Skip to main content

Secure Customer Service

SENET.cloud 

Trust Center

At SENET.cloud, we understand you’re entrusting us with your data, your operations and your business. That’s why we’ve built our product and processes to meet high standards of security, user privacy, reliability and regulatory compliance. This page shows how we protect your systems, how we handle our terms and policies, and what you can expect from us in every interaction.

zombie i1 e sport club in college big space light walls photore 7e18b35a 0b4f 4f5d b877 23d61afbbdc3%202 1

SENET is built on internationally recognized security and data protection practices to help keep customer data safe across our cloud platform. We process personal data transparently and apply strict controls to protect information from unauthorized access, disclosure, or misuse. Access to sensitive systems and data is limited to authorized personnel based on their role and responsibilities. We also use industry-standard encryption protocols to protect data in transit and at rest, helping gaming venues operate with greater confidence and security.

trust center award bold
trust center award Business Excellence Award Logo
trust center award member esports
trust center award venue management software 1
trust center award top rated
trust center award best performer


Privacy policy


VERSION 1-01/05/2025 DATED MAY 1, 2025

Definitions

The processing of personal data is carried out by the following legal entities depending on the region and applicable legislation:


ENESTECH – legal entities ENESTECH SOFTWARE (CYPRUS) LTD and ENESTECH SOFTWARE CORPORATION:


ENESTECH SOFTWARE (CYPRUS) LTD – a legal entity registered under the laws of Cyprus, located at: 28 Terpsichoris Street, 3086, Limassol, Cyprus.

Jurisdiction: processing of data in Europe and other countries governed by the GDPR.


ENESTECH SOFTWARE CORPORATION is a legal entity duly incorporated and existing under the laws of the State of Delaware, USA, with its registered address at 108 West 13th Street, Wilmington, DE 19801, and office located at 235 W Florence Ave, Inglewood, CA 90301, registration number EIN 83–125-6337.


Jurisdiction: processing of data from clients in the USA and other countries governed by U.S. law.


SENET Software – software for managing personal computers and related devices in internet cafés, educational institutions, and other organizations.


SENET 1.0 – the original version of the software developed and owned by ENESTECH SOFTWARE CORPORATION. Used exclusively in the United States.


SENET 2.0 – an independent version developed based on SENET 1.0 with modifications by ENESTECH SOFTWARE (CYPRUS) LTD. Used in Europe and other countries outside the USA. In Turkey, presented under the brand name Enes-T.


Unless otherwise specified, SENET Software refers to both versions of the software.


Client (You) – a legal entity or individual managing a computer club, or an authorized representative of a computer club holding a valid license from ENESTECH to use SENET and SENET BOOT software.


End User – a natural person renting a personal computer or other devices from the Client under the SENET software.


Personal Data – any information relating to an identified or identifiable natural person that can be used to identify them either directly or in combination with other data.


Personal Data Processing – any operation or set of operations performed on personal data using automated or non-automated means (e.g., collection, recording, storage, alteration, transmission, deletion, etc.).


Data Controller – an entity (legal or natural person) that determines the purposes and means of processing personal data. In certain cases, ENESTECH may act as the Data Controller.


Data Processor – an entity that processes personal data on behalf of and under instructions from the Data Controller. In some cases, ENESTECH may act as the Data Processor.

Data Subject – a natural person whose personal data is processed by the Data Controller. In the context of this Privacy Policy, Data Subjects include:


End Users – individuals renting computers or other devices from the Client and interacting with ENESTECH services.


Individuals representing the Client (e.g., owners, administrators, and employees of legal entities who sign contracts, use SENET Software, or contact ENESTECH in the context of business relations).


Consent – a freely given, specific, informed, and unambiguous indication of the Data Subject’s agreement to the processing of their personal data for specified purposes, provided in written or electronic form.


Website – the website owned and administered by ENESTECH, available at: https://senet.cloud/

1. General provisions

ENESTECH is committed to protecting your personal data. Before you provide us with your Consent to process your Personal Data or submit your data to us, we ask you to carefully read this Privacy Policy. We want to ensure that you fully understand when and what data we collect, how we process it, and what rights you have.


1.1. DATA CONTROLLER VS. DATA PROCESSOR

ENESTECH acts as a Data Controller when it independently determines the purposes and means of personal data processing, including user behavior analysis, activity monitoring, marketing, and platform security.

In all other cases, ENESTECH acts as a Data Processor on behalf of the Clients.


