Sentinel Data Processing Addendum
Version 1.0 · Last updated: 10 September 2026
Parties and effective date
Sentinel is operated by Flat Abs Fitness LLC, a Utah limited liability company (“Sentinel”, “we”, “us”). Notices under this Addendum, including the breach notification in Section 12 and the requests contemplated by Sections 10 and 11, should be sent to collabs@roirockstars.com.
This Addendum takes effect on the earlier of the date you accept the Terms of Service and the date you first connect a data source to Sentinel, and stays in force for as long as we process personal data on your behalf. No signature is required for it to apply. If you would rather have a countersigned copy, use your own data processing agreement, or execute the Standard Contractual Clauses as a standalone document, Section 10 says how.
1. Scope and roles
This Addendum governs Sentinel’s processing of personal data on behalf of a customer (“Customer”, “you”) in connection with the Sentinel service. It supplements, and forms part of, the Sentinel Terms of Service and any separate services agreement between us. Where this Addendum conflicts with those terms on the processing of personal data, this Addendum governs.
- You are the controller (or, where you act for another party, the processor) of the personal data you connect to Sentinel — your customers’ order records, contact details and site activity.
- We are the processor (or sub-processor) of that data. We process it only to provide the service described in Section 3.
- We are an independent controller for a narrow set of data: your own account and login records, billing information, and service telemetry used to keep the platform secure and operational. That processing is described in our Privacy Policy.
You are responsible for having a lawful basis for the data you send us, and for any consent, cookie disclosure or notice your own site requires.
2. Definitions
“Personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” carry the meanings given in the EU General Data Protection Regulation (GDPR). “Data protection law” means the GDPR, the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the CPRA (“CCPA”), and any other privacy law applicable to a party’s processing under this Addendum. “SCCs” means the Standard Contractual Clauses approved by the European Commission in Decision 2021/914.
3. Subject matter, duration, nature and purpose
Subject matter. Provision of the Sentinel advertising analytics, attribution, alerting and creative-intelligence service.
Duration. For as long as you hold a Sentinel account, plus the deletion window in Section 9.
Nature and purpose. We process personal data to:
- attribute orders, leads and bookings to advertising campaigns, ad sets and individual ads;
- calculate performance metrics (ROAS, MER, CPA, contribution margin) and detect anomalies against your targets;
- match returning visitors to prior paid clicks so revenue is credited to the campaign that earned it;
- send server-side conversion events to advertising platforms you have connected, where you enable that;
- generate written recommendations, alerts and reports, including via the AI subprocessors listed in Section 6.
We do not sell personal data, and we do not use it to build cross-customer profiles, train models for third parties, or serve advertising for anyone other than you.
4. Categories of data subjects and personal data
Data subjects: your customers, prospects and site visitors; and your own personnel who hold Sentinel logins.
| Category | Examples | Source |
|---|---|---|
| Contact identifiers | Email address, phone number, first and last name | Your store, CRM or checkout platform |
| Online identifiers | _stl_vid (visitor id), _stl_cid (click id), _fbp, _fbc, platform click ids | Sentinel tracking pixel and ad-platform redirects |
| Device and connection | IP address, user agent, referrer, page URL, coarse location derived from IP | Sentinel tracking pixel |
| Commercial records | Order id, line items, order value, currency, discount codes, refund and subscription status | Shopify, WooCommerce, Stripe and other connected revenue platforms |
| Behavioural records | Page views, ad impressions, click and touchpoint sequences forming an attribution journey | Sentinel tracking pixel and ad platforms |
| Account records | Your users’ names, email addresses, hashed passwords, role assignments and access logs | You, when creating Sentinel logins |
Sentinel is not designed to receive special-category data under GDPR Article 9, payment card numbers, government identifiers, or data relating to children. Do not send it. If you do, you do so as controller and outside the intended scope of this Addendum.
Where Sentinel transmits identifiers to an advertising platform as a server-side conversion, contact identifiers are hashed (SHA-256) before transmission in line with that platform’s requirements.
