Legal
Data Processing Agreement
Version 2026-09-15. This is the text in force today; earlier versions are kept, and the version you accepted is recorded against your account.
In short. For everything inside your workspace you are the controller and we are your processor. We act only on your instructions, we keep the data in Germany, we name every subprocessor, and we delete on request.
1.Roles, subject matter and duration
This agreement applies where [COMPANY] ("processor") processes personal data on behalf of your agency ("controller") in the course of providing sentryq Cloud. It forms part of, and is governed by, the Terms of Service.
The subject matter is the operation of your workspace: synchronising and storing conversations, fan records, payments, media, staff scheduling and performance data from the platforms you connect.
Processing lasts as long as your workspace exists, plus the retention period described in the deletion section below.
2.Processing only on your instructions
We process personal data only on your documented instructions, including in relation to transfers, unless we are required to do otherwise by law. Where the law requires it, we will tell you before processing unless the law forbids us to.
Your instructions are: this agreement, the Terms of Service, the settings you choose in your workspace, and anything you ask us in writing through our support address.
If we consider an instruction to breach data protection law, we will tell you and may pause that processing until it is resolved.
3.Confidentiality
Everyone we allow to process your data is bound by a duty of confidentiality that survives the end of their engagement, and is given access only to what their role requires.
Access to production systems holding customer data is restricted to named operators, is logged, and is reviewed when someone's role changes.
4.Security measures
We implement technical and organisational measures appropriate to the risk, including those below. We may change a measure for an equivalent or better one; we will not reduce the overall level of protection.
- Tenant isolation: a separate database, a separate object store and separate credentials per agency, rather than shared tables with a customer column.
- Encryption in transit (TLS) for every connection, and at rest for the secrets we hold on your behalf (AES-256-GCM).
- Passwords hashed with argon2id; session cookies signed, httpOnly and short-lived.
- Least-privilege credentials for storage and database access, scoped per workspace.
- Daily backups with tested restores, retained for 30 days.
- Audit logging of administrative actions, retained for two years.
- Rate limiting and abuse controls on authentication and signup.
5.Subprocessors
You give general authorisation for us to engage subprocessors. The current list, with what each does and where it operates, is published at /legal/subprocessors and forms part of this agreement.
We will give at least 30 days' notice before adding or replacing a subprocessor, by email to your account address. If you reasonably object on data protection grounds within that period, we will work with you to find an alternative; if none is available, you may terminate the affected part of the service without penalty.
Every subprocessor is bound by written terms imposing obligations no less protective than these. We remain liable to you for their performance.
6.International transfers
Your workspace, its database, its media and its backups are hosted in Germany.
Where a subprocessor is outside the EEA, transfers are covered by an adequacy decision or by Standard Contractual Clauses, and the data transferred is limited to what the subprocessors page describes for that provider.
7.Assisting you with data subject rights
Your workspace gives you the tools to find, export, correct and delete records yourself, which is the fastest route for most requests.
Where you need more, we will assist you by appropriate technical and organisational measures, taking into account the nature of the processing. We will acknowledge a request for assistance within two business days.
If a data subject contacts us directly about data inside your workspace, we will not respond substantively. We will tell them to contact you, and tell you that they contacted us.
8.Assisting you with obligations under Articles 32 to 36
We will assist you in ensuring compliance with your obligations on security, breach notification, impact assessments and prior consultation, taking into account the information available to us.
We will notify you of a personal data breach affecting your data without undue delay after becoming aware of it, and in any case within 72 hours, with the nature of the breach, the categories and approximate number of records affected as far as known, the likely consequences and the measures taken.
9.Deletion and return
You can export your data at any time from your workspace, in a machine-readable form.
When your workspace closes, data is retained for 30 days so that an accidental cancellation is recoverable, then permanently deleted. Copies in backups are removed as those backups rotate out, within a further 30 days.
You may instruct us to delete immediately rather than wait out the 30-day window. We will confirm in writing when deletion is complete.
We keep no copy afterwards except where the law requires us to, in which case we will tell you what and why.
10.Audit
We will make available the information necessary to demonstrate compliance with this agreement, and allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint.
Audits are at your cost, no more than once a year unless a breach or a regulator's instruction makes another necessary, on 30 days' notice, during business hours, and subject to confidentiality. They must not compromise the security or the data of other customers.
11.Annex 1 — what is processed
Categories of data subject: the fans who message your creators; the creators whose accounts you manage; your own staff, being chatters, managers and reviewers.
Categories of personal data: platform identifiers and display names; message content and attachments; purchase, tip and subscription records; fan notes and segment membership; staff names, email addresses, shift records, clock entries and performance scores.
Special category data: none is required by the service. Message content is written by fans and may incidentally contain anything they choose to write, which is why the workspace is isolated and access within it is role-based.
Nature and purpose: storing, organising, retrieving, synchronising with connected platforms, analysing for reporting, and sending messages at your instruction.
12.Annex 2 — technical and organisational measures
As set out in the security section above, which is incorporated here as Annex 2. The subprocessors page sets out the location and role of each provider involved in processing.
This document is drafted in plain English for clarity and is not legal advice. [COMPANY] is a placeholder for the operating entity and is replaced when that entity is named.