1.2. PROCESSING CLIENT DATA

When ENESTECH is the Data Controller, it processes data in the following cases:

Client registration and account management – when the Client creates an account, we process their personal data (name, email, phone number, company details), determining the purposes and means of processing.

Platform maintenance and support – when we log SENET software usage to detect failures, ensure security, and enhance the user experience.

Financial operations and billing – when we process payment data related to subscriptions, invoicing, and accounting, including:

Account top-ups by the Client;

Purchase of subscriptions, time packages, or other digital services;

Payment for goods and services offered through SENET Software;

Transaction history and financial flow tracking;

Generation of billing and payment reports;

Marketing, communication, and advertising – if the Client provides consent, we may use their contact data to send marketing materials, updates, and offers. Also, depending on the selected plan, SENET Software may display promotional and informational materials in the interface.

Product analytics and improvement – we collect aggregated interaction data to enhance functionality.

When ENESTECH is the Data Processor, we process:

Data submitted by the Client about their employees or partners – if the Client stores employee data in the SENET system, the Client remains the Data Controller, and ENESTECH processes the data only to fulfill the contract.

Data uploaded by the Client into SENET Software – if the Client uses the platform for internal recordkeeping (e.g., user management), ENESTECH does not determine the purpose of processing and acts as a Processor only.

1.3. PROCESSING END USER DATA

ENESTECH acts as a Data Controller when:

IP addresses and geolocation – we collect anonymized IP addresses to monitor system security or prevent fraud.

Activity logging – we log data about sessions, crashes, and platform interactions to ensure stability.

Marketing consent – if an End User subscribes to ENESTECH newsletters directly.

Advertising technologies – SENET Software may display advertisements and collect interaction metrics (e.g., views, view time, anonymized device data). This data is used to improve ad relevance and personalization.


ENESTECH acts as a Data Processor when:

User registration at the club – when End User data (e.g., name, contact info) is entered into SENET Software by the Client or the End User.

Gaming activity data – if the Client uses SENET to record gaming sessions, the Client remains the Data Controller.

In-club payments – if the club processes payments using SENET, ENESTECH only provides the processing tool and does not manage this data.

2. Legal bases for data processing

ENESTECH processes your personal data only on legal grounds provided by international and national data protection laws. Processing may occur for security purposes, fulfilling contractual obligations, providing services, or improving the software’s performance.


Depending on the context, data may be processed to comply with contracts, internal policies, or to ensure the reliability and protection of user data.


2.1. Processing Based on Consent

We process your personal data if you provide us with clear and informed consent. This includes:

Subscribing to marketing emails;

Processing data for personalized advertising;

Collecting analytics to improve user experience;

Participation in surveys and research.

SENET Software may use advertising technologies to load and display ads while the software is running. Data collected for ad personalization includes anonymized IPs, generalized geolocation, device data, and ad interaction metrics.


You can withdraw your consent at any time by sending a request to [email protected]. However, this does not affect the legality of the processing performed prior to the withdrawal.


2.2. Processing Necessary for Contract Performance

ENESTECH processes personal data when necessary to fulfill contractual obligations to the Client, including:

Account registration and granting access to SENET Software;

Providing technical support and maintenance;

Handling payments and issuing invoices;

Managing subscriptions and licenses;

Fulfilling other obligations under the License Agreement.

Without processing this data, it is not possible to deliver our services.


2.3. Processing Based on ENESTECH’s Legitimate Interests

ENESTECH processes personal data where necessary to pursue its legitimate interests, provided such processing does not override the rights and freedoms of Data Subjects. This includes:

Compliance with Cyprus financial and accounting laws – including storage of transaction data, invoices, and paid taxes;

Platform analysis and product improvement – monitoring SENET performance, identifying bugs, and enhancing features;

Fraud prevention and security – including monitoring suspicious activity, protection from cyberattacks, and account access control;

Statistics and business analytics – analyzing site visits, financial metrics, and optimizing internal operations;

ENESTECH promotion – via email campaigns, social media, affiliate networks, and advertising platforms.

You have the right to object to data processing based on ENESTECH’s legitimate interests by emailing [email protected].


2.4. Processing Required for Legal Compliance

We process personal data where necessary to comply with legal obligations, including:

Tax and accounting compliance;

Responding to requests from authorities or law enforcement;

Fulfilling obligations under data protection laws, including providing data upon a Data Subject’s request.

