimisation, log redaction and retention controls. No system is perfectly secure. Users must protect credentials, email accounts, devices, alert destinations and share links and promptly report suspicious activity to help@senriko.com. 14. Security incidents SENRIKO maintains a process to assess, contain, document and notify relevant incidents. Where SENRIKO acts as processor and the Kyrgyz processor rule applies, it notifies the affected Customer without undue delay and no later than 48 hours after SENRIKO discovers the incident, using the information then available and supplementing it as the investigation develops. Where SENRIKO acts as controller, owner of records or service provider and an incident affects digital resilience or individual rights, SENRIKO notifies the competent regulator no later than 72 hours after discovery where the Digital Code requires it; a delayed notice includes the reason. Information may be provided in phases. Affected individuals are informed when mandatory law requires it. 15. Individual rights Depending on applicable law and SENRIKO’s role, a person may request: - confirmation whether personal data is processed; - access and a copy; - correction of inaccurate data; - deletion or restriction; - portability in an available structured format; - objection to processing based on legitimate interests; - withdrawal of consent; - information about sources, recipients and transfer safeguards; - review of an automatic decision where applicable; - complaint to a regulator or court. Use the Account export/deletion controls, https://senriko.com/contact, or help@senriko.com. We may verify identity and authority without collecting excessive information. Where the Kyrgyz Digital Code applies, SENRIKO provides processing information and access or a copy within seven business days; provides information about correction or supplementation within seven business days; gives a reasoned decision on an objection within seven business days; restricts disputed processing while a qualifying correction, deletion or objection is considered; and gives any required restriction or lifting notice by the next business day. A statutory deletion trigger is acted on without delay unless lawful retention applies. Where the GDPR applies, its ordinary one-month period applies unless a shorter mandatory period controls. If SENRIKO processes the data solely for a Customer, it may direct the request to that Customer and reasonably assist under the DPA. Deletion may be limited by another person’s rights, security, fraud prevention, payment/accounting duties, a legal hold or the establishment, exercise or defence of claims. 16. Account closure, export and deletion SENRIKO provides JSON export and Account deletion through the Account or an equally effective support route. Cancellation of a paid renewal does not itself delete the Account. When a withdrawal or closure request requires a choice about return/export or deletion, SENRIKO calculates any supplied value/refund, identifies the user’s digital records, explains available copy/portability and deletion options, preserves the records unchanged while the choice is pending where law requires, and then performs the lawful choice. If no choice is received after a withdrawal governed by the Digital Code of the Kyrgyz Republic, SENRIKO deletes the user records after the end of the calendar year following the year of withdrawal, except records that law requires it to retain, and identifies the retained categories to the user. Retained records are restricted from ordinary use. 17. Cookies and public-Site analytics The Cookie Policy (https://senriko.com/legal/cookies) lists cookies, local storage, Google Consent Mode and Paddle checkout technologies. SENRIKO uses Basic Consent Mode on public pages: the Google tag is not loaded before a choice and remains unloaded after rejection. Acceptance enables analytics storage only; advertising-storage and personalisation categories remain denied. GA4 is used on selected public and sign-in/registration pages, but not in the Customer Account, admin area or public incident-share pages. Contact-form fields are not sent to GA4. 18. Public links and incidental third-party data A Customer controls what a public incident link displays. SENRIKO masks common identifiers where feasible, but a screenshot or page controlled by the Customer may contain personal information. Customers must minimise, restrict and revoke such links. Third-party data may incidentally appear in screenshots, URLs or autoresponder subjects. Customers should use test pages, avoid authenticated personal views and URLs containing secrets/identifiers, and request deletion when needed. 19. Automated analysis SENRIKO automatically detects changes and anomalies and creates findings, scores and incidents. These outputs do not make decisions that produce legal or similarly significant effects for an individual. A user reviews and can close, accept, reject or ignore the output. 20. Children SENRIKO does not knowingly offer Accounts to persons under 18 or intentionally collect children’s data. Customers must not use children’s real details in test forms or monitor authenticated areas containing children’s data without a separately assessed lawful arrangement. 21. Responsibility allocation A Customer is responsible for the legality of its Sites, instructions, test values, recipients, public links and connected systems. SENRIKO is responsible for its own controller processing and for processor duties imposed by the DPA and applicable law. Nothing in this Policy limits a non-waivable data-subject right or liability that cannot lawfully be excluded. 22. Changes SENRIKO may update this Policy for product, provider, security or legal changes. The current version shows the date and remains saveable. Material changes affecting users’ rights or the contractual processing will be notified in advance, ordinarily at least one month before effectiveness where the Digital Code or the Terms require that period. An urgent lawful security change may take effect sooner with prompt explanation. 23. Languages and contact This Policy is available in English and Russian. For interpretation under the law of the Kyrgyz Republic, the Russian version prevails to the extent permitted by mandatory law. - Operator: Individual Entrepreneur Izotov Aleksandr Olegovich, TIN 23006199301704; full registered address and provider details: https://senriko.com/legal/notice. - Privacy and support: help@senriko.com or https://senriko.com/contact. - Supervisory authority: Personal Data Protection Agency under the Cabinet of Ministers of the Kyrgyz Republic, https://dpa.gov.kg/.