This Data Processing Agreement ("DPA") forms part of the Sento International B2B Terms or another agreement that incorporates it (the "Agreement") whenever [CONTRACTING_ENTITY_NAME] ("Sento") processes Customer Personal Data on behalf of Customer.
1. Roles
Customer is the controller/business or, where Customer processes data for another controller, the upstream processor. Sento is the processor/service provider/contractor or closest equivalent role for Customer Personal Data processed solely to provide the Service under Customer's documented instructions.
Sento acts independently as controller/business for its own account administration, billing, legal compliance, certain security/fraud-prevention activities, website operations and other independent purposes described in the International Privacy Policy. Those activities are outside this DPA.
2. Processing details
Subject matter: Customer Personal Data contained in Customer Content or otherwise provided to Sento for the Service.
Duration: for the Service term and the return/deletion period described below, unless applicable law requires longer retention.
Nature and purpose: receiving and routing communications; retrieving Customer-approved knowledge; AI inference, classification, summarization and response generation; ticket/record handling; Customer-configured workflow actions; integrations; account/service administration; security; troubleshooting; backup; support; and other processing documented in the Agreement or Customer configuration.
Data subjects: Customer personnel, Customer end users/customers and other persons whose Personal Data Customer lawfully provides to Sento.
Personal Data: business contact and account data; communication content; CRM/order/subscription/service-status data; documents and knowledge-base content; technical/usage/security data; and other ordinary Personal Data Customer lawfully provides for a supported use case.
The Supported and Restricted Data Schedule excludes categories and high-risk use cases that Sento does not support in the ordinary Service.
3. Documented instructions
Sento processes Customer Personal Data only on documented instructions expressed through the Agreement, Order Form, Customer configuration, API/integration settings and authorized support requests.
If applicable law requires Sento to process Customer Personal Data outside Customer instructions, Sento will notify Customer before the processing unless that law prohibits notice.
If Sento reasonably believes an instruction infringes applicable data-protection law, Sento may suspend the affected processing and notify Customer so the parties can address the issue.
4. Confidentiality and access
Sento limits access to personnel and providers that need access for an authorized purpose. Persons authorized to process Customer Personal Data are bound by confidentiality or equivalent legal duties.
5. Security
Sento maintains appropriate technical and organizational measures based on the nature, scope, context and purposes of processing and the risks to individuals. The public Security and Trust document describes the baseline. More specific verified measures may be stated in an Order Form or Security Addendum.
Sento does not represent that it holds a certification or attestation unless Sento expressly identifies the current certification, scope and status in writing.
6. Personal Data breaches
After becoming aware of a Personal Data breach affecting Customer Personal Data, Sento will notify Customer without undue delay and provide information reasonably available to support Customer's legal obligations, including the nature of the breach, affected data/data-subject categories, likely consequences and mitigation where known.
Sento may provide information in phases as the investigation progresses. Notification does not require completion of a final root-cause analysis.
A shorter mandatory processor-notification obligation in applicable law or an executed agreement controls where applicable.
7. Subprocessors
Customer grants Sento general authorization to use Subprocessors in the current Sento Subprocessors and Third-Party Recipients list.
Before a material new Subprocessor begins processing Customer Personal Data, Sento will provide reasonable prior notice where Customer has a legally required or contractually granted notice or objection right. Customer may object within the period stated in that notice on reasonable documented data-protection grounds.
Sento will work in good faith to address a valid objection through a reasonable alternative where available. If no reasonable alternative exists, the Agreement governs suspension or termination of the affected feature or Service.
Sento imposes written privacy, confidentiality and security obligations appropriate to the processing on each Subprocessor and remains responsible for Subprocessor performance to the extent required by applicable law and the Agreement.
8. Assistance
Taking into account the nature of processing and information available to Sento, Sento will reasonably assist Customer with:
- data-subject/consumer rights requests;
- security and breach obligations;
- data-protection impact assessments, risk assessments and prior consultations required for Customer's use; and
- reasonable regulator inquiries concerning Sento's processing for Customer.
Sento may charge reasonable fees for assistance that materially exceeds ordinary Service support where permitted by law and disclosed in advance. No fee limits a mandatory statutory assistance duty.
