Sentsai← Legal
Sentsai

Data Processing Agreement

Effective date: June 2025

This Data Processing Agreement ("DPA") is incorporated by reference into the Sentsai Terms of Service and becomes legally binding when you accept the Terms of Service. It constitutes a valid written agreement for the purposes of Article 28(3) of the UK GDPR and EU GDPR. No separate signature is required.

1.Definitions

In this DPA, the following terms have the meanings set out below:

  • "Controller" means the Customer - the organization that has accepted the Terms of Service and connected its Microsoft 365 tenant to Sentsai. The Controller determines the purposes and means of processing Personal Data.
  • "Processor" means Sentsai, which processes Personal Data on behalf of the Controller to deliver the contracted service.
  • "Personal Data" means any information relating to an identified or identifiable natural person that is contained within the Microsoft 365 tenant data processed by Sentsai under this Agreement, as further described in clause 4.
  • "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, retrieval, storage, consultation, use, transmission, restriction, and deletion.
  • "GDPR" means the UK General Data Protection Regulation (as retained in UK law by the European Union (Withdrawal) Act 2018) and/or the EU General Data Protection Regulation (Regulation (EU) 2016/679), as applicable to the Controller's jurisdiction.
  • "Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data processed under this Agreement.
  • "Sub-Processor" means any third party engaged by Sentsai to process Personal Data on the Controller's behalf.
  • "Agreement" means this DPA together with the Terms of Service.

2.Roles

The parties acknowledge and agree that:

  • The Customer is the Controller. The Customer determines which Microsoft 365 tenant to connect, when to initiate a scan, and what to do with the resulting report.
  • Sentsai is the Processor. Sentsai processes Personal Data solely on the documented instructions of the Controller, being: to connect to the Microsoft 365 tenant via the Microsoft Graph API and run a licensing and security configuration analysis scan to produce a report.
  • Sentsai shall not process Personal Data for any purpose other than those described in this DPA, unless required to do so by applicable law, in which case Sentsai shall inform the Controller before that processing (unless prohibited by law from doing so).

3.Subject Matter and Duration of Processing

Subject matter: Sentsai processes Personal Data to:

  • Identify license assignment inefficiencies (unused, over-provisioned, or redundant licenses);
  • Detect security configuration gaps, including missing MFA registration, inactive guest accounts, and over-privileged directory roles;
  • Analyze usage patterns to distinguish active from inactive users;
  • Generate a written audit report summarizing findings and recommended actions.

Duration: Processing occurs during each scan (typically a few minutes) and continues for the data retention period thereafter. By default, scan data is retained for 90 days after which it is automatically and permanently deleted. The Controller may configure the retention period between 30 and 365 days via account settings.

4.Categories of Personal Data Processed

Sentsai processes the following categories of Personal Data about individuals in the Controller's Microsoft 365 tenant:

  • User display names
  • User principal names (UPNs / email addresses)
  • Microsoft internal user object IDs (GUIDs)
  • License assignment records (which Microsoft 365 SKUs and service plans are assigned to each user)
  • Last interactive sign-in date and time
  • Per-application last-activity dates from Microsoft 365 usage reports (Exchange, Teams, SharePoint, OneDrive, Visio, Project)
  • Account status (enabled or disabled)
  • MFA authentication method registration status (whether the user has registered at least one authenticator method)
  • Mailbox storage usage in bytes
  • The name and email address of the Controller’s own user who initiates each scan, recorded for accountability and displayed on the resulting report
  • Guest account type flag (whether an account is an external guest) and guest account creation date
  • Directory role assignments (e.g., Global Administrator, Exchange Administrator, Security Administrator)

This data is retrieved exclusively via the Microsoft Graph API using permissions delegated by the Controller. Sentsai does not access email content, calendar entries, files, or chat messages.

5.Categories of Data Subjects

The Personal Data processed relates to the following categories of data subjects:

  • Employees of the Controller who have Microsoft 365 user accounts in the connected tenant;
  • Contractors, consultants, and temporary workers who have Microsoft 365 user accounts in the connected tenant;
  • External guest users who have been invited to the Controller's Microsoft 365 tenant.

