Data Processing Agreement
- Last updated
- Effective
How Senitix processes the personal data in your CRM workspace on your behalf, with GDPR, CCPA and KVKK processor terms, EU and UK transfer clauses, sub-processors and security measures.
This Data Processing Agreement (the “DPA”) sets out the terms on which Senitix processes personal data on behalf of its customers when they use Senitix CRM and the other Senitix services. It is part of each customer’s agreement with Senitix and applies automatically when that agreement is accepted, so no separate signature is needed.
1. About this DPA
1.1 Parties. This DPA is between Senitix Teknoloji LTD. ŞTİ., a limited liability company organized under the laws of the Republic of Türkiye (MERSİS No. 0478-1132-3580-0001), with its registered office at Cevizli Mah. Zuhal Cad. A Blok No:46 İç Kapı No:50, Maltepe, İstanbul, Türkiye (“Senitix”), and the business that has accepted the Senitix Terms of Service or signed an Order Form with Senitix (“Customer”). Senitix has no US subsidiary. Senitix Teknoloji LTD. ŞTİ. is the contracting party for customers in the United States and everywhere else.
1.2 How this DPA takes effect. This DPA is incorporated into the Terms of Service and any Order Form (together with this DPA, the “Agreement”). It takes effect when Customer first accepts the Terms of Service or signs an Order Form. Where Section 11 makes the Standard Contractual Clauses or the UK Addendum apply, that acceptance also serves as Customer’s signature of them, and Senitix signs them by providing the Services. Customer may request a countersigned copy of this DPA from legal@senitix.com. The countersigned copy contains the same terms as this page.
1.3 Business customers. The Services are offered to businesses and other organizations, not to consumers acting for personal, family or household purposes. The individual who accepts this DPA confirms that they have authority to accept it on Customer’s behalf.
1.4 What this DPA covers. This DPA applies to Customer Personal Data that Senitix processes on Customer’s behalf to provide the Services. It does not apply to personal data that Senitix processes for its own purposes as a controller. That processing is described in Section 3.3 and in the Privacy Policy.
1.5 Version. This version of the DPA is effective September 12, 2026.
2. Definitions
Capitalized terms that this DPA does not define have the meanings given in the Terms of Service. In this DPA:
- “Applicable Data Protection Law” means every law on privacy and the protection of personal data that applies to the processing of Customer Personal Data under the Agreement. Depending on the data and the parties, this can include the GDPR, the UK GDPR, the Swiss FADP, KVKK and US State Privacy Laws.
- “Authorized User” means an employee, contractor or other individual whom Customer allows to use the Services under its account.
- “Customer Content” means all data that Customer or its Authorized Users submit to, import into, sync with or create in the Services, including records, notes, files, email messages and calendar events.
- “Customer Personal Data” means (a) Personal Data contained in Customer Content and (b) Personal Data about Authorized Users that appears in Customer’s workspace, such as user profiles, roles and records of their activity in the workspace, in each case processed by Senitix on Customer’s behalf.
- “GDPR” means Regulation (EU) 2016/679, the General Data Protection Regulation.
- “UK GDPR” means the GDPR as it forms part of the law of the United Kingdom under section 3 of the European Union (Withdrawal) Act 2018, together with the Data Protection Act 2018, each as amended.
- “Swiss FADP” means the Swiss Federal Act on Data Protection of September 25, 2020.
- “KVKK” means Turkish Law No. 6698 on the Protection of Personal Data and the regulations issued under it.
- “US State Privacy Laws” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and its regulations (together, the “CCPA”), and the comprehensive consumer privacy laws of other US states, in each case as in effect and to the extent they apply.
- “Order Form” means an ordering document for the Services signed by Customer and Senitix.
- “Personal Data” means any information relating to an identified or identifiable natural person. It includes “personal information”, “personal data” and equivalent terms as defined in Applicable Data Protection Law.
- “Processing” (and “process”) means any operation performed on Personal Data, whether or not by automated means, such as collection, recording, organization, storage, adaptation, retrieval, use, disclosure, combination, restriction, erasure or destruction.
- “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration or unauthorized disclosure of, or access to, Customer Personal Data transmitted, stored or otherwise processed by Senitix or its Sub-processors. Unsuccessful attempts and activities that do not compromise the security of Customer Personal Data are not Security Incidents. Examples include blocked sign-in attempts, pings, port scans, and denial-of-service attacks that do not lead to access.
- “Services” means Senitix CRM and the other Senitix online services that Customer uses under the Agreement, including Senitix AI.
- “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by European Commission Implementing Decision (EU) 2021/914 of June 4, 2021.
- “Sub-processor” means a third party that Senitix engages to process Customer Personal Data in providing the Services. Senitix’s own employees are not Sub-processors. Neither are the providers of services that Customer chooses to connect (Section 9).
- “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A(1) of the Data Protection Act 2018 (version B1.0, in force since March 21, 2022), as amended or replaced.
- The terms “controller”, “processor”, “data subject”, “supervisory authority”, “business”, “service provider”, “consumer”, “sell”, “share” and “business purpose” have the meanings given to them in Applicable Data Protection Law. Under KVKK, “controller” and “processor” mean veri sorumlusu and veri işleyen.
3. Roles and scope
3.1 Customer as controller. Customer is the controller of Customer Personal Data (under US State Privacy Laws, the “business” or “controller”), and Senitix is its processor (the “service provider” or “processor”). Customer decides what Personal Data enters the Services, for what purposes and for how long, within the retention rules in Section 16.
