Privacy Policy
for the SENRIKO website and cloud service
This is an archived version. It was in force from September 21, 2026 to September 22, 2026 and has been replaced. Read the current version
Effective date: September 12, 2026. Last updated: September 21, 2026.
Download as textPrevious versions
1. Who is responsible for personal data
The data controller and operator of SENRIKO is Izotov Aleksandr Olegovich (“Operator”, “SENRIKO”, “we”, “us”, or “our”).
Registration details: Individual Entrepreneur Izotov Aleksandr Olegovich, TIN 23006199301704. Address: 104 Toktonaliev St., apt. 31, Bishkek, Kyrgyz Republic. Privacy requests: the contact form at senriko.com/contact or help@senriko.com.
SENRIKO has not appointed an EEA or UK representative or a formal data protection officer because those requirements do not currently apply. This position is reviewed before actively targeting those markets and whenever the scale or nature of processing materially changes.
2. Scope
This Policy applies to senriko.com, its English and Russian versions, the account area, administration and public pages, free tools, correspondence, notifications, and the SENRIKO website-monitoring SaaS. It explains what personal data we obtain, why and on what basis we process it, recipients and transfers, retention, security, and individual rights.
It does not govern the independent practices of monitored websites, CRMs, email systems, Google Analytics, or other third-party services. A link or integration does not mean that SENRIKO controls or assumes responsibility for another party’s privacy practices.
The Service is intended primarily for businesses, website owners, marketers, and agencies. It is not intended for anyone under 18.
3. Our role and the customer’s role
SENRIKO acts as an independent controller for account data, senriko.com visitor data, inquiries, security, product analytics, usage metering, and its own legal obligations.
When a customer instructs SENRIKO to monitor a website, submit a test form, store a screenshot, receive autoresponder metadata, or read aggregated GA4 data, the customer determines the purpose and lawfulness of that activity. To the extent those materials contain personal data, SENRIKO acts as the customer’s processor or service provider within documented instructions, while the customer remains the controller/business. The parties should enter into a Data Processing Agreement where required.
A single feature may involve both roles. For example, a monitoring result may be customer-controlled data, while an access log is processed by SENRIKO for its own security purposes.
4. People whose data may be processed
- registered users and workspace owners;
- additional alert recipients added by a user;
- visitors to public senriko.com pages;
- people who send a contact or early-access request;
- owners and personnel of monitored websites;
- people whose information is incidentally visible in a screenshot, autoresponder subject, or monitored URL;
- anonymous users of free tools;
- authorized SENRIKO staff.
5. Information we process
| Category | Information |
|---|---|
| Account | Email; password hash (not the password itself); language; time zone; status; creation, verification, sign-in, and modification timestamps. |
| Sessions and security | Session-token hash, expiry/use timestamps, browser string, hashed IP; IP, URL, and headers in technical logs; rate-limit data. Cookies and authorization headers are redacted from logs. |
| Workspace | Name, plan, status, time zone, configuration, monitoring token, usage and execution-cost records. |
| Sites and pages | Domains and URLs, redirect destinations, labels, ownership-verification method/code, and detected revenue paths. |
| Monitor settings | Monitor types/frequency, selectors, synthetic field values, accepted baselines, alert rules, owner-permission confirmation, and CRM-filter status. |
| Monitor results | Response codes and timings, SSL/DNS/RDAP signals, titles/canonicals, analytics tags, JavaScript/resource failures, forms, crawl URLs, findings, incidents, evidence, Health Score, and reports. Raw HTML and request bodies are generally not stored. |
| Form checks | Steps, status/response, hidden-field delivery, observed analytics/advertising signals, and configured test values. A PNG screenshot of the visible viewport may be stored on failure. |
| Autoresponder email metadata | Sender, subject up to 200 characters, time, and associated check. The email body is discarded immediately. |
| Alerts | Encrypted recipient email, confirmation and severity settings, delivery status, provider message ID, and error details. |
| Customer GA4 | Property ID/name/time zone, access/quota status; aggregated daily conversion-event and session counts, sometimes grouped by device/channel. Individual visitor identifiers and events are not requested. |
| Inquiries | Name, email, company, website, language, and message. They are emailed to the Operator and are not stored in SENRIKO’s main database. |
| Public-site data | Cookie choice, page/referrer, browser/device, approximate geography, form-success events without form fields, and technical logs. |
| Free text | Reasons for closing incidents, ignoring findings or rejecting paths; exclusion notes, feedback, and missed-issue descriptions. |
| Public incident links | Token hash, expiry, display settings, revocation, and open count/timestamps. We do not intentionally record the viewer’s identity. |
6. Information we intentionally do not collect
- full payment-card details - payments are not accepted during early access;
- identity documents, birth dates, home addresses, or user phone numbers;
- session replay, heatmaps, or Google Analytics behavior inside the account area;
- autoresponder bodies or access to the customer’s CRM;
- individual visitor identifiers or event-level data from the customer’s GA4;
- domain-owner contact details from RDAP/WHOIS;
- special-category or sensitive data on purpose. Users must not place real, sensitive, secret, or regulated information in test fields, URLs, project names, or comments.
