Skip to main content
Sencai
FeaturesHow it worksPricingSecurity

Who it's for

For MSPs & AgenciesRun every client's infrastructure from one console instead of a browser full of them. For Regulated IndustriesNIS2, DORA and GDPR evidence produced as you operate, not before an audit. For Cloud ProvidersGet listed where customers pick their provider, at the moment they provision. For GovernmentA European control plane for cloud and for the servers you already run yourself.

Deployment

Business & On-PremYour own racks and bare metal, enrolled through the same agent.
Not sure which fits?Tell us how you run infrastructure today and we will map it out with you.
BlogDocsDownload agentContact
  • ENEnglish
  • CSČeština
  • DEDeutsch
  • FRFrançais
  • ESEspañol
  • PLPolski
  • ITItaliano
  • ELΕλληνικά
  • RORomână
  • NONorsk
  • SVSvenska
  • FISuomi
  • ETEesti
  • UKУкраїнська
  • TRTürkçe
Log inStart free
  • ENEnglish
  • CSČeština
  • DEDeutsch
  • FRFrançais
  • ESEspañol
  • PLPolski
  • ITItaliano
  • ELΕλληνικά
  • RORomână
  • NONorsk
  • SVSvenska
  • FISuomi
  • ETEesti
  • UKУкраїнська
  • TRTürkçe
Log in
Start free
FeaturesHow it worksPricingSecurity
Solutions
For MSPs & AgenciesFor Regulated IndustriesFor Cloud ProvidersFor GovernmentBusiness & On-Prem
BlogCareersDocsDownload agentContact
← Back to home

Data Processing Agreement

Last updated: 2026-09-14

This Data Processing Agreement ("DPA") sets out how Sencai processes personal data on behalf of its customers, as required by Article 28 of the EU General Data Protection Regulation (GDPR). It forms part of the Terms of Service and applies to every customer from the moment the Terms are accepted. Terms such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meaning given to them in the GDPR.

Parties and how this DPA applies

This DPA is concluded between Sencai Tech s.r.o., with registered office in Prague, Czech Republic, registered with the Municipal Court in Prague ("Sencai", "we"), and the customer that has accepted the Terms of Service ("you"). It forms part of the Terms and becomes binding when you accept them; no separate signature is needed. If you want a signature record for your files, an owner or admin of your organisation can sign this DPA in the platform. The current version is published at sencai.space/legal/dpa/. This is version 1.0 of this DPA. For customers who accepted an earlier version of the Terms, it applies as an amendment to the Terms in accordance with their provisions on changes.

Scope and roles

This DPA applies to personal data that Sencai processes on your behalf in providing the service, as described below ("Customer Personal Data"). For Customer Personal Data you, or the organisation you represent, are the controller and Sencai is the processor. Where you are yourself a processor for another controller - for example a managed service provider acting for its clients - Sencai acts as your sub-processor, and you ensure that your instructions to Sencai are authorised by that controller. Personal data that Sencai processes for its own purposes, such as account registration, billing and keeping the service secure, is outside this DPA and governed by the Privacy Policy, under which Sencai is the controller. Some records, such as sign-in events and the audit trail, serve both purposes: they are processed under this DPA when used to provide the service to you, and under the Privacy Policy when used to keep the service secure.

Order of precedence and language

If this DPA and the Terms conflict on the processing of personal data, this DPA prevails. This DPA is written in English. Translations are provided for convenience; where a translation differs from the English version, the English version prevails.

Subject matter, duration, nature and purpose

The subject matter of the processing is the provision of the Sencai platform, a multi-cloud control plane provided as software-as-a-service under the Terms. The processing lasts for the term of the agreement and afterwards until Customer Personal Data has been deleted as described in the section on deletion and return. It consists of collecting data through the connections you set up; storing, organising and displaying it to your authorised users; analysing it, for example for security scanning, cost analysis and, where you use them, the AI features; transmitting it to your infrastructure and to the providers you work with through the platform; carrying out the actions you request at cloud providers and on your servers; and deleting it. The purpose is to provide the service to you in accordance with the Terms and your instructions, including the support you ask for and the security of that processing as required by Article 32 GDPR.