3.2 Customer as processor. Where Customer processes Customer Personal Data on behalf of another controller (for example, an agency running a CRM for its clients), Senitix is Customer’s sub-processor. Customer warrants that the controller has authorized Customer’s instructions, including the appointment of Senitix. Customer remains Senitix’s only point of contact, and Senitix owes no obligations directly to that controller except where Applicable Data Protection Law or the SCCs require it.
3.3 Senitix as a controller. Senitix processes some Personal Data for its own purposes as an independent controller, not under this DPA. This covers account registration and administration, billing and payments, sign-in and platform security, fraud and abuse prevention, Senitix’s communications with Customer, and compliance with Senitix’s own legal obligations. The Privacy Policy describes that processing.
3.4 Customer’s responsibilities. Customer is responsible for:
- having a lawful basis for the Customer Personal Data it puts into the Services, and giving the notices and obtaining the consents that Applicable Data Protection Law requires for its collection and for its processing under this DPA;
- the accuracy and lawfulness of Customer Content, and the lawfulness of its instructions;
- configuring the Services for its needs, including Authorized Users, roles and permissions, multi-factor authentication, connected services and retention settings, and keeping its own credentials and API tokens secure; and
- its own obligations as a controller, including answering data subjects and, where the law requires, notifying supervisory authorities and individuals of a Security Incident.
3.5 Sensitive data. The Services are built for business relationship data. Customer will not submit the following unless it has a lawful basis, has decided that the Services’ security measures are appropriate for that data, and restricts it with the access controls available (such as field-level permissions):
- special categories of personal data under Article 9 of the GDPR, or data about criminal convictions and offenses under Article 10;
- special categories of personal data under Article 6 of KVKK; or
- “sensitive” personal information or data under US State Privacy Laws, such as government identification numbers, financial account credentials, precise geolocation or health information.
3.6 Compliance. Each party will comply with the Applicable Data Protection Law that applies to it in performing the Agreement.
4. Customer instructions
4.1 Documented instructions. Senitix will process Customer Personal Data only on Customer’s documented instructions, including instructions about transfers to a third country or an international organization, unless the law requires otherwise. Customer instructs Senitix to process Customer Personal Data:
- to provide, maintain, secure and support the Services under the Agreement;
- as Customer and its Authorized Users direct through their use of the Services, for example by importing records, connecting a mailbox or calendar, running an automation, using Senitix AI, exporting data or deleting it; and
- as the parties otherwise agree in writing.
The Agreement, including this DPA, is Customer’s complete set of instructions when it is accepted. Instructions outside that scope require the parties’ written agreement.
4.2 Instructions that infringe the law. Senitix will inform Customer promptly if, in its opinion, an instruction infringes Applicable Data Protection Law. Senitix may suspend the affected processing until Customer confirms or changes the instruction.
4.3 Processing required by law. If the law requires Senitix to process Customer Personal Data other than on Customer’s instructions, Senitix will tell Customer about that legal requirement before processing, unless the law prohibits it on important grounds of public interest.
4.4 Records. Senitix will keep a record of the processing it carries out on behalf of customers, as Article 30(2) of the GDPR requires.
5. US state privacy law terms
This section applies to the extent US State Privacy Laws apply to Customer Personal Data.
5.1 Business Purposes. Senitix acts as Customer’s service provider and, where the term applies, processor. Customer discloses Customer Personal Data to Senitix only for the following limited and specified business purposes, and Senitix processes it only for them (the “Business Purposes”):
- providing, maintaining and supporting the Services described in the Agreement, including storage, synchronization with services Customer connects, search, reporting, AI-assisted features at a user’s request, and customer support;
- helping to ensure the security and integrity of the Services, including detecting Security Incidents and protecting against fraudulent or illegal activity;
- debugging to identify and repair errors that impair the Services’ intended functionality; and
- complying with the law.
5.2 Restrictions. Senitix will not:
- sell or share Customer Personal Data;
- retain, use or disclose Customer Personal Data for any purpose other than the Business Purposes, including any commercial purpose, except as the CCPA and its regulations otherwise permit service providers to do;
- retain, use or disclose Customer Personal Data outside the direct business relationship between Customer and Senitix. For example, Senitix will not use it to market its own or anyone else’s products to the individuals in it;
- combine Customer Personal Data with Personal Data that Senitix receives from or on behalf of another person, or collects from its own interactions with individuals, except as the CCPA regulations permit service providers to do; or
- use Customer Personal Data for targeted advertising, or to build profiles of individuals for anyone other than Customer.
5.3 Same level of protection. Senitix will comply with the obligations that US State Privacy Laws place on service providers and processors, and will provide the same level of privacy protection that those laws require of Customer. This includes the security measures in Annex II and helping Customer respond to consumer requests (Section 13).
5.4 Customer’s oversight. Customer may take reasonable and appropriate steps to make sure that Senitix uses Customer Personal Data consistently with Customer’s obligations under US State Privacy Laws. It can do so through the information and audit rights in Section 15, at least once every 12 months. On notice to Senitix, Customer may also take reasonable and appropriate steps to stop and remediate any unauthorized use of Customer Personal Data, including by suspending the affected processing and requiring Senitix to cure it.
5.5 Notice if Senitix cannot comply. Senitix will notify Customer within five business days if it determines that it can no longer meet its obligations under US State Privacy Laws.
5.6 Consumer requests. Customer will inform Senitix of any consumer request under US State Privacy Laws that Senitix must act on, and will give Senitix the information needed to do so. Senitix will help as described in Section 13.
