← Legal

Sentaro - Data Processing Agreement

Last updated: 2026-06-29

Parties

This Data Processing Agreement ("DPA") forms part of the agreement governing the Customer's use of the Services (the "Agreement") between Sentaro AB, org. no. 559350-3120, Birger Jarlsgatan 57, 113 56 Stockholm, Sweden ("Sentaro"), and the Customer identified in the Agreement or Order Form ("Customer"). Each a "Party" and together the "Parties".

1. Definitions

Capitalized terms not defined here have the meaning given in the Agreement. "Data Protection Laws", "Controller", "Processor", "Processing", "Personal Data", "Data Subject", "Supervisory Authority", "Subprocessor", "Restricted Transfer" and "SCCs" retain their meaning from the published DPA.

1.1 "Customer Data" means Personal Data Processed by Sentaro on behalf of the Customer in connection with the Services, including raw email content and metadata to the extent the Services are configured to process it.

1.2 "Derived Data" means data that Sentaro generates from Customer Data, including threat indicators, classifications, behavioral signals, features, embeddings, model weights and other model artifacts. Derived Data comprises Pseudonymized Data and Anonymized Data. Sentaro owns Derived Data; retention is set out in Section 9.

1.3 "Pseudonymized Data" means Derived Data from which direct identifiers have been removed or replaced but where re-identification may still be possible. Pseudonymized Data constitutes Personal Data and is Processed under this DPA.

1.4 "Anonymized Data" means data that has been irreversibly de-identified so that an individual cannot reasonably be singled out, linked across records, or inferred. Anonymized Data does not constitute Personal Data.

1.5 "Global Model" means Sentaro's closed and proprietary detection model that is trained on data derived from multiple customers and made available to all customers.

1.6 "Third-Party AI" means an external model (for example Anthropic Claude) that Sentaro uses as a Subprocessor to analyze a limited volume of anonymized data for the purpose of identifying threat signals.

2. Scope, Roles and Term

2.1 Roles. For the provision of the Services, the Customer is the Controller and Sentaro is the Processor of Customer Data.

2.2 Dual role for model development. To the extent Sentaro generates and uses Derived Data and Anonymized Data to develop, train and improve its detection models and the Global Model under Section 7, Sentaro acts as an independent Controller for that activity (and, for genuinely Anonymized Data, outside the scope of Data Protection Laws).

2.3 Term. This DPA begins on the Agreement effective date and ends when Sentaro has ceased Processing Customer Data, subject to the retention rules in Section 9.

2.4 Order of precedence. On conflict: (1) SCCs and transfer mechanisms; (2) this DPA; (3) Security Exhibit / TOMs; (4) the Agreement.

3. Processing Instructions

3.1 Sentaro Processes Customer Data only on the Customer's documented instructions, including to provide the Services as described in the Agreement, this DPA, and the Customer's configuration.

3.2 Sentaro notifies the Customer if it believes an instruction infringes Data Protection Laws and may suspend the relevant Processing until resolved.

3.3 The subject matter, categories and purposes of Processing are described in Annex 1.

4. Confidentiality and Access Model

4.1 Sentaro ensures personnel authorized to Process Customer Data are bound by confidentiality.

4.2 Limited human access. Sentaro is designed so that no Sentaro personnel read raw Customer email content in the ordinary course of providing the Services; analysis is automated. Access to limited Customer Data may occur only (a) where the Customer requests support and provides content; (b) to address a Security Incident or service integrity issue, under logged, approved controls; (c) where required by law; or (d) for the limited Third-Party AI analysis described in Section 7.4.

5. Security Measures

5.1 Encryption. Customer Data and Derived Data are encrypted in transit and at rest. Encryption keys are managed under Sentaro's key management procedures with role-based access. Further measures are described in Annex 2.

5.2 Security Incident notification. Sentaro notifies the Customer without undue delay and in any event within 48 hours of confirming a Security Incident, and provides information reasonably necessary for the Customer to meet its obligations.

6. Subprocessors

6.1 The Customer provides general authorization for Sentaro to engage Subprocessors to provide the Services.

6.2 Sentaro enters into written agreements with Subprocessors imposing data protection obligations substantially similar to this DPA and remains responsible for their acts and omissions.

6.3 Subprocessor list and notice. Sentaro maintains an up-to-date Subprocessor list on this page (see Annex 3) and gives at least 30 days prior notice of new Subprocessors (or via a subscription mechanism).

6.4 Third-Party AI Subprocessors. Where Sentaro uses Third-Party AI (e.g., Anthropic Claude) it engages such providers only under terms that (a) prohibit the provider from using Customer Data to train or improve the provider's own models, and (b) prohibit retention beyond what the processing requires. Such providers are listed in Annex 3.

6.5 The Customer may object to a new Subprocessor on reasonable data protection grounds within 10 days of notice; the Parties will work in good faith and, failing resolution, Sentaro may offer an alternative or the Customer may terminate the affected component.

7. Model Development and AI Training

7.1 Model development. The Customer instructs and agrees that Sentaro may generate Derived Data and Anonymized Data from the Processing of Customer Data and may use such data to develop, train, test, improve and operate its detection models, the Services, and the Global Model that is trained on data derived from multiple customers and made available to all customers, and for threat research. Sentaro does not train models on raw email content in identifiable form beyond what is required to deliver the Services.

