Data Processing Addendum

Sentinel Data Processing Addendum

Version 1.0 · Last updated: 10 September 2026

Parties and effective date

Sentinel is operated by Flat Abs Fitness LLC, a Utah limited liability company (“Sentinel”, “we”, “us”). Notices under this Addendum, including the breach notification in Section 12 and the requests contemplated by Sections 10 and 11, should be sent to collabs@roirockstars.com.

This Addendum takes effect on the earlier of the date you accept the Terms of Service and the date you first connect a data source to Sentinel, and stays in force for as long as we process personal data on your behalf. No signature is required for it to apply. If you would rather have a countersigned copy, use your own data processing agreement, or execute the Standard Contractual Clauses as a standalone document, Section 10 says how.

1. Scope and roles

This Addendum governs Sentinel’s processing of personal data on behalf of a customer (“Customer”, “you”) in connection with the Sentinel service. It supplements, and forms part of, the Sentinel Terms of Service and any separate services agreement between us. Where this Addendum conflicts with those terms on the processing of personal data, this Addendum governs.

You are responsible for having a lawful basis for the data you send us, and for any consent, cookie disclosure or notice your own site requires.

2. Definitions

“Personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” carry the meanings given in the EU General Data Protection Regulation (GDPR). “Data protection law” means the GDPR, the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the CPRA (“CCPA”), and any other privacy law applicable to a party’s processing under this Addendum. “SCCs” means the Standard Contractual Clauses approved by the European Commission in Decision 2021/914.

3. Subject matter, duration, nature and purpose

Subject matter. Provision of the Sentinel advertising analytics, attribution, alerting and creative-intelligence service.

Duration. For as long as you hold a Sentinel account, plus the deletion window in Section 9.

Nature and purpose. We process personal data to:

We do not sell personal data, and we do not use it to build cross-customer profiles, train models for third parties, or serve advertising for anyone other than you.

4. Categories of data subjects and personal data

Data subjects: your customers, prospects and site visitors; and your own personnel who hold Sentinel logins.

CategoryExamplesSource
Contact identifiersEmail address, phone number, first and last nameYour store, CRM or checkout platform
Online identifiers_stl_vid (visitor id), _stl_cid (click id), _fbp, _fbc, platform click idsSentinel tracking pixel and ad-platform redirects
Device and connectionIP address, user agent, referrer, page URL, coarse location derived from IPSentinel tracking pixel
Commercial recordsOrder id, line items, order value, currency, discount codes, refund and subscription statusShopify, WooCommerce, Stripe and other connected revenue platforms
Behavioural recordsPage views, ad impressions, click and touchpoint sequences forming an attribution journeySentinel tracking pixel and ad platforms
Account recordsYour users’ names, email addresses, hashed passwords, role assignments and access logsYou, when creating Sentinel logins

Sentinel is not designed to receive special-category data under GDPR Article 9, payment card numbers, government identifiers, or data relating to children. Do not send it. If you do, you do so as controller and outside the intended scope of this Addendum.

Where Sentinel transmits identifiers to an advertising platform as a server-side conversion, contact identifiers are hashed (SHA-256) before transmission in line with that platform’s requirements.

5. Our obligations as processor

In accordance with GDPR Article 28(3), we will:

6. Subprocessors

You give general written authorisation for us to engage the subprocessors below. We impose data protection obligations on each of them no less protective than those in this Addendum, and we remain fully liable to you for their performance.

SubprocessorPurposePersonal data reached
RailwayApplication hosting, PostgreSQL database, backupsAll categories in Section 4
AnthropicAI recommendations, alert analysis, agent chatMetrics and campaign context; contact identifiers only where present in text you supply
OpenAICreative scoring and copy generation; speech recognition and synthesis for the optional voice assistantCreative assets and campaign context; where voice is enabled, spoken audio and its transcript
Google (Gemini)Video and creative analysisCreative media and transcripts
SentryError and exception monitoringIncidental identifiers appearing in error context
MaxMindCoarse geolocation from IP addressIP address
SlackAlert, report and agent-answer deliveryMetrics, creative assets, and any identifiers in an alert body
TelegramOptional mobile alert deliveryAs above, where you enable it
Email (SMTP) providerPassword reset and notification emailYour users’ email addresses

Connected platforms are not subprocessors. Where you connect Meta, Google Ads, TikTok, AppLovin, Amazon, Shopify, WooCommerce, Klaviyo, Stripe, Recharge, Triple Whale, Guesty or a similar platform, Sentinel exchanges data with that platform on your instruction and under your own relationship with it. Each acts as an independent controller or as your own processor, on its own terms.

