Legal
Data Processing Agreement
The contract that governs how we handle the personal data you put into the platform — written to be read by your legal team, not around them.
- Status
- In force
- Version
- 1.0
- In force from
- 8 September 2026
Sintoralabs OÜ · Registry code 17456201
This English text is the authentic version of this document. Translations into other languages are provided for convenience only; in the event of any discrepancy between a translation and this English version, the English version prevails.
1. Parties and how this agreement is entered into
This Data Processing Agreement ("DPA") governs the processing of personal data that Sintoralabs OÜ, registry code 17456201, Narva mnt 7-636, Kesklinna linnaosa, Tallinn, Harju maakond, 10117, Estonia ("Sintora", "we", the processor) carries out on behalf of the customer ("you", the controller) when providing the Sintora platform.
It forms part of the agreement between us: accepting the Terms of Use, or signing an order form that references them, brings this DPA into effect without a separate signature. Where your procurement process requires a signed counterpart, we will sign one on request — the terms are the same.
Where you act as a processor for your own customers, you are the controller towards us and we act as your sub-processor. The obligations below apply unchanged, and you remain responsible for having the authority to instruct us.
2. Subject matter, duration, nature and purpose
We process personal data only to provide, support, secure and maintain the platform, and only for as long as the agreement between us is in force. The processing covers the operations needed to run the service — collection, recording, organisation, structuring, storage, retrieval, use, disclosure by transmission, restriction, erasure and destruction.
The nature and purpose of processing, the categories of data and data subjects, and the duration are set out in Annex 1. That annex forms part of this DPA.
3. Roles of the parties
You determine the purposes and means of processing the personal data you put into the platform, and you are the controller for it. We process that data on your behalf and are the processor.
Separately, we act as a controller for a limited set of data we need for our own purposes: your account and billing records, security and audit logs, and aggregated usage statistics that do not identify a data subject. That processing is described in our Privacy Policy and is not governed by this DPA.
4. Your instructions
We process personal data only on your documented instructions, unless required otherwise by Union or Member State law — in which case we will tell you before processing, unless that law forbids it.
Your instructions are: this DPA, the agreement between us, and the configuration you set in the product — the settings, roles, retention options, integrations and routing you switch on are instructions in themselves. Written requests from an authorised address of yours also count as instructions.
If we consider an instruction to infringe data protection law, we will tell you promptly with our reasons, and may suspend that instruction until it is confirmed or replaced. We will not use your personal data for our own purposes, for marketing, or disclose it to third parties except as this DPA allows.
5. AI features and model training
The platform includes AI features that summarise conversations, draft content, propose tasks and highlight risks. Personal data processed by those features is processed for you and under this DPA, on the same footing as the rest of the service.
We do not use your content, your prompts or the output generated for you to train, fine-tune or improve any generative model, whether ours or a third party’s. Where model inference is performed by a sub-processor, that provider is bound by the same restriction and is listed in Annex 2.
We may use aggregated and de-identified statistics — counts, latencies, error rates — to operate and improve the service, provided they cannot be attributed to you or to any data subject.
Under the EU AI Act we are the provider of the AI features we make available under our name, and you are the deployer when you put them to use in your own operations. Each role carries its own duties under the Regulation directly, and neither of us can move its own onto the other by agreement. Depending on how a feature is deployed — in particular where you make it available to your own clients, guests or tenants — you may carry transparency duties of your own under Article 50. We provide the product disclosures and the means to support you in discharging them, and our AI transparency page sets out, paragraph by paragraph, which of those duties we read as ours. What your own regulator asks of you for your deployment is yours to determine.
There are two arrangements and the difference matters, so we set both out rather than describing one.
For AI features built into the platform — the AI agents and the content tools among them — inference runs on our own account with an inference provider. That provider is our sub-processor, it is named in Annex 2, and it is bound by the training prohibition above through the terms of our agreement with it. The developer of the model it runs is a separate party and not our sub-processor, because no content of yours reaches them; the paragraph under Annex 2 sets out why. Where a provider is established outside the EEA, the transfer mechanism for it is stated in Annex 2.
Where you connect an AI provider through your own account — Companion is the one that works this way today — inference runs on your account with that provider. The nature of the processing relationship depends on your configuration and on your agreement with that provider; we do not use an account of our own for that inference route, and the retention and abuse-monitoring practices that apply to it are set by your relationship with them.