5.7 Processor terms under other state laws. For state laws that set out required terms for processors, such as the laws modeled on the Virginia Consumer Data Protection Act:
- Annex I sets out the processing instructions, the nature and purpose of processing, the types of data processed, the duration of processing, and the parties’ rights and obligations;
- Senitix will make sure that each person processing Customer Personal Data is under a duty of confidentiality (Section 6);
- at Customer’s direction, Senitix will delete or return Customer Personal Data when the Services end, unless the law requires it to be kept (Section 16);
- Senitix will make available the information needed to demonstrate its compliance, and will allow and cooperate with reasonable assessments by Customer or its designated assessor (Section 15). As an alternative, Senitix may arrange for a qualified and independent assessor to assess its policies and technical and organizational measures against an appropriate and accepted control standard, and provide the report to Customer on request; and
- Senitix will engage Sub-processors only under written contracts that pass these obligations on to them, after giving Customer an opportunity to object (Section 8).
5.8 Certification. Senitix certifies that it understands the restrictions in this Section 5 and will comply with them.
6. Confidentiality
6.1 Personnel. Senitix will make sure that everyone it authorizes to process Customer Personal Data is bound by written confidentiality obligations or an appropriate statutory duty of confidentiality, and that the duty continues after their work for Senitix ends.
6.2 Need to know. Senitix gives its personnel access to Customer Personal Data only where they need it to provide the Services, give support that Customer has asked for, protect the Services, or comply with the law.
6.3 Requests from public authorities. Senitix will not disclose Customer Personal Data to a third party, including a public authority, except as this DPA permits or the law requires. If a public authority asks Senitix for Customer Personal Data, Senitix will do the following, unless the law prohibits it:
- try to redirect the authority to Customer;
- notify Customer promptly, so that Customer can seek a protective order or another remedy;
- review whether the request is lawful, and challenge it where there are reasonable grounds to consider it unlawful; and
- disclose only the minimum information the request lawfully requires.
7. Security
7.1 Security measures. Senitix will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data, as described in Annex II. In setting them, Senitix takes into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks to individuals. These measures are intended to meet Article 32 of the GDPR, Article 12(1) of KVKK and the reasonable-security requirements of US State Privacy Laws.
7.2 Updates. Senitix may update the measures in Annex II as its technology and threats change, provided that no update materially reduces the overall protection of Customer Personal Data.
7.3 Customer’s part. Customer is responsible for how it uses the Services. That includes deciding who gets access and with which role, requiring multi-factor authentication where appropriate, protecting its credentials and API tokens, reviewing the services it connects, and securing data it exports from the Services. Customer agrees that the measures in Annex II, together with the controls Customer can configure, provide a level of security appropriate to the risk for Customer Personal Data, subject to Section 3.5.
8. Sub-processors
8.1 General authorization. Customer gives Senitix general written authorization to engage Sub-processors. Customer approves the Sub-processors listed on the Sub-processors page on the date it accepts this DPA. Annex III reproduces that list as of the effective date of this version. If the page and Annex III ever differ, the page governs, because Senitix gives notice of changes there under Section 8.3.
8.2 Conditions. Before a Sub-processor processes Customer Personal Data, Senitix will:
- assess the Sub-processor’s security and data protection practices for the service it will provide;
- enter into a written contract with it that imposes the same data protection obligations as this DPA, to the extent they are relevant to its service. That includes sufficient guarantees of appropriate technical and organizational measures, restrictions consistent with Section 5, and a valid transfer mechanism where Section 11 requires one; and
- limit its access to the Customer Personal Data it needs to provide that service.
Senitix remains fully liable to Customer for each Sub-processor’s performance of those obligations. On Customer’s request, Senitix will provide a copy of the data protection terms of a Sub-processor agreement. Senitix may remove commercial terms and confidential information from that copy.
8.3 Notice of changes. Senitix will give Customer at least 14 days’ notice before it adds or replaces a Sub-processor. It will give notice by updating the Sub-processors page and by email to Customer’s workspace administrators. The notice will name the Sub-processor and say what service it provides, which Customer Personal Data it will process, and where.
8.4 Objections. Customer may object to a new Sub-processor on reasonable grounds relating to data protection by writing to privacy@senitix.com within 14 days of the notice. The parties will discuss the objection in good faith, and Senitix may offer a way to use the Services without that Sub-processor processing Customer Personal Data. If the objection is not resolved before the change takes effect, Customer may terminate the affected Services by written notice, with no penalty for early termination. Fees already paid remain subject to the refund terms in the Terms of Service. If Customer does not object within 14 days, the change is treated as accepted.
8.5 Urgent replacement. If Senitix must replace a Sub-processor urgently, for example because the Sub-processor has stopped providing its service or presents a security risk, Senitix may make the change immediately. It will give notice as soon as practicable, and Customer’s right to object under Section 8.4 runs from the date of that notice.
9. Services Customer connects
9.1 Customer-directed connections. The Services can connect to third-party services that Customer or its Authorized Users choose to enable. These include Google (Gmail and Google Calendar), Microsoft (Outlook mail and calendar), other mail servers over IMAP and SMTP, and signing in with a Google, Microsoft or GitHub account where that option is offered. When Customer or an Authorized User connects one, Customer instructs Senitix to exchange Customer Personal Data with that service as the connection requires, for example to sync email messages and calendar events to the records they belong to. The provider of a connected service is not Senitix’s Sub-processor. Its processing is governed by Customer’s or the Authorized User’s own agreement with that provider.
9.2 Disconnecting. The user who connected a mailbox or calendar can disconnect it at any time. Disconnecting a mailbox revokes Senitix’s access and deletes the email synced through it. Disconnecting a calendar stops the sync, and activities already created from it stay in Customer Content until they are deleted under Section 16.
