Legal

Privacy Policy

Last updated: 2 October 2026 Regulation: UK GDPR

1 Who we are

SentinelHQ is a family of compliance and safeguarding platforms — CareSentinel, ClubSentinel, ReferenceSentinel, CountyConsent and SportConsent — operated by SentinelHQ Limited, a company registered in England & Wales (Company No. 17242389). We are the data controller for account and billing data, and a data processor for the operational records our customers store in each platform, for which the customer is the controller.

Data Controller: SentinelHQ Limited
Registered: England & Wales · Company No. 17242389
Contact: hello@sentinelhq.co.uk
ICO registration: ZC175485

2 What data we collect

  • Account data — names, work email addresses, job roles and authentication details of the staff who use the platform.
  • Operational records — the compliance, safeguarding and consent records your team enters (incidents, audits, training, COSHH, references, parental consent, medical/emergency details, and related evidence). The exact categories vary by product.
  • Usage data — basic technical logs (IP address, browser type, timestamps) needed to operate and secure the service.

Voice features process only the text transcript — audio does not leave the browser. Customers are instructed not to store data beyond each platform's intended compliance and safeguarding purpose.

3 Why we use it (lawful bases)

  • Contract (Art. 6(1)(b)) — to provide the service you subscribe to.
  • Legitimate interests (Art. 6(1)(f)) — securing, maintaining and improving the platform, and communicating with account holders.
  • Legal obligation (Art. 6(1)(c)) — where we must retain records to meet our own duties.
  • Consent (Art. 6(1)(a)) — for optional marketing, which you can withdraw at any time.

4 How & where we store it

Data is held in a PostgreSQL database managed by Supabase and served through Vercel, configured to UK / EU regions. Data is encrypted in transit (TLS 1.2+) and at rest (AES-256), with row-level security isolating each organisation's data. Administrative actions are logged.

5 How long we keep it

  • During your subscription — data is retained and accessible.
  • After cancellation — retained for 30 days to allow export, then permanently deleted.
  • Backups — rotated and purged within 90 days. Certain compliance records may be retained longer where a legal obligation applies.

6 Your rights

Under UK GDPR you have the right to access, rectify, erase, restrict or object to processing, and to data portability. Contact hello@sentinelhq.co.uk and we will respond within 30 days. Where we hold data on behalf of your employer (the controller), we will direct the request to them and assist. You may also complain to the ICO at ico.org.uk.

7 Data sharing & sub-processors

We do not sell, rent or share your personal data for marketing. We use a small number of trusted sub-processors:

Sub-processorPurposeLocation
SupabaseDatabase, authentication & file storageUK / EU
VercelApplication hosting & deliveryUK / EU
ResendTransactional email deliveryEU / US
AnthropicAI text processing — no model training on your dataUK / EU / US
StripePayments and subscription billingUK / EU / US
ClickSendSMS reminders (ReferenceSentinel)AU / UK

Some of these sub-processors operate outside the UK/EEA. Where personal data is transferred outside the UK/EEA, we rely on an appropriate safeguard: the UK International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses with the UK Addendum.

8 Cookies

We use essential cookies only — strictly necessary for authentication and session security. No advertising cookies, tracking pixels or third-party analytics.

9 Breach notification

In the event of a personal data breach posing a risk to rights and freedoms, SentinelHQ Limited will notify the ICO within 72 hours of becoming aware and inform affected organisations without undue delay.

10 Changes

We may update this policy from time to time. Material changes are reflected by the "last updated" date and, where significant, notified by email or in-app notice.

11 Contact

SentinelHQ Limited
32 Thornbridge, Washington, NE38 8TJ
Registered in England & Wales No. 17242389 · ICO ZC175485
hello@sentinelhq.co.uk

Security

Security at SentinelHQ

Last updated: 2 October 2026 ICO: ZC175485

Every SentinelHQ platform is trusted with information that matters — incident records, compliance evidence, hazardous-substance data, and the consent and safeguarding details of young and vulnerable people. We take that responsibility seriously. This page sets out exactly how we protect your data.

1 Your data, your control

Our platforms use a multi-tenant architecture — many organisations use the same system, but your organisation's data is completely isolated from every other organisation's, enforced at the database level via Row-Level Security (RLS).

✓

Row-Level Security across every table. The database itself refuses to return another organisation's data, even in the event of an application-level bug.

2 Where your data lives

Application hostingVercel (UK/London region for UK customers)
Database & file storageSupabase (EU region, on AWS)
Email deliveryResend
AI processingAnthropic (UK/EU where available)
PaymentsStripe
SMS reminders (ReferenceSentinel)ClickSend

Your core records are stored in UK/EU regions. Some providers (email, AI processing, payments and SMS) operate outside the UK/EEA; those transfers are covered by the UK IDTA or the EU Standard Contractual Clauses with the UK Addendum. All providers are enterprise-grade with their own SOC 2 and ISO 27001 certifications.

