Privacy Policy
1. Introduction
Sentcroft Private Limited ("SentCroft," "Company," "we," "us," or "our") operates the website sentcroft.com and the SentCroft membership network, together with the AI Governance, Trust & Security Leaders Summit and other SentCroft-branded events (collectively, the "Services"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and the choices and rights available to you.
By accessing sentcroft.com, submitting any form on our Services, applying for membership, registering as a delegate, enquiring about sponsorship, or nominating a candidate for a SentCroft award, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Services or submit your personal data to us.
This Policy should be read together with our Terms of Use, Cookie Policy, and, for members, our Membership Agreement.
2. Who We Are
SentCroft is operated by Sentcroft Private Limited, a company incorporated under the laws of India, with its registered office at [Registered Office Address, City, State, PIN Code, India] ("Company," "we," "us"). For the purposes of applicable data protection law, including the Digital Personal Data Protection Act, 2023 ("DPDP Act"), we act as the Data Fiduciary in respect of the personal data described in this Policy.
3. Personal Data We Collect
3.1 Information You Provide Directly
Through the forms available on our Services:
| Form | Typical fields collected |
|---|---|
| Membership Application | Full name, email, phone, job title, organization, country, membership tier of interest, and any message |
| Delegate Pass Request | Full name, email, phone, job title, organization, country, event/city edition, pass tier and window, and any message |
| Sponsorship Inquiry | Full name, email, phone, job title, organization, country, event edition, sponsorship package of interest, and any message |
| Award Nomination | Nominator's name and email, nominee's name, title, and organization, award category, and any supporting message |
3.2 Payment Information
Where you pay a membership fee or delegate pass fee, payment is processed by Stripe, our third-party payment processor. We do not receive or store your full card number, CVV, or other sensitive card authentication data. This is collected and processed directly by Stripe under its own privacy policy. We retain only limited transaction metadata (amount, currency, date, status, and a masked reference) for our own accounting and support records. Sponsorship fees are paid by bank transfer; for these we keep the remitting organization's name, bank reference, amount, and date.
3.3 Information Collected Automatically
Our hosting and security infrastructure automatically logs limited technical information when you visit sentcroft.com, such as IP address, browser type, device type, referring page, and access timestamps, for the purposes in Section 4. As described in our Cookie Policy, sentcroft.com does not currently set analytics, advertising, or tracking cookies.
3.4 Information From Third Parties
If you are nominated for an award, or your organization is proposed as a sponsor or delegate by a colleague, we may receive limited professional contact details about you from the nominating or referring individual.
We do not knowingly collect any special category or sensitive personal data (health information, biometric data, government identity numbers, etc.) through the Services, and ask that you not include such information in any free-text field.
4. How We Use Your Personal Data
- To process your request (membership, pass, sponsorship, or nomination) and communicate with you about it, which is necessary to take steps at your request prior to a contract, and to perform a contract once accepted.
- To administer your SentCroft membership, including benefits, concierge introductions, event access, and renewal reminders, necessary for performance of the Membership Agreement.
- To process payments via Stripe, and to reconcile sponsorship bank transfers, necessary for contract performance and financial record-keeping.
- To operate and improve our events, including sharing attendee lists with venue/security personnel on a need-to-know basis, badge production, and post-event sponsor reporting in aggregate/de-identified form unless you separately consent to being named, reflecting our legitimate interest in safely and effectively running the Services.
- To send service communications (confirmations, logistics, changes), which is necessary for contract performance, and to send newsletters, reports, or invitations, based on your consent, withdrawable at any time (Section 8).
- To maintain security and integrity, prevent fraud, and enforce our Terms of Use and Membership Agreement, reflecting our legitimate interests and, where applicable, legal obligation.
- To comply with applicable law, including tax, accounting, foreign exchange, and cross-border payment regulation.
We do not sell your personal data and do not use it for automated decision-making producing legal or similarly significant effects on you.
5. How We Share Your Personal Data
- Service providers acting on our instructions: hosting, email delivery, events-management/CRM tooling, and Stripe for payments, all contractually restricted from using your data for their own purposes.
- Venue, security, and logistics partners, limited to what is needed to grant physical event access.
- Sponsors and partners, only as aggregate, de-identified attendee statistics, unless you opt in to a named attendee/speaker list (disclosed to you at collection).
- Professional advisors and authorities, where necessary to establish, exercise, or defend legal claims, or as required by law or valid legal process.
- A successor entity, on a merger, acquisition, financing, or sale of all or part of our business, subject to it assuming this Policy's commitments.
We do not share your personal data with third parties for their own independent marketing without your explicit consent.
6. International Data Transfers
SentCroft is a global network with members, delegates, and sponsors across India, MENA, Europe, the Americas, and Asia-Pacific. Your data may be transferred to and processed in India and other countries where our service providers (including our hosting provider and Stripe) operate, which may have different data protection laws than your home jurisdiction. For transfers of personal data of individuals in the EEA/UK, we take reasonable steps to ensure adequate protection, including relying on a recipient's own certified compliance frameworks (such as Stripe's) or contractual safeguards, to the extent applicable.
7. Data Retention
- Enquiry/application data that does not convert into a relationship: up to 24 months from submission, then deleted or anonymized.
- Active member and delegate records: for the duration of your relationship with us, plus a reasonable period for renewals, disputes, and legal/financial record-keeping (typically up to 7 years for financial records under Indian law).
- Payment metadata: as required by applicable tax and accounting law.
8. Your Rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you;
- Correct inaccurate or incomplete data;
- Erase your data, subject to our legitimate need to retain certain records;
- Withdraw consent to marketing at any time (every marketing email includes an unsubscribe option);
- Object to or restrict processing based on our legitimate interests;
- Nominate another individual to exercise your rights on your death or incapacity, to the extent recognized under the DPDP Act;
- Lodge a complaint with the Data Protection Board of India, your local supervisory authority (EEA/UK), or exercise CCPA/CPRA rights if you are a California resident (we do not sell or share personal data as defined under the CCPA).
To exercise these rights, contact privacy@sentcroft.com. We respond within the timeframe required by law (and in any event within 30 days), and may verify your identity first.
9. Security
We apply reasonable technical and organizational measures, including encrypted transport (HTTPS/TLS), access controls, and reputable PCI-DSS-compliant payment infrastructure (Stripe), designed to protect personal data against unauthorized access, alteration, disclosure, or destruction. No method of transmission or storage is 100% secure.
10. Children's Privacy
The Services are intended for business and professional use by individuals aged 18 and above. We do not knowingly collect personal data from anyone under 18, and will delete any such data promptly if we become aware of it.
11. Changes to This Policy
We may update this Policy to reflect changes in our practices or the law. Revisions are posted here with an updated "Last Updated" date, with additional notice for material changes where required by law.
12. Grievance Officer / Contact Us
For questions, concerns, or complaints about this Policy or your rights under Section 8:
Sentcroft Private Limited
[Registered Office Address, City, State, PIN Code, India]
Email: privacy@sentcroft.com