Sub-processors
- Last updated
- Effective
Every third party that processes personal data for Senitix: what it does, the data it handles, where it processes it and how transfers are protected, and how we notify customers of changes.
1. About this list
Senitix Teknoloji LTD. ŞTİ. (“Senitix,” “we” or “us”) provides Senitix CRM. When a customer stores personal data in Senitix, we process that data on the customer’s behalf, as its processor or service provider, under our Data Processing Agreement (DPA). A sub-processor is a third party we engage to process that customer data so that we can provide the service.
This page is the list of sub-processors that the DPA refers to. By accepting the DPA, a customer authorizes us to use the sub-processors listed here, and we give notice before we add or replace one (section 8). If this page and the DPA differ, the DPA governs.
The page also lists, separately, the providers that handle personal data Senitix controls for its own purposes, such as billing, account security and website analytics (section 4), and the services a customer can choose to connect to Senitix, which are not our sub-processors (section 5).
Last changed: September 12, 2026. The change history is in section 8.4.
2. Where customer data is stored
Customer data in Senitix is hosted by Amazon Web Services (AWS) in Frankfurt, Germany (AWS region eu-central-1), with disaster recovery in Ireland (eu-west-1). Backups are kept in those two regions. Requests to Senitix AI are processed by Amazon Bedrock in the European Union.
Hosting in the EU does not mean that data never leaves it. Senitix is established in Türkiye, and our staff there operate, secure and support the service, so they can access customer data remotely when that work requires it. Some of the providers below are based in the United States and process limited data there, and Cloudflare handles traffic at the location nearest each user. Section 6 explains how these transfers are protected.
3. Current sub-processors
These providers may process customer data, meaning the personal data that customers and their users put into Senitix, in order to deliver the service. They also handle some of the account and security data that Senitix controls, as part of the same services.
| Provider | What it does for Senitix | Personal data involved | Where it processes data | Transfer safeguard |
|---|---|---|---|---|
| Amazon Web Services (AWS) | Hosts the Senitix application: servers, databases, file storage, encryption key management and backups. Amazon CloudFront delivers the application’s web files. | All data in the Senitix service, including customer data, user accounts, billing records and logs | EU: Frankfurt, Germany, with disaster recovery in Ireland. CloudFront serves web files from AWS locations worldwide. | Stored in the EEA. The SCCs in AWS’s data processing terms cover any processing outside the EEA. |
| Amazon Web Services (AWS): Amazon Bedrock | Runs the AI models behind Senitix AI | What a user asks Senitix AI, the CRM records needed to answer, and the response | EU: Bedrock routes each request to an AWS region in the EU | Processed in the EEA under AWS’s data processing terms |
| Tavily | Runs the web search Senitix AI can use when a user turns it on | The search query Senitix AI writes for the request, which can include customer data, and the search results it returns | United States | SCCs in Tavily’s data processing terms |
| Cloudflare, Inc. | DNS, content delivery, web application firewall, DDoS protection and bot management for senitix.com and the Senitix application | IP addresses, request metadata, and the traffic that passes through its network, including customer data in transit | Cloudflare’s global network, at the location nearest each user. Cloudflare is based in the United States. | SCCs in Cloudflare’s data processing terms |
| Twilio Inc. (Twilio SendGrid) | Sends the emails the Senitix service generates, such as invitations, password resets and notifications; receives email sent to Senitix service addresses; relays messages from the senitix.com contact form | Names and email addresses of senders and recipients, and email content, which can include customer data | United States | SCCs in Twilio’s data processing terms |
| Twilio Inc. | Sends verification codes by SMS, for phone verification and for multi-factor authentication where a user chooses SMS | Phone numbers and the text of verification messages | United States | SCCs in Twilio’s data processing terms |
| Functional Software, Inc. (Sentry) | Error monitoring for the Senitix application | Error reports and diagnostic data, which can include an IP address, a user or workspace identifier, and fragments of the data being processed when an error occurred | EU: Sentry’s EU region, Frankfurt, Germany | Stored in the EEA. The SCCs in Sentry’s data processing terms cover any access from outside the EEA. |
| Google LLC (Google Workspace) | Our company email, including the mailboxes that receive support and privacy requests | Emails and attachments that customers, users and others send us, which can include customer data | United States and Google’s other data center locations | SCCs in Google’s data processing terms |
| IPinfo | Looks up the approximate location of the IP address used for each sign-in and session, for account security | IP addresses | United States | SCCs in IPinfo’s data processing terms |
Twilio’s SMS service and IPinfo also support the account security Senitix provides as a controller, described in our Privacy Policy.
When a user works with Senitix AI, the request and the records needed to answer it are processed by models running inside Amazon Bedrock. We do not send customer data to the companies that develop those models, and customer data is not used to train AI models. If a user turns on Senitix AI’s web search, the search query Senitix AI writes for that request is sent to Tavily, as the table above describes. Senitix AI conversations are deleted after 180 days without activity.
