Effective date: June 2025
In this DPA, the following terms have the meanings set out below:
The parties acknowledge and agree that:
Subject matter: Sentsai processes Personal Data to:
Duration: Processing occurs during each scan (typically a few minutes) and continues for the data retention period thereafter. By default, scan data is retained for 90 days after which it is automatically and permanently deleted. The Controller may configure the retention period between 30 and 365 days via account settings.
Sentsai processes the following categories of Personal Data about individuals in the Controller's Microsoft 365 tenant:
This data is retrieved exclusively via the Microsoft Graph API using permissions delegated by the Controller. Sentsai does not access email content, calendar entries, files, or chat messages.
The Personal Data processed relates to the following categories of data subjects:
Sentsai shall, in its capacity as Processor:
The Controller grants Sentsai general written authorization to engage Sub-Processors, subject to the following conditions:
Where Personal Data is processed. Sentsai is established in Ontario, Canada. The Service runs on Microsoft Azure infrastructure located in the United States, and the Sub-Processors listed in the Privacy Policy are all established in the United States. Sentsai personnel located in Canada access Personal Data from Canada in the course of operating and supporting the Service. Accordingly, Personal Data processed under this Agreement is stored in the United States and may be accessed from Canada.
Transfers from Canada. Where the Controller is subject to PIPEDA, Sentsai processes Personal Data outside Canada as described above. Sentsai remains accountable for that Personal Data while it is in the hands of a Sub-Processor, and uses contractual means to provide a comparable level of protection to that required under PIPEDA. The Controller acknowledges that Personal Data stored in the United States is subject to the laws of that jurisdiction, including lawful access by United States authorities.
Transfers from the European Economic Area, the United Kingdom and Switzerland. Where the Controller transfers Personal Data subject to the GDPR, the UK GDPR or the Swiss FADP to Sentsai, the following applies:
Onward transfers. Sentsai shall not transfer Personal Data to a Sub-Processor located outside the country of the Controller unless that Sub-Processor is bound by obligations equivalent to those in this DPA, including, where required, the Standard Contractual Clauses or another lawful transfer mechanism. The current Sub-Processors and their locations are listed in the Privacy Policy.
Transfer impact assessment and government access. On the Controller's reasonable written request, Sentsai shall provide the information in its possession that the Controller needs in order to carry out a transfer impact assessment, including the categories of Personal Data transferred, the locations of processing, and the Sub-Processors involved. Sentsai has not, as at the date of this DPA, received any legally binding request from a public authority for disclosure of Personal Data processed under this Agreement. If Sentsai receives such a request it shall, unless legally prohibited, notify the Controller without undue delay, challenge any request it considers unlawful, and disclose only the minimum data lawfully required.
Change of processing location. Sentsai shall give the Controller at least 30 days' written notice before moving the primary storage location of Personal Data to a different country. The Controller may object on reasonable data protection grounds under the same process set out in clause 7 for Sub-Processor changes.
Sentsai shall provide reasonable technical assistance to help the Controller fulfill its obligations under Chapter III of the GDPR (data subject rights). Specifically:
GET /gdpr/export), delete all Personal Data (DELETE /gdpr/erase), perform full account deletion (DELETE /account/delete), and configure the retention period (PUT /gdpr/retention).In the event of a Data Breach affecting Personal Data processed under this Agreement, Sentsai shall:
Breach notifications should be directed to the Controller's primary account email address and to any security contact the Controller has registered with Sentsai.
Upon termination of the Agreement (for any reason) or upon receipt of a written deletion request from the Controller, Sentsai shall:
The Controller may trigger immediate deletion of all scan data at any time by calling DELETE /gdpr/erase with administrator credentials. This is permanent and irreversible.
Sentsai implements and maintains the following technical and organizational security measures:
The Controller has the right to audit Sentsai's compliance with this DPA, subject to the following conditions:
Each party's liability to the other under or in connection with this DPA is subject to the limitations of liability set out in the Terms of Service (clause 10 of those Terms).
Where both parties are at fault for a Data Breach or GDPR infringement that results in a fine or penalty imposed by a supervisory authority, each party shall bear liability in proportion to their respective degree of fault, as determined by the relevant supervisory authority or, in the absence of such determination, as agreed between the parties in good faith.
Sentsai's total aggregate liability for breaches of this DPA shall not exceed the cap set out in clause 10(a) of the Terms of Service.
This DPA is governed by the laws of the Province of Ontario, Canada, and is subject to the exclusive jurisdiction of the courts of Ontario. For US-based Controllers, this DPA also serves as a CCPA Service Provider Agreement; see the CCPA Addendum for California-specific terms.
Where the GDPR of a particular jurisdiction imposes additional mandatory requirements on data processing agreements, those requirements are incorporated into this DPA to the extent necessary to ensure compliance.
Questions regarding this DPA should be directed to legal@sentsai.com.