9.3 Google user data. Senitix’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The same applies to information received from Google Workspace APIs. Senitix uses Gmail and Google Calendar data only to provide the features the user has turned on. It does not use that data for advertising, does not sell it, and does not use it to train AI models. Senitix personnel do not read it except with the user’s agreement for specific messages (for example, in a support request), where needed for security purposes such as investigating abuse, or to comply with the law.
9.4 Microsoft user data. Senitix applies the same restrictions to Outlook mail and calendar data it receives through Microsoft’s APIs.
10. Senitix AI
10.1 How it processes data. An Authorized User can ask Senitix AI to summarize an email thread, draft or rewrite an email, prepare a daily digest, answer a question about records, or suggest a next step. To do that, Senitix sends the user’s request, together with the relevant Customer Content the user is permitted to see, to AI models run through Amazon Bedrock in AWS Regions within the European Union, and returns the result to the user.
10.2 The user decides. Senitix AI prepares suggestions and drafts. It does not send a message or change a record until the user confirms. Customer is responsible for having its users review outputs before relying on them. Senitix AI is not designed to make decisions about individuals that produce legal or similarly significant effects, and Customer will not use it for that purpose.
10.3 No model training. Senitix does not use Customer Personal Data, including prompts and outputs, to train or fine-tune AI models. Amazon Bedrock, the model service Senitix uses, does not use them to train models or share them with model providers.
10.4 Retention and limits. Senitix AI conversations are deleted after 180 days without activity. Use is subject to the daily per-user request limits of Customer’s plan.
11. International transfers
11.1 Where Customer Personal Data is processed. Senitix stores Customer Content on Amazon Web Services in Frankfurt, Germany (eu-central-1), with disaster-recovery copies in Ireland (eu-west-1). Senitix does not offer hosting in the United States. Senitix is established in Türkiye, and its personnel access Customer Personal Data from there to provide the Services. Some Sub-processors process limited Customer Personal Data in the United States or on global networks, as Annex III shows. Customer authorizes these transfers on the terms of this Section 11.
11.2 Transfers from the European Economic Area. The European Commission has not found that Türkiye provides an adequate level of protection. Where Customer Personal Data subject to the GDPR is transferred to Senitix, the SCCs are incorporated into this DPA by reference and apply as follows:
- Module Two (controller to processor) applies where Customer is a controller, and Module Three (processor to processor) applies where Customer is a processor;
- Customer is the data exporter and Senitix is the data importer;
- Clause 7 (docking clause) applies;
- in Clause 9(a), Option 2 (general written authorization) applies, and the notice period is the 14 days in Section 8.3;
- the optional wording in Clause 11(a) does not apply;
- in Clause 13, the competent supervisory authority is the one set out in Annex I, Part C;
- in Clause 17, Option 1 applies, and the SCCs are governed by the law of Ireland;
- in Clause 18(b), disputes will be resolved by the courts of Ireland; and
- Annexes I, II and III of the SCCs are completed with Annexes I, II and III of this DPA.
11.3 How this DPA works with the SCCs. The parties agree that the audits in Clause 8.9 of the SCCs are carried out as Section 15 describes, that the certification of deletion in Clauses 8.5 and 16(d) is given on Customer’s request (Section 16.6), and that notice of Sub-processor changes under Clause 9(a) is given as Section 8.3 describes. These clarifications do not change the SCCs. If the SCCs conflict with this DPA or the rest of the Agreement, the SCCs prevail.
11.4 Transfers from the United Kingdom. For Customer Personal Data subject to the UK GDPR, the UK Addendum is incorporated into this DPA and applies to the SCCs as selected in Section 11.2. In the UK Addendum:
- Table 1 (parties) is completed with Annex I, Part A;
- Table 2 (selected SCCs, modules and clauses) is completed with Section 11.2;
- Table 3 (appendix information) is completed with Annexes I, II and III; and
- for Table 4, both the data importer and the data exporter may end the UK Addendum as its Section 19 allows.
The Mandatory Clauses of the UK Addendum apply.
11.5 Transfers from Switzerland. For Customer Personal Data subject to the Swiss FADP, the SCCs apply as set out in Section 11.2, with three changes. The Federal Data Protection and Information Commissioner is the competent supervisory authority insofar as the transfer is governed by the Swiss FADP. References to the GDPR are read as references to the Swiss FADP to that extent. And the term “Member State” in Clause 18(c) does not prevent data subjects in Switzerland from bringing proceedings where they habitually reside.
11.6 Onward transfers to Sub-processors. Where a Sub-processor processes Customer Personal Data subject to the GDPR, the UK GDPR or the Swiss FADP in a country without an adequacy decision, Senitix will make sure the transfer is covered by a valid mechanism. That means either the SCCs (Module Three, with the UK Addendum where relevant) entered into with the Sub-processor, or the Sub-processor’s certification under the EU-U.S. Data Privacy Framework (and its UK Extension or the Swiss-U.S. Data Privacy Framework) where that certification covers the transfer.
11.7 Transfer assessments and supplementary measures. On request, Senitix will give Customer the information reasonably necessary to assess the transfers under this DPA. That includes the information Senitix has about the laws and practices of the destination countries that are relevant under Clause 14 of the SCCs. The measures in Annex II also act as supplementary measures for these transfers: EU hosting, encryption in transit and at rest, and access limited to authorized personnel. So does the handling of public-authority requests in Section 6.3.
