Data Processing Addendum

This Data Processing Addendum (the “DPA”) governs the processing of personal data that Sentia Labs, Inc. (“Sentia”, “we”) carries out on behalf of a customer (“Customer”, “you”) in the course of providing the Sentia platform. It applies wherever your use of the platform involves personal data protected by the EU General Data Protection Regulation, the UK GDPR and the Data Protection Act 2018, Canadian federal or provincial privacy law, or United States state privacy law.

This addendum is already in force

If your procurement or legal process requires a countersigned copy, write to hello@sentialabs.ai with the legal name and registered address of the contracting entity and the name of the signatory. A countersigned copy records the same terms as this page; it does not change them, and it is not a precondition of the protections here.

Where this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails. Where it conflicts with the Standard Contractual Clauses described in International transfers, those clauses prevail.

Roles, scope and subject matter

Sentia processes personal data in two distinct capacities, and it matters which one applies to a given record.

As processor. For everything you bring into or generate inside your workspace, you are the controller and we are the processor. Where you are yourself a processor for your own customers, you are that processor and we are your subprocessor. This covers research material you upload, interview audio and video, evidence and verbatim quotes, analytics and product usage events sent through our SDK or drawn from your connected analytics provider, content synchronized from the integrations you connect, research screenshots, and the agent profiles, digital twins, embeddings and simulation results derived from all of it.

As controller. For the data we need to run Sentia as a business, we are the controller and this DPA does not apply. That is account identity (email, name, avatar), invitation email addresses, comment author names and email addresses, billing data, IP addresses recorded in our audit log, and our own product telemetry. That processing is described in our Privacy Policy.

Subject matter, nature and purpose

The subject matter of the processing is the provision of the Sentia platform: a system that ingests a customer's research and product data, builds panels of simulated agents grounded in that data, runs those agents through decision scenarios, and reports the results back with citations to the underlying evidence.

The nature of the processing includes collection by upload, by SDK ingest and by integration synchronization; transcription of audio and video to text; document parsing; extraction of evidence and verbatim quotes with citations; generation of vector embeddings; storage, indexing and retrieval; inference against AI models operated by the subprocessors referenced in Annex III; aggregation and statistical scoring; presentation in reports; export; and deletion.

The purpose is limited to providing, securing, supporting and maintaining the platform for you, and to nothing else. We do not use personal data processed on your behalf for our own purposes, and we do not use it to train or fine-tune any model.

Duration

Processing lasts for the term of your subscription, plus the period needed to complete the deletion or return described in Deletion or return of personal data.

Categories of data subject

  • Your end users. The people who use your product, whose behavioral events reach us through our SDK or through the analytics provider you connect.
  • Research participants. The people whose interviews, transcripts, survey responses and verbatim quotes you ingest, and whose words may ground a digital twin. Where you create a twin of a named individual, you are responsible for establishing and documenting the lawful basis and permissions required for that processing.
  • Your own personnel. Your employees and contractors who hold accounts on the platform, whose identity, role, comments and activity are processed so they can use it. Account identity and audit records for these people are also processed by us as controller.

Types of personal data

The categories we hold are itemized in Annex I. In summary: identifiers and pseudonymous identifiers; free-text content authored by or about a data subject, including interview verbatims and messages drawn from your integrations; behavioral event trails; derived profiles and embeddings; and, where you use authenticated browser research, credentials for your own systems.

Processing on documented instructions

We process personal data on your behalf only on your documented instructions, including with regard to transfers of personal data to a third country or an international organization.

Your documented instructions consist of:

  • this DPA and the Terms of Service;
  • the configuration choices you make in the platform, including the sources you connect, the panels you build, the simulations you run and the retention and deletion actions you take; and
  • any further written instruction you give us under this section, which we will act on where it is technically feasible and lawful.

Send further instructions to hello@sentialabs.ai. Where an instruction requires work beyond the functionality of the platform, we will tell you before we start, and we may charge on a time and materials basis after agreeing the scope with you.

We will inform you if, in our opinion, an instruction infringes the GDPR, the UK GDPR or another applicable data protection provision. We may suspend the affected processing until the instruction is withdrawn, confirmed or amended.

We will process personal data other than on your instructions only where a law to which we are actually subject requires it. Where such a law requires the processing, we will inform you of that legal requirement before processing, unless the law prohibits that notification on important grounds of public interest.