7. Purposes and legal bases
| Purpose | Data | Legal basis where applicable |
|---|---|---|
| Account registration and access | Email, password hash, sessions, language, time zone | Contract performance/pre-contract steps; consent where applicable law specifically requires it. |
| Monitoring service | Sites, settings, results, screenshots, reports, GA4 aggregates | Contract performance and documented customer instructions; legitimate interests in reliable operation. |
| Synthetic form submissions | Test identity, selected values, result metadata | Customer instruction after site/authority verification; customer supplies its own lawful basis. |
| Alerts and transactional email | Email, incident content, links, delivery log | Contract performance; recipient confirmation/consent; legitimate interest in reliable delivery. |
| Inquiries and early access | Contact details and message | Pre-contract steps, response to a request, and/or consent. |
| Security and abuse prevention | IP/hashed IP, browser, logs, audit events, blocked domains | Legitimate interests and/or legal duties to protect users, infrastructure, and legal rights. |
| Public-site analytics | Google Analytics events and cookies | Consent for analytics/advertising storage; legitimate interests only where lawful and consent is not required. |
| Product improvement | Aggregated/de-identified metrics, activation funnel, feedback | Legitimate interests in quality and development; consent where required. |
| Compliance and disputes | Relevant account, log, and communication data | Legal obligations and legitimate interests in establishing, exercising, or defending claims. |
By creating an account, the user accepts the Terms of Service and acknowledges the Privacy Policy. A separate consent is requested only where processing genuinely relies on consent and is not bundled with acceptance of the Terms.
Where consent is the basis, it must be freely given, specific, informed, and expressed through an unambiguous affirmative action. Consent may be withdrawn. Withdrawal does not affect earlier lawful processing or processing supported by another lawful basis.
8. Website checks and synthetic submissions
Most checks read publicly available website material: availability, SSL, DNS, page integrity, analytics tags, resources, mobile behavior, and browser errors. Deep Audit follows robots.txt; explicitly configured recurring checks may run independently of robots.txt. One comparison check uses a Googlebot User-Agent to identify differences in what a search crawler receives.
Form Check is an active feature. It can submit a real synthetic lead into a site owner’s CRM, email, or messenger and may trigger autoresponders, tasks, calls, or third-party charges. It requires site verification and the user’s confirmation of owner authorization. SENRIKO uses fictional email and phone details, visible and hidden test markers, utm_source=senriko-monitor, and the X-Senriko-Monitor header. It does not solve CAPTCHAs.
The customer must have authority for every monitored site and synthetic submission, notify appropriate personnel, configure filters, and avoid unsolicited messages. The customer is responsible for the lawfulness of its instruction, field choices, frequency, and effects in its systems. SENRIKO does not control how the target website or its vendors subsequently process a test submission.
Consent Matrix. When the public tool is used, SENRIKO processes the submitted URL, check time and technical status, test location, detected consent tool, and sanitised information about analytics and advertising network signals. An HMAC value derived from the initiator’s IP address is retained for up to seven days to prevent abuse; the plain IP address is not stored in the application database. Cloudflare Turnstile may independently process technical data to protect the form. A result is available through an unguessable link, is not indexed, and is automatically deleted after 30 days. Public publishing is off by default and is available only after control of the domain is verified. The website owner may request earlier deletion from the result page or contact form. SENRIKO does not retain or display cookies, authorisation headers, form contents, detected tokens, or personal identifiers.