11.8 Replacement mechanisms. The SCCs or the UK Addendum may be amended, replaced or invalidated. The European Commission may also adopt clauses for importers that are themselves subject to the GDPR under its Article 3(2). In any of those cases, Senitix may adopt the replacement or alternative mechanism by notice to Customer. That mechanism applies from the date stated in the notice, and the parties will cooperate to put it in place.
12. Türkiye (KVKK)
This section applies to the extent KVKK applies to the processing of Customer Personal Data.
12.1 Roles. Customer is the data controller and Senitix is the data processor. Customer is responsible for informing data subjects (KVKK Article 10), for the legal basis of the processing (Articles 5 and 6), for registering with the Data Controllers’ Registry (VERBİS) where the law requires, and for answering data subjects’ applications under Article 11.
12.2 Shared responsibility for security. Under KVKK Article 12(2), Customer and Senitix are jointly responsible for taking the measures that Article 12(1) requires for the processing Senitix carries out on Customer’s behalf. Senitix’s measures are in Annex II, and Customer’s part is described in Section 7.3.
12.3 Confidentiality. Senitix will not disclose Customer Personal Data in breach of KVKK or use it for anything other than the purposes of processing. This duty continues after the Agreement ends (Article 12(4)).
12.4 Transfers abroad. Customer Content is hosted outside Türkiye (Section 11.1), which is a transfer abroad under KVKK Article 9. Senitix will make those transfers, including transfers to Sub-processors, only on a basis that Article 9 allows. In practice that is the standard contract published by the Personal Data Protection Board for processor-to-processor transfers. The party making the transfer notifies the standard contract to the Personal Data Protection Authority within five business days of signing it, as Article 9(5) requires. Customer, as controller, remains responsible for informing data subjects of transfers abroad.
12.5 Unlawful access. If Customer Personal Data subject to KVKK is obtained by others through unlawful means, Senitix will notify Customer as Section 14 describes. This lets Customer notify the data subjects and the Personal Data Protection Board as soon as possible, as KVKK Article 12(5) requires.
12.6 Applications by data subjects. Senitix will forward and help with data subjects’ applications as Section 13 describes, in time for Customer to answer within the 30 days KVKK allows.
13. Data subject requests and assistance
13.1 Self-service tools. The Services let Customer access, correct, export (as CSV or Excel files), restrict access to and delete Customer Personal Data, so Customer can handle most data subject requests itself.
13.2 Requests that reach Senitix. If Senitix receives a request from a data subject or consumer about Customer Personal Data, it will promptly forward the request to Customer where the requester identifies Customer. Senitix will not respond to the request itself, except to direct the requester to Customer, unless Customer authorizes it or the law requires it.
13.3 Further help. Taking into account the nature of the processing, Senitix will assist Customer through appropriate technical and organizational measures, insofar as possible, in responding to requests to exercise rights under Applicable Data Protection Law. If Customer instructs Senitix to erase a data subject’s Customer Personal Data that Customer cannot erase itself, Senitix will complete the erasure within 30 days.
13.4 Assessments and consultations. Using the information available to it, Senitix will give reasonable assistance with:
- Customer’s data protection impact assessments (GDPR Article 35) and prior consultations with supervisory authorities (Article 36);
- data protection assessments under US State Privacy Laws; and
- Customer’s compliance with its security and breach-notification obligations (GDPR Articles 32 to 34).
13.5 Costs. Assistance through the Services’ standard features is included. For assistance that requires significant work beyond those features, Senitix may charge reasonable fees agreed with Customer in advance. It will not charge where the need arises from its own breach of this DPA.
14. Security incidents
14.1 Notice. Senitix will notify Customer of a Security Incident without undue delay, and in any event within 72 hours after becoming aware of it. Where Applicable Data Protection Law requires a service provider to give notice sooner, Senitix will meet that shorter deadline.
14.2 How notice is given. Senitix sends the notice by email to Customer’s workspace administrators, and may also use in-app notices or other contacts Customer has provided. Customer is responsible for keeping those contacts current.
14.3 Content of the notice. To the extent known at the time, the notice will describe:
- the nature of the Security Incident, including the categories and approximate number of data subjects and records concerned;
- its likely consequences;
- the measures Senitix has taken or proposes to take to address it and to mitigate its possible effects; and
- a contact point for more information.
Where not all of this information is available at once, Senitix will provide it in phases without further undue delay.
14.4 Response. Senitix will promptly take reasonable steps to contain, investigate and mitigate the Security Incident and will keep Customer informed. It will cooperate with Customer’s reasonable requests, including for information Customer needs for its own notifications to supervisory authorities, data subjects or consumers. Senitix will document each Security Incident and the steps taken.
14.5 Notifications to others. Customer decides whether to notify authorities and individuals about a Security Incident affecting Customer Personal Data. Senitix will not notify them on Customer’s behalf without Customer’s approval, unless the law requires Senitix to do so itself. Senitix reports service-wide incidents on its status page at status.senitix.com.
14.6 No admission. Notice of a Security Incident, or Senitix’s response to it, is not an acknowledgment of fault or liability.
15. Audits and information
15.1 Information. On Customer’s written request, Senitix will make available the information necessary to demonstrate its compliance with this DPA and Applicable Data Protection Law. That information includes:
- documentation of the measures in Annex II;
- answers to Customer’s reasonable security questionnaire, no more than once in any 12-month period unless there has been a Security Incident; and
- information about the certifications and independent audit reports that Senitix’s hosting provider, AWS, has obtained for the facilities used for the Services.
Senitix does not currently hold SOC 2 or ISO/IEC 27001 certification. A SOC 2 Type II audit is in preparation. Once Senitix has an independent audit report of its own, it will make that report available to customers under confidentiality.
