Sentsai← Legal
Sentsai

CCPA Service Provider Addendum

Effective date: June 2025

This Addendum applies when you are a business subject to the California Consumer Privacy Act (as amended by the California Privacy Rights Act - "CCPA/CPRA"), or when you process personal information of California residents using the Sentsai service. It is incorporated by reference into the Sentsai Terms of Service and Data Processing Agreement.

1.Definitions

Terms used but not defined here have the meanings given in the CCPA/CPRA.

  • "Business" means you, the customer organization that is subject to the CCPA/CPRA and that uses Sentsai.
  • "Service Provider" means Sentsai Inc., which processes Personal Information on behalf of the Business pursuant to a written contract.
  • "Personal Information" has the meaning set forth in Cal. Civ. Code § 1798.140(v): information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.
  • "Sell" / "Share" have the meanings given in Cal. Civ. Code §§ 1798.140(ad) and (ah).

2.Service Provider Obligations

Sentsai, as Service Provider, shall:

  • (a) Process Personal Information only for the Business Purpose specified in this Addendum and the Terms of Service (providing Microsoft 365 license analysis services), and for no other commercial purpose;
  • (b) Not sell or share Personal Information, as those terms are defined in the CCPA/CPRA;
  • (c) Not retain, use, or disclose Personal Information for any purpose other than providing the service, including not retaining, using, or disclosing the Personal Information for a commercial purpose other than providing the service;
  • (d) Not combine Personal Information received from the Business with Personal Information received from or collected in connection with other sources or clients;
  • (e) Not use Personal Information for cross-context behavioral advertising;
  • (f) Implement and maintain reasonable security procedures and practices appropriate to the nature of the Personal Information, as required by Cal. Civ. Code § 1798.81.5;
  • (g) Notify the Business if Sentsai determines it can no longer meet its obligations under the CCPA/CPRA;
  • (h) Grant the Business the right to take reasonable and appropriate steps to ensure Sentsai uses Personal Information in a manner consistent with the Business's obligations under the CCPA/CPRA;
  • (i) Allow reasonable audits by the Business or its designated auditor to verify compliance with this Addendum.

3.Business Purpose

Sentsai processes Personal Information solely for the following Business Purposes:

  • Analyzing Microsoft 365 license assignments, usage patterns, and security configuration to identify potential cost savings and compliance gaps;
  • Generating written reports summarizing findings for the Business;
  • Maintaining audit logs for security and compliance;
  • Fulfilling data subject rights requests on behalf of the Business as required by applicable law.

Sentsai certifies that it understands these restrictions and will comply with them.

4.Categories of Personal Information Processed

The Personal Information processed includes the following CCPA/CPRA categories:

  • Identifiers - Employee names, email addresses (user principal names), Microsoft user IDs;
  • Internet or network activity - Last sign-in timestamps, application usage patterns;
  • Professional or employment-related information - License assignments and directory role assignments.

No sensitive personal information (as defined in Cal. Civ. Code § 1798.121) is collected or processed by Sentsai.

5.Consumer Rights Requests

The Business is responsible for receiving and responding to consumer (employee) rights requests under the CCPA/CPRA. Sentsai will assist the Business to the extent technically feasible:

  • Right to Know / Access - Sentsai provides a data export endpoint (GET /gdpr/export) containing all Personal Information held for the Business;
  • Right to Delete - Sentsai provides a deletion endpoint (DELETE /gdpr/erase) to remove all Personal Information;
  • Right to Correct - As Sentsai's data is derived in real-time from Microsoft Graph API, correction requests should be directed to Microsoft. Sentsai can re-run a scan to refresh data;
  • Right to Opt Out of Sale/Sharing - Not applicable. Sentsai does not sell or share Personal Information.

If a consumer submits a rights request directly to Sentsai, Sentsai will forward it to the Business within 5 business days.

6.Sub-Processors

Sentsai uses the following sub-processors that may process Personal Information. Each is engaged under a written contract that imposes equivalent privacy obligations:

Microsoft Corporation
Microsoft Graph API - source of Microsoft 365 tenant data · United States · Microsoft DPA / Standard Contractual Clauses
Stripe, Inc.
Payment processing (no Microsoft 365 data shared) · United States · Stripe DPA
Resend (Plus Five Five, Inc.)
Email delivery (transactional and lifecycle emails; recipient address and message content only, no Microsoft 365 tenant data) · United States · Resend DPA
Microsoft Azure
Database and compute hosting for the Sentsai application · United States · Microsoft DPA / Standard Contractual Clauses

7.Data Retention and Deletion

Sentsai retains Personal Information for the retention period configured by the Business - 90 days by default, configurable between 30 and 365 days - after which it is automatically deleted. On termination of the agreement, or on request, all Personal Information is deleted within 30 days. One exception, disclosed for accuracy: entries in our immutable audit trail are retained as a record that an action occurred. Their IP address and user-agent fields are erased, leaving an action name, a timestamp and internal identifiers that do not identify a person.

8.Security

Sentsai implements reasonable security measures including: encryption in transit for internet-facing traffic (TLS 1.2+), field-level encryption at rest, tenant-level data isolation, access logging, and retention-based automatic deletion. In the event of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Information, Sentsai shall notify the Business without undue delay.

9.Conflicts

To the extent there is any conflict between this Addendum and the Terms of Service or DPA with respect to CCPA/CPRA obligations, this Addendum shall control solely with respect to such CCPA/CPRA obligations.

Questions about this Addendum

Contact us at privacy@sentsai.com. If you require a signed copy of this Addendum for your procurement process, please contact us and we will provide one.