3 How we protect it

Encryption in transit
TLS 1.2+
Every connection is encrypted with TLS 1.2 or higher.
Encryption at rest
AES-256
All database content and file storage encrypted by Supabase.
Authentication
Signed & time-limited
Password hashing via bcrypt; sessions expire automatically.
File access
Signed URLs only
Uploads and documents are never accessible by URL guessing.

4 Who has access

Each platform uses role-based access control — admins manage records and users, leads have module-level access, and staff/viewers have read-only or limited access. SentinelHQ Limited staff do not access your data in normal operations; access is granted only with your explicit permission (e.g. to debug a specific issue) and every such access is logged.

5 AI and your data

  • AI requests are processed by Anthropic under contract. Anthropic does not train models on your data.
  • Voice transcripts are processed in real time by your browser — audio is not sent to our servers or stored.
  • Document and data-sheet uploads are processed and the result returned to your database; nothing is shared externally.
→

To disable AI features for your organisation, contact hello@sentinelhq.co.uk.

6 Compliance & certifications

  • UK GDPR and the Data Protection Act 2018.
  • ICO registration: ZC175485.
i

SentinelHQ Limited does not yet hold ISO 27001 or SOC 2 certification directly — these are on our roadmap. Our infrastructure providers (Vercel, Supabase, Anthropic) hold these certifications themselves.

7 Incident response

  1. Notify you within 72 hours of confirming an incident affecting your data.
  2. Provide a clear summary of what happened, what data was involved and the actions taken.
  3. Notify the ICO within 72 hours where required by law.
  4. Support onward notifications to individuals or regulators if needed.

8 Reporting a concern

If you believe you've found a security vulnerability, email hello@sentinelhq.co.uk. We aim to acknowledge within one working day and do not take legal action against good-faith researchers who follow responsible disclosure.

9 Questions

SentinelHQ Limited
32 Thornbridge, Washington, NE38 8TJ
Registered in England & Wales No. 17242389 · ICO ZC175485
hello@sentinelhq.co.uk

Legal

Terms of Service

Last updated: 2 October 2026 Jurisdiction: England & Wales

1 Acceptance

By subscribing to or using any SentinelHQ platform ("the Service") you agree to these Terms and our Privacy Policy on behalf of your organisation. The Service is operated by SentinelHQ Limited, registered in England & Wales (Company No. 17242389).

!

If you do not agree to these Terms, you must not use the Service.

2 The service

SentinelHQ provides subscription compliance and safeguarding platforms for regulated sectors (care, golf, recruitment and junior sport). We provide the Service with reasonable skill and care and add features over time. We may modify, suspend or discontinue features with reasonable notice.

3 Accounts

You are responsible for keeping credentials secure, for all activity under your account, for ensuring invited users comply with these Terms, and for notifying us promptly of any suspected unauthorised access. Credentials must not be shared — each user must have their own account. You must be at least 18 to create an account.

4 Subscription & payment

  • Pricing depends on the product and plan you select and is set out at sign-up. Some tiers are free.
  • You may choose monthly or annual billing; annual is charged for ten months (two months free).
  • Fees are payable in advance and are non-refundable except where required by law.
  • Fees are exclusive of VAT where applicable. We may revise pricing on renewal with reasonable notice.

5 Acceptable use

You agree not to: upload false, misleading or unlawful content; attempt unauthorised access to another organisation's data; reverse-engineer or extract source code; transmit malware; scrape or systematically extract data; or place unreasonable load on our infrastructure. We may suspend accounts that breach this policy.

6 Your data & ownership

✓

You own your data. All records you enter remain the property of your organisation (the controller). You grant us a limited licence to store and process it solely to provide the Service.

We do not use your operational data to train AI models, sell it, or use it for any purpose other than delivering the Service. See the and .

7 Intellectual property

The SentinelHQ platforms — software, design, features and documentation — are owned by SentinelHQ Limited and protected by intellectual-property law. Your subscription grants a limited, non-exclusive, non-transferable licence to use the Service. You retain all rights to the records you create.

8 Liability

!

SentinelHQ platforms are management and record-keeping tools. They support, but do not replace, your own compliance, safeguarding and regulatory responsibilities, or professional advice.

To the maximum extent permitted by law, we are not liable for indirect, incidental or consequential loss, and our total liability in any 12-month period is limited to the fees paid in that period. Nothing excludes liability for death or personal injury caused by negligence, fraud, or any liability that cannot lawfully be excluded.