Confidentiality

We ensure that every person authorized to process personal data on your behalf has committed to confidentiality, in writing, or is under an appropriate statutory obligation of confidentiality. This applies to our employees and equally to contractors, temporary staff and any individual working under our direction who may come into contact with your data.

These commitments survive the end of the person's engagement:

  • written confidentiality obligations are a condition of employment or engagement, executed before any access is granted;
  • access is granted on a least-privilege basis and is limited to the individuals who need it to deliver, support or secure the service; and
  • access is revoked on the termination of employment or engagement, and administrative access to customer environments is recorded in our audit log.

Security of processing

We implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as well as the risk to the rights and freedoms of natural persons.

Those measures are set out in Annex II, which forms part of this DPA. Our Security page summarizes them.

We may update the measures in Annex II over time, provided that no update materially reduces the overall level of security of the service.

Subprocessors

You give us a general written authorization to engage subprocessors. The current list is published and maintained at Subprocessors, and is referenced in Annex III. The published list is the authoritative version.

Before we add a subprocessor or replace an existing one, we will give at least 30 days' advance notice. To subscribe to those notifications, email hello@sentialabs.ai. Within 30 days of the notice you may object in writing, on reasonable data protection grounds, by writing to the same address. We will work with you in good faith to address the objection, for example by making the affected functionality optional or by routing the processing differently. If we cannot accommodate the objection within a reasonable period, you may terminate the affected part of the service, without penalty and with a pro-rata refund of prepaid fees for the terminated portion.

Every subprocessor is engaged under a written contract imposing data protection obligations that are, in substance, no less protective than those in this DPA. Where a subprocessor fails to fulfill those obligations, we remain fully liable to you for the performance of that subprocessor's obligations.

Assistance with data subject rights

Taking into account the nature of the processing, we assist you by appropriate technical and organizational measures, insofar as this is possible, in fulfilling your obligation to respond to requests to exercise a data subject's rights under Chapter III of the GDPR and the equivalent provisions of the UK GDPR and other applicable law: access, rectification, erasure, restriction of processing, notification of rectification or erasure, data portability, objection, and rights relating to automated decision-making.

Most of these can be exercised directly by you inside your workspace, because you control the data in it. Where they cannot, we will assist on request within a period that allows you to meet your own statutory deadline.

  • Access and portability. The platform supports a workspace-scoped export of the personal data associated with a data subject, in a structured, commonly used and machine-readable format.
  • Rectification and restriction. You can correct or remove source material in your workspace directly. Where a correction must reach derived material, we will assist.
  • Objection and automated decision-making. Sentia does not make automated decisions producing legal or similarly significant effects about the data subjects whose data it processes. Its output is a simulated result presented to a human, and our Acceptable Use Policy forbids using it to make or materially inform a decision about a specific individual.

If a data subject contacts us directly about data we process on your behalf, we will not respond to the substance of the request ourselves. We will tell them to contact you, and we will tell you promptly.

Personal data breach, DPIAs and prior consultation

We will notify you of a personal data breach affecting personal data we process on your behalf without undue delay, and in any event within 72 hours of becoming aware of it. This duty is ours and stands alone: it does not depend on you asking, and it is not conditional on our having finished the investigation.

Notification goes to the workspace owners and administrators on record and, where you have given us one, to your designated security contact. Keep that contact current in your workspace settings.

To the extent the information is available to us at the time, the notification will describe:

  • the nature of the breach, including where possible the categories and approximate number of data subjects and of personal data records concerned;
  • the name and contact details of our point of contact for further information;
  • the likely consequences of the breach; and
  • the measures we have taken or propose to take to address it, including measures to mitigate its possible adverse effects.

Where we cannot provide all of that at once, we will provide it in phases without further undue delay rather than waiting for a complete picture. We will cooperate with you and take reasonable steps as you direct to assist in your investigation, mitigation and remediation, and to help you meet your own notification obligations to supervisory authorities and to data subjects. Our notification is not, and should not be read as, an acknowledgement of fault or liability.

Report a suspected security issue to hello@sentialabs.ai. Our Security page sets out what we commit to in response.

