Back to home

Privacy Policy

How we collect, use, store, and protect personal data — on our website and on behalf of our customers — in line with the UK GDPR and applicable data protection law.

Last updated: 1 June 2026 Fydelia by Sentinel Software Ltd

Introduction

This Privacy Policy explains how Sentinel Software Limited (trading as Fydelia) collects, uses, stores, and protects personal data. We are committed to complying with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR) where it applies, and other applicable data protection laws.

This policy covers two distinct contexts:

  • Our website and marketing — where Fydelia acts as the data controller for visitors who browse fydelia.com, contact us, or sign up for trials and communications.
  • Guest WiFi data on our platform — where Fydelia acts as a data processor on behalf of our customers (venues, resellers, and other Fydelia users). In that context, our customer is the data controller and decides what data is collected, how long it is kept, and how it is used.

Please read this policy carefully. For technical and security details about how we protect guest WiFi data, see our Information System Security Policy.

Who we are

Fydelia is operated by Sentinel Software Limited, Gemini House, 136-140 Old Shoreham Road, Brighton, BN3 7BD, United Kingdom.

Registered in England and Wales: 6463344 · VAT Reg 135 2946 10

For privacy enquiries: info@fydelia.com or support@fydelia.com

Guest WiFi data we process on behalf of customers

When a venue or organisation uses Fydelia to provide guest WiFi access, we process personal data strictly on their instructions. The data belongs to our customer — we do not sell it, use it for our own marketing, or analyse it for purposes unrelated to delivering the service.

What data may be collected

Which fields are collected is configured by each Fydelia customer through their splash pages and consent settings. Data may optionally include:

  • First name and last name
  • Email address
  • Phone number
  • Date of birth
  • MAC address of the connecting phone or device
  • Associated metadata, such as connection date and time, device type, and similar technical information

Only the data fields enabled by the customer and accepted by the guest (where consent is required) will be collected and stored.

How we use guest WiFi data

As a processor, we use guest WiFi data solely to:

  • Provide and operate the captive portal and WiFi access service
  • Store and make data available to the customer within their Fydelia account
  • Transmit data to external connectors or third-party platforms only when configured by the Fydelia customer (for example, CRM or marketing integrations they have enabled)
  • Meet legal, security, and operational requirements necessary to run the platform

We do not use guest WiFi data for Fydelia's own purposes beyond providing the contracted service.

Data access and export

Our customers can access and export the data held in their Fydelia account at any time through the platform, or by contacting us. If you are a guest who connected to WiFi at a venue using Fydelia and wish to exercise your rights, please contact the venue directly in the first instance — they are the data controller. We will assist our customers in responding to valid requests in line with our data processing obligations.

Data retention

Retention periods are configurable to suit each customer's requirements. For example, a customer may choose to retain only the most recent 90 days of data, with anything older automatically removed on a rolling basis. If no custom period is set, our default retention applies as described in our Information System Security Policy. When a retention period expires, data is securely deleted or anonymised.

Where data is hosted

Platform data is hosted with Hetzner, a German hosting provider, and is stored on servers located in Germany (within the European Economic Area). This helps ensure that guest WiFi data benefits from EU/EEA data protection standards.

We also have hosting facilities in the United Kingdom that may be used where appropriate or requested. Where data is processed in the UK, it is protected under UK GDPR. Where processing involves a transfer outside the UK or EEA, we use appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms as required by law.

Personal data we collect on our website

When you visit fydelia.com, contact us, request a demo or trial, subscribe to communications, or interact with our support channels, we may collect:

  • Contact details (name, email address, phone number, company name)
  • Information you provide in forms, emails, or support tickets
  • Technical data such as IP address, browser type, and pages visited

Legal bases for processing (website)

We process website personal data on the following bases under UK/EU GDPR:

  • Contract — to respond to enquiries, provide trials, and deliver services you request
  • Legitimate interests — to operate and improve our website, prevent fraud, and understand how our services are used (balanced against your rights)
  • Consent — where required for non-essential cookies or marketing communications you have opted into
  • Legal obligation — where we must comply with applicable law

Cookies and similar technologies

Our website uses cookies and similar technologies to remember preferences, measure traffic, and improve your experience. Some cookies are essential for the site to function; others (such as analytics) are used only with your consent where required by law.

You can control cookies through your browser settings. Disabling certain cookies may affect how parts of the site work. We may use trusted third-party services (for example, analytics or tag management) that set their own cookies subject to their privacy policies.

Sharing personal data

We do not sell personal data.

We may share data with:

  • Service providers who help us operate our website and platform (such as hosting, email, and support tools), under contracts that require them to protect the data and use it only on our instructions
  • Third-party connectors chosen and configured by Fydelia customers to receive guest WiFi data from the platform
  • Authorities where we are legally required to do so

Our website may contain links to third-party sites. Those sites have their own privacy policies and we are not responsible for their practices.

Security

We implement appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls, and monitoring. Details of our security practices for guest WiFi data are set out in our Information System Security Policy and Security Assurance Plan.

Your rights under GDPR

Depending on your location and the context in which your data is processed, you may have the following rights:

  • Access — to obtain a copy of your personal data
  • Rectification — to correct inaccurate data
  • Erasure — to request deletion in certain circumstances
  • Restriction — to limit how we process your data
  • Data portability — to receive data you provided in a structured, machine-readable format
  • Objection — to object to processing based on legitimate interests or for direct marketing
  • Withdraw consent — where processing is based on consent, without affecting the lawfulness of prior processing

To exercise rights relating to data collected through a venue's guest WiFi, contact that venue first. For website data or processor queries, contact us at info@fydelia.com. We will respond within one month, as required by GDPR, and may ask you to verify your identity.

You also have the right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner's Office (ICO).

Data breaches

If a personal data breach occurs that is likely to result in a risk to individuals, we will notify affected data controllers without undue delay and, where we act as controller, notify affected individuals and the relevant supervisory authority as required by GDPR — typically within 72 hours of becoming aware of the breach where notification to the authority is required.

Children

Our website and platform are not directed at children under 16. We do not knowingly collect personal data from children. If you believe we have collected such data, please contact us so we can delete it.

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will post the revised policy on this page and update the "Last updated" date. Material changes affecting how we process guest WiFi data on behalf of customers will be communicated to those customers where appropriate.


Contacting us

If you have questions about this Privacy Policy or how we handle personal data, please contact us:

Sentinel Software Limited (Fydelia)
Gemini House, 136-140 Old Shoreham Road, Brighton, BN3 7BD, United Kingdom

Email: info@fydelia.com · support@fydelia.com
Phone: (+44) 203-368-8870