6.Processor Obligations

Sentsai shall, in its capacity as Processor:

  • (a) Process only on instructions: process Personal Data only on documented instructions from the Controller (as set out in this DPA), and notify the Controller immediately if, in Sentsai's opinion, an instruction infringes the GDPR or other applicable data protection law;
  • (b) Confidentiality: ensure that all persons authorized to process Personal Data on Sentsai's behalf are subject to enforceable confidentiality obligations and are informed of the sensitive nature of the data;
  • (c) Security: implement and maintain the technical and organizational security measures described in clause 11;
  • (d) Sub-processing: not engage any Sub-Processor without prior authorization from the Controller (granted under clause 7) and ensure any Sub-Processor agreement imposes data protection obligations equivalent to those in this DPA;
  • (e) Assistance with rights: assist the Controller in fulfilling its obligations to respond to data subject rights requests, using the technical capabilities described in clause 8;
  • (f) Deletion: upon termination of this Agreement or at the Controller's written request, delete all Personal Data processed under this Agreement in accordance with clause 10;
  • (g) Compliance evidence: make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA, and cooperate with audits conducted under clause 12;
  • (h) Breach notification: notify the Controller without undue delay (and in any event within 72 hours) upon becoming aware of a Data Breach affecting Personal Data processed under this Agreement, as set out in clause 9.

7.Sub-Processors

The Controller grants Sentsai general written authorization to engage Sub-Processors, subject to the following conditions:

  • The current list of authorized Sub-Processors is set out in the Privacy Policy (clause 7 of that document). This list is incorporated into this DPA by reference.
  • Sentsai shall provide the Controller with at least 30 days' written notice of any intended addition or replacement of a Sub-Processor. Sentsai will provide the name, country, and purpose of the new Sub-Processor.
  • The Controller may object to the change within 30 days of receiving notice, on reasonable data protection grounds, by notifying Sentsai in writing. If the parties cannot resolve the objection, either party may terminate the relevant services with no penalty.
  • Sentsai shall impose data protection obligations on each Sub-Processor that are equivalent to those in this DPA and shall remain fully liable to the Controller for the acts and omissions of Sub-Processors.

8.International Transfers

Where Personal Data is processed. Sentsai is established in Ontario, Canada. The Service runs on Microsoft Azure infrastructure located in the United States, and the Sub-Processors listed in the Privacy Policy are all established in the United States. Sentsai personnel located in Canada access Personal Data from Canada in the course of operating and supporting the Service. Accordingly, Personal Data processed under this Agreement is stored in the United States and may be accessed from Canada.

Transfers from Canada. Where the Controller is subject to PIPEDA, Sentsai processes Personal Data outside Canada as described above. Sentsai remains accountable for that Personal Data while it is in the hands of a Sub-Processor, and uses contractual means to provide a comparable level of protection to that required under PIPEDA. The Controller acknowledges that Personal Data stored in the United States is subject to the laws of that jurisdiction, including lawful access by United States authorities.

Transfers from the European Economic Area, the United Kingdom and Switzerland. Where the Controller transfers Personal Data subject to the GDPR, the UK GDPR or the Swiss FADP to Sentsai, the following applies:

  • Canada benefits from a European Commission adequacy decision covering commercial organizations subject to PIPEDA, so a transfer to Sentsai in Canada does not itself require an additional safeguard. That adequacy decision does not extend to the onward storage of Personal Data in the United States, which is addressed below.
  • Standard Contractual Clauses. To the extent Personal Data is transferred to a country that is not the subject of an adequacy decision, the parties incorporate into this DPA by reference the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor). By entering into this DPA, the parties are deemed to have signed those Clauses. Where the transfer is subject to the UK GDPR, the parties further incorporate the UK International Data Transfer Addendum (version B1.0) issued under section 119A of the Data Protection Act 2018. Where the transfer is subject to the Swiss FADP, references in the Clauses to the GDPR and to supervisory authorities are read as references to the FADP and to the Swiss Federal Data Protection and Information Commissioner.
  • Completion of the Clauses. For the purposes of the Standard Contractual Clauses: the Controller is the data exporter and Sentsai is the data importer; the optional docking clause in Clause 7 does not apply; the option in Clause 9(a) is Option 2, general written authorization, with the notice period set out in clause 7 of this DPA; the option in Clause 11(a) relating to an independent dispute resolution body does not apply; the governing law under Clause 17 is the law of the Republic of Ireland; and the forum under Clause 18(b) is the courts of Ireland. Annex I (parties, description of the transfer, and competent supervisory authority) is completed by clauses 2, 3, 4 and 5 of this DPA together with the Controller account record; Annex II (technical and organizational measures) is completed by clause 12 of this DPA; and Annex III (sub-processors) is completed by clause 7 of this DPA.
  • Precedence. If there is any conflict between the Standard Contractual Clauses and the remainder of this DPA or the Terms of Service, the Standard Contractual Clauses prevail in respect of the transfer they govern. Clause 15 (Governing Law) of this DPA does not displace Clause 17 of the Standard Contractual Clauses.

