Sintora Give Your Company One Brain

Legal

Data Processing Agreement

The contract that governs how we handle the personal data you put into the platform — written to be read by your legal team, not around them.

Effective date: 1 August 2026 · Sintoralabs OÜ · Registry code 17456201

Draft — pending legal review

This document is a working draft prepared for review. It is not yet in force and does not create obligations for Sintoralabs OÜ or its customers. Sections marked “to be confirmed” still need company-specific detail before publication.

1. Parties and how this agreement is entered into

This Data Processing Agreement ("DPA") governs the processing of personal data that Sintoralabs OÜ, registry code 17456201, Narva mnt 7-636, Kesklinna linnaosa, Tallinn, Harju maakond, 10117, Estonia ("Sintora", "we", the processor) carries out on behalf of the customer ("you", the controller) when providing the Sintora platform.

It forms part of the agreement between us: accepting the Terms of Use, or signing an order form that references them, brings this DPA into effect without a separate signature. Where your procurement process requires a signed counterpart, we will sign one on request — the terms are the same.

Where you act as a processor for your own customers, you are the controller towards us and we act as your sub-processor. The obligations below apply unchanged, and you remain responsible for having the authority to instruct us.

2. Subject matter, duration, nature and purpose

We process personal data only to provide, support, secure and maintain the platform, and only for as long as the agreement between us is in force. The processing covers the operations needed to run the service — collection, recording, organisation, structuring, storage, retrieval, use, disclosure by transmission, restriction, erasure and destruction.

The nature and purpose of processing, the categories of data and data subjects, and the duration are set out in Annex 1. That annex forms part of this DPA.

3. Roles of the parties

You determine the purposes and means of processing the personal data you put into the platform, and you are the controller for it. We process that data on your behalf and are the processor.

Separately, we act as a controller for a limited set of data we need for our own purposes: your account and billing records, security and audit logs, and aggregated usage statistics that do not identify a data subject. That processing is described in our Privacy Policy and is not governed by this DPA.

4. Your instructions

We process personal data only on your documented instructions, unless required otherwise by Union or Member State law — in which case we will tell you before processing, unless that law forbids it.

Your instructions are: this DPA, the agreement between us, and the configuration you set in the product — the settings, roles, retention options, integrations and routing you switch on are instructions in themselves. Written requests from an authorised address of yours also count as instructions.

If we consider an instruction to infringe data protection law, we will tell you promptly with our reasons, and may suspend that instruction until it is confirmed or replaced. We will not use your personal data for our own purposes, for marketing, or disclose it to third parties except as this DPA allows.

5. AI features and model training

The platform includes AI features that summarise conversations, draft content, propose tasks and highlight risks. Personal data processed by those features is processed for you and under this DPA, on the same footing as the rest of the service.

We do not use your content, your prompts or the output generated for you to train, fine-tune or improve any generative model, whether ours or a third party’s. Where model inference is performed by a sub-processor, that provider is bound by the same restriction and is listed in Annex 2 with the role "model inference".

We may use aggregated and de-identified statistics — counts, latencies, error rates — to operate and improve the service, provided they cannot be attributed to you or to any data subject.

Under the EU AI Act we are the provider of the AI features we make available under our name and you are the deployer. Where you make those features available to your own clients, guests or tenants, you are responsible for telling them they are interacting with an AI system.

To be confirmed before publication: which providers perform model inference and in which regions, whether any provider retains prompts for abuse monitoring and for how long, and whether AI features can be disabled per tenant. These are the first questions an enterprise buyer asks, so the answers belong here rather than in a sales call.

6. Confidentiality of personnel

Everyone we authorise to process personal data is bound by a duty of confidentiality — by contract or by statute — that survives the end of their engagement. Access is granted by role, on a need-to-know basis, and revoked promptly on departure or role change.

7. Security of processing

We implement and maintain the technical and organisational measures set out in Annex 3, appropriate to the risk, as required by Art. 32 GDPR. Those measures cover encryption in transit and at rest, access control, environment separation, backup and recovery, vulnerability management, logging and incident response.

We may update the measures as the platform and the threat landscape change, provided the overall level of protection is not reduced.

8. Sub-processors

You give us general written authorisation to engage sub-processors. The current list is in Annex 2, which we keep up to date and publish here.

Before a new sub-processor starts processing your personal data we will give you at least 30 days’ notice. You may object on reasonable data-protection grounds within that period. If you do, we will work with you in good faith to offer an alternative; if none can be found within 30 days of your objection, you may terminate the affected part of the service without penalty and receive a pro-rata refund of prepaid fees for it.

