Legal notice
Privacy Policy
How Sentria processes customer-authorized integration, Sync, and CRM workspace data. Effective July 25, 2026.
Back to legal documentsWho we are and scope
- Strider Solutions e.U. operates Sentria CRM and Sentria Sync. This notice covers the web application, connected-source setup, sync routes, CRM workspace features, security/audit records, and support operations.
- Sentria Sync connects customer-authorized iCloud Contacts, Google Contacts, Microsoft Contacts, CardDAV address books, Zoho CRM contacts, HubSpot CRM contacts, Pipedrive people, and Salesforce contacts. Customer business data remains organization-scoped whether Sync is used standalone or together with the CRM workspace.
- When a customer uses Sentria for organization data, the customer normally decides the purposes and means of processing. Sentria acts as processor for that customer data and as controller for account administration, billing, security, service analytics, and support records.
Data processed
- Organization, user, role, integration, route, and source-selection metadata.
- Sentria CRM workspace records created or imported by the customer, including accounts, contacts, leads, deals, activities, notes, events, documents and links, pipeline data, saved views, memberships, invitations, and audit history.
- Contact, CRM-contact, external identity, sync run, review queue, conflict, approval, skip, retry, and write-back evidence selected or generated by the customer for public Sync contact routes.
- Integration credentials, app-specific passwords, API keys, OAuth tokens, sync cursors, and comparable secrets are stored in encrypted credential fields and are not shown after save.
Google user data we access
- When a user connects Google Contacts, Sentria receives the Google account identifier, name, email address, OAuth access token, OAuth refresh token, granted scopes, and token-expiry information needed to identify and maintain that connection.
- Through the Google People API, Sentria accesses only the connected user's contacts and the fields used by the visible Contacts sync feature: Google contact/resource identifiers, names, email addresses, phone numbers, organization or company name, job title, postal address, website or profile URLs, and contact update metadata such as ETags and update timestamps.
- If the user authorizes a route that writes to Google Contacts, Sentria may create, update, or delete Google contact records using those same contact fields. The public Contacts route does not access Google Calendar, Google Tasks, Gmail messages, Google Drive files, or unrelated Google account data.
How we use Google user data
- Sentria uses Google account and OAuth data to connect the account selected by the user, keep that connection authorized, and show its connection status.
- Sentria uses Google contact data only to provide the user-facing route the customer configured: read selected contacts, normalize and match them with contacts from the other chosen endpoint, identify duplicates or conflicts, generate a preview, and perform the customer-authorized create, update, or delete operation.
- Sentria may use limited sync-run, conflict, error, approval, and security records to operate, secure, troubleshoot, and support that configured feature. Sentria does not use Google user data for advertising, data brokerage, credit decisions, or to develop, improve, or train generalized or personalized AI or machine-learning models.
How Google user data is shared
- Google contact data is transferred to another provider only when the customer selects that provider as the other endpoint of a visible Sentria Sync route and authorizes the preview or configured automatic operation. The transferred fields are limited to the contact fields needed for that route.
- Sentria stores and processes Google user data on EU infrastructure supplied by its published hosting subprocessor, Hetzner Online GmbH. Access by authorized Sentria personnel is limited to operational, security, legal, or customer-support need and is subject to confidentiality and access controls.
- Sentria may disclose data when legally required or to protect users and the service. Sentria does not sell, rent, disclose for advertising, or transfer Google user data to unrelated third parties. It does not allow humans to read Google user data except with the user's affirmative agreement for support, when necessary for security or abuse investigation, or when legally required.
How Google user data is protected
- Production browser, OAuth callback, API, and provider traffic uses HTTPS/TLS. Google OAuth tokens and other integration credentials are encrypted with AES-256-GCM before database storage, and production storage and backups are protected by infrastructure access controls.
- Sentria enforces organization-scoped authorization, least-privilege Google scopes, write-back disabled until the user selects a receiving route side, preview and approval controls, volume and conflict guards, and security/audit records for sensitive integration operations.
- Credentials and tokens are not displayed after save and are excluded from user exports, ordinary logs, screenshots, and support messages. Production access is limited to authorized operational need, and suspected incidents follow Sentria's published security and notification process.
Google user data retention and deletion
- Google OAuth tokens are retained only while the Google connection remains active. Deleting the connection or beginning organization deletion removes the stored access and refresh tokens from active storage immediately and stops future Google access. The user can also revoke Sentria from the Google Account permissions page.
- Google-derived contact data is retained while the customer keeps the connection, route, or resulting workspace record. Deleting a connection removes its Google source identities and source-only imported contacts; a contact also linked to another source or intentionally retained in the workspace can remain without the deleted Google credential and can be removed through workspace cleanup or a verified deletion request.
- Verified organization deletion requests remove active customer data from primary storage within 30 days. Sync and write-back audit evidence may be retained for up to 180 days, security investigation records for up to one year when necessary, support records for up to 24 months, and legally required billing records for the applicable statutory period. Deployment backups are limited to the latest three verified copies per environment and are removed as that rolling set is replaced, unless a legal or security hold requires longer retention.
- Users can delete a connection in Sentria settings, delete imported data through the cleanup flow, delete their account or workspace where available, or request access, export, correction, restriction, or deletion through the built-in issue-reporting flow or by contacting privacy@strider.solutions.
Google Limited Use compliance
- Sentria's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements: https://developers.google.com/terms/api-services-user-data-policy
- Changing a route, disconnecting Google, or revoking access stops future collection for that connection. Sentria will request renewed consent before using materially broader Google data or adding a new sensitive Google scope.
Purpose and customer control
- Sentria processes data to authenticate users, connect selected sources, discover selected collections, synchronize records, normalize and match data, preview proposed changes, apply approved write-back, detect errors, and provide audit evidence.
- Admins can connect or disconnect integrations, select collections, set sync windows and limits, keep write-back off, require preview approval, exclude selected contacts, and remove imported leftovers.
- Customer-directed deletion removes active customer data where technically and legally possible. Retained operational evidence and backup copies follow the periods stated above and the applicable legal requirements.
Rights and requests
- Users and customers may request access, correction, export, restriction, deletion, or portability of personal data according to applicable law and the customer agreement.
- Requests are verified before action. Organization-wide requests require organization-owner/admin authority. Data-subject requests involving customer CRM/contact data may require customer instruction.
- Sentria does not sell customer personal data. Customer-authorized providers such as Apple/iCloud, Google, Microsoft, CardDAV, Zoho, HubSpot, Pipedrive, and Salesforce remain independent systems chosen and controlled by the customer.