Data protection impact assessments and prior consultation

Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with your data protection impact assessments under Article 35 and with any prior consultation of a supervisory authority under Article 36, where the assessment or consultation relates to processing we carry out on your behalf. This assistance includes the information in Annex I and Annex II, our Security page, our Privacy Policy, and answers to reasonable written questions.

Deletion or return of personal data

At the end of the provision of services, we will delete or return all personal data processed on your behalf, and delete existing copies, unless a law to which we are subject requires storage of the personal data.

The choice between deletion and return is yours, not ours. Tell us which you want, at hello@sentialabs.ai, within 30 days of termination or expiry. If you choose return, we will make an export available in a structured, commonly used and machine-readable format and then delete. If you do not tell us within 30 days, we will proceed to deletion.

Deletion is executed across the systems that hold your data, including our databases, object storage, search and vector indexes, caches, and content held with the subprocessors that process it on our behalf. Each erasure is recorded in an append-only log, which records that a deletion occurred and what it covered. It does not retain the deleted content.

Some systems hold transient copies that are not addressable for individual deletion, such as processing queues, workflow execution records, and encrypted backups. These expire on fixed retention cycles rather than being edited to remove individual records, and a restored backup is re-subjected to any outstanding deletion. Our Privacy Policy explains the criteria we use for retention.

Workspace erasure, per-subject erasure and export are available to workspace administrators through our API, and we will run any of them for you on request. Write to hello@sentialabs.ai and we will confirm when it has completed.

Information and audit

We make available to you all information necessary to demonstrate compliance with the obligations in Article 28 of the GDPR and the equivalent provisions of the UK GDPR, and allow for and contribute to audits, including inspections, conducted by you or by another auditor you mandate.

By default we satisfy this by providing information. On request, and no more than once in any 12-month period, we will provide the current version of this DPA and its annexes, our security documentation, our subprocessor list, our retention statement, the results of any independent audit or certification we then hold, and written responses to a reasonable security questionnaire.

You retain the right to inspect. Where the information we provide is genuinely insufficient to demonstrate compliance, or where you are required by a supervisory authority to inspect, you may conduct an on-site inspection of the facilities and systems used to process your personal data, subject to the following:

  • at least 30 days' written notice, and a scope agreed in advance;
  • no more than once in any 12-month period, except following a personal data breach affecting your data or where a supervisory authority requires a further inspection, in which case the frequency limit does not apply;
  • conducted during normal business hours, in a manner that does not disrupt our operations or the security or confidentiality of other customers' data;
  • by you or by an independent auditor you mandate who is not a competitor of ours, and who is bound by confidentiality obligations no less protective than those in this DPA; and
  • at your cost, save that where the inspection reveals a material breach of this DPA by us, we will bear the reasonable cost of that inspection.

Where a facility is operated by a subprocessor rather than by us, we will use reasonable efforts to obtain the access needed, and will provide the subprocessor's own audit reports and certifications where our contract with them permits.

International transfers

We are based in the United States. Personal data may be processed in the United States and in other countries where we or our sub-processors operate.

Transfer mechanism

For transfers of personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on the Standard Contractual Clauses. The Commission Implementing Decision (EU) 2021/914 Standard Contractual Clauses are incorporated into this DPA by reference and take effect automatically, with no further signature, whenever a restricted transfer occurs. Where you are a controller and we are a processor, Module Two applies. Where you are a processor and we are your subprocessor, Module Three applies.

For the purposes of those clauses, and unless we agree otherwise in writing:

  • you are the data exporter and Sentia Labs, Inc. is the data importer;
  • the optional docking clause applies, and in Clause 9 the parties select Option 2, general written authorization, with the 30 days' notice period set out in Subprocessors;
  • in Clause 11 the optional independent dispute resolution body language does not apply;
  • Annexes I, II and III to the clauses are populated by Annex I, Annex II and Annex III of this DPA respectively.

For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, issued by the Information Commissioner under section 119A of the Data Protection Act 2018, is incorporated by reference and applies to those transfers, with the EU Standard Contractual Clauses as its Approved EU SCCs and with Tables 1 to 4 populated by the corresponding details in this DPA.