15.2 Audits. Customer, or an independent auditor it appoints, may audit Senitix’s compliance with this DPA, including through inspections, in any of these cases: the information in Section 15.1 does not reasonably demonstrate compliance; a supervisory authority requires the audit; there has been a Security Incident; or there are indications of non-compliance. Customer may also audit once in any 12-month period without any of those reasons.
15.3 Conditions. Audits are subject to these conditions:
- Customer will give at least 30 days’ written notice. The notice can be shorter where a supervisory authority requires it or after a Security Incident. The parties will agree the scope in advance;
- audits take place during Senitix’s business hours, İstanbul time, and without unreasonable disruption to the Services;
- auditors must be bound by confidentiality and must not be Senitix’s competitors. They will not have access to other customers’ data or to information that would compromise the security of the Services;
- audits of Sub-processors’ facilities are satisfied by the Sub-processors’ own independent audit reports and certifications;
- Customer bears its own costs. Senitix may charge reasonable costs, agreed in advance, for supporting an on-site audit, unless the audit shows material non-compliance by Senitix; and
- Customer will share the audit report with Senitix, and Senitix will promptly address any material non-compliance it identifies.
15.4 Supervisory authorities. Senitix will cooperate with competent supervisory authorities in the performance of their tasks.
16. Return and deletion
16.1 During the Agreement. Customer can export Customer Content at any time as CSV or Excel files and can schedule a full data export. Records that a user deletes go to a recycle bin, where they can be restored until the retention period in Section 16.5 ends.
16.2 When the Agreement ends. After cancellation, closure of the workspace or termination of the Agreement, the workspace stays available in read-only mode for 30 days so that Customer can export Customer Content. That export is how Senitix returns Customer Personal Data. After the 30 days, Senitix deletes Customer Personal Data from its production systems and its Sub-processors’ systems, except as Section 16.4 allows.
16.3 Backups. Backup copies are used only to restore the Services and remain protected under this DPA. They are overwritten as the backup cycle runs. Daily backups are kept for 35 days and monthly backups for 365 days, so the last backup copy of deleted data expires no later than 365 days after its deletion from production. If a restore brings back data that had been deleted, Senitix will delete it again.
16.4 Retention required by law. Senitix may keep Customer Personal Data where the law requires it, only for as long as required and only for that purpose. Senitix will continue to protect that data under this DPA. Separately from Customer Content, Senitix keeps its own platform audit logs for seven years to protect the Services, investigate incidents and meet legal obligations. These logs record sign-ins, account and permission changes and similar events, and can include a user’s name, email address and IP address.
16.5 Retention periods in the Services. The Services apply the following periods. The Data Retention Policy describes them in more detail.
| Data | Retention |
|---|---|
| Records in the recycle bin | Permanently deleted 90 days after deletion by default. Workspace administrators can set a period between 30 days and seven years. |
| Deleted quotes, contracts, orders and invoices | Kept in the recycle bin for 10 years after deletion. When a workspace closes, Senitix anonymizes rather than deletes these records early, so it can keep the accounting records the law requires (Section 16.4). |
| Files in the storage trash | 90 days after deletion |
| Custom objects an administrator deletes, with their records | 15 days after deletion |
| Email synced from a connected mailbox | 365 days after it was synced, whatever sync period is configured, or earlier if the mailbox is disconnected. Email moved to the trash in the Services is deleted after 30 days. |
| Senitix AI conversations | 180 days after the last message |
| Export files | Up to 30 days after they are created; full-workspace export archives after 7 days |
| Workspace audit log, setup audit trail and security event log | Seven years, and deleted earlier if the workspace is closed |
| Field change history on records | 10 years, and deleted earlier if the workspace is closed |
| Approval history | 365 days by default. Workspace administrators can set a period between 30 days and 10 years. |
| Sign-in attempts and expired sessions | 30 days |
| Workspace membership of a removed user | 365 days after removal |
| Workspace after cancellation or closure | Read-only for 30 days for export, then deleted as Section 16.2 describes |
| Backups | Daily backups 35 days; monthly backups 365 days; point-in-time recovery covers the last seven days |
16.6 Confirmation. On Customer’s written request, Senitix will confirm in writing that deletion has been completed.
17. Liability
17.1 Limits. Each party’s liability arising out of or relating to this DPA, including under the SCCs to the extent they allow it, is subject to the exclusions and limitations of liability in the Terms of Service. Those limitations apply to claims under the Terms of Service and this DPA together, not separately.
17.2 What is not limited. Nothing in this DPA limits either party’s liability to data subjects under the third-party beneficiary provisions of the SCCs, or any liability that cannot be limited under applicable law.
18. Term, precedence and changes
18.1 Term. This DPA stays in effect for as long as Senitix processes Customer Personal Data, including after the Agreement ends and until deletion under Section 16. Provisions that by their nature should survive will survive.
18.2 Order of precedence. If documents conflict on the processing of Customer Personal Data, they apply in this order:
- the SCCs and the UK Addendum, where they apply;
- this DPA; and
- the Terms of Service and any Order Form.
An Order Form signed by both parties prevails over this DPA only where it expressly names the provision of this DPA it changes. It never prevails over the SCCs.
18.3 Changes to this DPA. Senitix may update this DPA to reflect changes in Applicable Data Protection Law, guidance from supervisory authorities, or changes to the Services. Senitix will give at least 30 days’ notice of a change that materially reduces Customer’s protection or rights. Notice will be sent by email to Customer’s workspace administrators and given by posting the new version on this page. If Customer objects to such a change, it may terminate the Agreement by written notice before the change takes effect, and the previous version continues to apply to Customer until termination. A change that the law requires may take effect sooner if the law requires it. Other changes take effect when they are posted. Changes to Sub-processors follow Section 8 instead.
