Agreement entrusting the processing of personal data
Version: 1.0
Valid from: July 30, 2026
This Agreement, hereinafter referred to as "DPA", is concluded between:
- the organization indicated in the Sentivaro account, hereinafter referred to as the "Administrator", and
- Dawid Balcer, running the Sentivaro project as a natural person not running a business, correspondence address: ul. Jana Brzechwy 8, 60-195 Poznań, e-mail: contact@sentivaro.com, hereinafter referred to as the "Processor".
The DPA is part of the agreement to use Sentivaro.
1. Subject and time
- The Administrator entrusts the Processor with personal data to the extent necessary to configure, implement, measure and settle authorized cybersecurity awareness campaigns and provide related educational materials.
- Processing lasts from the first transfer of data until their deletion or return after using the Service, taking into account the period of overwriting the backup copy.
- A detailed Campaign constitutes the Administrator's documented instructions regarding its configuration, recipients, events and retention.
2. Nature and purpose of the operation
Operations may include:
- acceptance or import;
- ordering and assigning to the Campaign;
- storage;
- generating and sending a controlled message;
- registration of configured events;
- pseudonymization and aggregation;
- presentation of results to authorized users;
- export at the Administrator's request;
- providing educational material;
- proofreading;
- limit;
- deletion.
The sole purpose is to implement the Administrator's authorized cybersecurity awareness program.
3. People and data
- Categories of people:
- employees and associates of the Administrator;
- other persons covered by the Administrator's legal and authorized program, after prior arrangement.
- Data categories:
- name and surname;
- work e-mail address;
- department, team, organizational unit or training category;
- internal participant ID;
- the fact of delivering, opening, clicking, reporting and completing the learning activity, depending on the configuration;
- result correction data;
- limited technical data, if necessary.
- The Administrator may not transfer without prior written consent:
- special categories of data under Art. 9 GDPR;
- data from art. 10 GDPR;
- real passwords, MFA codes or credentials;
- financial data, document numbers or national identifiers;
- private e-mail addresses;
- content of private correspondence.
4. Administrator commands
- The processing entity processes data only on the documented instructions of the Administrator, unless the obligation to process results from EU law or Polish law.
- Campaign configuration and actions of an authorized user in the panel constitute commands if they comply with the DPA, Regulations and Acceptable Use Policy.
- The Processor shall immediately inform the Administrator if, in its opinion, the order violates the GDPR or other data protection provisions. He may suspend execution of the command until it is clarified.
- The Processing Entity does not use Campaign Data for advertising, its own employee evaluation, data trading or training of artificial intelligence models.
5. Obligations of the Administrator
Administrator:
- ensures the legality of data transfer and processing;
- establishes the legal basis;
- fulfills information obligations;
- conducts balance test and DPIA if required;
- ensures compliance with labor law and internal regulations;
- limits data to a minimum;
- gives users appropriate permissions;
- verifies the results before using them against a specific person;
- does not use the result as the sole basis for automatic personnel decisions;
- provides the Processor with only lawful instructions.
6. Confidentiality
- Only persons acting under the authorization of the Processor and for whom access is necessary have access to the data.
- These persons are obliged to confidentiality under contract or law.
- The obligation of confidentiality also applies after the end of cooperation.
7. Security
- The processor shall implement risk-appropriate measures in accordance with Article. 32 GDPR.
- The measures shall include, as appropriate to the current architecture:
- transmission encryption;
- secure password hashing;
- role control;
- separation of Organization data;
- tokens with appropriate randomness and validity period;
- recording administrative activities;
- backup copies and reconstruction tests;
- process of updating and removing vulnerabilities;
- limitation of retention;
- incident response procedure;
- administrative access protection;
- regular review of measures.
- The current description of the measures may be made available to the Administrator without information, the disclosure of which would increase the security risk.
8. Sub-processors
- The Administrator grants general written consent to the use of further entities listed on the `/subprocessors` page.
- The Processor will inform the Administrator about the planned change at least 14 days in advance, unless an urgent change is necessary to remove the threat.
- The administrator may raise a justified objection regarding data protection within this period.
- If the reason for the objection cannot be reasonably removed, the Administrator may terminate the use of the part of the Service that requires a given provider.
- The processor imposes data protection obligations on the sub-processor corresponding to the obligations under this DPA and is responsible for the performance of its obligations in accordance with Art. 28 GDPR.
9. Transfers
- Campaign Data is processed in the EEA, unless the list of sub-processors expressly states otherwise.
- Transfer outside the EEA may only take place upon a documented order of the Administrator or using a mechanism permitted by the GDPR.
- If standard contractual clauses, transfer assessment or supplementary measures are required, the Processor shall provide the Controller with available information needed to assess them.
10. Rights of persons
- The Processor, taking into account the nature of the processing, helps the Controller to exercise the rights of persons using available technical and organizational means.
- If the Participant submits a request directly to the Processor, it will forward the request to the Administrator without undue delay and will not respond substantively without its instructions, unless required by law.
- The administrator is responsible for verifying the person and timely response.
11. Compliance assistance
The Processor, taking into account the nature of processing and available information, assists the Controller in the following areas:
- security;
- risk assessment;
- reporting violations;
- notifying people;
- DPIA;
- consultation with the supervisory authority;
- demonstrating the deletion of data.
The assistance does not include issuing a legal opinion or assuming the Administrator's liability.
12. Data Breaches
- The Processor shall notify the Administrator about a breach of Campaign Data without undue delay after its discovery.
- Where available, the notice shall include:
- the nature of the infringement;
- categories and approximate number of people;
- categories and approximate number of records;
- possible consequences;
- measures taken or proposed;
- point of contact;
- time of detection and known time frame of the event.
- Information may be transferred in stages.
- Notice does not constitute an admission of liability.
- The administrator decides to report to the authority and notify persons.
13. Deletion and return
- The Administrator can delete Campaign Data in the panel or issue a deletion order.
- After completion of the service, the Processor, at the Administrator's discretion, deletes or returns active Campaign Data, unless the law requires their storage.
- Data temporarily remaining in rotating backups is isolated from ordinary use and deleted when the relevant backup is overwritten in the technical backup cycle.
- Aggregated data may only be retained where an individual can no longer reasonably be identified.
14. Audits
- The processor shall provide the information necessary to demonstrate compliance with Art. 28 GDPR.
- The administrator may conduct an audit no more than once a year, unless a violation has occurred or the authority requires additional control.
- The audit should:
- be announced at least 14 days in advance;
- take place at agreed times;
- not violate the security of other Organizations;
- use remote documents and responses first;
- be performed by persons obliged to confidentiality.
- The administrator bears his own audit costs. The Processor does not charge a fee for reasonable assistance under the free Service model, but may refuse excessive actions or propose an agreed alternative means of demonstrating compliance.
15. Responsibility and priority
- The parties' liability results from the GDPR, applicable law and the Regulations.
- In the event of a conflict between the DPA and the Regulations in matters of protection of Campaign Data, the DPA shall prevail.
- Where standard contractual clauses apply and conflict with the DPA, the clauses shall prevail.
16. Ending
The DPA applies for as long as the Processor processes the Campaign Data on behalf of the Controller.