Every sub-processor is bound by written terms that impose data protection obligations at least as protective as those in this DPA. We remain fully liable to you for their acts and omissions as if they were our own.

Subscribe to changes by writing to privacy@sintora.ai — we will notify the address you give us before the list changes, not after.

9. International transfers

We keep customer data within the European Economic Area by default. Where a transfer to a third country is necessary, it relies on a mechanism recognised under Chapter V GDPR: an adequacy decision, or the Standard Contractual Clauses adopted by the Commission in Decision (EU) 2021/914 in the module appropriate to the transfer, incorporated into this DPA by reference.

Where the Clauses apply, the docking clause is available, the governing law is Estonian, and the competent supervisory authority is the Estonian Data Protection Inspectorate.

On request we will provide the information you reasonably need to carry out a transfer impact assessment, and we will apply supplementary technical measures where the assessment calls for them.

10. Assistance with your obligations

Taking into account the nature of the processing and the information available to us, we will assist you with:

  • Data subject requests — access, rectification, erasure, restriction, portability and objection. The product includes export and deletion tools so you can answer most requests yourself; where you need us, we respond within 10 working days and always in time for your own statutory deadline.
  • Requests we receive directly from a data subject — we forward them to you without undue delay and do not answer on the merits without your documented instructions, unless the law requires us to.
  • Security of processing under Art. 32, data protection impact assessments under Art. 35 and prior consultation under Art. 36, by providing the information we hold about our measures, risks and sub-processors.
  • Requests from public authorities — where legally permitted we notify you first, disclose only the minimum required, and challenge requests that are manifestly unlawful or excessive.

11. Personal data breach

We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting personal data we process for you.

The notification will describe the nature of the breach and, where possible, the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it and mitigate its effects; and a contact point for further information. Where the full picture is not available at once, we will provide it in phases as it emerges.

We will assist you in meeting your own obligations under Art. 33 and 34 GDPR, and will not notify a supervisory authority or data subjects on your behalf unless you ask us to or the law requires it of us.

12. Audits and inspections

We will make available the information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.

In practice that means, in order of least disruption: our security documentation and completed questionnaires on request; an independent audit report or certification where one is available, which satisfies this section for the period and scope it covers; and, where those do not answer your question, an audit conducted at most once in any 12 months on 30 days’ written notice, during business hours, subject to confidentiality, and not extending to other customers’ data.

You bear the cost of an audit, unless it reveals a material breach of this DPA by us, in which case we bear the reasonable cost of the audit and of remediation. A supervisory authority exercising its own powers is not limited by this section.

To be confirmed before publication: we currently hold no third-party security certification and do not claim one, so the report-based route above is not yet available. If certification is a hard requirement for your procurement process, tell us early — see the Security Summary for what we do operate.

13. Return and deletion

You can export your data in a structured, commonly used, machine-readable format at any time during the term, from the product itself.

On termination we keep the data available for export for 30 days. After that we delete it from active systems. Copies held in encrypted backups are overwritten in the ordinary backup rotation, which does not exceed 90 days; during that window the data is not available for ordinary processing and is not restored except to recover the service as a whole.

We will confirm deletion in writing on request. We keep data beyond these periods only where Union or Member State law requires it, and only for as long as that law requires.

14. Records of processing

We maintain a record of the processing carried out on your behalf, as required by Art. 30(2) GDPR, and will provide the relevant extract on request within a reasonable period.

15. Liability

Each party is liable for damage caused by processing that infringes the GDPR to the extent Art. 82 provides. Liability under this DPA is subject to the limitations and exclusions in the agreement between us, except where those limitations cannot be applied under mandatory law.

To be confirmed before publication: the aggregate liability cap. A cap set below the value of the data being processed is the single item most likely to stop an enterprise deal, and it should be set with counsel rather than copied from a template.

16. Changes to this DPA

We may update this DPA where the law, the service or our processing changes. Where a change materially affects your rights, we will give reasonable notice before it takes effect. Changes to Annex 2 follow the sub-processor notice period rather than this section.

The effective date at the top of this page shows the current version. Previous versions are available on request.

17. Governing law and order of precedence

This DPA is governed by the laws of Estonia, and the courts of Estonia have jurisdiction, without prejudice to a data subject’s rights under Art. 79 GDPR or to the terms of the Standard Contractual Clauses where they apply.

In case of conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the Terms of Use and any order form, in each case only as regards the processing of personal data.