Onward transfers. Sentsai shall not transfer Personal Data to a Sub-Processor located outside the country of the Controller unless that Sub-Processor is bound by obligations equivalent to those in this DPA, including, where required, the Standard Contractual Clauses or another lawful transfer mechanism. The current Sub-Processors and their locations are listed in the Privacy Policy.

Transfer impact assessment and government access. On the Controller's reasonable written request, Sentsai shall provide the information in its possession that the Controller needs in order to carry out a transfer impact assessment, including the categories of Personal Data transferred, the locations of processing, and the Sub-Processors involved. Sentsai has not, as at the date of this DPA, received any legally binding request from a public authority for disclosure of Personal Data processed under this Agreement. If Sentsai receives such a request it shall, unless legally prohibited, notify the Controller without undue delay, challenge any request it considers unlawful, and disclose only the minimum data lawfully required.

Change of processing location. Sentsai shall give the Controller at least 30 days' written notice before moving the primary storage location of Personal Data to a different country. The Controller may object on reasonable data protection grounds under the same process set out in clause 7 for Sub-Processor changes.

9.Data Subject Rights

Sentsai shall provide reasonable technical assistance to help the Controller fulfill its obligations under Chapter III of the GDPR (data subject rights). Specifically:

  • Requests addressed to Sentsai directly: if a data subject contacts Sentsai directly to exercise a right (access, erasure, portability, restriction, objection), Sentsai will forward the request to the Controller within 5 business days and will not respond to the data subject on the Controller's behalf without the Controller's authorization.
  • Self-service tools: Sentsai provides API endpoints that allow the Controller to: export all Personal Data associated with their tenant (GET /gdpr/export), delete all Personal Data (DELETE /gdpr/erase), perform full account deletion (DELETE /account/delete), and configure the retention period (PUT /gdpr/retention).
  • Individual-level deletion: the Controller may request deletion of data relating to a specific individual by contacting privacy@sentsai.com with the user's UPN or Microsoft object ID. Sentsai will complete deletion within 30 days.

10.Data Breach Notification

In the event of a Data Breach affecting Personal Data processed under this Agreement, Sentsai shall:

  • Notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach;
  • Provide in the notification (or as soon as the information becomes available): (i) a description of the nature of the breach; (ii) the categories and approximate number of data subjects affected; (iii) the categories and approximate number of Personal Data records affected; (iv) the likely consequences of the breach; and (v) the measures taken or proposed to address the breach and mitigate its possible adverse effects;
  • Cooperate with the Controller and provide further information as reasonably required to allow the Controller to fulfill its own notification obligations to supervisory authorities and data subjects.

Breach notifications should be directed to the Controller's primary account email address and to any security contact the Controller has registered with Sentsai.

11.Deletion on Termination

Upon termination of the Agreement (for any reason) or upon receipt of a written deletion request from the Controller, Sentsai shall:

  • Delete all Personal Data processed under this Agreement within 30 days, unless applicable law requires retention for a longer period (in which case Sentsai shall inform the Controller of the legal obligation and isolate the retained data from further processing);
  • Procure that each Sub-Processor deletes the relevant Personal Data within the same timeframe;
  • Confirm completion of deletion to the Controller in writing within 35 days of the request.

The Controller may trigger immediate deletion of all scan data at any time by calling DELETE /gdpr/erase with administrator credentials. This is permanent and irreversible.

