Data Processing Agreement
Last updated: 2026-07-13
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Seentrix Ltd (company number 17169165, registered in England and Wales at 167-169 Great Portland Street, London W1W 5PF; "Processor", "Seentrix") and you or the entity you represent ("Controller", "Customer"). It applies whenever Seentrix processes personal data on behalf of the Controller in connection with the Service.
1. Definitions
Terms such as "personal data", "processing", "controller", "processor", and "sub-processor" have the meanings given to them in Regulation (EU) 2016/679 (the "GDPR"), and the equivalent meanings under the UK GDPR where it applies.
2. Subject matter and duration
Seentrix processes personal data as a processor for the purpose of providing the Service, for as long as the Controller's account exists. Ending a paid subscription does not delete data — the organisation continues on the free tier with its data intact. Deletion happens only at the Controller's request or on account deletion, as described in §9.
3. Nature and purpose of processing
Seentrix processes personal data to: authenticate users, organise compliance artefacts (products, SBOMs, incidents, DoCs), generate regulatory documents, answer questions through the Seentrix AI assistant, deliver transactional communications — including security notices the Controller composes for its own product users (CRA Art. 14(8)) — and record audit-grade activity logs, including a database-level audit trail of changes to the Controller's records (the fields changed with their old and new values, the acting member or system process, and the time) kept as supporting compliance evidence for the Controller.
4. Categories of data subjects and data
- Data subjects: the Controller's employees and contractors who use the Service; individuals named as signatories on Declarations of Conformity; researchers who submit reports through the Controller's public PSIRT page; end users of the Controller's products who receive security notices sent through the Service.
- Personal data: names, business email addresses, roles, avatar images, signatures (typed name + title), optional reporter contact details, end-user recipient email addresses supplied by the Controller for security notices (with delivery status records), support and feedback messages, and Seentrix AI prompts and responses.
5. Processor obligations
Seentrix will:
- Process personal data only on documented instructions from the Controller (the Terms, this DPA, and the Controller's use of the Service's features), and inform the Controller if, in our opinion, an instruction infringes the GDPR.
- Ensure all personnel authorised to process personal data have committed to confidentiality.
- Implement appropriate technical and organisational measures (TOMs) as described in Schedule A.
- Taking into account the nature of the processing, assist the Controller with data-subject requests (Arts. 12–23) and — insofar as information is available to us — with its obligations under Arts. 32–36 GDPR (security, breach notification, data-protection impact assessments).
- Notify the Controller of any personal-data breach affecting its data without undue delay and in any event within 72 hours of becoming aware of it.
- Make available the information necessary to demonstrate compliance with Art. 28 GDPR, and allow and contribute to audits as described in §10.
6. Sub-processors
The Controller authorises Seentrix to engage the sub-processors listed at Schedule B. This page is the authoritative, always-current list. We will announce the addition or replacement of a sub-processor at least 30 days in advance by updating this page and the product changelog; Controllers who want to receive change notices by email can request this at support@seentrix.com. The Controller may object to a change on reasonable data-protection grounds; if we cannot accommodate the objection, either party may terminate the affected portion of the Service.
7. International transfers
Where a transfer outside the EEA occurs, the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) apply as incorporated by this DPA, supplemented by the UK Addendum where the UK GDPR applies. Additional safeguards are applied based on Transfer Impact Assessments ("TIAs") we perform per sub-processor.
8. Controller obligations
The Controller warrants that it has a valid legal basis for every data-subject's data uploaded to the Service — including the email addresses of end users it supplies for security notices — and will not upload special-category data (GDPR Art. 9) unless a specific data-class addendum has been signed.
9. Return and deletion
The Controller can export all processed data in a machine-readable format (JSON) self-service at any time while the account exists. Upon the Controller's deletion request, a 30-day grace period applies during which the request can be cancelled; after it expires, Seentrix permanently deletes the organisation's data, files, and member accounts from live systems, and residual copies expire from encrypted backups within at most a further 30 days. Records that Seentrix must keep under applicable law (e.g. billing records for tax purposes) are retained only as long as that law requires. Note: the CRA's 10-year documentation retention duty rests with the Controller as manufacturer — export your compliance records before deletion.
