Privacy statement
Last updated: 23 August 2026
Sento processes personal data. Below is what we collect, why, how long we keep it and who else gets to see it. In plain language, because a privacy statement you cannot read is worth very little.
This statement covers the website, your account, and the company data you put into Sento. We process that company data on your behalf rather than for ourselves; that calls for a data processing agreement, which we sign with you before you upload anything.
This is a translation. In case of any difference, the Dutch version prevails.
Who is responsible
Sento, a trading name of a general partnership registered with the Dutch Chamber of Commerce under number 97593494.
Questions about your data, or a request to see or delete it? Email info@sentofinance.com. We respond within a month, usually much sooner.
We do not have a data protection officer, and we are not required to: we do not monitor anyone on a large scale and we process no special categories of personal data.
What we process
When you create an account
Your name, email address, the name of your organisation and your language preference. Your password is stored encrypted – we cannot read it, even if we wanted to.
When you sign in with Google
Google passes us your name and email address. Nothing more: we do not request access to your Gmail, calendar or files. Using a password instead is always an option.
When you set up two-step verification
A secret key that your authenticator app uses to generate codes. It is stored encrypted and never leaves our environment.
While you use Sento
We keep a log of security-related events: signing in, signing out, changing a password, turning two-step verification on or off. For each we record the time, your IP address and your browser type.
That is deliberate. If you cannot see who accessed your data and when, then “we handle your data carefully” is a claim rather than something you can verify.
When you take out a subscription
Your name, email address, billing address, VAT number if applicable, and the status and term of your subscription.
Your payment details never reach us. Checkout happens entirely at Stripe; we are only told that payment succeeded. Your card number never passes through our systems.
Why, and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Creating your account and signing you in | name, email, password, organisation | Performance of the contract |
| Confirming your email address | email address | Performance of the contract |
| Two-step verification | your authenticator key | Legitimate interest: securing your account |
| Security log | time, IP address, browser type | Legitimate interest and the GDPR security obligation |
| Subscription and invoicing | name, email, billing details | Performance of the contract |
| Retaining invoices | billing details | Legal obligation: Dutch tax retention rules |
| Remembering your language | language choice | Legitimate interest: keeping the site usable |
Where we rely on a legitimate interest, we have weighed it against your privacy. For a security log we consider it justified: it protects your data, and we record no more than that requires.
How long we keep it
| Data | Retention |
|---|---|
| Your account | For as long as your account exists |
| After you delete your account | Removed from our systems within 30 days; backups expire within 90 days |
| Security log | 12 months |
| What goes to Anthropic when a file is recognised | Not retained there |
| Invoices and payment records | 7 years – required by Dutch tax law |
You can delete your account at any time: email us and it happens. Only the invoices have to be kept longer, and we have no choice in that.
Who else sees it
We do not sell your data, and we do not use it to train AI models. We do work with a small number of suppliers, who process your data only for us and never for themselves.
| Party | What for | Where it is processed |
|---|---|---|
| Supabase | Database, accounts and sign-in | European Union (Frankfurt) |
| Vercel | Hosting the website and the portal | European Union |
| Stripe | Payments, invoicing and VAT | Ireland, with transfer to the United States |
| Anthropic | Analysing the structure of a file you upload | United States |
| Only if you choose to sign in with Google | United States |
A data processing agreement is in place with Supabase, Vercel and Stripe. For Anthropic, the data processing agreement that forms part of their commercial terms applies. Google is not a processor: if you choose to sign in with Google, Google decides for itself what it does with your Google account.
When we analyse the structure of a file you upload, a sample goes to Anthropic in the United States: the column names and a handful of values per column, so that their model can see which column holds which piece of information. No value from a column we recognise as personal data goes with it: names, addresses, postcodes, email addresses, phone numbers, bank accounts and free-text note fields are held back – for those columns only the column name goes. That check works on your column names, so a column with a name we do not recognise as personal data can still send sample values; if you come across one, tell us. Per column at most eight individual sample values go – never a complete row, never a complete column, never a total. Because those samples are picked per column independently, together they do not form an actual row from your file. Nothing from your file is stored at Anthropic and nothing is learned from it. The figures in Sento never come from an AI model; we calculate those ourselves.
Your data is stored in the European Union. Supabase, Vercel, Stripe and Anthropic are US companies; with Anthropic the analysis described above is actually performed in the United States, and with the other three access from outside the EU cannot be entirely ruled out – for instance when their support looks into an incident. For all of those transfers the European Commission’s standard contractual clauses apply, supplemented by the EU-US Data Privacy Framework where relevant.
If you sign in with Google, Google remains responsible for your Google account itself. Their own privacy policy applies to that.
How we protect it
- Your data is stored in the European Union. The only exception is the AI analysis described above, which stores nothing.
- Traffic runs over TLS; storage is encrypted.
- Customer data is separated inside the database itself, not only in the application – so a mistake in our code cannot get around it. We verify this with an automated test.
- Two-step verification is available on every account, and we recommend it.
- Security events are written to a log that cannot be altered.
- Keys and passwords live in secure vaults, never in our source code.
Perfect security does not exist. If you suspect something is wrong with your account or with our security, email info@sentofinance.com: we take such reports seriously and respond quickly.
Cookies
Sento uses no advertising or tracking cookies, and does not measure what you do on the site. That is also why you see no cookie banner: there is nothing to ask.
| Cookie | What for | How long |
|---|---|---|
sb-…-auth-token |
Keeps you signed in | Until you sign out |
sento-lang |
Remembers whether you want Dutch or English | 12 months |
Automated decision-making
There is none. No decisions about you are made by a computer without a person involved.
Sento will provide analysis and advice based on your company data. That remains support for a decision you make. The figures also come from deterministic calculations you can check, not from a language model. If that changes, we will update this statement before it does.
Your rights
You have the right to:
- see what data we hold about you;
- have it corrected if it is wrong;
- have it deleted;
- have processing restricted;
- take your data with you in a common file format;
- object to processing based on a legitimate interest.
Email info@sentofinance.com. We respond within a month. To avoid handing data to the wrong person, we may ask you to confirm your identity.
If you disagree with how we handle your data, you can lodge a complaint with the Dutch Data Protection Authority. We would rather hear it from you first, so we can put it right.
Changes
Sento is under development, so this statement will change with it. The date at the top shows when it was last updated. If something material changes in what we do with your data, we will tell everyone with an account – so you hear it from us rather than having to notice it yourself.