2.5. Processing Vital Interests 

In exceptional cases, ENESTECH may process personal data to protect the vital interests of the Client or third parties. This may include: 

Preventing security threats; 

Protection from fraud or misuse of the platform; 

Identifying and preventing hacking or unauthorized access attempts. 

2.6. Processing in the Public Interest 

In rare cases, ENESTECH may process personal data to carry out tasks in the public interest if legally required to do so. 

3. Categories of personal data collected by Enestech

ENESTECH processes the personal data of Clients (owners of computer clubs) and End Users (gamers, club visitors) depending on their role and interaction with the SENET Software Platform. In different processing scenarios, we may act as either a Data Controller or a Data Processor.


3.1. Data Collected from Clients

ENESTECH may collect the following categories of data from Clients using the SENET Software:


3.1.1. Personal data if the Client is an individual:

Full name;

Contact details (phone number, email address);

Registration details (licensing information, tax identification information).


3.1.2. Personal data if the Client is a legal entity:

Full company name;

Legal address;

Physical address;

Company registration number;

Full name of the authorized representative (e.g., director or club administrator);

Information about the SENET Software subscription.


3.1.3. Information about the computer club:

Club name;

Physical address of the club;

Number of workstations and servers;

Licenses connected to the SENET Software.

3.1.4. Contact information:

Email address;

Phone number;

Login and password (encrypted);

Server name (if server-side software is used).


3.1.5. Financial information:

Information about payment methods (e.g., linked bank cards, PayPal, payment providers);

Invoicing and transaction data;

Payment history related to the subscription.


3.1.6. Data related to interactions with ENESTECH:

Correspondence with our technical support team;

Requests to change pricing plans, licenses, or SENET Software configurations;

Information about errors and system failures;

Data related to interaction with advertising materials in the SENET Software (e.g., ad views, link clicks, engagement with personalized ads).


3.2. Data Collected from End Users

ENESTECH collects certain data from End Users of computer clubs strictly within the scope of the SENET platform's operation and based on instructions from the Client (club owner). In this case, ENESTECH typically acts as a Data Processor, while the Client is the Data Controller.


3.2.1. Personal data of the End User:

Name (if registration at the club is required);

Contact information (email address, phone number – if provided);

Gender (if provided);

Age (if entered during registration at the club);

IP address and geolocation data (automatically collected by the system);

Data on PC rental (e.g., session time, applications used);

Login and logout history within the SENET Software.


3.2.2. User activity data in SENET Software:

Gaming activity (launched applications, usage time);

History of interaction with advertising materials (number of ad impressions, clicks, ad viewing time, interest in advertising offers, if applicable);

Ad viewing history within the SENET Software (if applicable);

Response to advertising offers (if enabled);

Unique device identifier (used for account protection);
Device settings connected to the SENET Software.


3.2.3. Automatically collected data:

To support system operation and ensure security, ENESTECH may collect:

Server log files (user activity logs);

Error and system failure data related to the SENET Software;

Cookies, web beacons, pixel tags (for fraud prevention and analytics);

Information about connected peripherals (e.g., game controllers, headsets);

Technical data related to advertising technologies used in the SENET Software, including ad frequency and user preferences.


3.2.4. Data for advertising purposes:

The SENET Software may display advertising and informational materials depending on the selected pricing plan and the user’s consent. We do not share personally identifiable information of end users (e.g., name, email, phone) with advertisers, but we use aggregated and anonymized data to deliver more relevant ads.


We may collect and analyze the following advertising-related data:

Device technical specifications (operating system, browser version, screen resolution, connection characteristics);

Anonymized IP addresses (used to determine general geolocation without precise user identification);

Interaction with ads (number of views, viewing time, clicks, conversions, interest in advertising offers);

Unique session identifier (not containing personal data and used for temporary analysis);

Cookies and pixel tags (used for analytics, fraud prevention, and improving ad relevance).

How we protect End User data:

Data is transmitted to advertising partners only in aggregated and anonymized form;

No information that could directly identify the user is shared;

ENESTECH employs measures to prevent unauthorized data usage (e.g., encryption and secure transmission protocols).


These data help us analyze ad effectiveness, deliver relevant ads, and enhance ad technologies within the SENET Software. If the End User or Client does not wish their data to be used for marketing or advertising purposes, they may disable personalized ads in the settings or submit a request to ENESTECH Support.