10. Audits
Seentrix will respond to a reasonable data-processing-related audit inquiry from the Controller once per calendar year by completing the Controller's security questionnaire and providing documentation of the measures in Schedule A (plus independent attestations if and when we obtain them). On-site audits are limited to when strictly necessary and the Controller bears the cost.
Schedule A — Technical and organisational measures
- Encryption in transit (TLS) and at rest; integration credentials and webhook signing secrets are additionally encrypted at the application layer with AES-256-GCM envelope encryption.
- Multi-factor authentication (TOTP) is mandatory for every user, including Seentrix platform staff; recovery codes are single-use and stored only as one-way hashes.
- Step-up re-authentication (short-lived, 5-minute window) is required for sensitive operations: issuing a Declaration of Conformity, minting API keys or SCIM tokens, revealing webhook secrets, removing members or changing roles, changing SSO settings, and scheduling irreversible deletions.
- Tenant isolation enforced with row-level security on every organisation-scoped database table — no cross-customer query path exists at the database layer.
- Role-based access control (admin / compliance officer / CTO / editor / viewer).
- Activity logging on customer actions (members cannot modify or delete log entries); a database-level audit trail of changes to organisation records, written only by the database itself and immutable to every application role — when a member's account is deleted, that member's identifying details are automatically redacted from the trail (Art. 17 GDPR) while the change record itself is preserved; and an append-only audit log of every action Seentrix staff take on customer accounts.
- Scheduled retention enforcement: automated purges of AI transcripts (plan-tiered), prospect support threads, and organisation data after the deletion grace period.
- Hardened outbound integrations: webhook payloads signed with HMAC-SHA256, HTTPS-only delivery with SSRF and DNS-rebinding protections.
- Rate limiting on authentication and public endpoints; bot protection (Cloudflare Turnstile) on public forms.
- Error monitoring configured for data minimisation: IP addresses and cookies stripped, known-sensitive fields scrubbed before events leave the runtime, diagnostic replays captured only on errors with all text masked and media blocked.
- Least-privilege access to production; incident-response process with 72-hour breach notification to the Controller (§5).
Schedule B — Sub-processors
| Processor | Purpose | Location of processing |
|---|---|---|
| Supabase, Inc. (US) | Database, authentication, file storage | United Kingdom (London, eu-west-2 — EU adequacy decision) |
| Vercel Inc. (US) | Web application hosting; cookieless aggregated page analytics (no cookies, no device identifiers, query strings stripped client-side; only aggregated, non-identifying statistics retained) | EU (Frankfurt, fra1) application functions; global edge network; US control plane |
| Stripe Payments Europe, Ltd. and affiliates (incl. Stripe, Inc., US) | Billing and payments | Ireland + US |
| Resend (US) | Transactional email delivery, incl. Controller-composed security notices | US |
| Sentry (Functional Software, Inc., US) | Error monitoring | Germany (EU) — de.sentry.io data residency |
| Mistral AI SAS (France) | Seentrix AI — LLM inference + embeddings (zero data retention, no training on Customer data) | France (EU) |
| Upstash, Inc. (US) | Rate-limit counters for Seentrix AI quotas (no message content) | EU region |
| Cloudflare, Inc. (US) | Turnstile bot protection on public forms (technical browser signals only) | Global network |
Controller-elected integrations are not sub-processors. If the Controller connects Slack, Jira, Microsoft Teams, Discord, or its own webhook endpoints, data flows to those services on the Controller's instruction and under the Controller's own agreements with them; the Controller can disconnect them at any time.
Sign a counter-signed copy of this DPA by emailing support@seentrix.com.
Seentrix Ltd · Company number 17169165 · Registered in England and Wales · 167-169 Great Portland Street, London W1W 5PF, United Kingdom