This document distinguishes third parties that process Customer Personal Data for Sento from recipients used for Sento's own controller/business activities.
1. Definitions
A Subprocessor is a third party engaged by Sento to process Customer Personal Data on Sento's behalf while Sento acts as processor/service provider under the DPA.
An independent controller or other recipient receives Personal Data for an independent legal or business purpose and is not automatically a Subprocessor.
A website analytics provider may process website visitor data for Sento's own controller/business analytics and is not automatically a Customer Personal Data Subprocessor.
2. Customer Personal Data Subprocessor categories
| Category | Purpose | Customer Personal Data potentially processed | Processing location | Transfer safeguard | Customer-selected? |
|---|---|---|---|---|---|
| Hosting, database, object-storage and backup providers | Host, store, protect, recover and operate the Service | Customer Content and related account/service metadata required for the Service | Current deployment / provider record | International Data Transfer Addendum and applicable lawful mechanism | Usually no, unless the Order Form states otherwise |
| AI inference, model and embedding providers | Provide enabled inference, classification, retrieval, embedding and generation functions | Customer-approved prompts/context, documents, messages, Input and Output required for the enabled function | Current provider/deployment record | International Data Transfer Addendum and applicable lawful mechanism | May be Customer-selectable where the Service offers model/provider choice |
| Communication and authentication providers | Send or receive enabled communications and support authentication/account functions | Contact details, message-routing metadata, authentication/account data and, where required by the enabled channel, message content | Current provider/deployment record | International Data Transfer Addendum and applicable lawful mechanism | May depend on Customer-selected integration |
| Monitoring, security and support providers | Protect, monitor, troubleshoot and support the Service | Limited technical, security, diagnostic or support data; Customer Content only where necessary and authorized for support | Current provider/deployment record | International Data Transfer Addendum and applicable lawful mechanism | Usually no |
The actual legal entity, service, processing location and applicable safeguard for an engaged Customer Personal Data Subprocessor must be maintained in Sento's current provider/deployment record and disclosed to Customer where the DPA or applicable law requires it. Sento does not use this public category table to invent or imply a provider that has not actually been engaged.
3. General authorization and changes
Customer gives the general Subprocessor authorization described in the DPA. Before a material new Subprocessor begins processing Customer Personal Data, Sento provides prior notice where the DPA or applicable law requires notice and gives Customer the objection opportunity described in the DPA.
Sento imposes written privacy, confidentiality and security obligations appropriate to the processing and remains responsible for its Subprocessors to the extent required by the DPA and applicable law.
4. Sento's own recipients and independent controllers
For Sento's own controller/business processing, recipients may include:
- payment, banking and tax providers;
- professional advisers, auditors and legal counsel;
- communications and marketing providers used for Sento's own permitted outreach;
- fraud-prevention and security providers;
- public authorities, regulators and courts where legally required; and
- a successor or transaction counterparty in a merger, financing, acquisition or sale, subject to appropriate safeguards.
A recipient that determines its own purpose and means of processing is treated as an independent controller or equivalent role where applicable rather than as a Subprocessor merely because Sento provides data to it.
5. Website analytics
For the international website, Google Analytics 4 may be used when configured. The applicable Google contracting entity and processing locations are determined by the current service terms/configuration and must not be inferred from this document.
Website analytics is governed by the International Privacy Policy and Cookie Notice. It is not part of Customer Personal Data processing under the DPA unless a specific deployment expressly makes it so.
6. International transfers
Restricted international transfers of Customer Personal Data are governed by the International Data Transfer Addendum and the mandatory transfer instrument applicable to the relevant transfer. The actual transfer route depends on the exporter/importer roles, processing locations and deployment facts.
7. Contact
Questions or Subprocessor objections under the DPA may be sent to [LEGAL_EMAIL].