9 Termination

By you: cancel at any time; access continues to the end of the current billing period. By us: we may suspend or terminate for material breach or non-payment, with at least 30 days' notice of service discontinuation except in cases of breach. On termination, your data remains available for export for 30 days, then is securely deleted.

10 Governing law

These Terms are governed by the laws of England & Wales, whose courts have exclusive jurisdiction.

11 Changes

We may update these Terms; the "last updated" date reflects the current version. We will give at least 14 days' notice of material changes. Continued use after the effective date constitutes acceptance.

12 Contact

SentinelHQ Limited
32 Thornbridge, Washington, NE38 8TJ
Registered in England & Wales No. 17242389 · ICO ZC175485
hello@sentinelhq.co.uk

Legal

Data Processing Agreement

Last updated: 2 October 2026 Standard: UK GDPR Article 28

1 Parties & roles

Data Controller: the customer organisation that subscribes to a SentinelHQ platform.

Data Processor: SentinelHQ Limited (Company No. 17242389, England & Wales), processing personal data only on the customer's documented instructions.

This DPA forms part of and is incorporated into the Terms of Service. In the event of conflict on data-protection matters, this DPA takes precedence.

2 Subject matter & duration

The processing of compliance, safeguarding and consent records within the relevant SentinelHQ platform, for the duration of the subscription and the limited post-termination export window described below.

3 Nature & purpose

To host, store, organise and make available the customer's records, and to provide platform features (including AI-assisted structuring of text the customer submits). We process personal data only on the customer's documented instructions.

4 Categories of data

  • Identity & contact: names, work email addresses.
  • Employment: job titles, roles, training and certification records.
  • Operational records: incidents, audits, COSHH, references, and (for consent products) parental consent, medical, dietary and emergency details of participants.
  • Activity logs: user actions and timestamps for audit purposes.

5 Data subjects

  • Customer staff, employees and volunteers.
  • Participants, workers, residents and — for consent products — children and their parents/guardians, where entered by the customer.
  • Third-party contractors, where their details appear in records.

6 Processor obligations

We process only on documented instructions; ensure personnel are bound by confidentiality; implement the security measures in Section 9; engage sub-processors only under Section 7; assist with data-subject requests (Articles 15–22); notify breaches without undue delay; and delete or return data on termination.

7 Sub-processors

Sub-processorPurposeLocation
SupabaseDatabase, authentication & file storageUK / EU
VercelApplication hosting & deliveryUK / EU
ResendTransactional emailEU / US
AnthropicAI text processing (no model training)UK / EU / US
StripePayments and subscription billingUK / EU / US
ClickSendSMS reminders (ReferenceSentinel)AU / UK

We will notify the customer of intended changes to sub-processors. The customer may object within 30 days; absent objection the change is deemed accepted.

8 Rights assistance

We provide reasonable technical assistance — data export, deletion of individual records on instruction, and provision of audit logs — to help the customer meet its UK GDPR obligations. The customer, as controller, remains responsible for handling data-subject requests.

9 Security measures

  • Encryption at rest (AES-256) and in transit (TLS 1.2+).
  • Row-level security enforcing strict tenant isolation.
  • Role-based access control and least-privilege administration.
  • Audit logging of material changes with user identity and timestamp.
  • Automatic backups with point-in-time recovery.
  • UK/EU-region hosting; dependency monitoring and updates.

10 Breach notification

We will notify the customer within 72 hours of becoming aware of a personal data breach affecting their data, with the information reasonably needed for the customer to meet its own duties under Articles 33–34.

11 Deletion on termination

  • Data remains available for export for 30 days after termination.
  • After 30 days, personal data is permanently deleted from production systems.
  • Backups are purged within 90 days. Written confirmation of deletion is available on request.

12 Audit

On at least 30 days' notice and no more than once per year, the customer may request an audit of our processing activities. We may satisfy this via up-to-date certifications, written questionnaires, or an on-site audit at a mutually agreed time (customer's cost).

13 International transfers

Our core database and application hosting run in UK/EU regions. Some sub-processors (including Resend, Anthropic, Stripe and ClickSend) operate outside the UK/EEA. Any such transfer is made under an appropriate safeguard: the UK International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses with the UK Addendum. We will notify the customer before adding a sub-processor that transfers data outside the UK/EEA.

14 Governing law

This DPA is governed by the laws of England & Wales. Contact: hello@sentinelhq.co.uk.

SentinelHQ Limited
32 Thornbridge, Washington, NE38 8TJ
Registered in England & Wales No. 17242389 · ICO ZC175485
hello@sentinelhq.co.uk