Categories of data subjects

Customer Personal Data may relate to the following data subjects:

  • Your authorised users of the platform, such as your employees and contractors.
  • Members of your workforce whose records are synchronised from a directory you connect, such as Microsoft Entra ID, Microsoft 365 or Google Workspace.
  • Individuals whose personal data is contained in the infrastructure, servers, logs, terminal sessions or secret values you connect to or manage through the platform, for example your own customers and end users.

Categories of personal data

Depending on the features you use, Customer Personal Data may include the categories below. The service is not designed for special categories of personal data (Article 9 GDPR) or personal data relating to criminal convictions and offences (Article 10 GDPR). If your infrastructure, logs or secret values contain such data, you are responsible for assessing whether the measures in this DPA are appropriate before processing it through the service.

  • Infrastructure data: inventory, configuration and metadata of the cloud resources and servers you connect or provision, such as resource names, tags, IP addresses, DNS records and firewall rules, which can contain personal data.
  • Credentials for the cloud accounts you connect, stored encrypted.
  • Data collected by the Sencai agent from servers where you install it, such as installed software and patch status, security scan results, and system and application logs.
  • Browser terminal sessions: records of who connected to which server and when, and the data passing through a session while it is open.
  • Directory and identity data, where you connect a directory: user and group records, sign-in and administrative events including email addresses, IP addresses and browser or device information, and mailbox inventory.
  • The audit trail of your organisation: which user performed which action and when, with IP address and browser information.
  • Secret values you provide for Secret Injection.
  • Content you submit to the AI features, together with the infrastructure context sent with it.

Documented instructions

Sencai processes Customer Personal Data only on your documented instructions, including with regard to transfers to countries outside the European Economic Area, unless EU or Member State law requires otherwise; in that case Sencai informs you of that legal requirement before processing, unless that law prohibits it on important grounds of public interest. Your instructions are the Terms, this DPA and the way you use and configure the service, including through its interface and API. Additional instructions must be given in writing, for example to privacy@sencai.space, and must be consistent with the Terms. Sencai informs you immediately if, in its opinion, an instruction infringes the GDPR or other EU or Member State data protection law. You are responsible for the lawfulness of your instructions and of the personal data you process through the service.

Confidentiality

Sencai gives access to Customer Personal Data only to persons who need it to provide, support or secure the service, and ensures that everyone authorised to process Customer Personal Data is bound by confidentiality obligations or is under an appropriate statutory obligation of confidentiality.

Security of processing

Sencai implements technical and organisational measures to ensure a level of security appropriate to the risk, as Article 32 GDPR requires. The measures currently in place include those listed below. Sencai may update them as technology and risks develop, provided the overall level of security is not reduced.

  • Hosting of the platform in EU regions of Google Cloud.
  • Separation between organisations: resources are associated with the organisation they belong to, and your users' access is checked against that organisation.
  • Role-based access within each organisation, so users can see and change only what their role allows.
  • Encryption with TLS for connections to the platform over public networks; the Sencai agent on servers additionally uses a mutually authenticated connection.
  • Encryption at rest (AES-256-GCM) of the credentials for connected cloud accounts, which are not displayed back through the platform.
  • Secret values held in Sencai Vault, as described in the next section.
  • Protection of sign-in against repeated password guessing, short-lived access tokens, and support for multi-factor authentication and single sign-on.
  • Network policies that limit which internal services can communicate with each other.
  • An append-only, hash-chained audit trail in which altering or removing a past entry is detectable.
  • Backups of the platform database that are encrypted before they are stored.

