Controller: The organisation that has entered into a subscription agreement with Senshin ("Customer").
Processor: Senshin Ltd, registered in England and Wales, 71-75 Shelton Street, London WC2H 9JQ ("Senshin").
Terms used in this DPA have the meanings given in the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the UK Data Protection Act 2018. "Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Supervisory Authority" are as defined therein.
Senshin processes Personal Data on behalf of the Customer solely for the purpose of providing the Senshin project delivery platform and related services as described in the subscription agreement.
Categories of data subjects: Customer employees, contractors, project stakeholders, and guest users.
Types of Personal Data: Name, email address, job title, organisation, project role, communication preferences, and any data voluntarily entered into the platform by the Customer.
Duration: Processing continues for the duration of the subscription plus any retention period described in section 10.
Senshin shall:
The Customer authorises Senshin to engage the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud Platform (GCP) | Infrastructure, compute, storage, AI services | europe-west2 (London) |
| Firebase (Google) | Authentication and user management | EU/UK |
| Stripe | Payment processing and subscription management | EU/UK |
| SendGrid (Twilio) | Transactional email delivery | EU/US (with SCCs) |
Senshin will notify the Customer at least 30 days before adding a new sub-processor. The Customer may object within 14 days. If the objection cannot be resolved, the Customer may terminate the subscription.
All Customer data is stored and processed in Google Cloud Platform, europe-west2 (London, United Kingdom). Data does not leave the UK/EEA unless required by a sub-processor listed above, in which case Standard Contractual Clauses (SCCs) apply.
Senshin implements the following technical and organisational measures:
In the event of a Personal Data breach, Senshin shall:
Senshin shall assist the Customer in responding to requests from data subjects exercising their rights under GDPR, including: access, rectification, erasure, restriction of processing, data portability, and objection to processing.
The platform includes self-service tools for data export and deletion requests accessible via the admin console.
Active subscription: Data is retained for the duration of the subscription.
After termination: Customer data is retained for 30 days to allow retrieval, then permanently deleted.
Backups: Backup copies are purged within 90 days of deletion.
Audit logs: Retained for 2 years for compliance purposes, then archived or deleted.
The Customer may request immediate deletion at any time via the GDPR tools in the admin console.
The Customer may audit Senshin's compliance with this DPA by:
Senshin's liability under this DPA is subject to the limitations set out in the subscription agreement. Nothing in this DPA excludes or limits liability for breaches caused by wilful misconduct or gross negligence.
This DPA is effective for the duration of the subscription agreement. It automatically terminates when the subscription ends, subject to the retention periods in section 10.