9. Recipients and service providers
| Recipient | Role and information | Processing location |
|---|---|---|
| Hetzner Online GmbH | Hosts the application, database, files, and backups; technical access to hosted information. | Nuremberg, Germany under the current configuration. |
| Resend / Plus Five Five, Inc. | Email delivery: recipient address, alerts, verification/reset links, reports, inquiries, and takedown requests. | United States and other locations described by the provider. |
| ImprovMX Incorporated | Forwards mail sent to addresses at senriko.com to the Operator’s mailbox: sender, recipient, and message content in transit. | France (AWS Paris region; inbound mail is stored only until delivered); outbound delivery from France and the United States. |
| GA4 for senriko.com; Analytics Admin/Data APIs for customer aggregates after customer authorization; the Operator’s Gmail mailbox, which receives contact-form inquiries and mail forwarded from senriko.com addresses. | United States and Google’s global infrastructure. | |
| Cloudflare | Turnstile token and user IP only if Consent Matrix is enabled. | United States and Cloudflare’s global network. |
| RDAP/WHOIS registries and DNS operators | Domain-name queries for registration/DNS checks; we do not collect owner contact fields. | Depends on registry/operator. |
| Monitored websites and customer systems | Monitor requests, SENRIKO IP, User-Agent, X-Senriko-Monitor, synthetic identity, and test markers. | Determined by the customer/site owner. |
| Authorities, courts, advisers, and successors | Only information needed for a valid legal demand, rights protection, abuse investigation, or corporate transaction. | Depends on circumstances and applicable law. |
We do not sell personal data or disclose it to advertisers for payment. Providers receive only information needed for their function and must be engaged under appropriate confidentiality, security, and data-processing terms.
10. International transfers
Core data is hosted in Germany. Email delivery, forwarding of mail sent to senriko.com addresses, and Google services, including the Operator’s mailbox, can result in processing in the United States and other countries with different privacy rules. Where required, the Operator uses contractual or other lawful safeguards, assesses vendors, minimizes information, and obtains separate consent when no other transfer mechanism is available. A user who connects GA4 or specifies a foreign destination may also initiate a transfer.
Before serving people subject to mandatory data-localization rules, SENRIKO must assess and, where necessary, change its architecture. Publishing this Policy does not waive those statutory requirements.
11. Public links and third-party data
A user may create a public link to one incident for 1 hour to 90 days. Anyone with the link can access it without signing in. Limited information is shown by default; evidence and screenshots require separate user choices. SENRIKO masks URL parameter values, emails, and phone numbers, but cannot guarantee that a screenshot or other customer-controlled content contains no identifying information.
The user is responsible for recipients, duration, and included material and must revoke access when no longer needed. To the maximum extent permitted by law, SENRIKO is not responsible for a recipient’s further copying or disclosure.
Third-party data may incidentally appear in screenshots, autoresponder subjects, or URLs. Customers must minimize this risk: use test pages, avoid authenticated personal views and URLs with secrets/identifiers, restrict reports and alerts, and notify SENRIKO when deletion is needed.
12. Retention
| Information | Current period / criterion |
|---|---|
| Account, workspace, settings, sites | Until the relevant object or account is deleted, unless law requires longer retention. |
| Sessions | Valid up to 30 days; removed on logout, password reset, account deletion, or later cleanup after expiry. |
| One-time tokens | Become unusable at expiry/use; the technical record may remain until account deletion or scheduled cleanup. |
| Monitor history, findings, incidents, audits | In the current implementation, until the site or account is deleted. A plan display/visibility period is not a promise of physical deletion until automated cleanup is implemented. |
| Screenshots and autoresponder metadata | By plan: 3 / 14 / 30 / 60 / 90 / 180 days; cleanup is checked approximately hourly. |
| Site timeline | Up to 1 year or earlier site deletion. |
| Customer GA4 and verdicts | Until disconnect, monitor/site deletion, or account deletion. |
| Usage ledger and monthly summaries | For the life of the workspace. |
| Inquiries | Not in the main database; retained in the Operator’s mailbox as needed for response, support, security, and claims. |
| Consent records | Up to 3 years after the processing based on that consent ends, or after the consent is withdrawn, whichever applies, to show that consent was given. Account registration is not recorded here: creating an account is an acceptance of the Terms, not a consent. The email address is not stored in plain text; a cryptographic HMAC value generated with a separately protected secret is used, alongside a hashed IP and the browser user agent. These records are treated as pseudonymised, not anonymous, personal data. |
| Terms acceptance records | Three years after account deletion or other termination of the contract, and longer where a dispute, refund, chargeback, investigation, or legal proceeding is live. Described in full below. |
| Technical and audit logs | As needed for security, troubleshooting, abuse prevention, and claims. Some logs do not yet have a fixed automated deletion period. |
| Rate-limit entries | Usually 15 minutes to 1 hour. |
| Database backups | 14 daily copies; deleted primary data may remain up to 14 days and is used only for disaster recovery. |
| Cookies/local storage | As listed in the Cookie Policy. |
Terms acceptance records. We separately retain the date and time of acceptance, Terms version, language, user identifier, an HMAC value derived from the IP address, browser or device information, and, where available, the payment transaction identifier. We process this information to enter into and perform the contract, demonstrate the version accepted, prevent abuse, and establish, exercise, or defend legal claims. It is retained for three years after account deletion or other termination of the contract. If a dispute, refund, chargeback, investigation, or legal proceeding arises before that period ends, relevant records may be retained until the matter is finally resolved and the applicable claim period expires, after which they are deleted or irreversibly anonymised.
