01Roles and scope
For personal data contained in the systems, repositories, and databases you connect to Sentrail, you are the controller and we are the processor. For account administration, billing, and security of our own platform, we act as an independent controller under our Privacy Policy.
We process personal data only to provide the Service, on your documented instructions, and for no independent purpose. We will notify you if an instruction appears to conflict with applicable data protection law.
02Annex I — Details of processing
- Subject matter
- Automated security analysis of the code, databases, configurations, and deployments you connect, and the drafting of remediations you approve.
- Duration
- For the term of your subscription, plus the retention periods stated in Section 7 of the Privacy Policy.
- Nature and purpose
- Reading schemas, policies, configuration, dependency manifests, and source files; running static and dynamic checks; generating findings, evidence records, and proposed diffs or SQL.
- Categories of data subjects
- Your personnel who use Sentrail, and any individuals whose personal data happens to be present in connected systems (for example in database rows sampled during a check, or in code comments and fixtures).
- Categories of personal data
- Identifiers and contact data of your users; incidental personal data present in connected repositories or databases. We do not require special-category data and ask you not to route it through the Service.
- Sensitive data
- None requested. If sensitive or special-category data is present in a connected system, you remain responsible for determining whether processing it through the Service is lawful.
03Annex II — Technical and organisational measures
We maintain the measures below. They may change as the Service evolves, but not in a way that materially reduces overall protection.
- Encryption: TLS 1.2+ for all data in transit; encryption at rest for our databases and object storage; envelope encryption with a separate key for stored OAuth tokens and provider credentials.
- Credential minimisation: database connection strings are held in volatile memory for the duration of a request and are not written to our persistent stores.
- Least privilege: row-level security on tenant tables, role-based access control, and scoped provider credentials. Repository write access is limited to opening draft pull requests.
- Human approval gates: production-changing actions (migrations, pull requests, configuration changes) are queued as pending actions and require explicit approval by an authorised user.
- Isolation: static analysis and penetration-test tooling run in ephemeral, network-restricted containers that are destroyed after each run.
- Redaction: secrets and credentials are stripped from code excerpts, logs, error reports, and model prompts.
- Logging and audit: append-only audit records of agent tool calls, approvals, and administrative changes.
- Secure development: code review, dependency and secret scanning in continuous integration, and least-privilege deployment credentials.
- Personnel: access on a need-to-know basis, confidentiality obligations, and revocation on role change or departure.
- Resilience: managed database backups with point-in-time recovery from our infrastructure providers.
04Subprocessors
You give general authorisation for us to engage the subprocessors listed at sentrail.dev/subprocessors. We impose data protection obligations on each of them that are no less protective than this Addendum and remain responsible for their performance. We will give at least thirty (30) days' notice before adding a subprocessor that processes customer personal data, and you may object on reasonable data protection grounds within that period.
05International transfers
We process personal data primarily in the United States. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (Module Two, controller-to-processor) together with the UK International Data Transfer Addendum, incorporated here by reference, and we carry out a transfer impact assessment where required. Annex I and Annex II above serve as the corresponding annexes to those clauses.
06Assistance with data subject rights
We will promptly notify you if we receive a request from a data subject relating to your data and will not respond to it ourselves except to direct the individual to you. We will provide reasonable assistance, taking account of the nature of the processing and the information available to us, in responding to access, correction, deletion, restriction, portability, and objection requests, and in carrying out data protection impact assessments and prior consultations.
07Personal data breach notification
We will notify you without undue delay, and in any event within seventy-two (72) hours of becoming aware, of a personal data breach affecting your data. The notice will describe the nature of the breach, the categories and approximate volume of data involved, the likely consequences, and the measures taken or proposed. We will cooperate with you in meeting your own notification obligations. Notifying you is not an acknowledgement of fault.
08Audits and information rights
On request, and no more than once in any twelve-month period unless required by a supervisory authority, we will make available the information reasonably necessary to demonstrate compliance with this Addendum, including any then-current third-party examination report. Where audit information is insufficient, we will cooperate with a reasonable, scoped audit conducted at your expense under confidentiality obligations and at a mutually agreed time, without unreasonable disruption to the Service.
09Return and deletion
On termination or expiry, and on written request, we will delete or return the personal data we process on your behalf, except where retention is required by law or for the limited periods described in the Privacy Policy (for example audit logs and billing records). You may export your project, finding, and evidence records before deletion.
10Order of precedence and contact
If this Addendum conflicts with the Terms of Service, this Addendum controls for matters of personal data processing. Where the Standard Contractual Clauses apply and conflict with this Addendum, the Clauses control. This Addendum is otherwise governed by the law stated in the Terms (Ohio), except where data protection law requires otherwise. For a countersigned copy or any question about this Addendum, contact privacy@sentrail.dev.
Structured around GDPR Art. 28(3) requirements and the Annex format of the European Commission's 2021 Standard Contractual Clauses, following the pattern used in published DPAs from major cloud vendors. Provided for information; it is not legal advice. Review with qualified counsel before relying on it.