Data Processing Agreement
Last updated: 15 July 2026 · Effective date: 13 July 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Sentinella LLC, 8 The Green STE A, Dover, DE 19901, United States, with European headquarters in Brussels, Belgium ("Sentinella," the "Processor") and the customer identified in the applicable Order or subscription ("Customer," the "Controller") for the provision of the Sentinella Mare platform and related services (the "Services"), and is incorporated by reference into the Terms & Conditions and each Order.
This DPA applies to the extent Sentinella processes personal data on behalf of the Customer in the course of providing the Services ("Customer Personal Data"), within the scope of the GDPR (Regulation (EU) 2016/679) or equivalent applicable data protection law.
1. Roles and Scope
- For Customer Personal Data submitted to the Services, the Customer is the controller (or a processor acting on behalf of another controller) and Sentinella is the processor.
- For data Sentinella collects for its own purposes — such as account, billing, and Site data — Sentinella acts as an independent controller as described in our Privacy Policy, and that processing is outside the scope of this DPA.
2. Details of Processing
| Item | Description |
|---|---|
| Subject matter | Provision of maritime hybrid threat intelligence services via the Sentinella Mare platform |
| Duration | The term of the applicable Order, plus the deletion period in Section 9 |
| Nature and purpose | Hosting, monitoring, analysis, scoring, alerting, reporting, and related support as instructed by the Customer through the Services |
| Categories of data subjects | Customer's authorised users; Customer personnel; individuals whose data is contained in content the Customer submits to the Services |
| Categories of personal data | Name, business contact details, credentials, role/title; usage data; any personal data contained in Customer-submitted content or assistant queries |
| Special categories | None intended. The Customer agrees not to submit special category data (Art. 9 GDPR) to the Services. |
3. Processor Obligations
Sentinella will:
- Process Customer Personal Data only on the Customer's documented instructions — including as given through the Customer's configuration and use of the Services — unless required otherwise by EU or Member State law, in which case Sentinella will inform the Customer before processing unless legally prohibited (Art. 28(3)(a));
- Ensure persons authorised to process Customer Personal Data are bound by confidentiality obligations (Art. 28(3)(b));
- Implement appropriate technical and organisational measures as described in Annex II (Art. 32);
- Respect the sub-processor conditions in Section 5 (Art. 28(3)(d));
- Taking into account the nature of the processing, assist the Customer with data subject requests under Chapter III GDPR (Art. 28(3)(e));
- Assist the Customer with its obligations under Articles 32–36 GDPR, including breach notification and data protection impact assessments, taking into account the nature of processing and information available to Sentinella (Art. 28(3)(f));
- At the Customer's choice, delete or return Customer Personal Data at the end of the Services as set out in Section 9 (Art. 28(3)(g));
- Make available information necessary to demonstrate compliance with Article 28 and allow and contribute to audits as set out in Section 8 (Art. 28(3)(h));
- Inform the Customer immediately if, in Sentinella's opinion, an instruction infringes the GDPR or other applicable data protection law.
4. Customer Obligations
The Customer is responsible for: the lawfulness of Customer Personal Data and of its instructions; providing any required notices and establishing a lawful basis for the data it submits; configuring and using the Services appropriately for the sensitivity of its data; and not submitting special category data or data of minors to the Services.
5. Sub-processors
- The Customer provides general written authorisation for Sentinella to engage the sub-processors listed in Annex III, and for updates to that list.
- Sentinella will provide at least fourteen (14) days' notice of any intended addition or replacement of a sub-processor (via the Site or email), during which the Customer may object on reasonable data protection grounds. If the parties cannot resolve an objection, the Customer may terminate the affected Services and receive a pro-rata refund of prepaid, unused fees.
- Sentinella will impose data protection obligations on each sub-processor materially equivalent to those in this DPA and remains liable for its sub-processors' performance.
6. International Transfers
Where the provision of the Services involves a transfer of Customer Personal Data from the EEA, the UK, or Switzerland to a country without an adequacy decision (including to Sentinella LLC in the United States), the parties agree that the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), Module Two (controller-to-processor) or Module Three (processor-to-processor) as applicable, are incorporated into this DPA by reference, completed as follows: Clause 7 (docking) included; Clause 9(a) Option 2 with the notice period in Section 5; Clause 11 optional language not included; Clause 17 governed by Belgian law; Clause 18 courts of Brussels, Belgium; Annexes I–III of the SCCs completed by the Annexes to this DPA. Sentinella will implement supplementary measures where reasonably necessary to ensure an essentially equivalent level of protection.