If law, a dispute, a security investigation, or a binding order requires longer retention, we may restrict use and retain only the necessary minimum. At expiry, information is deleted, de-identified, or overwritten through the backup cycle.
13. Security
- HTTPS/HSTS, content-source restrictions, and other protective HTTP headers;
- scrypt password hashing and hashing of session, one-time, and public-link tokens;
- hashed IPs in session-related records and encrypted alert addresses with a key outside the database;
- access controls, server-only staff enablement, and audit logging of administrative changes;
- rate limits, blocked-domain controls, and server-side request forgery (SSRF) protection;
- isolated Chromium sessions and a separate process for browser checks;
- backups and automated service-health monitoring.
No transmission or storage method is completely secure. We use measures appropriate to risk and available technology, but cannot guarantee that every attack, error, loss, or unauthorized access will be prevented. Users must protect their password, email account, devices, alert destinations, and public links and promptly report suspicious activity.
14. Your rights
Depending on applicable law, you may request confirmation and access; a copy; correction; deletion; restriction; portability; objection; withdrawal of consent; information about sources, recipients, and transfer safeguards; and may complain to a regulator or court.
A JSON export and account deletion are available in the account area. For other requests, use the contact form at senriko.com/contact or write to help@senriko.com. We may reasonably verify identity and authority. We respond within the time required by applicable law; where the GDPR applies, normally within one month.
A request about customer-controlled monitored-site data may be referred to that customer as controller, and SENRIKO will reasonably assist. Deletion can be limited by mandatory retention, security, third-party rights, or the establishment, exercise, or defense of legal claims.
Supervisory authority: State Agency for Personal Data Protection under the Cabinet of Ministers of the Kyrgyz Republic, https://dpa.gov.kg/.
15. Cookies and analytics
Our separate Cookie Policy lists cookies, localStorage, and Google Consent Mode behavior. Necessary cookies support sign-in, security, language, and consent choice. GA4 operates on public, sign-in/registration, and /lab pages, but not in the account area, admin area, or public incident-share pages.
The site uses Google’s Basic Consent Mode: before a choice and after rejection, the Google tag is not loaded and nothing is sent to Google. Accept enables analytics only; the advertising categories stay denied. _ga and _ga_<ID> analytics cookies are created only after acceptance. The /lab training page is the exception described in the Cookie Policy.
16. Automated analysis
SENRIKO automatically detects technical changes and conversion anomalies and creates findings, Health Scores, and incidents. These outputs inform customers and do not make decisions that produce legal or similarly significant effects for an individual. Users review the output and may close incidents, accept a new baseline, ignore findings, or provide feedback.
17. Data-related limitations of responsibility
To the maximum extent permitted by law, SENRIKO is not responsible for processing caused by an unlawful or erroneous user instruction; a user’s lack of authority over a site or data; target-site, CRM, email, or third-party content and practices; information placed by a user/site owner in URLs, forms, screenshots, subjects, comments, alerts, or public links; public-link recipient actions; browser/cookie blocking; or events outside SENRIKO’s reasonable control.
SENRIKO does not warrant absolute security, uninterrupted availability, or detection of every appearance of personal data. Users must use synthetic values, minimize data, and meet their own controller obligations. Nothing in this Policy excludes liability that cannot lawfully be excluded or limits mandatory data-subject rights.
18. Changes and languages
We may update this Policy when the product, providers, or law changes. The current version will show a new date. Material changes may be notified in the Service or by email before or shortly after they take effect, unless the law requires another process.
This Policy is available in English and Russian. If the versions differ, the English version prevails, unless mandatory applicable law requires otherwise.
19. Contact
Operator: Izotov Aleksandr Olegovich.
Address: 104 Toktonaliev St., apt. 31, Bishkek, Kyrgyz Republic.
Privacy requests: the contact form at senriko.com/contact or help@senriko.com.
Support: senriko.com/contact or help@senriko.com.