Legal notice
Data Processing Addendum
Controller/processor roles, processing instructions, and security commitments. Effective July 25, 2026.
Back to legal documentsRoles
- The customer is normally the controller for customer data synchronized through Sentria Sync.
- Sentria is normally the processor for that customer data and may be controller for account, billing, security, abuse-prevention, and support operations.
- Customer-authorized sources and targets are third-party systems selected and authorized by the customer, not Sentria subprocessors in the usual processor sense.
Instructions and processing
- Sentria processes data to authenticate sources, discover contact collections or CRM views, pull selected records, normalize, match, preview, route, and apply approved write-back operations.
- Sentria maintains operational evidence for sync runs, conflicts, approvals, retries, skips, failures, support, and security.
- Sentria follows the customer's documented configuration and in-app instructions unless required by law or needed to protect the service, another customer, or connected systems.
Security
- Security measures include TLS for production traffic, encrypted credential storage, organization-scoped access controls, least-privilege provider scopes where available, audit evidence, backup controls, and incident response.
- Access to production data is limited to authorized operational need. Secrets are redacted from exports, audit metadata, and user-facing responses.
- Sentria notifies the customer without undue delay after becoming aware of a personal-data breach affecting customer data, so the customer can meet its controller obligations.
Subprocessors, transfers, and deletion
- Sentria uses only listed core subprocessors for production customer data and keeps a subprocessors page with purpose, region, and data categories.
- International transfers, if any, rely on an applicable transfer mechanism such as an adequacy decision or Standard Contractual Clauses.
- At termination or verified request, Sentria exports or deletes customer data according to the agreement and retention schedule. Backup deletion follows the documented backup-retention cycle unless immediate deletion is technically feasible and required.