Senshin

Data Processing Agreement
Last updated: 4 April 2026 · Version 1.0 · GDPR Article 28 Compliant

Contents

  1. Parties
  2. Definitions
  3. Scope and purpose
  4. Processor obligations
  5. Sub-processors
  6. Data location
  7. Security measures
  8. Breach notification
  9. Data subject rights
  10. Retention and deletion
  11. Audit rights
  12. Liability
  13. Termination

1. Parties

Controller: The organisation that has entered into a subscription agreement with Senshin ("Customer").

Processor: Senshin Ltd, registered in England and Wales, 71-75 Shelton Street, London WC2H 9JQ ("Senshin").

2. Definitions

Terms used in this DPA have the meanings given in the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the UK Data Protection Act 2018. "Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Supervisory Authority" are as defined therein.

3. Scope and purpose

Senshin processes Personal Data on behalf of the Customer solely for the purpose of providing the Senshin project delivery platform and related services as described in the subscription agreement.

Categories of data subjects: Customer employees, contractors, project stakeholders, and guest users.

Types of Personal Data: Name, email address, job title, organisation, project role, communication preferences, and any data voluntarily entered into the platform by the Customer.

Duration: Processing continues for the duration of the subscription plus any retention period described in section 10.

4. Processor obligations

Senshin shall:

5. Sub-processors

The Customer authorises Senshin to engage the following sub-processors:

Sub-processorPurposeLocation
Google Cloud Platform (GCP)Infrastructure, compute, storage, AI serviceseurope-west2 (London)
Firebase (Google)Authentication and user managementEU/UK
StripePayment processing and subscription managementEU/UK
SendGrid (Twilio)Transactional email deliveryEU/US (with SCCs)

Senshin will notify the Customer at least 30 days before adding a new sub-processor. The Customer may object within 14 days. If the objection cannot be resolved, the Customer may terminate the subscription.

6. Data location

All Customer data is stored and processed in Google Cloud Platform, europe-west2 (London, United Kingdom). Data does not leave the UK/EEA unless required by a sub-processor listed above, in which case Standard Contractual Clauses (SCCs) apply.

7. Security measures

Senshin implements the following technical and organisational measures:

8. Breach notification

In the event of a Personal Data breach, Senshin shall:

  1. Notify the Customer without undue delay and in any event within 72 hours of becoming aware of the breach.
  2. Provide sufficient information for the Customer to fulfil its own breach notification obligations.
  3. Take immediate steps to contain and remediate the breach.
  4. Cooperate with the Customer and any supervisory authority in investigating the breach.

9. Data subject rights

Senshin shall assist the Customer in responding to requests from data subjects exercising their rights under GDPR, including: access, rectification, erasure, restriction of processing, data portability, and objection to processing.

The platform includes self-service tools for data export and deletion requests accessible via the admin console.

10. Retention and deletion

Active subscription: Data is retained for the duration of the subscription.

After termination: Customer data is retained for 30 days to allow retrieval, then permanently deleted.

Backups: Backup copies are purged within 90 days of deletion.

Audit logs: Retained for 2 years for compliance purposes, then archived or deleted.

The Customer may request immediate deletion at any time via the GDPR tools in the admin console.

11. Audit rights

The Customer may audit Senshin's compliance with this DPA by:

12. Liability

Senshin's liability under this DPA is subject to the limitations set out in the subscription agreement. Nothing in this DPA excludes or limits liability for breaches caused by wilful misconduct or gross negligence.

13. Termination

This DPA is effective for the duration of the subscription agreement. It automatically terminates when the subscription ends, subject to the retention periods in section 10.

Enterprise customers: If you require a custom DPA with specific clauses for your organisation, contact legal@senshin.app.