9. Return and deletion
At the end of the relevant Service, Customer may export Customer Personal Data using available Service functionality or another agreed method. Sento will then delete Customer Personal Data in accordance with the Agreement and Customer instructions unless applicable law requires retention.
Protected backups may remain until their normal overwrite/deletion cycle if isolated from ordinary use and protected under this DPA. Data retained solely because law requires it will not be used for an incompatible purpose.
10. Audits and compliance information
Sento will make available information reasonably necessary to demonstrate compliance with mandatory processor obligations. Where required by applicable law, Customer may conduct or commission a reasonable audit subject to confidentiality, security, scope and non-disruption safeguards.
Sento may satisfy an audit request first through current independent reports, certifications (if any), questionnaires or other compliance materials where those materials reasonably address the request. On-site or intrusive audits are limited to cases where legally required or where existing information is insufficient to address a substantiated compliance concern.
11. Government requests
Unless prohibited by law, Sento will notify Customer of a legally binding government request specifically seeking Customer Personal Data. Sento will disclose only the data legally required and, where reasonable and lawful, seek to narrow or challenge a request that appears unlawful or disproportionate.
12. AI processing
Customer Personal Data may be processed by Sento-operated or approved third-party AI components only to provide enabled Service functions, security or support under Customer instructions and the Agreement.
This DPA does not authorize Customer Content, Input or Output for generalized Sento or third-party model training. Generalized training requires a separate express arrangement and all independently required legal bases, notices, rights and transfer/provider controls.
Customer-specific indexing, embeddings, retrieval, inference and agreed Customer-specific adaptation are service processing and are not generalized model training merely because machine-learning technology is used.
13. Restrictions for US service-provider / contractor processing
Where the California CCPA/CPRA or another applicable US state privacy law treats Sento as a service provider, contractor or processor, Sento will comply with the restrictions applicable to that role.
For Customer Personal Data within such a role, Sento will not sell the data, share it for cross-context behavioral advertising, use it for targeted advertising, or retain/use/disclose it outside the direct business relationship except as the applicable law expressly permits. Sento will not combine Customer Personal Data across unrelated sources except where the applicable law permits the combination for a service-provider/processor purpose.
Sento will provide the same level of privacy protection required of the applicable processor/service-provider role and will assist Customer with applicable consumer requests, assessments and security duties as required by law.
14. International transfers
A restricted international transfer is governed by the Sento International Data Transfer Addendum and the official transfer mechanism required by the applicable law for the actual exporter, importer, roles and destination.
Where EU Standard Contractual Clauses, the UK International Data Transfer Agreement, the UK Addendum to the EU SCCs, ANPD standard contractual clauses or another mandatory transfer instrument applies, the official instrument prevails over inconsistent terms of this DPA and may be modified only as the instrument permits.
15. Precedence and liability
Mandatory data-protection and transfer obligations prevail over inconsistent contractual terms. Subject to those mandatory obligations, the liability provisions of the Agreement apply to this DPA.
Schedule 1 - Processing description
| Item | Description |
|---|---|
| Service | Sento AI-enabled customer-relations/help-desk platform and enabled integrations |
| Data subjects | Customer personnel; Customer end users/customers; other persons represented in supported Customer Content |
| Data categories | Ordinary business contact/account data; communications; CRM/order/subscription/service-status data; documents/knowledge content; technical/security/usage data; other supported Personal Data supplied under Customer instructions |
| Processing operations | Receive, record, organize, store, retrieve, transmit, classify, analyze, generate from, update, restrict, export, back up and delete as necessary for the Service |
| Purposes | Service delivery, AI-enabled functions, configured workflows/integrations, security, support, troubleshooting and backup |
| Duration | Service term plus return/deletion period, subject to legally required retention and protected backup overwrite |
Schedule 2 - Subprocessor authorization
Customer authorizes the categories and current providers identified in the Sento Subprocessors and Third-Party Recipients list, subject to Section 7 of this DPA. The list, Order Form and applicable deployment record identify actual providers and processing locations where disclosure is required.
Questions about this DPA may be sent to [LEGAL_EMAIL].