5. Our obligations as processor
In accordance with GDPR Article 28(3), we will:
- Documented instructions. Process personal data only on your documented instructions, which comprise this Addendum, the Terms of Service, your configuration of the service, and any further written instruction you give. If we believe an instruction breaches data protection law, we will tell you.
- Confidentiality. Ensure that anyone authorised to process personal data is bound by a duty of confidentiality.
- Security. Implement and maintain the technical and organisational measures in Section 7.
- Subprocessors. Engage subprocessors only on the terms in Section 6.
- Data subject rights. Assist you, by appropriate technical and organisational measures and insofar as possible, in responding to requests to exercise rights under Chapter III of the GDPR (Section 8).
- Breach and assessment support. Assist you in meeting your obligations under Articles 32 to 36, including security, breach notification and data protection impact assessments, taking into account the nature of processing and the information available to us.
- Deletion or return. At the end of the service, delete or return personal data as set out in Section 9.
- Demonstrating compliance. Make available the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, as set out in Section 11.
6. Subprocessors
You give general written authorisation for us to engage the subprocessors below. We impose data protection obligations on each of them no less protective than those in this Addendum, and we remain fully liable to you for their performance.
| Subprocessor | Purpose | Personal data reached |
|---|---|---|
| Railway | Application hosting, PostgreSQL database, backups | All categories in Section 4 |
| Anthropic | AI recommendations, alert analysis, agent chat | Metrics and campaign context; contact identifiers only where present in text you supply |
| OpenAI | Creative scoring and copy generation; speech recognition and synthesis for the optional voice assistant | Creative assets and campaign context; where voice is enabled, spoken audio and its transcript |
| Google (Gemini) | Video and creative analysis | Creative media and transcripts |
| Sentry | Error and exception monitoring | Incidental identifiers appearing in error context |
| MaxMind | Coarse geolocation from IP address | IP address |
| Slack | Alert, report and agent-answer delivery | Metrics, creative assets, and any identifiers in an alert body |
| Telegram | Optional mobile alert delivery | As above, where you enable it |
| Email (SMTP) provider | Password reset and notification email | Your users’ email addresses |
Connected platforms are not subprocessors. Where you connect Meta, Google Ads, TikTok, AppLovin, Amazon, Shopify, WooCommerce, Klaviyo, Stripe, Recharge, Triple Whale, Guesty or a similar platform, Sentinel exchanges data with that platform on your instruction and under your own relationship with it. Each acts as an independent controller or as your own processor, on its own terms.
Notice of change. We will give at least 30 days’ notice before adding or replacing a subprocessor, by updating this page and notifying the account contact. If you reasonably object on data protection grounds within that period, we will work with you to find an alternative; if none is available, you may terminate the affected part of the service without penalty.
7. Security measures
Our technical and organisational measures under GDPR Article 32:
- Encryption in transit. TLS for all connections to the application, its API and its database.
- Encryption of credentials at rest. Platform access tokens, webhook secrets and other connection credentials are encrypted with Fernet (AES-128-CBC with HMAC-SHA256) before storage. Production startup rejects a missing or invalid encryption key.
- Authentication. Passwords are hashed with bcrypt. Sessions use signed JWTs with server-side revocation.
- Authorisation. Every data request is scoped to a brand the requesting user has been granted access to. API keys carry explicit read and write scopes, enforced at the request level, and a key without a write scope cannot use a mutating method anywhere in the API.
- Tenant isolation. Records are brand-scoped and re-checked against the requesting user’s access on every read; an identifier alone never grants access.
- Resilience and recovery. The production database runs on Railway-managed PostgreSQL with point-in-time recovery (continuous write-ahead log archiving) and scheduled volume snapshots.
- Monitoring. Application errors and background-task failures are reported to our error-tracking subprocessor. Access and administrative actions are logged.
- Staff access. Limited to personnel who need it to operate and support the service, over authenticated channels.
- Environment separation. Production data is separated from development and test environments.
Our full controls are described in the Data Loss Prevention Policy and the Security Incident Response Policy, which form part of this Addendum.
8. Data subject rights
Where a data subject contacts us directly about data we process on your behalf, we will not respond substantively; we will refer them to you and tell you promptly.