3.3. How ENESTECH uses the collected data:

The collected personal data may be used to:

Ensure the functioning of the SENET Software;

Fulfill contractual obligations with Clients;

Improve the platform and fix bugs;

Conduct marketing campaigns (with consent);

Prevent fraud and enhance system security;

Handle client requests and provide technical support.

4. Cookies and other similar technologies

4.1. Use of Cookies and Tracking Technologies

When using our services, including our website, we utilize cookies, web beacons, pixel tags, and other technologies to analyze traffic, improve user experience, and ensure system security. These technologies allow us to collect automated information about your actions, device settings, and preferences while using the platform.


4.2. What Data We May Collect

During operation of the SENET software, the following categories of data may be automatically collected:

Device identifiers – unique identifiers, including cookies and similar technologies;

Device information – operating system, browser type, device model, interface language;

IP address and location data – depending on your device settings (geolocation consent is requested separately);

System login data – information about the time, date, and frequency of visits, as well as actions within the software;

Technical log files – diagnostic information about system performance, including errors and failures;

Beacons and tags – small software elements recording visits and interactions with website content;

Cookies and other tracking technologies – used to personalize user interactions and enhance platform security.


4.3. Types of Cookies Used by ENESTECH

Our services use several categories of cookies:

Strictly necessary cookies – technical files essential for website operation (e.g., authentication in the user account);

Functional cookies – store user preferences and facilitate easier use of the software;

Analytical cookies – help analyze user behavior and improve the service;

Advertising cookies – used to display personalized advertising (only with user consent);

Security and fraud prevention – track suspicious activities and detect threats automatically.


4.4. How to Manage Cookies

You can manage cookies yourself through your browser settings. You may disable certain types of cookies, but this may affect the functionality of some SENET software features. More detailed information on how to modify your cookie settings is provided in our Cookie Policy.

5. Data transfer and security

5.1. General Principles of Data Transfer

ENESTECH works with contractors, service providers, and partners to ensure the efficient operation of SENET software and the provision of services to Clients and End Users.

Personal data may be transferred to third parties only with strict security measures in place, including:

Data Processing Agreement (DPA) – a contract regulating the processor’s obligations in accordance with GDPR;

Standard Contractual Clauses (SCCs) – legal mechanisms approved by the European Commission ensuring lawful cross-border data transfers;

Access limitation – data is transferred only within the purposes established in the Privacy Policy and in accordance with applicable laws (GDPR, CCPA, LGPD, and others).


5.2. Categories of Service Providers

ENESTECH uses the following categories of service providers to support SENET software and fulfill obligations to Clients and End Users:

Cloud computing and data storage – Microsoft Azure, Amazon Web Services, Digital Ocean (server infrastructure, backups);

Payment systems and billing – Chargebee, Stripe (subscriptions, payment processing, account management);

Customer support and CRM systems – Zendesk, Pipedrive (support services, customer communication, interaction analytics);

Analytics and marketing services – tools for monitoring platform performance, error logging, and site traffic analysis.


5.3. Transfer of Data Outside the European Economic Area (EEA)

In certain cases, ENESTECH may transfer personal data to contractors and service providers located outside the EEA, including countries that do not ensure an adequate level of data protection.

To comply with GDPR and other applicable regulations, ENESTECH implements the following safeguards:

Transfers only to countries with adequate protection recognized by the European Commission or countries with legal safeguards (SCCs, Binding Corporate Rules);

Use of certified cloud services that meet international security standards (ISO 27001, SOC 2, etc.);

Limited access to data for contractors – only the data necessary for task fulfillment is shared;

Legal accountability of data recipients – contractors are contractually obligated to comply with data protection requirements.


5.4. Protection of Transferred Data

To secure personal data during transfers, ENESTECH implements the following technical and organizational measures:

Data encryption – data is transmitted and stored in encrypted form using advanced cryptographic standards (AES-256, TLS 1.3);

Access limitation – only authorized personnel and contractors are granted access based on the need-to-know principle;

Regular audits and contractor evaluations – ENESTECH conducts data protection assessments, including security audits and risk management policy reviews;

Contractual obligations – suppliers’ contracts include strict data confidentiality and access protection requirements.


5.5. Consent to Data Transfer

By providing personal data, the Client or End User consents to its transfer to third parties within the purposes defined in the Privacy Policy.

The Client may withdraw their consent at any time by sending a request to [email protected]. However, this does not affect the lawfulness of processing carried out prior to the withdrawal.


