Trust
Where your data lives,
and who can see it.
You are handing us your client book. This page is written to be true rather than reassuring, including the parts that are not finished yet.
Last updated 2026-09-11.
The short version
- No other agency using Sentira can see your clients, your stock, your deals or your email.
- Your data is stored in Germany, in the EU, and backed up daily in the same region.
- Our platform administrators can sign in to your CRM and see and change everything your own administrator can. That access is not yet shown in your own activity log.
- You can export everything, at any time, from your own setup page, without asking us.
- You can close the account yourself. Everything is erased 30 days later.
- We do not sell your data and we do not use it to train AI models.
How one platform keeps agencies apart
Sentira is one application serving many agencies. Every record carries the company it belongs to, and every query the application makes is scoped to the company of the person asking. There is no screen, no export, no search and no report that crosses from one agency to another.
The practical consequences, spelled out:
- Your properties are your properties. Another agency's stock never appears in your CRM, in your assistant's suggestions, in your emails or in your website.
- Your enquiries are yours. If the same buyer writes to you and to another agency on the platform, neither of you is told.
- Your alerts stay inside your company. A new lead bells your people, never ours.
- Your client email leaves from your mailbox. If your mailbox is not connected yet, the message is held rather than sent from an address that is not yours.
What our staff can see
We run the platform, so there is access we genuinely have. Hiding that would be the wrong kind of trust page.
- Support access. Our platform administrators can sign in to your CRM on your own address and see and do everything your own administrator can: clients, deals, emails, contracts, settings. This is how a support question gets answered.
- The platform console. We can see your company's plan, seats, user count, lead count, activity and setup progress. We do not read your clients from that console.
- The server. The database is one file on one server that we operate, and it is in our daily backups. Anybody with root on that machine can read it. Today that is us.
- The shared AI account. Assistant traffic is routed through our own account with the AI gateway, so usage and cost per company are visible to us. The conversations themselves are stored in your CRM, on the client's card.
- The platform enquiry mailbox. Before you connect your own mailbox, the forwarding address we give you delivers into a mailbox we operate. Mail that passes through it is readable by our platform administrators, and the full original message is stored on the client's card in your CRM. Connect your own mailbox and this stops.
What we are not happy with yet. When one of our administrators works inside your CRM, that does not currently appear in your own activity log. We think it should, and it is on the list. We would rather tell you than let you find out.
Where it lives
| What | Where |
|---|---|
| The application and the database | A server we operate at Hetzner, Germany (EU) |
| Backups | Daily, same provider, same region |
| Uploaded files (logos, documents, photos) | The same server |
| Your own website and microsites | The same server |
No copy of your database is kept outside the EU. Individual messages leave the EU only where a sub-processor below is outside it, and that is listed.
Sub-processors
These are the companies that can touch your data on our behalf, and exactly what reaches them. Some of them only exist for you if you switch that channel on.
| Who | What they do | What reaches them | Where |
|---|---|---|---|
| Hetzner Online GmbH | Hosting and backups | Everything, at rest | Germany (EU) |
| OpenRouter, and the AI providers it routes to (including Anthropic) | The assistant's replies, translations, summaries | The text of the conversation and the property facts the assistant is answering with | United States, under the standard contractual clauses |
| Google (Google Workspace) | Platform email, and the enquiry mailbox before you connect your own; calendar sync where you use it | Login and account email, and enquiry mail that passes through the platform address | EU and United States |
| Stripe | Card payment for your own subscription | Your billing name, address, VAT number and card details. Card details go to Stripe, never to us. | EU and United States |
| Meta Platforms | WhatsApp and lead ads, only if you connect them | The messages and lead forms of those channels | EU and United States |
| ElevenLabs | The voice channel, only if you switch it on | Call audio and transcripts for that channel | United States |
If we add or change a sub-processor we will tell account administrators by email before it starts.
The assistant, and AI
- The assistant only works from your own data: your stock, your client cards, your settings. It is not given another agency's anything.
- Conversations are sent to the AI gateway to produce a reply and are stored in your CRM. They are not used to train models: that is the API contract we buy under, and we do not opt in to anything else.
- Every message the assistant sends is written onto the client's card in full, so you can read exactly what your clients were told.
- The assistant stands down for a client the moment one of your agents replies.
- You can switch it off per company and per client.
Security practice
- Traffic runs over HTTPS. Each customer address gets its own certificate, issued automatically.
- Passwords are salted and hashed, never stored or emailed in the clear. Repeated failed sign-ins are throttled.
- Session cookies are HttpOnly and marked Secure behind HTTPS. Signing in is bound to the address you sign in on.
- State-changing requests are checked against the origin they came from.
- Public forms are rate limited and gated against automated abuse.
- Uploaded logos must be real images. Scriptable file types are refused, and user-uploaded files are served with a policy that makes them inert.
- The website preview for an agency's unpublished site requires a session belonging to that agency or a signed link.
What we do not claim. We have no ISO 27001 or SOC 2 certification, and no third-party penetration test to publish. We do not offer a formal uptime guarantee today. Disk-level encryption is a property of the hosting platform rather than something we implement ourselves, so we do not claim it as a control of ours. If any of that changes we will say so here with a date.
Your data, and getting it back
- It is yours. We process it for you, as your processor, under the data processing agreement. We do not use it for our own purposes.
- Export. From your setup page, at any time, in machine-readable form: clients, activity, deals, properties, contracts, invoices and users, as one JSON file or a spreadsheet per table. It is your records, not your files: logos, photos and uploaded documents are not in it today. Ask us and we will send them to you.
- Erasure. Close the account from the same page. Access stops immediately and everything is erased after 30 days, which is the window that lets somebody undo a mistake. Backups roll off within the same period.
- Your clients' rights. If one of your clients asks you to erase them, you can do it from their card without asking us. You are the controller for your clients' data; we are the processor.
Reporting a problem
If you think you have found a security problem, email hello@sentiracrm.com with enough detail to reproduce it. We will confirm within two working days. Please do not test against another customer's data, and please give us a reasonable window to fix it before publishing.