AI features can be disabled for your tenant. Ask us and we switch them off; no feature depends on them to function.
6. Confidentiality of personnel
Everyone we authorise to process personal data is bound by a duty of confidentiality — by contract or by statute — that survives the end of their engagement. Access is granted by role, on a need-to-know basis, and revoked promptly on departure or role change.
7. Security of processing
We implement and maintain the technical and organisational measures set out in Annex 3, appropriate to the risk, as required by Art. 32 GDPR. Those measures cover encryption in transit and at rest, access control, environment separation, backup and recovery, vulnerability management, logging and incident response.
We may update the measures as the platform and the threat landscape change, provided the overall level of protection is not reduced.
8. Sub-processors
You give us general written authorisation to engage sub-processors. The current list is in Annex 2, which we keep up to date and publish here.
Before a new sub-processor starts processing your personal data we will give you advance written notice. The notice period is to be confirmed and will be recorded in this section. Until it is, we give as much notice as is reasonably practicable in the circumstances. You may object on reasonable data-protection grounds within the notice period. If you do, we will work with you in good faith to offer an alternative; if none can be found within the same period from your objection, you may terminate the affected part of the service without penalty and receive a pro-rata refund of prepaid fees for it.
Every sub-processor is bound by written terms that impose data protection obligations at least as protective as those in this DPA. We remain fully liable to you for their acts and omissions as if they were our own.
Subscribe to changes by writing to info@sintora.ai — we will notify the address you give us before the list changes, not after.
9. International transfers
We keep customer data within the European Economic Area by default. Where a transfer to a third country is necessary, it relies on a mechanism recognised under Chapter V GDPR: an adequacy decision, or the Standard Contractual Clauses adopted by the Commission in Decision (EU) 2021/914 in the module appropriate to the transfer, incorporated into this DPA by reference.
Where the Clauses apply, the docking clause is available, the governing law is Estonian, and the competent supervisory authority is the Estonian Data Protection Inspectorate.
On request we will provide the information you reasonably need to carry out a transfer impact assessment, and we will apply supplementary technical measures where the assessment calls for them.
10. Assistance with your obligations
Taking into account the nature of the processing and the information available to us, we will assist you with:
- Data subject requests — access, rectification, erasure, restriction, portability and objection. The product includes export and deletion tools so you can answer most requests yourself; where you need us, we respond within 10 working days and always in time for your own statutory deadline.
- Requests we receive directly from a data subject — we forward them to you without undue delay and do not answer on the merits without your documented instructions, unless the law requires us to.
- Security of processing under Art. 32, data protection impact assessments under Art. 35 and prior consultation under Art. 36, by providing the information we hold about our measures, risks and sub-processors.
- Requests from public authorities — where legally permitted we notify you first, disclose only the minimum required, and challenge requests that are manifestly unlawful or excessive.
11. Personal data breach
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting personal data we process for you.
The notification will describe the nature of the breach and, where possible, the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it and mitigate its effects; and a contact point for further information. Where the full picture is not available at once, we will provide it in phases as it emerges.
We will assist you in meeting your own obligations under Art. 33 and 34 GDPR, and will not notify a supervisory authority or data subjects on your behalf unless you ask us to or the law requires it of us.
12. Audits and inspections
We will make available the information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
In practice that means, in order of least disruption: our security documentation and completed questionnaires on request; an independent audit report or certification where one is available, which satisfies this section for the period and scope it covers; and, where those do not answer your question, an audit conducted at most once in any 12 months on 30 days’ written notice, during business hours, subject to confidentiality, and not extending to other customers’ data.
You bear the cost of an audit, unless it reveals a material breach of this DPA by us, in which case we bear the reasonable cost of the audit and of remediation. A supervisory authority exercising its own powers is not limited by this section.
13. Return and deletion
You can export your data in a structured, commonly used, machine-readable format at any time during the term, from the product itself.
On termination we keep the data available for export for 30 days. After that we delete it from active systems. Copies held in encrypted backups are overwritten in the ordinary backup rotation, which does not exceed 90 days; during that window the data is not available for ordinary processing and is not restored except to recover the service as a whole.