5.6. Transfer of Data Upon Business Change

In the event of ENESTECH’s reorganization (merger, acquisition, asset sale, or ownership structure change), personal data may be transferred to the new business owner.

ENESTECH ensures that:

Data confidentiality will be maintained, and processing will continue in line with the Privacy Policy;

Clients and End Users will be informed in advance of the data transfer and any changes in processing conditions;

Users will have the right to delete their data if they do not agree with the new terms.


5.7. Protection Against Unauthorized Disclosure or Transfer

ENESTECH does not disclose or transfer personal data of Clients or End Users to third parties, except in the following cases:


5.7.1. Authorized Data Transfer

Required for contract performance (e.g., to payment providers for processing payments);

Required for legal compliance;

Explicit consent was given by the Client or End User.


5.7.2. Prohibition of Transfer Without Security Guarantees

Transfer to third parties is prohibited unless:

A signed Data Processing Agreement (DPA) exists when ENESTECH acts as the data processor;

Legal guarantees of confidentiality are in place (SCCs, Binding Corporate Rules).


5.7.3. Actions in Case of Unauthorized Data Disclosure or Breach

Immediate notification of the Client or End User (if required by law);

Measures taken to prevent further dissemination;


Internal investigation and, if necessary, notification of regulatory authorities.

6. Retention and processing periods for personal data

ENESTECH retains personal data only for the period necessary to fulfill the purposes of processing and in compliance with applicable data protection legislation, including the GDPR, CCPA, and local accounting and tax reporting laws.


6.1. General Data Retention Periods

ENESTECH applies the following data retention principles:


6.1.1. Active Accounts – Personal data is retained for as long as the Client's or End User’s account remains active, and for an additional 12 months following the last recorded activity, unless the Client requests deletion earlier.

6.1.2. Account Deletion – If the Client or End User initiates account deletion, ENESTECH retains the personal data for 90 days from the date of deletion to enable potential restoration upon request. After this period, the data is automatically deleted or anonymized.

6.1.3. Financial Information – Information related to transactions, payments, and financial documents is retained for up to 10 years in accordance with accounting and tax obligations (including EU Directive 2006/112/EC).


6.2. Exceptions for Extended Retention

In certain cases, ENESTECH may retain personal data beyond the standard retention period to comply with legal obligations or for other justified reasons, including:


6.2.1. Legal Disputes – If ENESTECH is subject to legal claims from a Client or End User, the relevant data may be retained until the final resolution of the case.

6.2.2. Regulatory Compliance – If law enforcement, regulatory authorities, or a court requires access to information, ENESTECH is obligated to retain the data until the respective procedures are concluded.

6.2.3. Security Purposes – If the data is related to investigations of suspicious activity, fraud prevention, or cybersecurity incidents, it may be retained for up to 180 days or longer, where reasonably necessary for investigation.


6.3. Deletion and Termination of Data Processing

Once the retention period expires, personal data is subject to permanent deletion or anonymization, depending on the nature of the data:


6.3.1. Client account data is deleted automatically or upon request.

6.3.2. Financial and accounting records are deleted after 10 years unless a longer retention is required by law.

6.3.3. Data used for marketing purposes is anonymized if the Client has withdrawn consent for processing.


ENESTECH ceases processing personal data in the following cases:


6.3.4. The established retention period has expired in accordance with Sections 6.1–6.2.

6.3.5. The Client or End User has requested deletion, and continued retention is not required for legitimate interests of ENESTECH.

6.3.6. Legal obligations require ENESTECH to terminate processing (e.g., a request from a data protection authority).


6.4. Data Return and Deletion After Contract Termination


6.4.1. Return of Data to the Client

6.4.1.1. Upon termination of the contract, the Client has the right to request an export of their data stored within the SENET software system.

6.4.1.2. ENESTECH provides the Client with access to download the data in a machine-readable format (CSV, JSON, or other agreed formats).

6.4.1.3. The Client must submit a data return request within 30 days following the termination of the contract.

6.4.1.4. If no request is received within the specified timeframe, the data will be deleted in accordance with Section 6.4.2.


6.4.2. Retention Period Before Deletion

6.4.2.1. After contract termination, Client data is retained for 90 days from the termination date.

6.4.2.2. During this period, the data remains accessible only to the Client and may be restored in case of contract renewal.

6.4.2.3. Upon expiration of the 90-day period, the data is permanently deleted unless otherwise required by law.


6.4.3. Secure Deletion Methods

6.4.3.1. Data is deleted using methods compliant with international information security standards (ISO 27001, NIST 800-88).

