This policy explains how we process your personal data when you use the JANES Sentinel website and service. Processing is based on Regulation (EU) 2016/679 (GDPR) and Hungarian Act CXII of 2011 on informational self-determination and freedom of information.
1. Controller
- Name
- Janes Zsolt egyéni vállalkozó
- Registered office
- 1144 Budapest, Szentmihályi út 20–22. V/143.
- hello@janes.hu
- Phone
- +36 (30) 374 0737
2. What we process and why
Registration and client account
- Data: company name, name, email address, password (stored only as an irreversible hash), language, and two-factor and passkey data if you set them up.
- Purpose: creating your client account, signing you in, approving your registration and providing the service.
- Legal basis: performance of a contract and steps prior to entering into it (Art. 6(1)(b) GDPR).
- Retention: until the account is closed, then as long as accounting and limitation rules require.
Monitoring data
- Data: the addresses of monitored websites, the steps of browser flows, test credentials used by the checks (stored encrypted), check results, response times, error messages and screenshots of failed runs.
- Purpose: performing the functional monitoring you ordered, opening incidents and sending alerts.
- Legal basis: performance of a contract (Art. 6(1)(b) GDPR). Personal data visible on a monitored website is processed on your behalf, as a processor.
- Retention: details of successful runs for 30 days, failed runs for 90 days, screenshots for 90 days, incidents until the contract ends.
Passwords, tokens, cookies, Authorization headers and API keys are never stored in diagnostics or logs – they are masked before anything is recorded.
Notifications
- Data: the notification email addresses and webhook URLs you provide, and the log of sent notifications.
- Purpose: alerting you about failures and recoveries.
- Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Contact
- Data: name, email address and – if you provide them – company, website and the text of your message.
- Purpose: answering your message.
- Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.
- Retention: one year after the matter is closed.
Security logs
- Data: IP address, time and the administrative action performed.
- Purpose: security of the service; preventing and investigating abuse such as bulk registrations or password guessing.
- Legal basis: our legitimate interest (Art. 6(1)(f) GDPR).
- Retention: at most one year.
3. Processors
Only the following parties access data, and only as far as needed to provide the service:
- hosting and server provider: Tárhely.Eu Szolgáltató Kft., 1097 Budapest, Könyves Kálmán körút 12–14., +36 1 789 2789, https://tarhely.eu;
- an email delivery provider – for alerts and system messages;
- an object storage provider – for encrypted, non-public storage of screenshots.
We do not transfer data to third countries unless the processor provides safeguards under Chapter V of the GDPR.
4. Security
Data is received over encrypted connections (HTTPS). Test credentials and notification settings are stored encrypted, screenshots are kept on non-public storage and are only available to signed-in, authorised users. Access is governed by roles and permissions, and administrative actions are logged.
5. Your rights
Under Articles 15–22 of the GDPR you have the right to:
- access the data we hold about you;
- have your data rectified or erased;
- restrict processing;
- object to processing based on legitimate interest;
- receive your data in a machine-readable format (portability);
- withdraw your consent at any time, without affecting the lawfulness of earlier processing.
We answer your request within one month. You can also delete your account yourself in your profile settings.
6. Remedies
If you believe we have infringed your data protection rights, please contact us first. You can lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH, 1055 Budapest, Falk Miksa utca 9–11, www.naih.hu) or go to court.
7. Cookies
See the cookie policy.