We will confirm deletion in writing on request. We keep data beyond these periods only where Union or Member State law requires it, and only for as long as that law requires.
14. Records of processing
We maintain a record of the processing carried out on your behalf, as required by Art. 30(2) GDPR, and will provide the relevant extract on request within a reasonable period.
15. Liability
Each party is liable for damage caused by processing that infringes the GDPR to the extent Art. 82 provides. Liability under this DPA is subject to the limitations and exclusions in the agreement between us, except where those limitations cannot be applied under mandatory law.
Where no other cap is agreed in a signed order form, the aggregate cap in the Terms of Use applies to this DPA as well: the fees paid in the twelve months before the event, or EUR 1,000 where no fees have been paid. Enterprise customers routinely negotiate a higher cap for data protection claims, and we expect to; ask, and it is a commercial conversation rather than a refusal.
16. Changes to this DPA
We may update this DPA where the law, the service or our processing changes. Where a change materially affects your rights, we will give reasonable notice before it takes effect. Changes to Annex 2 follow the notice and objection right in the "Sub-processors" section rather than this one.
The revision number at the top identifies the version you are reading. Any change to this document will be listed in the document history, with its date.
17. Governing law and order of precedence
This DPA is governed by the laws of Estonia, and the courts of Estonia have jurisdiction, without prejudice to a data subject’s rights under Art. 79 GDPR or to the terms of the Standard Contractual Clauses where they apply.
In case of conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the Terms of Use and any order form, in each case only as regards the processing of personal data.
18. Contact
Questions about this DPA, requests for a signed counterpart, sub-processor notifications and data protection matters generally: info@sintora.ai, or by post to Sintoralabs OÜ, Narva mnt 7-636, Kesklinna linnaosa, Tallinn, Harju maakond, 10117, Estonia.
We have assessed the Article 37 criteria and are not required to appoint a Data Protection Officer: we are not a public authority, our core activities are not regular and systematic monitoring of data subjects on a large scale, and we do not process special categories of data on a large scale. Data protection matters go to the address above, which is monitored by the person accountable for them. We keep the assessment under review and will publish contact details here if a DPO is appointed.
19. Annex 1 — Details of processing
Duration: for the term of the agreement between us, plus the retention window in the "Return and deletion" section.
| Item | Detail |
|---|---|
| Subject matter | Provision of the Sintora platform — operations, marketing and product delivery on a shared data model, plus industry solutions installed as modules. |
| Nature and purpose | Hosting, storage, transmission, retrieval, structuring, analysis and display of customer content in order to provide, support, secure and maintain the service. |
| Categories of data subjects | Your employees, contractors and administrators; your customers, leads and their contacts; the tenants, guests and clients of your own business, including where you use an industry solution; participants in calls, chats and tickets. |
| Categories of personal data | Identity and contact data (name, role, email, phone); account and authentication data (logins, IP address, device and session data); communications content (messages, call recordings and transcripts, comments, documents); customer relationship data (deals, tickets, activity history); HR data where the HR module is used; billing and transaction data; anything else you choose to put into the platform. |
| Special categories | Not processed under this DPA unless expressly agreed in writing, with a description of the additional safeguards. You undertake not to instruct us to process Art. 9 or Art. 10 data without that agreement. |
| Frequency | Continuous, for the duration of the agreement. |
20. Annex 2 — Sub-processors
The following sub-processors are engaged in the provision of the service. Each is bound by written data protection terms at least as protective as this DPA, and transfers outside the EEA rely on the mechanisms described in the "International transfers" section.
Where a cell reads "to be confirmed", that is the state of the entry and not a formula: the provider is confirmed, the detail after the dash is not, and we would rather this annex said so than state a region nobody has checked. We confirm these before we ask you to sign.
