Data processing agreement

Last updated on 21 August 2026

If you use Sentro to manage sites for your own clients, we process personal data on your instructions. This agreement sets out exactly what we do and do not do with it. It applies as soon as you create an account or use the service; no separate signature is required. If you would rather have a signed copy, email hello@rootswp.com.

1. Parties and roles

You, the customer, are the controller: you decide which sites you connect and for what purpose. Code Roots (Chamber of Commerce 96111208, VAT NL867473861B01), trading as Sentro, is the processor and processes data solely on your instructions.

This agreement forms part of the terms of service. Where the two differ on the processing of personal data, this agreement prevails.

2. Subject matter and duration

The processing serves one purpose: delivering the management environment you use to monitor, update, back up, scan and report on WordPress sites.

The agreement runs for as long as you hold an account and ends when that account is terminated.

3. What data we process

About your team members: name, email address, language preference, role within the organisation and the sign-in details you create with us.

About your clients: the contact details you enter in the client record yourself, such as company name, contact person, email address and phone number.

About connected sites: the URL, version numbers of core, plugins and themes, availability and response-time measurements, the outcome of security and malware checks, backup information, and screenshots of the pages you designate for visual checks.

We do not process visitor data from the connected sites and we do not retrieve database content.

4. Instructions

We process the data only as described in this agreement or as you instruct us, unless the law requires otherwise. In that case we tell you beforehand, unless the law forbids it.

We do not use your data for our own purposes, do not sell it, and do not use it to build profiles or train models.

5. Security

Traffic between the management environment and the connected sites runs over https and is signed with HMAC-SHA256, including a nonce that prevents replay. The hub calls the site; the site never calls back.

Connection keys are stored encrypted with AES-256-GCM and are not visible to ordinary team members. Access to production systems is limited to the people who need it for their work, with two-factor authentication.

Access inside your organisation is yours to manage through the owner, admin and member roles. Who may perform which action is enforced on the server, not merely hidden in the interface.

6. Sub-processors

You give general authorisation for engaging sub-processors for hosting, database and storage, email delivery, payment processing and screenshot capture.

With every sub-processor we conclude an agreement imposing at least the same obligations as this one. An up to date list, including name and country of establishment, is available on request via hello@rootswp.com.

If we replace a sub-processor, we tell you in advance. If you have a substantiated objection, you may terminate the subscription free of charge before the change takes effect.

7. Where the data lives

Data is stored and processed within the European Economic Area.

Where a transfer outside the EEA is unavoidable, it takes place only under an adequacy decision or the European Commission's standard contractual clauses, with supplementary measures where needed.

8. Confidentiality

Everyone on our side with access to your data is bound by a duty of confidentiality that survives the end of the engagement.

9. Data breaches

If we establish a personal data breach affecting your data, we notify you without undue delay and no later than 48 hours after discovery, describing the nature of the breach, the data involved, the likely consequences and the measures taken.

Notifying the supervisory authority and the data subjects is your responsibility as controller. We supply the information you need to do so.

10. Data subject rights and assistance

If you receive a request for access, rectification, erasure or portability, we help you handle it within the statutory deadline. If such a request reaches us directly, we refer the data subject to you.

We also assist with a data protection impact assessment and with consulting the supervisory authority, insofar as this can reasonably be expected of us.

11. Audits

On request we provide the information needed to demonstrate compliance with this agreement. Once a year you may have an audit carried out by an independent expert bound by confidentiality, with at least thirty days' notice, at your own expense and without disrupting the service.

12. Retention and deletion

Availability measurements and log entries are kept for thirteen months. Account data and connected site data are deleted within thirty days of the account ending; during that window you can request an export.

Invoices and the related administration are kept for seven years because tax law requires it.

13. Liability

The liability provisions of the terms of service apply to this agreement. Dutch law applies, and disputes are submitted to the competent court in the district where Code Roots is established.

14. Contact

Questions about this agreement, a request for a signed copy, or a request for the sub-processor list: email hello@rootswp.com.