7. Personal Data Breach
Sentinella will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to assist the Customer in meeting its obligations under Articles 33–34 GDPR, followed by updates as the investigation progresses. Sentinella's notification is not an acknowledgement of fault or liability.
8. Audits
Sentinella will make available documentation reasonably necessary to demonstrate compliance with this DPA (including summaries of third-party audits or certifications where available). Where the Customer reasonably determines documentation is insufficient, the Customer may conduct an audit — at most once per 12-month period, on at least 30 days' notice, during business hours, without disrupting operations, subject to confidentiality obligations, and at the Customer's cost — or the parties may agree on a mutually acceptable independent auditor.
9. Return and Deletion
Upon termination or expiry of the Services, Sentinella will, at the Customer's choice, return Customer Personal Data in a commonly used format or delete it, and delete existing copies within ninety (90) days, unless EU or Member State law requires longer storage. Deletion from backups occurs in the ordinary backup rotation cycle, during which the data remains protected under this DPA.
10. Liability and Order of Precedence
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms & Conditions or the applicable Order, to the maximum extent permitted by applicable law. Nothing in this Section limits either party's liability to data subjects under Article 82 GDPR. In case of conflict, the order of precedence is: (1) the SCCs, (2) this DPA, (3) the Order, (4) the Terms & Conditions.
Annex I — Processing Details
As set out in Section 2 of this DPA. Data exporter: the Customer. Data importer: Sentinella LLC, 8 The Green STE A, Dover, DE 19901, USA; contact james@sentinellaglobal.com. Competent supervisory authority: the Belgian Data Protection Authority, unless otherwise determined under Clause 13 SCCs.
Annex II — Technical and Organisational Measures
Sentinella implements the following measures, proportionate to the nature and risk of the processing, and will develop and strengthen these measures as the Services evolve:
- Encryption of data in transit: all Site and Platform traffic is served over HTTPS/TLS, enforced at the infrastructure level;
- Managed cloud infrastructure: the Platform runs on established managed providers (Vercel, Neon, Upstash, Railway, Convex) whose platforms provide infrastructure-level security controls, physical security, and availability measures;
- Access controls: production systems and administrative accounts are protected by unique credentials, with access limited to authorised personnel;
- Data keying: customer billing and entitlement data is keyed and retrieved per individual user account;
- Error monitoring and diagnostics (Sentry) to detect and remediate application faults;
- Payment isolation: payment card data is collected and processed directly by Stripe and never stored on Sentinella systems;
- Vendor selection: sub-processors are established providers operating under their own published security and compliance programmes;
- Incident handling: faults and suspected security events are triaged by the engineering team, supporting the breach notification commitments in Section 7.
Sentinella reviews these measures periodically and updates this Annex as additional controls (including enhanced security monitoring, formalised access management, and audit processes) are implemented.
Annex III — Authorised Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Frontend and Platform hosting, global content delivery (CDN), serverless functions, and scheduled jobs | USA / EU |
| Neon, Inc. | Serverless PostgreSQL database storing account, subscription, transaction, billing, churn, and conversion records | USA / EU |
| Upstash, Inc. | Managed caching layer for Platform data | USA / EU |
| Railway Corp. | Full-stack backend deployment and always-on persistent services, including background workers and real-time maritime data relays | USA |
| Convex, Inc. | Database services for email and waitlist registration | USA |
| Anthropic, PBC | Large language model API powering the in-platform assistant ("Maria"), processing user queries and associated dashboard context | USA |
| GitHub, Inc. (Microsoft) | Source-code version control, collaboration, and CI/CD deployment automation | USA |
| Functional Software, Inc. (Sentry) | Error monitoring and application diagnostics | USA / EU |
| Stripe, Inc. | Payment processing | USA / EU |
| HubSpot, Inc. | Customer relationship management | USA / EU |
| Google LLC (Google Workspace) | Email and business correspondence | USA / EU |
| Slack Technologies (Salesforce, Inc.) | Internal communications supporting service delivery and customer support | USA / EU |