| Sub-processor | Purpose | Data | Location | Transfer | Engaged |
|---|---|---|---|---|---|
| Hetzner Online GmbH | Infrastructure, compute, databases, storage and backups for the website and the platform | Customer content, account and application data, files, logs | EEA — to be confirmed: the specific region and availability zone | Processing within the EEA — to be confirmed: which Hetzner location production runs in | Always |
| Cloudflare, Inc. | DNS, content delivery, WAF, DDoS mitigation and bot protection — to be confirmed: which of these are enabled in front of the site today, since only Turnstile is proven | IP address, request headers, request and security metadata | EU / global edge, depending on configuration — to be confirmed: the edge configuration in force | DPF or the Standard Contractual Clauses, where applicable — to be confirmed: whether the DPF certification is current and whether our contract carries the Clauses | Always |
| Scaleway SAS | AI inference using agreed models on Scaleway infrastructure | Prompts, selected context, files where applicable, generated output | France / EEA — to be confirmed: the specific region | Processing within the EEA — to be confirmed: which Scaleway region inference runs in | AI features |
Our workflow automation is deliberately absent: it is open-source software we deployed and operate ourselves, so it is us processing rather than a third party we hand your data to. It runs on the infrastructure of our hosting provider inside the EEA, and that provider is on this list. Where you connect an AI provider through your own account — Companion works this way — that provider is likewise absent, because this annex lists the parties we engage and we do not engage that one: inference runs on your account and we do not use an account of our own for that route. What the processing relationship is between you and that provider depends on your configuration and your agreement with them, and it belongs in your own records rather than in this annex.
The developers of the models run for built-in AI features are also absent, and for a reason worth stating rather than leaving to inference. A sub-processor is a party we hand your data to. Where the inference provider above executes a model’s weights on its own infrastructure, the model’s developer receives none of your prompts, none of the context and none of the generated output — so they are not our sub-processor for that processing. The model families in use are published on our Trust Center under “AI and your data”; they are named there because the question is worth answering, not because a model is a party to this annex.
The inference provider above is added or changed under the same notice as any other sub-processor. If you need a specific provider excluded for your tenant, tell us and we will confirm whether the affected features can run without it.
A transactional email provider is also absent because we do not yet use one. When we do, it is added here on the same notice as any other.
Every addition to this annex follows the notice and objection right set out above. If you want to be told directly rather than checking this page, write to info@sintora.ai and we will add you to the notification list.
21. Annex 3 — Technical and organisational measures
The measures below implement Art. 32 GDPR. They describe what we operate. Specific parameters — versions, intervals, thresholds — are provided on request under NDA rather than published, because a public list of exact configuration is a map for anyone probing it, and because a figure published today is a figure that silently goes stale.
- Encryption — TLS for data in transit; storage-level encryption at rest; secrets held in a managed secret store rather than in code or configuration. The enforced TLS version, cipher policy and key rotation interval are provided on request.
- Access control — least privilege, named accounts, multi-factor authentication for administrative access, periodic access review, prompt revocation on departure, and logging of administrative actions.
- Tenant isolation — each customer is a separate tenant and data is segregated so one tenant cannot read or affect another’s. Industry solutions install as modules inside your own tenant, which keeps isolation, permissions and audit consistent. The technical isolation model is described on request under NDA.
- In-product controls you operate — granular roles assigned per action rather than per screen, scoped by network, object or team; an audit log of significant actions; export in CSV and PDF; and administration of your own users.
- Environment separation — production, staging and development are separated, with distinct credentials and network policies; production data is not used for development or testing.
- Secure development — version control, peer review and automated checks before release; dependencies monitored for known vulnerabilities and updated as part of routine maintenance.
- Backup and recovery — regular encrypted backups stored separately from production, with documented continuity and recovery plans. Backup frequency and retention, recovery objectives and the date of the last restore test are provided on request; where you need them committed rather than described, they belong in a signed order form.
- Logging and monitoring — application, infrastructure and security logs collected, availability and error rates monitored, anomalies alerted on, log access restricted. Website and server logs are retained for 30 days.
- Vulnerability management — risk-based patching prioritised by severity and exposure; findings from scanning, code review and third-party reports tracked to resolution. We have not yet commissioned an independent penetration test; when we do, a summary is available under NDA. Remediation targets by severity are agreed in a signed order form where a customer requires them.
- Incident response — a defined process covering detection, triage, containment, eradication, recovery and post-incident review, with roles and escalation paths agreed in advance.
- People — confidentiality obligations for everyone with access to customer data, security and data protection awareness training, and access granted by role on joining. Everyone with access completes data protection awareness training on joining and annually thereafter.
- Physical security — inherited from the infrastructure provider’s data centres, including access control, monitoring and their own certifications.