6.4.3.2. Deletion procedures include:


6.4.3.2.1. Physical deletion from servers, including backups;


6.4.3.2.2. Overwriting (wiping) with multiple passes to prevent recovery;


6.4.3.2.3. Cryptographic destruction (crypto-shredding) – removing encryption keys to render data irretrievable.


6.4.3.3. Upon completion of the deletion process, the Client may request a data destruction certificate confirming full erasure.


6.5. Requests for Information on Security and Confidentiality Measures


6.5.1. General Access to Security Information

6.5.1.1. ENESTECH adheres to high data protection standards and implements security measures aligned with international frameworks (ISO 27001, SOC 2).

6.5.1.2. Clients may request generalized information about the applied security measures, including:


6.5.1.2.1. Access management policies;


6.5.1.2.2. Data protection procedures during transmission and storage;


6.5.1.2.3. Key principles for preventing unauthorized access.


6.5.2. Restricted Access to Security Procedures

6.5.2.1. To mitigate security and confidentiality risks, ENESTECH’s security framework is an internal corporate asset.

6.5.2.2. Detailed information about protective measures is disclosed only in accordance with legal obligations or upon requests from regulatory authorities or legally binding orders.

7. Your rights as a data subject in relation to the processing of your personal data

7.1. Right to Confirmation

You have the right to obtain confirmation from ENESTECH as to whether or not your personal data is being processed.


7.2. Right of Access

You have the right to access your personal data that is being processed by ENESTECH.


7.3. Right to Rectification

You have the right to request that ENESTECH complete any incomplete personal data or rectify any inaccuracies.


7.4. Right to Erasure (Right to Be Forgotten)

You have the right to request that ENESTECH erase your personal data. In most cases, ENESTECH will comply with such a request unless retention is required by law. To request the deletion of your personal data, you may contact us by email at [email protected]. We will respond to your deletion request within 30 days and inform you of the outcome.


7.5. Right to Restrict Processing

You may request a restriction on the processing of your personal data in certain cases, such as when you dispute the accuracy of your data or when ENESTECH no longer needs the data for processing purposes, but you wish to retain it for legal claims. In such cases, the processing of your personal data will be limited instead of being deleted.


7.6. Right to Data Portability

You have the right to request the direct transfer of your personal data from one controller to another, where technically feasible and provided that such transfer does not adversely affect the rights and freedoms of others.


7.7. Right to Object to the Processing of Your Personal Data by ENESTECH

You have the right to object to the processing of your personal data where such processing is carried out in the public interest or in the exercise of official authority vested in us. You may also object when we process your data based on our legitimate interests or those of a third party, if you believe that your fundamental rights and freedoms outweigh those interests. Upon receiving such an objection, we will cease processing your personal data unless we can demonstrate compelling legitimate grounds for the processing.


7.8. Right to Withdraw Consent at Any Time by Contacting Us

Once ENESTECH receives your request to withdraw consent, we will process it in a timely manner and will no longer process your personal data, unless otherwise required by law.


Please note that where the processing of your personal data is carried out for direct marketing purposes, you have the right to object to such processing at any time without the need to provide justification, and we will cease processing your data for direct marketing purposes.

8. Cross-border data transfers

ENESTECH processes personal data both within and outside of the European Economic Area (EEA). We recognize that different jurisdictions may have varying legal regimes concerning personal data protection. Therefore, we take all necessary steps to ensure a high level of confidentiality and data security regardless of where the data is processed.


8.1. How We Protect Transferred Data

When transferring personal data outside of the EEA, we ensure that the data remains protected at a level equivalent to that required under the GDPR. To achieve this, we implement:


8.1.1. Standard Contractual Clauses (SCCs) approved by the European Commission;

8.1.2. Legal agreements with data recipients that ensure the confidentiality of the data;

8.1.3. Additional safeguards, including data encryption and access controls;

8.1.4. An assessment of the level of data protection in the destination country prior to the transfer.


8.2. When Is Data Transferred Abroad?

ENESTECH may transfer personal data to other jurisdictions under the following circumstances:


8.2.1. Where necessary for the operation of our infrastructure, including cloud services (e.g., Microsoft Azure, Amazon Web Services, DigitalOcean);

8.2.2. When engaging contractors and service providers to process data on our behalf (e.g., payment system providers);

8.2.3. When required to fulfill legal obligations, including requests from regulatory authorities.


8.3. Your Rights Regarding Cross-Border Transfers

If your personal data is transferred to jurisdictions outside the EU, you have the right to:


8.3.1. Request a copy of the data protection mechanisms in place for your data;

8.3.2. Object to the transfer of your data to countries that do not provide adequate protection;

8.3.3. Know which countries your data may be transferred to and for what purposes.

9. Response time and handling of requests

ENESTECH undertakes to provide information on the measures taken in response to your request concerning the exercise of your rights specified in this Privacy Policy within 30 days from the date of receipt of such request.