18. Contact

Questions about this DPA, requests for a signed counterpart, sub-processor notifications and data protection matters generally: privacy@sintora.ai, or by post to Sintoralabs OÜ, Narva mnt 7-636, Kesklinna linnaosa, Tallinn, Harju maakond, 10117, Estonia.

To be confirmed before publication: whether a data protection officer has been appointed and, if so, their contact details.

19. Annex 1 — Details of processing

Duration: for the term of the agreement between us, plus the retention window in the "Return and deletion" section.

ItemDetail
Subject matterProvision of the Sintora platform — operations, marketing and product delivery on a shared data model, plus industry solutions installed as modules.
Nature and purposeHosting, storage, transmission, retrieval, structuring, analysis and display of customer content in order to provide, support, secure and maintain the service.
Categories of data subjectsYour employees, contractors and administrators; your customers, leads and their contacts; guests, tenants and clients where you use an industry solution; participants in calls, chats and tickets.
Categories of personal dataIdentity and contact data (name, role, email, phone); account and authentication data (logins, IP address, device and session data); communications content (messages, call recordings and transcripts, comments, documents); customer relationship data (deals, tickets, activity history); HR data where the HR module is used; billing and transaction data; anything else you choose to put into the platform.
Special categoriesNot processed under this DPA unless expressly agreed in writing, with a description of the additional safeguards. You undertake not to instruct us to process Art. 9 or Art. 10 data without that agreement.
FrequencyContinuous, for the duration of the agreement.

20. Annex 2 — Sub-processors

The following sub-processors are engaged in the provision of the service. Each is bound by written data protection terms at least as protective as this DPA, and transfers outside the EEA rely on the mechanisms described in the "International transfers" section.

Sub-processorPurposeLocation
Cloudflare, Inc.Content delivery, DDoS mitigation, DNS and bot protection (Turnstile) for the website and formsEU / US
To be confirmed — cloud infrastructure providerHosting, compute, storage and backup for the platformEEA (to be confirmed)
To be confirmed — model inference provider(s)Processing of prompts and content for the AI features, under a contractual prohibition on trainingTo be confirmed
To be confirmed — transactional email providerDelivery of service notifications and invitationsTo be confirmed

This annex is deliberately incomplete rather than speculative: the entries marked "to be confirmed" are those we cannot yet state accurately, and a sub-processor list that names vendors we do not actually use is worse than one that admits the gap. It will be completed before this document leaves draft, and every addition after that follows the 30-day notice above.

21. Annex 3 — Technical and organisational measures

The measures below implement Art. 32 GDPR. They describe what we operate; where a figure is not yet verified against the live environment it is marked as such rather than stated as fact.

  • Encryption — TLS for data in transit; storage-level encryption at rest; secrets held in a managed secret store rather than in code or configuration. To be confirmed: minimum TLS version enforced, cipher policy and key rotation.
  • Access control — least privilege, named accounts, multi-factor authentication for administrative access, periodic access review, prompt revocation on departure, and logging of administrative actions.
  • Tenant isolation — each customer is a separate tenant and data is segregated so one tenant cannot read or affect another’s. Industry solutions install as modules inside your own tenant, which keeps isolation, permissions and audit consistent. To be confirmed: the technical isolation model.
  • In-product controls you operate — granular roles assigned per action rather than per screen, scoped by network, object or team; an audit log of significant actions; export in CSV and PDF; and administration of your own users.
  • Environment separation — production, staging and development are separated, with distinct credentials and network policies; production data is not used for development or testing.
  • Secure development — version control, peer review and automated checks before release; dependencies monitored for known vulnerabilities and updated as part of routine maintenance.
  • Backup and recovery — regular encrypted backups stored separately from production, with documented continuity and recovery plans. To be confirmed: backup frequency and retention, RPO and RTO, and the date of the last restore test.
  • Logging and monitoring — application, infrastructure and security logs collected, availability and error rates monitored, anomalies alerted on, log access restricted. To be confirmed: log retention period.
  • Vulnerability management — risk-based patching prioritised by severity and exposure; findings from scanning, code review and third-party reports tracked to resolution. To be confirmed: penetration test cadence and target remediation times per severity.
  • Incident response — a defined process covering detection, triage, containment, eradication, recovery and post-incident review, with roles and escalation paths agreed in advance.
  • People — confidentiality obligations for everyone with access to customer data, security and data protection awareness training, and access granted by role on joining. To be confirmed: background screening and training cadence.
  • Physical security — inherited from the infrastructure provider’s data centres, including access control, monitoring and their own certifications.