Legal
Privacy policy
Version 2026-09-11.
1. Two different roles
This policy covers two situations, and it matters which one you are in.
- You are a visitor or a customer of ours. You read this website, book a demo, open an account, pay an invoice, email support. For that data we are the controller, and this policy is the whole story.
- You are a client of an agency that uses Sentira. Your details are in that agency's CRM because you contacted them. For that data the agency is the controller and we are only their processor: we hold it on their instructions and we do not decide what happens to it. Ask them, not us. The terms we hold it under are in the data processing agreement. If you write to us we will pass the request to the agency.
2. Who we are
Nicki Price Real Estate, S.L., VAT ESB21803580, Calle Úbeda 6B, 03193 San Miguel de Salinas (Alicante), Spain. Email hello@sentiracrm.com. We have not appointed a data protection officer; that address reaches the people responsible.
3. What we collect as controller, and why
| What | When | Why | Lawful basis |
|---|---|---|---|
| Name, work email, phone, agency name, message | You book a demo or write to us | To hold the appointment and to answer you | Steps before a contract, and our legitimate interest in replying |
| Company name, address, VAT number, billing email, contact name | You open an account | To create the account, invoice you and meet Spanish accounting law | Contract, and legal obligation for the invoice |
| Login email, password hash, role, sign-in times, IP address | You use the service | To let you in and to keep the account secure | Contract, and our legitimate interest in security |
| Card details | You pay by card | To take payment | Contract. Card details go to Stripe, never to us. We see the last four digits and the result. |
| Support emails and their attachments | You ask for help | To help you, and to remember what was agreed | Contract, and legitimate interest |
| Server logs: IP address, page, timestamp, user agent | Any request | To run the service and investigate abuse and faults | Legitimate interest |
We do not buy contact lists, we do not run advertising trackers on this website, and we do not profile you.
4. Cookies and this website
The public pages of this website set no cookies and load nothing from anybody else: no analytics, no fonts from a font service, no advertising pixels, no embedded video. There is no cookie banner because there is nothing to consent to.
Inside the CRM itself there is one cookie, which holds your sign-in session. It is strictly necessary, it is not shared, and it disappears when you sign out.
5. Who we share it with
Only with the sub-processors that make the service work. Each one is named, with what reaches them and where they are, on the trust page. In summary: hosting in Germany, an AI gateway for the assistant, Google Workspace for platform email, Stripe for payment, and Meta and a voice provider only for channels you switch on.
We also share data where the law requires it, for example a court order or a tax inspection. We will tell you unless we are forbidden from doing so. We do not sell personal data to anybody, ever.
6. Transfers outside the EU
Your database lives in Germany. Some sub-processors are in the United States. Where personal data reaches them it is transferred under the European Commission's standard contractual clauses, together with the technical measures described on the trust page. You can ask us for the details of a specific transfer.
7. How long we keep it
- Demo bookings and enquiries that go nowhere: we keep them as our record of who we spoke to. There is no automatic deletion today, and we would rather say so than print a number we do not honour. Write to us and we will delete yours.
- Account and CRM data: for as long as the account exists. When you close it, everything is erased 30 days later. If you stop paying we suspend the account rather than erasing it, so that you can come back to it or ask us for a copy.
- Invoices and accounting records: six years, because Spanish law requires it.
- Backups: rolled off within 30 days.
- Server logs: up to 90 days.
8. Your rights
Where we are the controller, you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or hand it to somebody else in a machine-readable form. You can object to processing we do on the basis of legitimate interest. Where you gave consent you can withdraw it at any time, and that does not affect what happened before.
Write to hello@sentiracrm.com. We answer within 30 days. If you are not satisfied you can complain to the Spanish data protection authority, the Agencia Espanola de Proteccion de Datos, at www.aepd.es, or to the authority in your own country.
If you are a client of an agency that uses Sentira, send the same request to that agency. They hold your data and they decide. We will help them act on it.
9. Security
What we do, and what we do not claim, is set out plainly on the trust page. In short: HTTPS everywhere, hashed passwords, per-company scoping of every query, rate limits on public forms, restricted uploads, daily backups in the EU, and no third-party certification to show you yet.
10. Changes
If we change this policy in a way that matters we will email account administrators before it takes effect and change the version date at the top.