7.2 Redaction. Sentaro redacts and pseudonymizes or anonymizes data used for training to the extent possible without losing the security signal the models require, and applies technical and organizational measures to limit exposure of identifiable content.

7.3 No reproduction of customer content. The Global Model is designed and tested not to reproduce one customer's raw email content to another customer in readable form.

7.4 Third-Party AI for analysis. Sentaro may have a limited volume of Customer Data analyzed by Third-Party AI (e.g., Anthropic Claude) solely to identify threat signals. Sentaro uses only providers whose terms prohibit using Customer Data to train or improve the provider's models and prohibit retention beyond the processing.

7.5 No third-party model training on Customer Data. Sentaro does not use Customer Data to train or fine-tune Third-Party AI and does not permit third-party providers to do so.

7.6 Legal basis. Sentaro relies on its legitimate interest in providing and improving cybersecurity for the Processing described in this Section, documented in a legitimate interest assessment, and updates its Privacy Policy and Annex 1 accordingly.

8. Assistance

8.1 Sentaro provides reasonable assistance for the Customer to respond to Data Subject requests, to the extent feasible.

8.2 Sentaro provides reasonable assistance with DPIAs and prior consultations, taking into account the nature of Processing and information available.

9. Deletion, Return and Retention

Retention follows three tiers based on how identifiable the data is. Only data that is no longer Personal Data is retained indefinitely.

9.1 Raw Customer Data. Raw email content is retained only as long as needed to deliver the Services: harmless email for 14 days, quarantined items for 180 days, and operational metadata for 180 days, after which it is deleted or de-identified.

9.2 Pseudonymized Data. Pseudonymized Data is retained for up to 5 years from collection and used during that period for model development and threat research, after which it is deleted or irreversibly anonymized.

9.3 Anonymized Data. Anonymized Data is owned by Sentaro and may be retained indefinitely, including after termination of the Agreement, because it does not constitute Personal Data.

9.4 On termination, and at the Customer's choice where available, Sentaro returns or deletes Customer Data within 30 days, except to the extent retention is required by law or permitted under this Section. On request, Sentaro certifies deletion.

10. Audits and Compliance Evidence

10.1 On request, Sentaro makes available reasonable information to demonstrate compliance (e.g., SOC reports, security documentation), subject to confidentiality.

10.2 The Customer may audit through an independent third party under reasonable conditions (notice, scope limits, no more than once per 12 months, no disruption).

11. International Transfers

11.1 Where Customer Data is subject to a Restricted Transfer, the Parties rely on an applicable transfer mechanism, including the SCCs (and UK/Swiss addenda as applicable), completed using Annex 1 and Annex 2. The Member State for SCC Clause 18 is Sweden.

12. Region-Specific Terms

California (CCPA/CPRA): Sentaro acts as a service provider for the provision of the Services and does not sell or share Customer Data. UK and Switzerland: the UK Addendum and Swiss modifications apply as needed.

13. Liability

Liability under this DPA is subject to the limitations in the Agreement, except where prohibited by Data Protection Laws or the SCCs.

14. Miscellaneous

14.1 The Parties cooperate in good faith to amend this DPA as needed to comply with changes in Data Protection Laws.

14.2 This DPA is governed by the law specified in the Agreement; if not specified, Swedish law applies, subject to mandatory Data Protection Laws and the SCCs.

Annex 1. Details of Processing

A. Subject matter: provision of cloud-based email security analysis, detection and response via Microsoft 365 and Google Workspace integrations, and development of Sentaro's detection models and the Global Model.

B. Duration: the term of the Agreement plus the retention periods in Section 9.

C. Nature and purpose: automated analysis of email and related signals to detect phishing, impersonation/BEC, malware and other threats; generation of security assessments; limited retention/quarantine/escalation; and model development and training, including the Global Model and limited Third-Party AI analysis.

D. Data Subjects: the Customer's employees, contractors and other end users whose email is processed, and external correspondents.

E. Categories: email headers and metadata; email content and attachments to the extent necessary for a security assessment; derived security signals; admin/account data.

F. Processing locations: Microsoft Azure regions as configured (EU and/or US), plus Subprocessors in Annex 3.

G. Retention: raw harmless email 14 days; quarantined items 180 days; operational metadata 180 days; Pseudonymized Data up to 5 years; Anonymized Data indefinite.

Annex 2. Technical and Organizational Measures (summary)

Access control with least privilege and MFA; encryption in transit (TLS 1.2+) and at rest (AES-256); data minimization; logical tenant isolation and scoped tokens for Microsoft 365 and Google Workspace APIs; secure development and change management; logging, monitoring and incident response; business continuity; third-party AI controls (no provider-side training, no retention beyond processing); reliance on Azure datacenter physical security.

Annex 3. Subprocessors

SubprocessorServiceLocationPurpose
Microsoft AzureCloud hostingEU and/or USInfrastructure, storage, networking
Anthropic (Claude)Third-Party AIUSLimited threat-signal analysis (no training on Customer Data)
CloudflareSecurity, DNS and CDNGlobalEdge protection, reliability
GrafanaData managementGlobalUsage logs, monitoring
GitHubDeveloper platformUSStoring and iterating with codebase

Annex 4. SCCs / UK Addendum / Swiss

Where applicable, the EU SCCs (Decision 2021/914) are incorporated and completed using Annex 1 and Annex 2. Module 2 (Controller to Processor) applies where the Customer is a Controller; Module 3 (Processor to Processor) where the Customer is a Processor for another Controller.