Legal

Data Processing Agreement

Last updated: 15 July 2026 · Effective date: 13 July 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Sentinella LLC, 8 The Green STE A, Dover, DE 19901, United States, with European headquarters in Brussels, Belgium ("Sentinella," the "Processor") and the customer identified in the applicable Order or subscription ("Customer," the "Controller") for the provision of the Sentinella Mare platform and related services (the "Services"), and is incorporated by reference into the Terms & Conditions and each Order.

This DPA applies to the extent Sentinella processes personal data on behalf of the Customer in the course of providing the Services ("Customer Personal Data"), within the scope of the GDPR (Regulation (EU) 2016/679) or equivalent applicable data protection law.

1. Roles and Scope

2. Details of Processing

ItemDescription
Subject matterProvision of maritime hybrid threat intelligence services via the Sentinella Mare platform
DurationThe term of the applicable Order, plus the deletion period in Section 9
Nature and purposeHosting, monitoring, analysis, scoring, alerting, reporting, and related support as instructed by the Customer through the Services
Categories of data subjectsCustomer's authorised users; Customer personnel; individuals whose data is contained in content the Customer submits to the Services
Categories of personal dataName, business contact details, credentials, role/title; usage data; any personal data contained in Customer-submitted content or assistant queries
Special categoriesNone intended. The Customer agrees not to submit special category data (Art. 9 GDPR) to the Services.

3. Processor Obligations

Sentinella will:

  1. Process Customer Personal Data only on the Customer's documented instructions — including as given through the Customer's configuration and use of the Services — unless required otherwise by EU or Member State law, in which case Sentinella will inform the Customer before processing unless legally prohibited (Art. 28(3)(a));
  2. Ensure persons authorised to process Customer Personal Data are bound by confidentiality obligations (Art. 28(3)(b));
  3. Implement appropriate technical and organisational measures as described in Annex II (Art. 32);
  4. Respect the sub-processor conditions in Section 5 (Art. 28(3)(d));
  5. Taking into account the nature of the processing, assist the Customer with data subject requests under Chapter III GDPR (Art. 28(3)(e));
  6. Assist the Customer with its obligations under Articles 32–36 GDPR, including breach notification and data protection impact assessments, taking into account the nature of processing and information available to Sentinella (Art. 28(3)(f));
  7. At the Customer's choice, delete or return Customer Personal Data at the end of the Services as set out in Section 9 (Art. 28(3)(g));
  8. Make available information necessary to demonstrate compliance with Article 28 and allow and contribute to audits as set out in Section 8 (Art. 28(3)(h));
  9. Inform the Customer immediately if, in Sentinella's opinion, an instruction infringes the GDPR or other applicable data protection law.

4. Customer Obligations

The Customer is responsible for: the lawfulness of Customer Personal Data and of its instructions; providing any required notices and establishing a lawful basis for the data it submits; configuring and using the Services appropriately for the sensitivity of its data; and not submitting special category data or data of minors to the Services.

5. Sub-processors

6. International Transfers

Where the provision of the Services involves a transfer of Customer Personal Data from the EEA, the UK, or Switzerland to a country without an adequacy decision (including to Sentinella LLC in the United States), the parties agree that the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), Module Two (controller-to-processor) or Module Three (processor-to-processor) as applicable, are incorporated into this DPA by reference, completed as follows: Clause 7 (docking) included; Clause 9(a) Option 2 with the notice period in Section 5; Clause 11 optional language not included; Clause 17 governed by Belgian law; Clause 18 courts of Brussels, Belgium; Annexes I–III of the SCCs completed by the Annexes to this DPA. Sentinella will implement supplementary measures where reasonably necessary to ensure an essentially equivalent level of protection.

7. Personal Data Breach

Sentinella will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to assist the Customer in meeting its obligations under Articles 33–34 GDPR, followed by updates as the investigation progresses. Sentinella's notification is not an acknowledgement of fault or liability.

8. Audits

Sentinella will make available documentation reasonably necessary to demonstrate compliance with this DPA (including summaries of third-party audits or certifications where available). Where the Customer reasonably determines documentation is insufficient, the Customer may conduct an audit — at most once per 12-month period, on at least 30 days' notice, during business hours, without disrupting operations, subject to confidentiality obligations, and at the Customer's cost — or the parties may agree on a mutually acceptable independent auditor.

9. Return and Deletion

Upon termination or expiry of the Services, Sentinella will, at the Customer's choice, return Customer Personal Data in a commonly used format or delete it, and delete existing copies within ninety (90) days, unless EU or Member State law requires longer storage. Deletion from backups occurs in the ordinary backup rotation cycle, during which the data remains protected under this DPA.

10. Liability and Order of Precedence

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms & Conditions or the applicable Order, to the maximum extent permitted by applicable law. Nothing in this Section limits either party's liability to data subjects under Article 82 GDPR. In case of conflict, the order of precedence is: (1) the SCCs, (2) this DPA, (3) the Order, (4) the Terms & Conditions.

Annex I — Processing Details

As set out in Section 2 of this DPA. Data exporter: the Customer. Data importer: Sentinella LLC, 8 The Green STE A, Dover, DE 19901, USA; contact james@sentinellaglobal.com. Competent supervisory authority: the Belgian Data Protection Authority, unless otherwise determined under Clause 13 SCCs.

Annex II — Technical and Organisational Measures

Sentinella implements the following measures, proportionate to the nature and risk of the processing, and will develop and strengthen these measures as the Services evolve:

Sentinella reviews these measures periodically and updates this Annex as additional controls (including enhanced security monitoring, formalised access management, and audit processes) are implemented.

Annex III — Authorised Sub-processors

Sub-processorPurposeLocation
Vercel Inc.Frontend and Platform hosting, global content delivery (CDN), serverless functions, and scheduled jobsUSA / EU
Neon, Inc.Serverless PostgreSQL database storing account, subscription, transaction, billing, churn, and conversion recordsUSA / EU
Upstash, Inc.Managed caching layer for Platform dataUSA / EU
Railway Corp.Full-stack backend deployment and always-on persistent services, including background workers and real-time maritime data relaysUSA
Convex, Inc.Database services for email and waitlist registrationUSA
Anthropic, PBCLarge language model API powering the in-platform assistant ("Maria"), processing user queries and associated dashboard contextUSA
GitHub, Inc. (Microsoft)Source-code version control, collaboration, and CI/CD deployment automationUSA
Functional Software, Inc. (Sentry)Error monitoring and application diagnosticsUSA / EU
Stripe, Inc.Payment processingUSA / EU
HubSpot, Inc.Customer relationship managementUSA / EU
Google LLC (Google Workspace)Email and business correspondenceUSA / EU
Slack Technologies (Salesforce, Inc.)Internal communications supporting service delivery and customer supportUSA / EU