Privacy Policy
How Sentrix collects, uses, shares and protects personal data across its real-time risk decisioning and case-operations platform. This policy is written against UAE Federal Decree-Law No. 45 of 2021 (the Personal Data Protection Law, or 'PDPL') as its baseline and should be read alongside our Data Processing Addendum, Sub-processors list, Cookie Policy and Security overview.
Last updated: 22 July 2026 · Governing law: United Arab Emirates
1. Who we are & our role
Sentrix provides a real-time risk decisioning and compliance case-operations platform to banks, acquirers, payment service providers and electronic money institutions. Our role under data-protection law depends on the data in question:
- Controller — for account and relationship data of the customer organisations and their authorised users (for example, names, work emails, authentication data, billing contacts and product usage telemetry, the purposes of which we determine).
- Processor — for the decisioning, screening and case data that our customers submit or generate through the platform about their own end users. The customer determines the purposes and means; we act on their documented instructions under the DPA.
Sentrix is a technology vendor. It is not itself a bank, licensed financial institution or a party to our customers' regulated relationships with their end users.
2. Applicable data-protection law
Our baseline is UAE Federal Decree-Law No. 45 of 2021 (PDPL) and its implementing regulations, together with guidance from the UAE Data Office. Because the specific UAE free zone in which the Sentrix contracting entity is established has not yet been finalised, the following free-zone data regimes may additionally apply depending on that choice, and are reflected in the executed agreement:
- DIFC Data Protection Law No. 5 of 2020 (with the Office of the DIFC Commissioner of Data Protection), if the entity sits in the Dubai International Financial Centre; or
- ADGM Data Protection Regulations 2021 (with the Abu Dhabi Global Market Office of Data Protection), if the entity sits in the Abu Dhabi Global Market.
Where a customer or its end users are subject to other regimes — for example the EU/UK GDPR or the California Consumer Privacy Act (as amended by the CPRA) — we support those obligations through the DPA and recognised transfer mechanisms, as described below.
3. Data we collect
Account data (as controller)
- Identity and contact details of authorised users — name, work email, job title, organisation.
- Authentication and security data — hashed credentials, session metadata, audit events.
- Commercial and billing data — order-form contacts, plan, invoicing details.
- Support and communications — messages you send us, briefing requests, correspondence.
Usage & technical data (as controller)
- Product telemetry — features used, decisioning volumes, configuration changes, performance and error logs.
- Device and connection data — IP address, browser/user-agent, timestamps, and strictly-necessary cookies (see our Cookie Policy).
End-user decisioning & screening data (as processor)
When customers operate the platform, they submit or generate data about their own end users — for example transaction and risk signals, identity attributes, sanctions/PEP/adverse-media screening inputs and results, case notes, decisions and overrides. We process this data only on the customer's documented instructions and do not use it for our own purposes. In this evaluation environment, screening providers run in sandbox and results are simulated.
4. How & why we use data — lawful bases
Under the PDPL, personal data may be processed with the data subject's consent or on another lawful basis set out in Article 4 of the law (including where processing is necessary to perform a contract, to protect the vital interests of the data subject, to comply with a legal obligation, or for the legitimate interests of the controller that do not prejudice the data subject's rights). We rely on the following:
| Purpose | Lawful basis (PDPL / equivalent) |
|---|---|
| Provide and operate the Services customers configure | Performance of a contract |
| Secure the platform, prevent abuse, maintain audit trails | Legitimate interests; compliance with a legal obligation |
| Process end-user decisioning/screening data | Processor acting on the customer's instructions (the customer establishes the basis) |
| Billing, tax and records | Contract; legal obligation |
| Service communications and support | Contract; legitimate interests |
| Optional product analytics | Consent (where required) |
5. Sharing & sub-processors
We share personal data only as needed to run the service: with vetted sub-processors under written contracts, with professional advisers, and where required by law or to protect rights and safety. A current list of named sub-processors — including category, purpose, region and status — is maintained on our Sub-processors page. We do not sell personal data and we do not share it for cross-context behavioural advertising.
6. International & cross-border transfers
The platform is hosted on cloud infrastructure that may process data outside the UAE. Under Articles 22 and 23 of the PDPL, personal data may be transferred outside the UAE where the destination provides an adequate level of protection, or, absent adequacy, on the basis of appropriate contractual safeguards, the data subject's consent, or another permitted ground. For customers or end users subject to the EU/UK GDPR, we additionally rely on the Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary technical and organisational measures. Customer-selectable data-residency (including UAE-region hosting) is on our roadmap, as described on our Regulatory & Compliance page.
7. Retention
Account and usage data is retained for the life of the relationship and for a limited period afterwards to meet legal, tax and security obligations. End-user data processed on a customer's behalf is retained per the customer's configured policy and the Data Processing Addendum, then returned or deleted on termination. We apply data minimisation and delete or anonymise data we no longer need. Where the customer's own regulatory obligations require records to be kept for a defined period (for example the five-year AML record-keeping period under UAE law), the customer configures retention accordingly.
8. Security
We protect personal data with encryption in transit and at rest, least-privilege access controls, tenant isolation, and continuous logging and monitoring. See our Information Security overview for the technical and organisational measures we implement.
9. Your rights
Subject to applicable law, and in particular the PDPL, you may have the right to:
- Be informed about how your personal data is processed.
- Access the personal data we hold about you and obtain a copy.
- Rectify inaccurate or incomplete data.
- Request erasure of your data where grounds apply.
- Restrict or stop certain processing, including automated processing and profiling that produces legal or similarly significant effects.
- Port data you provided to us in a structured, machine-readable format.
- Withdraw consent at any time where processing relies on consent.
Where Sentrix acts as a processor, please direct requests to the customer that controls the data; we will assist them in responding. To exercise controller-level rights, or to raise a concern with our data protection function, contact privacy@sentrix.world. You also have the right to lodge a complaint with the UAE Data Office (or, where a free-zone regime applies, the relevant DIFC or ADGM data protection authority), and, if you are subject to the GDPR/CPRA, with your local supervisory authority. Customers subject to the CPRA are advised that we do not "sell" or "share" personal information as those terms are defined under that law.
10. Cookies
We use strictly-necessary cookies and, optionally, privacy-preserving analytics. Details and controls are in our Cookie Policy.
11. Children
The Services are enterprise tools directed to businesses. They are not intended for, or directed to, children, and we do not knowingly collect personal data from children.
12. Changes & how to contact us
We update this policy as our practices evolve and will revise the "last updated" date above. Material changes are communicated through the platform or by email. For privacy questions or to reach our data protection function, contact privacy@sentrix.world. You may also use our Complaints & Dispute Resolution process at any time.
Company details
The operating entity for the Sentrix service is identified below. Fields marked “to be confirmed on execution” are completed with the contracting entity's registered particulars in the executed Order Form or master agreement.
This document forms part of the agreement between the customer and the Sentrix contracting entity. It is provided for information and does not itself constitute legal advice; customers should obtain their own advice on how it applies to their circumstances and regulatory obligations.