18.4 Governing law and disputes. This DPA is governed by the laws of the Republic of Türkiye, and disputes under it are resolved as the Terms of Service provide. Two exceptions apply: the SCCs are governed as Section 11.2 sets out, and the UK Addendum as its own terms set out. Nothing in this DPA limits a data subject’s rights or anyone’s right to complain to a supervisory authority.
18.5 Severability. If any provision of this DPA is held invalid or unenforceable, the rest of the DPA remains in effect. The invalid provision is replaced by a valid provision that comes closest to its intent.
18.6 Entire agreement. This DPA and the rest of the Agreement are the parties’ entire agreement on the processing of Customer Personal Data. They replace any earlier agreement between the parties on that subject.
19. Contact
- Questions about this DPA, data protection requests and objections to Sub-processors: privacy@senitix.com
- Security incidents and vulnerability reports: security@senitix.com
- Legal notices and countersigned copies of this DPA: legal@senitix.com
- Postal address: Senitix Teknoloji LTD. ŞTİ., Cevizli Mah. Zuhal Cad. A Blok No:46 İç Kapı No:50, Maltepe, İstanbul, Türkiye
Senitix’s security practices are summarized on the Security page.
Annex I: Details of processing
A. Parties
| Item | Data exporter | Data importer |
|---|---|---|
| Name and address | Customer, as identified in its Senitix account or Order Form | Senitix Teknoloji LTD. ŞTİ., Cevizli Mah. Zuhal Cad. A Blok No:46 İç Kapı No:50, Maltepe, İstanbul, Türkiye |
| Contact | Customer’s workspace administrators, at the email addresses registered in the Services | Privacy team, privacy@senitix.com |
| Activities | Use of the Services | Provision of the Services under the Agreement |
| Role | Controller, or processor where Section 3.2 applies | Processor, or sub-processor where Section 3.2 applies |
| Signature and date | Acceptance of the Terms of Service or signature of an Order Form, on that date | Provision of the Services, from the same date |
B. Description of the processing and transfer
| Item | Details |
|---|---|
| Categories of data subjects | Customer’s Authorized Users. Customer’s prospects, leads and customers, and their employees and representatives. Customer’s suppliers, distributors, resellers and other business partners, and their representatives. Other individuals whose data Customer or its Authorized Users enter, import or sync into the Services, such as the senders, recipients and participants of synced email messages and calendar events. |
| Categories of personal data | Identification and contact details (name, job title, employer, business email address, phone number, postal address). Relationship and transaction data (leads, deals, pipeline stages, quotes, orders, contracts, invoices, products, amounts, activities, tasks, meetings and notes). Communications (email messages, their metadata and attachments, and calendar events, synced from connected accounts or sent to Senitix for Customer’s workspace). Documents and files attached to records. Data in custom fields and custom objects that Customer defines. Authorized User data in the workspace (name, email address, role, department, permissions, activity and audit records, and sign-in information such as IP address, approximate location and device or browser details). Senitix AI prompts, conversations and outputs. Any other Personal Data that Customer chooses to include in Customer Content. |
| Sensitive data | None intended; see Section 3.5. If Customer submits sensitive data, the safeguards available are field-level permissions, application-level encryption of designated fields, audit logging and restricted personnel access (Annex II). |
| Frequency of transfer | Continuous, for as long as Customer uses the Services |
| Nature of processing | Hosting and storage; organization, search and display; synchronization with services Customer connects; sending email and notifications that Customer initiates; generating reports, dashboards and Senitix AI outputs at a user’s request; backup and restoration; export; deletion. |
| Purposes | The Business Purposes in Section 5.1 |
| Duration and retention | For the term of the Agreement and until deletion under Section 16, with the retention periods in Section 16.5 |
| Transfers to Sub-processors | As listed in Annex III, for the same subject matter and nature of processing, for the duration of the Agreement |
C. Competent supervisory authority
- European Economic Area: the supervisory authority determined under Clause 13 of the SCCs. That is the authority of the Member State where Customer is established. If Customer is not established in the EU but falls under Article 3(2) of the GDPR and has appointed a representative, it is the authority of the Member State where that representative is established. Otherwise, it is the authority of the Member State where most of the data subjects concerned are located.
- United Kingdom: the Information Commissioner’s Office.
- Switzerland: the Federal Data Protection and Information Commissioner.
- Türkiye: the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu).
Annex II: Security measures
Senitix maintains the following technical and organizational measures for the Services.