We will assist you in responding to access, rectification, erasure,
restriction, portability and objection requests, using the search, export
and deletion functions in the service. Where you use Shopify, requests
received through Shopify’s
customers/data_request, customers/redact and
shop/redact webhooks are processed in line with
Shopify’s requirements.
9. Retention, deletion and return
Records are pruned automatically on the schedule below. These are the windows the service actually enforces, not maximums.
| Record | Retention |
|---|---|
| KPI snapshots | 14 days |
| Ad impression records | 14 days |
| Check logs, tracked visits, passback events, creative fatigue snapshots | 30 days |
| Conversion events, attribution touchpoints, Amazon attribution events | 60 days |
| Tracked orders, daily briefs, budget rule logs, agent messages | 90 days |
| Paid-acquisition click records and visitor identity mappings | 10 years — required to credit a later order to the paid click that earned it |
| Customer and CRM contact records | Retained while your account is active, as they are the basis of ongoing attribution |
| Platform credentials | Deleted when you disconnect the integration |
On termination. You may export your data before closing your account. On account deletion we permanently delete personal data processed on your behalf — orders, attribution records, credentials and customer identifiers — within 30 days, except where we are required by law to retain it. Backups age out on their own retention cycle.
Hashed identifiers already transmitted to an advertising platform are subject to that platform’s retention, not ours.
10. International transfers
We process data in the United States. Where you transfer personal data of data subjects in the European Economic Area, the United Kingdom or Switzerland, the SCCs are incorporated into this Addendum by reference: Module Two (controller to processor) where you are a controller, and Module Three (processor to processor) where you are yourself a processor. The docking clause applies. For the UK, the UK International Data Transfer Addendum applies to the SCCs.
For the purposes of Clause 17, the SCCs are governed by the law of Ireland. Annexes I, II and III of the SCCs are populated by Sections 3, 4, 6 and 7 of this Addendum.
On request we will sign the SCCs as a standalone document, or your own data processing agreement, provided its terms are substantially consistent with this Addendum.
11. Audit and information rights
We will make available the information reasonably necessary to demonstrate compliance with Article 28, including our security policies and answers to a reasonable security questionnaire.
You may audit our compliance no more than once in any twelve-month period, on at least 30 days’ written notice, during business hours, subject to confidentiality, and without access to other customers’ data or to systems where access would breach a duty owed to a third party. You bear your own costs. We may satisfy an audit request by providing a current third-party report or completed questionnaire where one addresses the scope of your request. An audit may be conducted more frequently following a personal data breach affecting your data, or where a supervisory authority requires it.
12. Personal data breach
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting personal data we process on your behalf. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point — to the extent that information is available to us, supplemented as the investigation proceeds.
We will not make a public statement identifying you as affected without your prior agreement, unless legally compelled. Our handling procedure is the Security Incident Response Policy.
13. United States state privacy law
For personal information subject to the CCPA, we act as a service provider. We will not:
- sell or share that personal information;
- retain, use or disclose it for any purpose other than performing the service, or as otherwise permitted by the CCPA;
- retain, use or disclose it outside the direct business relationship between us;
- combine it with personal information received from another source, except as the CCPA permits a service provider to do.
We certify that we understand and will comply with these restrictions. Equivalent commitments apply where the Virginia, Colorado, Connecticut, Utah, Texas or a comparable state statute governs the processing.
14. Liability
Each party’s liability under this Addendum is subject to the limitations and exclusions of liability in the Terms of Service or the services agreement between us. Nothing in this Addendum limits either party’s liability to a data subject under Article 82 of the GDPR, or any liability that cannot lawfully be limited.
15. Changes to this Addendum
We may update this Addendum to reflect a change in the service, in our subprocessors, or in data protection law. We will give at least 30 days’ notice of a material change by updating this page and notifying the account contact. Changes required by law may take effect sooner where the law requires it.
16. Contact
Data protection enquiries, data subject requests, security questionnaires and requests to sign the SCCs: collabs@roirockstars.com.
Related documents: Privacy Policy · Terms of Service · Data Loss Prevention Policy · Security Incident Response Policy