For transfers subject to the Swiss Federal Act on Data Protection, the Standard Contractual Clauses apply with the amendments recognized by the Swiss Federal Data Protection and Information Commissioner: references to the GDPR are read as references to the Swiss Act, the competent authority is the Swiss Commissioner, and the clauses also protect the data of legal entities until the Swiss Act ceases to extend to them.

The transfer basis relied on for each subprocessor is stated on our Subprocessors page. We carry out transfer impact assessments for restricted transfers, will notify you if we become legally unable to comply with the Standard Contractual Clauses, and will notify you of any binding request from a public authority for personal data processed on your behalf unless we are legally prohibited from doing so. Where prohibited, we will challenge the prohibition and seek a waiver, and will provide the minimum amount of information permissible.

General terms

This DPA takes effect when you accept the Terms of Service and continues for as long as we process personal data on your behalf. Its obligations on confidentiality, deletion, transfers and audit survive termination for as long as we hold any of your personal data.

Liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service, except where applicable data protection law does not permit that. Nothing in this DPA limits a data subject's rights under the Standard Contractual Clauses.

We may update this DPA where a change in law, in the platform, or in our subprocessors requires it. Material changes are notified as described in the Terms of Service. Changes to the subprocessor list follow the notice and objection process in Subprocessors.

Privacy questions and data protection notices under this DPA go to hello@sentialabs.ai. Security incidents use the same monitored address.


Annex I: description of processing

A. Parties

Data exporter (controller, or processor acting for its own controllers): the Customer, being the legal entity that accepted the Terms of Service, at the address on its account. Its activities relevant to the transfer are its use of the Sentia platform for product research and decision simulation. Its contact is the workspace owner on record. Its role is controller, except where it is itself a processor for its own customers, in which case it is a processor.

Data importer (processor): Sentia Labs, Inc. Contact: hello@sentialabs.ai. Its activities relevant to the transfer are the provision of the Sentia platform. Its role is processor, or subprocessor where the Customer is a processor.

B. Description of the transfer

Sensitive data: none is requested or required. The platform is not designed for special category data, criminal offence data, protected health information, payment card data or government identifiers, and the Customer must not submit them without our prior written agreement. Because free-text research material is stored as submitted, the Customer is responsible for what appears in it.

Nature and purpose of the processing: as described under Roles, scope and subject matter. In outline: ingest, transcription, parsing, evidence extraction with citations, embedding, storage and retrieval, model inference, aggregation and scoring, reporting, export and deletion, for the sole purpose of providing, securing, supporting and maintaining the platform for the Customer.

Duration: the term of the subscription, plus the period needed to complete deletion or return under Deletion or return of personal data, subject to the retention cycles described in that section.

Transfers to subprocessors: the subject matter, nature and duration of the processing carried out by each subprocessor are set out on the Subprocessors page.

C. Competent supervisory authority

For transfers under the EU Standard Contractual Clauses, the competent supervisory authority is that of the Member State in which the data exporter is established, or, where the exporter is not established in the European Economic Area, that of the Member State in which its Article 27 representative is established or in which the data subjects are located. For UK transfers it is the Information Commissioner's Office. For Swiss transfers it is the Federal Data Protection and Information Commissioner.

Annex II: technical and organizational measures

We maintain administrative, technical and physical safeguards designed to protect personal data against unauthorized access, disclosure, alteration and loss. Our Security page summarizes them.

Core safeguards

  • Identity and access management based on least privilege.
  • Encryption in transit and at rest, with logical separation of customer data.
  • Secure change management, vulnerability management, monitoring, and auditability.
  • Incident response, backup, recovery, and business continuity processes.
  • Confidentiality obligations and security requirements for personnel and subprocessors.

Annex III: subprocessors

The authoritative and maintained list, including what each subprocessor does and the transfer basis relied on for it, is published at Subprocessors. That page is the version of record for the purposes of this annex and of Annex III to the Standard Contractual Clauses, and it is where the 30 days' advance notice described in Subprocessors is given.

Subprocessors fall into the following categories: AI model and inference providers, including the embedding, vector search, transcription, document parsing and evaluation services the platform depends on; hosting and data storage providers; platform services such as authentication, payments, metering and transactional email; and observability providers. AI providers that process customer data are included in the maintained list above.

Providers you connect yourself, such as your analytics platform or your issue tracker, are not our subprocessors. They are your own sources, connected on your instruction, and your relationship with each of them is your own.