| Area | Measures |
|---|---|
| Encryption in transit | Connections to the Services use TLS 1.2 or higher, with TLS 1.3 preferred, and older protocols are refused. HTTP Strict Transport Security (HSTS) tells browsers to connect only over HTTPS. Traffic between Senitix’s edge network and its servers is also encrypted. |
| Encryption at rest | Databases, file storage and backups are encrypted at rest, with encryption keys managed in AWS Key Management Service in the EU. Fields designated as sensitive are also encrypted in the application with AES-256-GCM, using a separate key for each customer. |
| Access control in the Services | Access is set by role, department and record ownership, with field-level permissions for sensitive values. Users can protect sign-in with an authenticator app, or with an SMS code where enabled, and workspace administrators can require multi-factor authentication. Single sign-on through OpenID Connect is available on plans that include it. Passwords are stored as salted bcrypt hashes, must meet complexity rules, and are checked against known breached passwords without the password leaving Senitix. Sessions expire after a period of inactivity. Session cookies are secure, HTTP-only and protected against cross-site request forgery. |
| Senitix personnel access | Access to production systems is limited to authorized personnel who need it for their role, and it is removed when no longer needed. Administrative tools sit behind an identity-aware access gateway (Cloudflare Access) and require multi-factor authentication. Personnel access Customer Content only to provide the Services, give support Customer has asked for, protect the Services or comply with the law. |
| Customer separation | Each workspace’s data is kept logically separate at the application layer. Every request is scoped to the workspace it belongs to, to prevent one customer’s users from reaching another customer’s data. |
| Network and edge protection | Traffic passes through Cloudflare’s network for DNS, web application firewall, DDoS mitigation and bot management. Storage buckets are private. Application secrets are held in AWS Secrets Manager. The public API enforces per-app scopes and rate limits. |
| Hosting and physical security | The Services run on AWS in Frankfurt, Germany, with disaster recovery in Ireland. Senitix operates no data centers of its own. AWS provides the physical and environmental security of the facilities, and its controls are independently audited, for example under SOC 2 and ISO/IEC 27001. |
| Availability, backups and recovery | The production database runs across multiple availability zones. Databases are backed up daily (kept 35 days) and monthly (kept 365 days) to a locked backup vault, with a copy in Ireland, and point-in-time recovery covers the last seven days. Stored files are replicated to Ireland. Restoration from backup is tested; the most recent full restore test was completed in July 2026. |
| Logging and monitoring | Changes and security-relevant events are logged and kept for seven years. On plans that include it, administrators can see who changed what and when in the audit log. Infrastructure and applications are monitored with automated alerting, and application errors are reported to an error-monitoring service hosted in the EU. Application logs are kept for 30 days. |
| Security testing | The Services have been penetration-tested, most recently in June 2026, and findings are addressed in order of severity. Anyone can report a vulnerability to security@senitix.com. |
| Incident management | Security incidents are triaged, contained, investigated and documented, and are notified to Customer where Section 14 applies. Service-wide incidents are reported at status.senitix.com. |
| Retention and deletion | Scheduled jobs apply the retention periods in Section 16 automatically. Deleted records pass through a recycle bin before permanent deletion. |
| Senitix AI | Requests are processed by models on Amazon Bedrock in AWS Regions within the EU. Senitix AI works only with records the signed-in user is permitted to see, and it does not send anything or change a record until the user confirms. Prompts and outputs are not used to train models. Conversations are deleted after 180 days without activity, and daily per-user limits apply. |
| Personnel | Personnel with access to Customer Personal Data are bound by confidentiality obligations that continue after their engagement ends. |
| Sub-processor management | Sub-processors are assessed before they are engaged and are bound by written data protection terms (Section 8). |
| Assistance to Customer | Self-service tools let Customer export data (as CSV or Excel files), correct it, restrict access to it and delete it. Requests to privacy@senitix.com are answered within 30 days. |
Certifications and current limits. Senitix does not currently hold SOC 2 or ISO/IEC 27001 certification; a SOC 2 Type II audit is in preparation. Customer-managed encryption keys (BYOK), data loss prevention (DLP) rules and field masking are not offered today.
Annex III: Sub-processors
This list reproduces the Sub-processors page as of September 12, 2026. Senitix gives notice of changes on that page, as Section 8.3 describes.
A. Sub-processors
| Sub-processor | Service | Customer Personal Data | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting: compute, databases, file storage, backups, encryption key management and secrets. AI model inference for Senitix AI through Amazon Bedrock. | All Customer Content, encrypted at rest | Germany (Frankfurt, eu-central-1), with disaster recovery in Ireland (eu-west-1). Senitix AI inference in AWS Regions within the EU. |
| Cloudflare, Inc. | DNS, content delivery, web application firewall, DDoS mitigation and bot management for traffic to the Services | IP addresses, request metadata, and Customer Content in transit | Global network |
| Twilio Inc. (Twilio SendGrid) | Delivery of system and notification email, and receipt of inbound email sent to Senitix for Customer’s workspace | Names, email addresses and message content | United States |
| Twilio Inc. | SMS verification codes for sign-in and phone verification | Phone numbers and message content | United States |
| Functional Software, Inc. (Sentry) | Application error monitoring | Technical error data, which can include IP addresses, user identifiers and fragments of the data involved in an error | European Union (Germany) |
| Google LLC (Google Workspace) | Senitix’s business email, including support correspondence | Customer Personal Data that Customer or its Authorized Users send to Senitix, for example in a support request | United States and other countries where Google operates |
| IPinfo | Approximate location of sign-ins, looked up from the IP address | IP addresses | United States |
Twilio’s SMS service and IPinfo also support Senitix’s own account security, which Senitix carries out as a controller (Section 3.3).
B. Services Customer connects (not Sub-processors)
| Provider | When it is used | Data exchanged |
|---|---|---|
| Gmail and Google Calendar sync; signing in with a Google account, where offered | Email messages, their metadata and attachments; calendar events; basic profile (name and email address) | |
| Microsoft | Outlook mail and calendar sync; signing in with a Microsoft account, where offered | Email messages, their metadata and attachments; calendar events; basic profile (name and email address) |
| GitHub | Signing in with a GitHub account, where offered | Basic profile and email address |
| Customer’s own mail servers | Email sync over IMAP and SMTP | Email messages, their metadata and attachments |
Senitix processes subscription payments through iyzi Ödeme ve Elektronik Para Hizmetleri A.Ş. (iyzico) in Türkiye. That concerns Customer’s billing data, which Senitix handles as a controller under the Privacy Policy. iyzico does not receive Customer Content.
