Legal notice

Data Processing Addendum

Controller/processor roles, processing instructions, and security commitments. Effective July 25, 2026.

Back to legal documents

Roles

  • The customer is normally the controller for customer data synchronized through Sentria Sync.
  • Sentria is normally the processor for that customer data and may be controller for account, billing, security, abuse-prevention, and support operations.
  • Customer-authorized sources and targets are third-party systems selected and authorized by the customer, not Sentria subprocessors in the usual processor sense.

Instructions and processing

  • Sentria processes data to authenticate sources, discover contact collections or CRM views, pull selected records, normalize, match, preview, route, and apply approved write-back operations.
  • Sentria maintains operational evidence for sync runs, conflicts, approvals, retries, skips, failures, support, and security.
  • Sentria follows the customer's documented configuration and in-app instructions unless required by law or needed to protect the service, another customer, or connected systems.

Security

  • Security measures include TLS for production traffic, encrypted credential storage, organization-scoped access controls, least-privilege provider scopes where available, audit evidence, backup controls, and incident response.
  • Access to production data is limited to authorized operational need. Secrets are redacted from exports, audit metadata, and user-facing responses.
  • Sentria notifies the customer without undue delay after becoming aware of a personal-data breach affecting customer data, so the customer can meet its controller obligations.

Subprocessors, transfers, and deletion

  • Sentria uses only listed core subprocessors for production customer data and keeps a subprocessors page with purpose, region, and data categories.
  • International transfers, if any, rely on an applicable transfer mechanism such as an adequacy decision or Standard Contractual Clauses.
  • At termination or verified request, Sentria exports or deletes customer data according to the agreement and retention schedule. Backup deletion follows the documented backup-retention cycle unless immediate deletion is technically feasible and required.