12.Technical and Organizational Measures

Sentsai implements and maintains the following technical and organizational security measures:

Encryption in transit
Traffic between your browser and Sentsai, and between Sentsai and the third-party services it calls, uses TLS 1.2 or higher, terminated at a reverse proxy with automatic certificate renewal and HTTP Strict Transport Security. Traffic between Sentsai internal components runs on a private container network that is not routable from the internet.
Encryption at rest
Field-level encryption (Fernet: AES-128-CBC with HMAC-SHA256 authentication) is applied to the database columns holding scan findings and generated reports - the fields containing data subjects' Personal Data. Controller account fields and audit-log entries are protected by tenant isolation, access controls, and automated anonymization. Encryption keys are held in environment configuration, separate from the database.
Access control and isolation
Every database query is scoped to the tenant of the authenticated session. That tenant is resolved server-side from an opaque session identifier and is never read from a client-supplied value, so one organization cannot request another organization data. Sentsai is operated by a single administrator who necessarily holds infrastructure-level access; there is no wider staff population and therefore no internal role hierarchy. Actions taken through the application are recorded in the audit log; direct database access by the operator is not separately logged. Routine operator access to customer records goes through a read-only administrative console that is reachable only over a private network and bound to an authenticated operator identity. The console displays account and billing records, including the administrator contact address; it cannot display the names, email addresses, or finding text of the directory users whose data is processed in scans. Every access is written to the immutable audit log under the tenant it concerns, where the Controller can see it in the data export.
Audit logging
Report views and downloads, scan-history views, scan initiation and completion, authentication events, payment events, consent changes, account deletion, and data subject rights actions are logged with timestamps, tenant identity, resource reference, IP address, and user-agent. Audit entries are written at these specific points; there is no general request-level logging of every API call. Audit action records are retained indefinitely as an immutable trail (protected by a PostgreSQL-level immutability trigger). IP address and user-agent fields within audit entries are anonymized after the tenant's configured retention period, in compliance with the GDPR storage limitation principle.
Automatic deletion
Scan data is automatically purged after the configured retention period. Deletion jobs run every 24 hours and failures are logged for operator review.
Vulnerability management
Dependency manifests are monitored for known vulnerabilities by automated tooling, and security updates are applied as they are triaged. Sentsai does not currently commission third-party penetration testing. If that changes, this schedule will be updated before the change is relied on.
Confidentiality
Any Sentsai personnel or contractor granted access to Personal Data is subject to a written confidentiality agreement before that access is granted. Sentsai currently has no employees or contractors with such access.

13.Audit Rights

The Controller has the right to audit Sentsai's compliance with this DPA, subject to the following conditions:

  • The Controller must provide at least 30 days' written notice before conducting an audit;
  • Audits may be conducted no more than once per calendar year, unless there has been a confirmed Data Breach or a documented and reasonable concern about Sentsai's compliance;
  • Audits are conducted at the Controller's own cost and must not unreasonably interfere with Sentsai's normal business operations;
  • Sentsai may satisfy its audit obligations by providing up-to-date third-party certifications (e.g., ISO 27001, SOC 2) or independent audit reports covering the relevant controls, in lieu of or in addition to a direct audit;
  • All audit findings and any Sentsai confidential information accessed during an audit are subject to confidentiality obligations.

14.Liability

Each party's liability to the other under or in connection with this DPA is subject to the limitations of liability set out in the Terms of Service (clause 10 of those Terms).

Where both parties are at fault for a Data Breach or GDPR infringement that results in a fine or penalty imposed by a supervisory authority, each party shall bear liability in proportion to their respective degree of fault, as determined by the relevant supervisory authority or, in the absence of such determination, as agreed between the parties in good faith.

Sentsai's total aggregate liability for breaches of this DPA shall not exceed the cap set out in clause 10(a) of the Terms of Service.

15.Governing Law

This DPA is governed by the laws of the Province of Ontario, Canada, and is subject to the exclusive jurisdiction of the courts of Ontario. For US-based Controllers, this DPA also serves as a CCPA Service Provider Agreement; see the CCPA Addendum for California-specific terms.

Where the GDPR of a particular jurisdiction imposes additional mandatory requirements on data processing agreements, those requirements are incorporated into this DPA to the extent necessary to ensure compliance.

Questions regarding this DPA should be directed to legal@sentsai.com.