Data Processing Agreement
Version 1.0 · Last updated: 5 August 2026 · Incorporated into the Terms of Service for every customer. A countersigned copy is available on request at [email protected].
1. Parties and role
This agreement is between the customer (the controller) and BRIGHTOPS SMART SOLUTIONS S.L., trading as Sentilai — CIF B22733836, Calle de les Eres 7, 46726 Almiserà (Valencia), Spain (the processor). It implements Article 28 GDPR for the personal data Sentilai processes inside the customer's tenant, and forms part of the Terms of Service. Where Sentilai acts as controller (accounts, tickets, billing contacts), the Privacy Policy applies instead.
2. Subject matter, nature and purpose
Sentilai operates an AI-governance platform for the customer's tenant: proxying and governing the customer's developers' AI tool traffic, applying the customer's configured policies, producing audit metadata, optionally capturing prompt content on the customer's instruction, and governing enrolled devices. Duration: the term of the customer's subscription, plus the deletion window in section 9.
3. What is processed
| Category | Detail |
|---|---|
| Data subjects | The customer's developers, admins and other users of governed AI tools |
| Identifiers | Name, email, device identifiers (public key, hostname), tool identity |
| AI request metadata | Model, token counts, timing, outcome, policy decision, risk findings — never prompt or response content in the audit record |
| Prompt content | In transit always (that is what a gateway is). At rest only under the customer-enabled capture feature — off by default, secrets redacted before storage, tool payloads excluded, size-capped |
| Device data | Enrolled-device inventory, compliance/drift flags, detected AI agents; optional device event logs (14-day fixed retention) |
| MCP inventory | Server names and policy state — no content |
4. Instructions
Sentilai processes this data only on the customer's documented instructions. The tenant's configuration is the documented instruction: the policy screens, the prompt-capture toggle (with its consent text), retention settings, SIEM export destinations and provider routing choices are instructions given by the customer's own admins, recorded in the control-plane audit log. Sentilai will inform the customer if, in its view, an instruction infringes data-protection law.
5. Customer-directed processing
Three flows follow the customer's configuration and agreements rather than Sentilai's:
- LLM providers (Anthropic, OpenAI, Google, Azure OpenAI): in managed-key mode requests use the customer's own API keys under the customer's own provider agreement; in subscription mode the developers' own sessions pass through unchanged. These providers are the customer's processors or independent services, not Sentilai sub-processors. Residency warnings shown in the console are advisory only.
- SIEM export: the customer pulls or pushes its own audit rows to its own systems — egress under the customer's control.
- Log sharing with support: device-log bundles reach Sentilai staff only when a customer admin explicitly shares them.
6. Confidentiality
Access to customer data is limited to Sentilai staff who need it to operate the service, all of whom are bound by confidentiality obligations. Staff access to raw customer content is gated by a mandatory reason-for-access step and recorded in an append-only audit log that the customer's data is never mixed into.
7. Security measures (TOMs)
- Authentication: passkey-first (phishing-resistant) for customer admins, developers and Sentilai staff alike; no shared accounts.
- Encryption in transit: TLS on every public endpoint and between regions.
- Encryption at rest: customer LLM provider keys encrypted with AES-256-GCM, readable only by the services that need them through restricted database grants; backups client-side encrypted (AES-256) before upload, stored with object-lock protection against deletion.
- Tenant isolation: every query is tenant-scoped; row-level security provides defense-in-depth on policy-bearing tables; per-region data planes with no cross-region replication of tenant data.
- Audit: append-only request audit; a separate control-plane audit of admin actions; a staff meta-audit with mandatory access reasons.
- Data minimisation by architecture: audit rows carry metadata, never content; prompt capture is opt-in with pre-storage redaction; device logs are allowlisted event types with a fixed 14-day life.
- Retention enforcement: automated purge loops enforce the configured retention — they are code, not policy documents.
Sentilai holds no security certifications today and does not claim any. This list describes controls that exist and run, verifiable in the product's own audit surfaces.
8. Sub-processors
The customer gives general authorisation for the sub-processors listed at sentilai.com/subprocessors. That page is updated at least 30 days before a new sub-processor processes customer data; the customer may object on reasonable data-protection grounds within that window, and if no resolution is found may terminate the affected service with a pro-rata refund of prepaid fees. Sentilai imposes data-protection obligations on each sub-processor equivalent to this agreement and remains liable for their performance.
9. Retention, return and deletion
- Audit data is retained per the tenant's configured retention period (default 14 days) and purged automatically; device logs live 14 days, fixed.
- The customer can export its data at any time through the product's SIEM export and evidence-pack features — no exit request needed.
- On termination, Sentilai deletes the tenant's data within 30 days using a rehearsed offboarding procedure that covers every tenant-scoped table and storage prefix, unless EU or member-state law requires longer retention of a specific record.
10. Cross-tenant threat intelligence
One security feature aggregates signals across tenants, and this agreement names it rather than burying it: suspicious package names (typo-squatting defense) and hashed MCP tool-change fingerprints (rug-pull defense) are shared across tenants in anonymised form, only once at least three distinct tenants exhibit the same signal (k≥3), and never with prompt content or identifiers. It is on by default; a customer can have it disabled via support.
11. Assistance and breach notification
- Sentilai assists the customer with data-subject requests concerning tenant data — most are self-serve through the console; the rest via [email protected].
- Sentilai assists with DPIAs and prior consultations, with the platform documentation as the starting point.
- Sentilai notifies the customer of a personal-data breach affecting its tenant without undue delay, and in any event within 72 hours of becoming aware, with what is known at the time and updates as the picture completes.
12. Audits
Sentilai makes available the information reasonably necessary to demonstrate compliance with this agreement — documentation and reports first. Where that is genuinely insufficient, the customer (or an independent auditor that is not a competitor) may audit once per 12 months, on 30 days' notice, during business hours, at the customer's cost, without access to other customers' data.
13. Transfers
Tenant workload data is processed in the EU. Where a sub-processor's role involves a transfer outside the EU/EEA (see the sub-processor list), it is covered by the EU–US Data Privacy Framework and/or Standard Contractual Clauses per that vendor's published mechanism.
14. Liability and precedence
Liability under this agreement follows the Terms of Service, except where the GDPR mandates otherwise. If this agreement and the Terms conflict about personal-data processing, this agreement wins.
© 2026 Sentilai · Terms · Refunds · Privacy · Sub-processors · [email protected]