Sencai Vault and Secret Injection

Where you use Secret Injection, Sencai stores the secret values you provide, encrypted at rest, in Sencai Vault, a secret store that Sencai operates itself on Google Cloud infrastructure in the EU. Sencai uses these values solely for delivery to your own infrastructure: a Kubernetes cluster, or servers running the Sencai agent where you enable it, and only to locations that the cluster's or server's own configuration allows. Stored values cannot be viewed or exported through the platform. Platform services can reach them only through dedicated credentials limited to storing them, reading them for delivery, or deleting them, and traffic between platform services and Sencai Vault is encrypted with TLS. Sencai Vault records an audit trail of access to it, in which credentials appear only as keyed hashes (HMAC). Each delivery is encrypted with a key generated for that delivery alone. A value is released to a cluster or server only after an administrator of your organisation has trusted its agent, and only to the credential that agent held when it was trusted. Earlier versions of a replaced value may be retained until the Secret Injection is revoked or deleted. After it is revoked or deleted, Sencai deletes the value and all retained versions from Sencai Vault without undue delay, and Sencai deletes all such values before an organisation is deleted. When you revoke a Secret Injection, Sencai instructs the agent that received the value to remove it where such an instruction can be sent; where it cannot be sent or the removal is not confirmed, for example because the agent is offline or has been disconnected or delivery is switched off, the value may remain on your infrastructure. Any copy delivered to your infrastructure is under your control and can be read by anyone with sufficient access to the system that holds it, including privileged users and anyone you allow to run commands through the Sencai agent.

Sub-processors

You give Sencai general written authorisation to engage the sub-processors listed in the sub-processor register at sencai.space/legal/subprocessors/. Sencai imposes on each sub-processor, by a written contract, data protection obligations that offer at least the same level of protection as those in this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures, as Article 28(4) GDPR requires. Sencai remains fully liable to you for the performance of each sub-processor's obligations, subject to the Liability section. Cloud providers whose accounts you connect yourself are not Sencai's sub-processors: those accounts remain under your own contract with the provider, and Sencai acts in them only on your instruction. Where Sencai runs your resources in cloud accounts it operates, the provider underneath is named to you as a sub-processor before the arrangement starts and is added to the register. Sencai gives notice of any intended addition or replacement of a sub-processor at least 14 days before it takes effect, by updating the register and emailing the owners of your organisation. You may object to the change in writing to privacy@sencai.space within that period; Sencai will then work with you in good faith to resolve the objection, and if it cannot be resolved, you may terminate the affected service, or the agreement where the service cannot be provided without that sub-processor, with effect before the change applies to your data.

International transfers

Customer Personal Data is stored primarily in the EU/EEA. Where a sub-processor processes it outside the European Economic Area, the transfer relies on the basis stated for that sub-processor in the register - an adequacy decision of the European Commission or the Standard Contractual Clauses - together with supplementary safeguards where required. The AI features send the content you submit to them to the model providers named in the register, which may process it outside the EU; they are engaged only when you use those features. Where you choose a region outside the European Economic Area in a cloud account you connect yourself, data goes there on your instruction.

Assistance with data subject requests

Taking into account the nature of the processing, Sencai assists you with appropriate technical and organisational measures, insofar as this is possible, in responding to requests from data subjects exercising their rights under Chapter III GDPR. The service provides self-service tools for this: your users can export the personal data held about their account and request erasure of their account from the platform's privacy settings, and your organisation's audit trail can be exported. Where these tools are not sufficient, Sencai provides reasonable further assistance on request to privacy@sencai.space. If Sencai receives a request directly from a data subject concerning Customer Personal Data, it informs you and does not respond to the request itself unless you instruct it to or the law requires it.

Assistance with security, impact assessments and consultations

Taking into account the nature of the processing and the information available to Sencai, Sencai assists you in meeting your obligations under Articles 32 to 36 GDPR - security of processing, notification of personal data breaches, data protection impact assessments and prior consultation of a supervisory authority. It does so in particular by making available this DPA and its description of security measures, the sub-processor register, the data residency statement, records of processing where your plan includes them, and an export of your audit trail, and by answering the reasonable questions you have for these purposes.