If the request is complex or ENESTECH receives a high volume of requests, this period may be extended by an additional two months. In such a case, we will notify you within the first month of the delay and the reasons for the extension.

10. Security

10.1. General Security Measures

ENESTECH implements technical, organizational, and administrative measures aimed at ensuring the security of personal data and preventing:


Unauthorized or unlawful access to data;

Accidental loss, destruction, or alteration of data;

Personal data breaches.

We use encryption, access controls, internal security policies, and cooperate only with trusted contractors who have signed data processing agreements.

10.2. Actions in Case of a Data Breach

10.2.1. Incident Identification

A personal data breach is defined as unauthorized access to, disclosure, alteration, or destruction of personal data of Clients or End Users.

ENESTECH continuously monitors its systems to detect anomalies and suspicious activity.

In case of a suspected security breach, the data is analyzed by ENESTECH’s internal control department.

10.2.2. Notification and Disclosure

If a breach is confirmed, ENESTECH will notify:

Clients and End Users whose data has been affected (if required by applicable law);

Contractual partners, if the incident involves contractual obligations.

The notification will include:

A description of the incident;

Potential risks and possible consequences;

Measures taken and planned to mitigate the impact.

10.2.3. Damage Mitigation

Implementation of technical and organizational measures to prevent further spread of the incident;

Temporary blocking of affected systems or accounts (if necessary);

Updating security policies and introducing additional safeguards (if required).

10.3. Investigation and Reporting

10.3.1. Incident Investigation

An internal investigation is conducted to analyze the causes and vulnerabilities in the system.

10.3.2. Breach Report

The report includes:

Date and time of the incident;

Type of breach;

Causes of the incident;

Impact on Clients’ and End Users’ data;

Measures taken to address and prevent recurrence.

10.3.3. Reporting to Supervisory Authorities

If required, the report is submitted to the relevant data protection supervisory authorities.

10.4. Long-Term Measures

Implementation of additional monitoring and security systems;

Staff training on incident prevention;

Regular security audits.

All audit reports, inspection results, and related documentation, including analyses, conclusions, and recommendations, are considered confidential and shall not be disclosed to third parties without the prior written consent of ENESTECH. Access to such information is granted solely for internal purposes or in accordance with legal requirements, if explicitly mandated by regulatory authorities.

11. Liability

11.1. Responsibility of Clients for End User Data

If a Client (e.g., the owner of a computer club) uses SENET software to collect personal data from End Users, the Client is independently responsible for ensuring compliance with applicable data protection laws, including:


Obtaining valid consent from End Users;

Complying with personal data protection laws;

Informing users about the purposes of data processing.


11.2. Obligation to Notify ENESTECH of End User Requests

The Client must notify ENESTECH within 5 business days if they receive a request from an End User related to:

The exercise of data subject rights under the GDPR or other applicable laws;

Complaints regarding the processing of personal data;

Any legal obligations related to data protection.

The Client must not respond to such requests independently without prior coordination with ENESTECH, except where legally required to do so.


11.3. Notification of Data Breaches

The Client is obliged to immediately inform ENESTECH of any identified personal data breaches involving End User data. This is necessary to fulfill ENESTECH’s obligations under Articles 33 and 34 of the GDPR and to ensure the timely investigation of such incidents.

12. Data ownership

12.1. Data Ownership Rights

12.1.1. ENESTECH retains ownership of all data generated in the course of using the SENET software, including:


12.1.1.1. Aggregated and anonymized data;


12.1.1.2. System usage statistics;


12.1.1.3. Platform operation logs and technical metadata.


12.1.2. Clients remain the owners of all personal data they upload, store, or process using the SENET software.


12.1.3. End Users retain ownership of their personal data and may request its deletion in accordance with this Privacy Policy.


