Sentink acts as a data processor when customers use Sentink Cloud to collect, store, and analyze survey and research responses.
This page summarizes the standard data protection commitments Sentink includes in its Data Processing Agreement (DPA) with customers.
Executed DPAs are provided during enterprise onboarding or upon written request for procurement and compliance review.
1. Scope and roles
When you use Sentink Cloud to run surveys or research programmes, you determine the purposes and means of processing respondent personal data and act as the data controller. Sentink FZ-LLC processes that data on your documented instructions and acts as a data processor under applicable data protection law, including GDPR Article 28 where it applies.
This DPA covers personal data contained in survey responses, related metadata you configure, and workspace content necessary to deliver the service. Account, billing, and support communications may be processed under separate controller arrangements described in our Privacy Policy.
2. Processing instructions
Sentink processes personal data only on documented instructions from the customer. Instructions are defined by the applicable subscription, order form, product configuration, and the executed DPA.
Sentink does not use customer survey or respondent data for advertising, unrelated product development, or any purpose outside providing and securing the contracted service.
3. Confidentiality
Personnel with access to customer data are subject to confidentiality obligations appropriate to their role. Access is limited to individuals who require it to operate, support, or secure the service.
4. Security measures
Sentink implements appropriate technical and organizational measures designed to protect personal data, including encryption in transit, encryption at rest for applicable storage tiers, access controls, role-based permissions, and monitoring of service infrastructure.
Further detail on security controls is available on our Security page. Specific measures may vary by deployment mode and contractual terms.
5. Subprocessors
Sentink may engage subprocessors to deliver hosting, infrastructure, communications, payment, or other operational functions. A current list of subprocessors relevant to Sentink Cloud is published on our Subprocessors page.
Customers are notified of material changes to subprocessors that process personal data on their behalf in accordance with the notice period stated in the executed DPA.
6. International transfers
Where personal data is transferred to countries that do not provide an adequacy decision recognized for the transfer, Sentink relies on lawful transfer mechanisms required by applicable law, such as Standard Contractual Clauses or equivalent contractual safeguards, as set out in the executed DPA.
7. Assistance with data subject rights
Where Sentink processes personal data as a processor, Sentink assists the customer in responding to data subject requests to the extent required by applicable law and technically feasible, taking into account the nature of processing and the information available to Sentink.
Requests relating to respondent data should generally be directed to the customer as controller. Sentink may require reasonable identity verification and scope confirmation before taking action.
8. Security incident notification
Sentink maintains documented procedures for identifying, assessing, and responding to security incidents. Where an incident is likely to affect personal data processed on behalf of a customer, Sentink notifies the customer without undue delay and provides information reasonably required to support the customer's regulatory obligations, in line with the executed DPA.
9. Data retention and deletion
Personal data is retained according to customer configuration, workspace settings, and applicable law. Upon termination of services, Sentink deletes or returns personal data processed on the customer's behalf within the timeframe specified in the executed DPA, subject to lawful retention requirements such as tax, audit, or dispute obligations.
10. Audit and compliance information
Sentink provides information reasonably necessary to demonstrate compliance with processor obligations under the DPA, which may include summaries of security measures, subprocessor information, and responses to standard security questionnaires submitted through the customer's procurement process.
Sentink does not represent third-party certifications unless explicitly documented in a current attestation shared with the customer.
Request an executed DPA
Customers requiring a signed Data Processing Agreement for procurement, vendor onboarding, or compliance review may contact Sentink. We will route your request to the appropriate legal and privacy team.