Notice of change. We will give at least 30 days’ notice before adding or replacing a subprocessor, by updating this page and notifying the account contact. If you reasonably object on data protection grounds within that period, we will work with you to find an alternative; if none is available, you may terminate the affected part of the service without penalty.

7. Security measures

Our technical and organisational measures under GDPR Article 32:

Our full controls are described in the Data Loss Prevention Policy and the Security Incident Response Policy, which form part of this Addendum.

8. Data subject rights

Where a data subject contacts us directly about data we process on your behalf, we will not respond substantively; we will refer them to you and tell you promptly.

We will assist you in responding to access, rectification, erasure, restriction, portability and objection requests, using the search, export and deletion functions in the service. Where you use Shopify, requests received through Shopify’s customers/data_request, customers/redact and shop/redact webhooks are processed in line with Shopify’s requirements.

9. Retention, deletion and return

Records are pruned automatically on the schedule below. These are the windows the service actually enforces, not maximums.

RecordRetention
KPI snapshots14 days
Ad impression records14 days
Check logs, tracked visits, passback events, creative fatigue snapshots30 days
Conversion events, attribution touchpoints, Amazon attribution events60 days
Tracked orders, daily briefs, budget rule logs, agent messages90 days
Paid-acquisition click records and visitor identity mappings10 years — required to credit a later order to the paid click that earned it
Customer and CRM contact recordsRetained while your account is active, as they are the basis of ongoing attribution
Platform credentialsDeleted when you disconnect the integration

On termination. You may export your data before closing your account. On account deletion we permanently delete personal data processed on your behalf — orders, attribution records, credentials and customer identifiers — within 30 days, except where we are required by law to retain it. Backups age out on their own retention cycle.

Hashed identifiers already transmitted to an advertising platform are subject to that platform’s retention, not ours.

10. International transfers

We process data in the United States. Where you transfer personal data of data subjects in the European Economic Area, the United Kingdom or Switzerland, the SCCs are incorporated into this Addendum by reference: Module Two (controller to processor) where you are a controller, and Module Three (processor to processor) where you are yourself a processor. The docking clause applies. For the UK, the UK International Data Transfer Addendum applies to the SCCs.

For the purposes of Clause 17, the SCCs are governed by the law of Ireland. Annexes I, II and III of the SCCs are populated by Sections 3, 4, 6 and 7 of this Addendum.

On request we will sign the SCCs as a standalone document, or your own data processing agreement, provided its terms are substantially consistent with this Addendum.

11. Audit and information rights

We will make available the information reasonably necessary to demonstrate compliance with Article 28, including our security policies and answers to a reasonable security questionnaire.

You may audit our compliance no more than once in any twelve-month period, on at least 30 days’ written notice, during business hours, subject to confidentiality, and without access to other customers’ data or to systems where access would breach a duty owed to a third party. You bear your own costs. We may satisfy an audit request by providing a current third-party report or completed questionnaire where one addresses the scope of your request. An audit may be conducted more frequently following a personal data breach affecting your data, or where a supervisory authority requires it.

12. Personal data breach

We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting personal data we process on your behalf. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point — to the extent that information is available to us, supplemented as the investigation proceeds.

We will not make a public statement identifying you as affected without your prior agreement, unless legally compelled. Our handling procedure is the Security Incident Response Policy.

13. United States state privacy law

For personal information subject to the CCPA, we act as a service provider. We will not:

We certify that we understand and will comply with these restrictions. Equivalent commitments apply where the Virginia, Colorado, Connecticut, Utah, Texas or a comparable state statute governs the processing.

14. Liability

Each party’s liability under this Addendum is subject to the limitations and exclusions of liability in the Terms of Service or the services agreement between us. Nothing in this Addendum limits either party’s liability to a data subject under Article 82 of the GDPR, or any liability that cannot lawfully be limited.

15. Changes to this Addendum

We may update this Addendum to reflect a change in the service, in our subprocessors, or in data protection law. We will give at least 30 days’ notice of a material change by updating this page and notifying the account contact. Changes required by law may take effect sooner where the law requires it.

16. Contact

Data protection enquiries, data subject requests, security questionnaires and requests to sign the SCCs: collabs@roirockstars.com.

Related documents: Privacy Policy · Terms of Service · Data Loss Prevention Policy · Security Incident Response Policy