Privacy Policy
What personal data Servers Sentinel collects, why, how long it is kept, who it is shared with, and the rights you have over it under the GDPR.
Last updated 2026-08-26
This policy explains what personal data File Master LLC (Serena app., office C13, Golden Sands, Varna 9007, Bulgaria, VAT 180842207) collects when you use Servers Sentinel, and what we do with it. For data your agents send us about your own users, see the Data Processing Addendum - there we act as your processor, not as a controller.
What we collect
| Data | Why we hold it | Basis |
|---|---|---|
| Account e-mail, password hash, workspace name, team membership and role | To create and secure your account and route notifications | Performance of a contract |
| Billing identifiers: subscription and transaction IDs, plan, country, tax status | To take payment, issue invoices and meet accounting obligations | Contract and legal obligation |
| Server telemetry: hostname, OS and version, CPU, memory, disk and network metrics, listening ports, service and process names, package and hardware inventory | To render the dashboard, evaluate rules and raise incidents | Contract |
| Security events: failed and successful SSH/RDP authentication, including source IP addresses and attempted usernames; sudo and new-user events | To detect brute-force attacks and show you who is trying to get in | Contract and legitimate interest in securing the service |
| Support correspondence and audit-log entries (who did what in the panel, and from which IP) | To answer you and to give you an accountable record of admin actions | Contract and legitimate interest |
| Site analytics: pages viewed, referrer, coarse device and screen information, campaign tags | To understand which pages work | Consent, where required |
Who we share it with
We do not sell personal data. We share it only with the processors we need in order to run the service:
- PayPro Global - international card and PayPal checkout, as merchant of record.
- YooKassa - payments in Russia.
- Cryptomus - cryptocurrency payments.
- Google Analytics 4 - aggregate website analytics on the marketing pages.
- Our own analytics endpoint at
godless-server.ru, operated by us, for first-party page analytics. - Our SMTP relay - transactional e-mail (verification, password reset, alert delivery).
- Telegram and Slack - only if you connect them yourself as alert channels, and only the alert content you have configured.
We also disclose data where we are legally required to, and to a successor in the event of a merger or acquisition - in which case we will tell you before your data becomes subject to a different policy.
Where it is stored, and for how long
Data for the hosted service is stored on servers in the European Union. Where a processor is outside the EEA, the transfer relies on the European Commission's Standard Contractual Clauses.
- Metric samples are retained according to your plan's history window, then aggregated or dropped.
- Security events and incidents are kept for 12 months.
- Audit-log entries are kept for 12 months.
- Account and billing records are kept for the life of the account, and for as long afterwards as tax law requires (10 years in Bulgaria).
- Backups age out within 30 days of a deletion.
Your rights
Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict or object to its processing, or hand it to another provider. Write to tech.support@recoverytoolbox.com and we will answer within 30 days. Most of it you can also do yourself: export through the API, and delete a workspace from Settings.
If you believe we have handled your data wrongly, you may complain to the Bulgarian Commission for Personal Data Protection, or to the supervisory authority where you live.
Cookies and local storage
We use local storage to keep you signed in and to remember your language and theme. Google Analytics sets its own cookies on the marketing pages; the panel itself sets none beyond what the session requires. Blocking analytics cookies does not affect the service.
Security
Agents authenticate with client certificates and stream over mutual TLS; enrollment tokens are single-use, expire, and are stored only as SHA-256 hashes. Certificates are bound to a device identifier so a copied key cannot be reused on another host. Passwords are stored hashed. Access to production data is limited to the people who operate the service.
Questions about this policy: tech.support@recoverytoolbox.com.