Security and data
Your recordings never leave your building.
Retention is your decision, access is yours and deletion is yours, because the files sit on the recording unit in your building rather than on our servers. Cyber security is implemented to the ISO 27001 standard and externally audited according to ISAE 3000, and that report is available under NDA.
Where it runs
On premise is the architecture, not an option.
There is no default cloud to opt out of, and no version of the product in which your recordings are sent somewhere else to be looked at. Five answers a data protection review normally asks for.
- The recording runs on premise. The unit holds an eight core processor, 8 GB of memory and a 2 TB SSD, and it processes the run as it happens rather than shipping images somewhere to be looked at. The full hardware specification lists it.
- The processing runs on premise, on the unit itself. Recognition and reconciliation against your stock file happen on the recording unit, in Docker on its own Linux host and with Nvidia CUDA acceleration where a suitable GPU is fitted. There is no separate server to stand up, because nothing is handed off to another machine.
- The storage is on the unit. Raw recordings, the derived discrepancy data and the exports all sit on the unit's own 2 TB SSD, inside your building. Nothing has to leave the site for the product to work.
- The only exception is optional anonymous statistics. Some optional modules send anonymous statistical data to Sentispec cloud storage, and if you do not use those modules nothing is transmitted at all. Sentispec is a Danish company and that storage sits in the EU.
- We never share your data with third parties. Recordings, discrepancy data and stock files are used to run your count and nothing else.
Because the data sits on the unit inside your own site, most of the questions on a data protection questionnaire become questions about your own estate rather than about ours.
Personal data
Designed not to capture it, with active measures to keep it out.
The camera exists to read a pallet label and register a racking position. Sentispec Inventory is designed not to capture personal data, and takes active measures to prevent personal data entering its systems.
What the unit captures
- Pallet labels and barcodes. Read and matched against your stock record.
- Racking positions. Occupied and empty, at the level driven.
- The image behind each discrepancy. Kept as the evidence a discrepancy line rests on, so a challenged line is checked by looking rather than by recounting.
Monochrome sensor, aimed at racking, focused at 1.5 m with a 1.5 m by 1.5 m field of view in the default configuration. It is a label reader, and it is built like one.
If a person does appear in an image
A driven aisle is a working aisle. In the unlikely event that anyone appears in a recording, two things follow from the on premise architecture:
- You can detect it and delete it. The means to find and remove that footage sits with you, on your own system, without raising a ticket with us.
- Sentispec has no access to it. The data is on the unit in your building. We cannot open it, and we do not run any processing that sets out to identify a person from an image.
Retention and access
Both are yours to set, because the data is yours to hold.
- Retention is entirely your decision. For raw recordings and for the discrepancy data derived from them. There is no vendor default to negotiate down, because the files are on the unit at your own site and the retention policy that applies to them is the one you already run. A 20 minute recording is about 60 GB at 3 GB per minute, so the retention period carries a storage cost, and your storage team can set it without us.
- Access is yours. Your own account holders open recordings and discrepancy lists. Sentispec can access the data only temporarily, for support or maintenance, and with your involvement, because there is no standing route into your estate from ours.
- Deletion is yours. If you decide a recording should not exist, you delete it, and you do not need us to agree.
| Question | Answer |
|---|---|
| Where is data stored | On premise, on the recording unit |
| Where does processing happen | On premise, on the same unit |
| What is transmitted to Sentispec | Optional anonymous statistical data |
| Shared with third parties | Never |
| Personal data | Designed not to be captured, with active measures to prevent it |
| Retention period | Entirely your decision, for recordings and derived data |
| Who can access a recording | You. Sentispec only temporarily, for support or maintenance |
| Incidental footage of a person | Detectable and deletable by you. Sentispec has no access to it |
| Transmission and encryption | SSL, over HTTPS |
| Security standard | Implemented to ISO 27001 |
| External assurance | Audited to ISAE 3000, report available under NDA |
None of this changes what the product does day to day. Reconciliation against your stock record, the four discrepancy types and the accuracy dashboard all work the same way. The architecture changes only where the data sits and who holds it. Two related answers a review usually needs: the price is published in full on pricing, and integration effort to start counting is zero, set out per system on integrations.
Assurance
Independently audited, not self assessed.
Our cyber security is implemented to the ISO 27001 standard, and we have been externally audited according to ISAE 3000. ISAE 3000 is an assurance engagement performed by an external auditor, so the opinion on those controls is a third party's, not ours. The report is available under NDA.
ISO 27001
Our information security management is built to the ISO 27001 standard: risk assessment, access control, supplier management, incident handling and the rest of the control set, applied to the systems that hold your recordings and your stock data.
ISAE 3000 audit
An independent auditor has examined those controls and reported on them. If your procurement process requires evidence, this is the document to ask for, and we will provide it under NDA.
The limits of the claim. Sentispec does not hold SOC 2, and does not claim GxP or 21 CFR Part 11 compliance for the product. Cyber security is implemented to the ISO 27001 standard, which is a different statement from holding a certificate. Where a specific control matters to your risk assessment, ask for the ISAE 3000 report.
Paperwork
What we will sign, and what we will fill in.
Sentispec is a Danish company and operates under GDPR as a matter of course. Because the recordings, the processing and the derived data all sit on the unit at your own site, you remain in control of that data as the controller, and the practical consequences are the ones set out above: your retention policy, your access, your deletion.
Sentispec will provide a data processing agreement and will answer a data protection questionnaire on request. Ask for both early rather than late. A written agreement is normally settled during the five day deployment, alongside calibration and driver training, rather than left until after go live. What the website itself collects, which is a form submission and nothing more, is set out on privacy.
Questions we get asked
Before data protection sign off.
Where is our data stored?
On your own premises. All data and all processing sit on the recording unit itself: it records the run, recognises the labels, reconciles against your stock file and holds the recordings and the derived discrepancy data on board. The only thing that may leave your site is optional anonymous statistical data.
Is our data ever shared with anyone outside Sentispec?
No. We never share customer data with third parties. Recordings, stock files and discrepancy data are used to run your count and reported back to you, and nowhere else.
How long do you keep our recordings?
We do not keep them, so the answer is entirely yours. Retention for raw recordings and for the discrepancy data derived from them is your decision, because both sit on the unit at your own site, under your own retention policy. At 3 GB per minute of recording it is worth making that decision deliberately rather than by default.
Who can open a recording?
You can. Sentispec can access your data only temporarily, for support or maintenance, because there is no standing route from our systems into yours. Your own account holders control access the rest of the time.
Does the recording identify our staff?
No. Sentispec Inventory is designed not to capture personal data and takes active measures to prevent personal data entering its systems, and no processing on our side sets out to identify anyone. In the unlikely event that a person does appear in an image, you have the means to detect and delete that footage yourself, and Sentispec has no access to it.
Will you sign a data processing agreement?
Yes, and we will answer a data protection questionnaire on request. Both are normally settled during the five day deployment rather than after go live.
Do you hold ISO 27001, SOC 2 or a similar certification?
Our cyber security is implemented to the ISO 27001 standard and we have been externally audited according to ISAE 3000, and we will share that audit report under NDA. We do not hold SOC 2. If your procurement process requires a specific certificate rather than an assurance report, ask us directly and we will answer in writing.
Next step
Put your data protection questions to us directly.
A meeting with your data protection or IT security lead, covering the on premise architecture, retention, access and the data processing agreement against your own estate.