Personal data breaches

Sencai notifies you of a personal data breach affecting Customer Personal Data without undue delay and in any case within 72 hours after becoming aware of it, by email to the owners of your organisation. The notification describes, to the extent the information is available at the time, the nature of the breach including, where possible, the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address the breach and mitigate its possible adverse effects; and a contact point for further information. Where not all of this information is available at once, Sencai provides it in phases without further undue delay. Sencai takes reasonable steps to contain the breach and supports you in notifying the supervisory authority and affected data subjects where you are required to do so.

Deletion and return at the end of the agreement

After the agreement ends you have 21 days to export your data using the export functions of the service, as set out in the Terms. Once that period has passed, Sencai deletes Customer Personal Data unless EU or Member State law requires it to be stored. Deletion is carried out as a process rather than at a single moment; until it is complete, the data is kept only for the purpose of deleting it. In addition:

  • Data in backups is not removed from each backup individually. It is deleted when the backups containing it are deleted, at the latest one year after each backup was made; until then, backups remain encrypted and are used only for restoring the service.
  • Entries in your organisation's audit trail are not deleted, because the audit trail is append-only by design. After the agreement ends, Sencai retains them as controller, solely for security and evidentiary purposes as described in the Privacy Policy, with access restricted to those purposes.
  • Secret values in Sencai Vault are deleted when the Secret Injection is revoked or deleted, and in any case before your organisation is deleted.
  • Resources in cloud accounts you connect yourself remain yours and are never deleted by Sencai as part of ending the agreement.

Audits and information

Sencai makes available to you the information necessary to demonstrate compliance with the obligations in Article 28 GDPR. It does so primarily through documentation: this DPA, the sub-processor register, the data residency statement, records of processing where your plan includes them, an export of your audit trail, and written answers to reasonable security questionnaires. Sencai does not hold ISO 27001 or SOC 2 certification. To the extent Article 28(3)(h) GDPR requires it, or where a supervisory authority demands it, Sencai also allows for and contributes to audits, including inspections, conducted by you or by an auditor you mandate. Such audits require reasonable prior notice, are carried out at your cost and under confidentiality obligations, and must not give access to other customers' data or compromise the security of the service. Requests go to privacy@sencai.space.

Liability

Liability arising out of or in connection with this DPA is subject to the limitation of liability in the Terms, to the extent mandatory law allows. Nothing in this DPA limits the rights that data subjects have under the GDPR.

Term, changes and governing law

This DPA applies for as long as Sencai processes Customer Personal Data on your behalf, including after the Terms end until deletion is complete. Sencai may amend this DPA in the same way as the Terms, with at least 14 days' notice by email or in-app notification; if you do not agree with a material change, you may terminate the agreement effective the date the change takes effect. This DPA is governed by the laws of the Czech Republic, and disputes will be resolved by the competent courts of Prague, Czech Republic, as set out in the Terms.

Contacts

Questions about this DPA, data protection requests, instructions and objections to sub-processor changes: privacy@sencai.space. Security incidents and vulnerability reports: security@sencai.space. Sencai sends notices under this DPA to the email addresses of the owners of your organisation, so please keep them current.

Sencai

Cloud Operating Platform for Europe.

Built in Europe · EU-sovereign by design

System Status

Product

  • Features
  • Pricing
  • How it works
  • Security
  • Blog
  • Documentation
  • Download agent
  • Developers
  • For MSPs & Agencies
  • For Regulated Industries
  • For Cloud Providers
  • For Government
  • FAQ
  • Investors
  • Contact
  • Business & On-Prem

Company

  • About
  • Contact
  • Careers
  • Blog
  • Changelog

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Imprint
  • SLA
  • Data Processing Agreement
  • Sub-processors
  • Data residency
  • Manage cookies

© 2026 Sencai Tech s.r.o. All rights reserved.

We use cookies

Sencai uses only cookies that are strictly necessary to operate this site. We don't currently use analytics, marketing, or third-party tracking - if that ever changes, your preference below will already be on record.

Strictly necessary

Required for the site to function. Always on.

Analytics

Not in use today - this just reserves your preference in case Sencai adds anonymous analytics later.

Marketing

We don't use marketing cookies.