In these tables, “EEA” means the European Economic Area, and “SCCs” means the Standard Contractual Clauses described in section 6. Services that receive no personal data, such as the exchange-rate feeds we use for billing, are not listed.
4. The providers for billing data and website analytics
Senitix controls the billing data it needs to invoice and collect payment for subscriptions, and, if a website visitor accepts analytics, the data our website analytics tool then collects, as our Privacy Policy and Cookie Policy describe. The providers below handle that data only. Because neither processes customer data, neither is a sub-processor under the DPA, but we list them here so that the picture is complete.
| Provider | What it does for Senitix | Personal data involved | Where it processes data | Transfer safeguard |
|---|---|---|---|---|
| iyzi Ödeme ve Elektronik Para Hizmetleri A.Ş. (iyzico) | Processes subscription payments and stores payment cards | Cardholder name and card details (stored by iyzico, not by Senitix), billing contact details and transaction records | Türkiye | Processed in Türkiye, where Senitix is also established |
| Google LLC / Google Ireland Limited (Google Analytics) | Measures how visitors use our marketing website, only for a visitor who accepts the Analytics category in our cookie banner; see our Cookie Policy | Pages viewed, referring site, device, browser, language, approximate city-level location derived from IP address (the IP address itself is not logged or stored), and the contact/sales-form and free-trial-click events described in the Cookie Policy | Google Ireland Limited for visitors in the EEA, the UK and Türkiye; Google LLC (United States) for other visitors | Standard contractual clauses in Google’s data processing terms; Google LLC is also certified under the EU-U.S. Data Privacy Framework |
5. Services a customer chooses to connect
Where a customer’s plan includes them, its users can connect their email, calendar and sign-in accounts to Senitix. Senitix then connects to that account with the user’s authorization and uses it only for the features the user turns on. A user can disconnect a service at any time, which stops further syncing.
These providers are not Senitix sub-processors. The customer or user holds the account with the provider, under the provider’s own terms, and decides to connect it; we do not engage the provider to process data for us. Email and calendar items synced into Senitix become customer data, stored and processed by the sub-processors in section 3. The same applies to any other third-party service a customer chooses to connect to its workspace.
| Service | Provider | What Senitix accesses | What it is used for |
|---|---|---|---|
| Gmail | Messages and their metadata in the connected mailbox, and the account’s name and email address | Showing email on the right contacts, accounts and deals, and sending the email a user writes in Senitix | |
| Google Calendar | Events in the connected calendars and the list of those calendars | Showing meetings on CRM records, and creating or updating the events a user schedules in Senitix | |
| Outlook mail (Microsoft 365) | Microsoft | Messages in the connected mailbox, and the account’s name and email address | The same purposes as Gmail |
| Outlook calendar (Microsoft 365) | Microsoft | Events in the connected calendar | The same purposes as Google Calendar |
| Other mailboxes, over IMAP and SMTP | The user’s own email provider | Messages in the connected mailbox, using the server details and credentials the user enters | The same purposes as Gmail |
| Sign-in with GitHub | GitHub | The user’s name, email address and confirmation that GitHub has signed the user in | Letting a user sign in with an identity they already have, where the customer’s plan and settings allow it |
| Sign-in with an existing account, and single sign-on | Google, Microsoft or another OpenID Connect provider the customer uses | The user’s name, email address and confirmation that the provider has signed the user in | Letting a user sign in with an identity they already have, where the customer’s plan and settings allow it |
5.1 Google user data and Limited Use
Senitix’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We use Gmail and Google Calendar data only to provide the features a user turns on. We do not use it for advertising, and we do not use it to develop, improve or train generalized AI or machine-learning models. When a user asks Senitix AI to summarize or draft email, the messages involved are processed through Amazon Bedrock as section 3 describes, and they are not used for training. The Privacy Policy’s section on Google user data explains what we access and how we protect it. A user can disconnect Gmail or Google Calendar in Senitix at any time, or remove Senitix’s access in their Google Account settings.
5.2 Outlook mail and calendar data
We handle Outlook mail and calendar data under the same limits: only to provide the features a user turns on, never for advertising, and never to train AI models. A user can disconnect Outlook in Senitix at any time, and the user or their organization’s Microsoft administrator can also remove Senitix’s access in Microsoft’s own settings.
6. How international transfers are protected
6.1 Under EU and UK law
When a provider outside the European Economic Area (EEA) and the UK processes personal data covered by the GDPR or the UK GDPR, we rely on the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 (the “SCCs”), as included in that provider’s data processing terms. The SCCs apply in their processor-to-processor form (Module 3) to customer data, and in their controller-to-processor form (Module 2) to data Senitix controls. For personal data covered by UK law, we rely on the International Data Transfer Addendum issued by the UK Information Commissioner.
