Skip to the main content
SentinelSphere CRA

The small print

Data processing agreement

The GDPR Article 28(3) processor terms we sign with customers: what we process, on whose instructions, our security measures, sub-processors, retention and audits.

  • Version of 7 September 2026

⚖ marks a point a French lawyer still has to confirm before we use these terms with a customer.

Jump to a section

1. When this applies

When you become a customer, the source code, SBOMs, configuration and documentation you give us — we call them customer materials — may contain personal data: the names and addresses of your engineers in commit metadata, identifiers in test fixtures, contacts in a configuration file. For that data you are the controller and we are the processor, and these terms govern what we may do with it.

Our own business data — the enquiry you sent us, your billing details, your portal accounts — is not covered here. For that we are the controller and our privacy notice applies.

2. What we process, and why

Subject matterPoint-in-time analysis of your source code, configuration, SBOMs and documentation; generation of the compliance documents; hosting the resulting evidence in your portal; and, where you order a monitoring set-up, temporary access to the tool account you own while we configure it.
DurationEach statement of work is a fixed-scope engagement that ends on acceptance; processing lasts for that engagement, plus the retention period in section 8. Access to a tool account you own lasts only as long as the set-up, and every credential is returned or destroyed at hand-over.
NatureAutomated scanning, storage, indexing, correlation with vulnerability feeds at the moment a deliverable is produced, AI-assisted drafting under human review, and document generation. We run no continuous monitoring on your behalf, we are sent no alerts, and we send none.
People concernedYour employees and contractors and, incidentally, your own customers or users whose data appears in the materials.
DataNames and business contact details (commit authors, code owners, escalation contacts), identifiers in code and configuration, and whatever incidental personal data your materials contain. We do not expect special categories of data and you undertake not to send them.

3. We act on your instructions

We process personal data only on your documented instructions: the agreement, this document, the statement of work and any written instruction from your point of contact. If we think an instruction breaks data protection law, we tell you. We process in the European Union and do not move your data outside it without your written authorisation.

4. Who can see it

Access is limited to the named people assigned to your engagement, with individual accounts and logged access. Everyone with access is bound by confidentiality.

5. How we protect it

  • EU hosting, in France, with encryption in transit and at rest and encrypted nightly backups whose restore we test.
  • One organisation per tenant on every table, with an automated test that proves one customer cannot read another's rows.
  • Least-privilege repository tokens that you issue and can revoke; we store references, not credentials, and we drop them at the end of the engagement.
  • An append-only audit log, hash-chained so a change to it is visible, and a checksum on every stored artefact.
  • A named engineer signs every deliverable before you can see it.
  • Working logs are redacted before they are written, and no customer material goes into our own system telemetry.
  • We run our own product through the pipeline we sell you and publish the result.

6. Helping you answer requests

If one of your people asks you for their data, most of the answer is already in your portal: a summary of what we hold, a full export as a zip with a checksum for every file, and an erasure request. A request that reaches us directly is forwarded to you without undue delay, and we help you answer it. We also help with your obligations on security, breach notification and impact assessments; work beyond reasonable effort is charged at the rate in your statement of work.

7. Sub-processors

You authorise the sub-processors on our published list at the date you sign. We give you at least 30 days' notice before adding or replacing one, and you may object in writing on reasonable data-protection grounds; if we cannot agree, either of us may end the affected statement of work without penalty. Each sub-processor is bound by written terms equivalent to these, and we stay responsible to you for what they do.

Model providers. We engage one only where its terms say inputs and outputs are not used to train its models and the processing happens in an EU region. The term, with its reference and the date we checked it, is recorded in the schedule to your agreement. See how we use AI.

8. Keeping and deleting

We delete customer materials — clones, uploaded SBOMs and their component inventories, scan findings, control mappings, threat models and unsigned drafts, with their stored artefacts — 30 days after the services end, unless you ask us in writing before that date to return them or keep them longer. The end of the services is recorded as a dated entry in your audit log, which is what starts the clock.

We keep, because you or the law needs them: signed deliverables and their sign-off records, acceptance certificates, your decision log, invoices and contracts, service-level measurements and the audit log itself. Backups expire on their own schedule and are restored only for disaster recovery.

The deletion job runs daily, records what it deleted in your audit log, and can be run first in a mode that reports what it would delete without deleting anything. We certify a deletion in writing on request.

9. If there is a breach

We notify you without undue delay after becoming aware of a personal data breach affecting your materials, to the contacts in your statement of work, with what we know at the time and more as we learn it. We do not notify a supervisory authority or your users on your behalf unless you instruct us in writing.

10. Audits

We give you what you need to check that we comply: this document, our record of processing, the sub-processor list, our security documentation and the audit log for your organisation. You, or an auditor bound by confidentiality who is not a competitor of ours, may audit us once a year on 30 days' notice, during business hours, at your cost, without disrupting the services. A remote audit by questionnaire and document review is the normal form.

11. Contacts

Ours: [DPO OR PRIVACY CONTACT EMAIL]. Yours: the privacy contact named in your statement of work.

12. Term and law

These terms apply for as long as we process personal data for you, and survive the end of the agreement until deletion under section 8. French law governs them, alongside the GDPR and the French loi Informatique et Libertés.

Schedules attached to the signed version

  1. The authorised sub-processors, with region, data and — for model providers — the no-training term.
  2. The technical and organisational measures, expanded from section 5.
  3. Your own instructions for the engagement: repositories and branches in scope, contacts, any pseudonymisation you want, any extended retention.

Ask us for the full signable version at any point in a conversation; we send it with the master services agreement and the statement of work.

Anything here you would like explained?

Ask us. An engineer answers, in plain words, and says so when a question is one for your own lawyer.