12.2. Data Control and Processing

12.2.1. ENESTECH acts as a Data Controller in cases where it independently determines the purposes and means of data processing, including:


12.2.1.1. Analysis of software usage to improve the platform;


12.2.1.2. Ensuring system security and fraud prevention;


12.2.1.3. Storage and processing of payment data of Clients for the performance of a contract.


12.2.2. Clients act as Data Controllers with respect to information they upload into the SENET software and are fully responsible for its lawful processing.


12.2.3. When acting as a Data Processor on behalf of a Client, ENESTECH processes personal data exclusively in accordance with the agreement with the Client and undertakes to delete such data:


12.2.3.1. Upon the Client’s request;


12.2.3.2. Upon expiration of the storage period following termination of cooperation.


12.3. Use of Aggregated and Anonymized Data

12.3.1. ENESTECH reserves the right to use aggregated and anonymized data, including statistical and analytical reports, for the following purposes:


12.3.1.1. Improving service quality and optimizing platform performance;


12.3.1.2. Analyzing system performance and hardware efficiency;


12.3.1.3. Developing new features and business solutions.

12.3.2. Anonymized data does not contain personal information of Clients or End Users and cannot be used to identify specific individuals.


12.4. Data Transfer and Deletion

12.4.1. In the event of a change in business ownership (merger, acquisition, reorganization), all data protection rights and obligations shall transfer to the new owner, provided that the Privacy Policy and applicable laws are respected.


12.4.2. Clients may export their data within 30 days following contract termination with ENESTECH.


12.4.3. Personal data processed by ENESTECH as a Data Processor shall be deleted after the agreed storage period or upon the Client’s request.


12.4.4. If ENESTECH acts as a Data Controller, data may be retained until legal obligations are fulfilled or security incidents are resolved:


12.4.4.1. For tax and accounting purposes;


12.4.4.2. For fraud prevention or violation investigation;


12.4.4.3. In the performance of legal obligations.


13. Responsibility for data security

13.1. ENESTECH's Responsibility

ENESTECH implements technical and organizational measures to ensure the security of Client data and prevent unauthorized access, loss, or alteration. Industry-standard protections are applied, including encryption, access controls, and activity monitoring, and ENESTECH works only with verified cloud service providers.


However, ENESTECH is not responsible for:

Actions of third parties, including cyberattacks, unless caused by ENESTECH’s fault;

Security breaches resulting from improper system use by the Client;

Data leaks caused by weak passwords, sharing credentials, or lack of security measures on the Client’s side.


13.2. Client’s Responsibility

The Client is responsible for:

Protecting login credentials and passwords, and controlling access to the system;

Establishing internal security policies within their organization;

Using up-to-date software and secure network connections;

Promptly notifying ENESTECH of any suspicious activity.


13.3. Data Transfer and Processing

ENESTECH transfers data only in accordance with contractual agreements and applicable data protection regulations.

When third-party processors are engaged, only verified vendors complying with security standards (e.g., ISO 27001, SOC 2) are used.

The Client is responsible for the legality of any data they upload to the system.


13.4. Security Incident Response Policy


13.4.1. In case of a data breach or suspected security incident, ENESTECH undertakes to:

Notify the Client of the incident within 72 hours (in accordance with the GDPR);

Conduct an internal investigation and take measures to eliminate the threat;

Provide a report on the identified issues and proposed protective measures.


13.4.2. The Client agrees to:

Immediately notify ENESTECH of any suspicious activity;

Cooperate in the course of the investigation.

14. Changes to the privacy policy

14.1. Procedure for making changes
ENESTECH reserves the right to unilaterally amend this Privacy Policy. The updated version shall take effect 30 (thirty) calendar days after its publication on the official website https://senet.cloud/, unless otherwise provided by law or agreement.


14.2. Notification of Clients

Clients will be notified of changes via:

Email sent to the address specified in their Personal Account;

A system notice in the Personal Account upon login.


14.3. Acceptance of Changes

If the Client continues to use ENESTECH services after the effective date of the updated Privacy Policy, such continued use shall constitute full and unconditional acceptance of the new terms.


14.4. Responsibility for Receiving Notifications

Clients are responsible for maintaining up-to-date contact information. Sending a notice to the registered email address and displaying it in the Personal Account shall be considered proper notification. Failure to receive the notice due to outdated contact information or it being viewed only by the club administrator does not exempt the Client from compliance with the Privacy Policy.


14.5. Rejection of Updated Terms

If a Client does not agree with the changes, they have the right to request deletion of their data and discontinue the use of the SENET software prior to the effective date of the new version.



Back to top