Our staff in Türkiye can access customer data (section 2), and the European Commission has not recognized Türkiye as providing an adequate level of data protection. For that reason, the DPA also incorporates the SCCs between each customer and Senitix, using Module 2 where the customer is a controller and Module 3 where the customer is itself a processor, together with the UK Addendum for UK data.
6.2 Under Turkish law
Because Senitix is established in Türkiye, Article 9 of Turkish Law No. 6698 on the Protection of Personal Data (KVKK) also governs the personal data we transfer from Türkiye to providers in other countries, including providers in the EU. No country has an adequacy decision under the KVKK, so these transfers rely on one of the safeguards Article 9 lists. The one suited to provider relationships is a standard contract in the form published by the Personal Data Protection Board, which must be notified to the Personal Data Protection Authority within five business days after it is signed.
6.3 Getting a copy
You can ask for a copy of the safeguards that apply to a given provider at privacy@senitix.com. We may remove commercially sensitive terms from the copy. A customer assessing a transfer can also ask us for the information its assessment needs.
7. How we select and oversee sub-processors
- Before we engage a provider that will handle personal data, we assess its security and privacy practices for the service it will provide.
- We engage a provider only under a written contract that requires it to process personal data solely to provide its service to us, to keep that data confidential and secure, and to meet data protection obligations at least as protective as those in the DPA. Where US state privacy laws apply, that contract limits the provider to the uses those laws permit for service providers and processors.
- We remain responsible to our customers for how our sub-processors perform these obligations, as the DPA sets out.
- We review this list when our services or providers change, and we keep this page current.
Giving personal data to these providers so that they can provide their services to us is not a sale or sharing of personal information. Senitix does not sell or share personal information. Our security page describes how we protect the data in our own systems.
8. Changes to this list and your right to object
8.1 How we notify you
Before a new or replacement sub-processor starts processing customer data, we give customers at least 14 days’ notice. We email the notice to the administrators of each customer workspace and update this page at the same time. The notice names the provider, the service it will provide, the customer data involved, where it will process that data and when it will start.
To have these notices sent to an additional address, such as your privacy or procurement team, write to privacy@senitix.com. Changes to section 4 are recorded in the change history below, but are not subject to the objection process, because those providers do not process customer data.
8.2 How to object
You can object to a new or replacement sub-processor on reasonable data protection grounds within 14 days of our notice, by writing to privacy@senitix.com and explaining your grounds. If we receive no objection in that period, the change is treated as authorized under the DPA.
If you object, we will work with you in good faith to resolve your concern, for example by explaining the safeguards in place or, where we reasonably can, by offering a way to use Senitix without the new sub-processor processing your data. If we cannot resolve the objection within a reasonable time, not longer than 30 days after we receive it, you may terminate your subscription by written notice without any termination fee.
8.3 Urgent replacement
If we must replace a sub-processor urgently, for example because it has stopped providing its service or presents a security risk, we may make the change immediately and give notice as soon as we practically can. In that case, your right to object under section 8.2 runs from the date of that later notice.
8.4 Change history
September 12, 2026. This list is published as a separate page for the first time. It replaces the sub-processor table in the previous version of our DPA (version 1.1, dated June 2, 2026). Compared with that table:
- Amazon Web Services is listed as our primary hosting provider, and Amazon Bedrock as the service behind Senitix AI.
- Tavily is added to section 3, as the provider behind Senitix AI’s web search.
- Google Workspace (company email), Twilio’s SMS service and IPinfo (sign-in location lookups) are added to section 3, because, like the other sub-processors there, they can process customer data. iyzico remains in section 4, because it processes only billing data that Senitix controls.
- Google Analytics is added to section 4, as our website’s analytics tool: it is not a sub-processor because it processes only website-visitor data that Senitix controls, and only for a visitor who has accepted analytics in our cookie banner.
- GitHub is added to section 5, as a sign-in option a customer can choose to offer its users.
- Sentry is shown in its EU region, and iyzico under its current legal name, iyzi Ödeme ve Elektronik Para Hizmetleri A.Ş.
- DigitalOcean, Contabo and Cloudflare R2 storage are no longer listed. None of them stores Senitix customer data.
9. Questions
- Questions about this list, objections to a sub-processor, or a copy of the safeguards for a provider: privacy@senitix.com
- Notices under the DPA and requests for a signed copy of the DPA: legal@senitix.com
Senitix Teknoloji LTD. ŞTİ., Cevizli Mah. Zuhal Cad. A Blok No:46 İç Kapı No:50, Maltepe, İstanbul, Türkiye. Our company information page has the rest of our details, and the GDPR and data protection page explains how these providers fit into our wider data protection program.
