This Addendum ("DPA") forms part of the agreement between the customer ("Controller") and HexaSentra ("Processor") and governs the processing of personal data under the EU/UK GDPR and comparable laws.
The Controller determines the purposes and means of processing. HexaSentra processes personal data only on documented instructions from the Controller to provide the Service.
The Controller authorizes the use of vetted sub-processors under equivalent obligations. We maintain a current list and give notice of intended changes, allowing reasonable objection.
Where personal data leaves its region, transfers rely on Standard Contractual Clauses or another valid mechanism.
Row-level tenant isolation; encryption in transit; secret management with access controls; least-privilege access; audit logging; append-only, content-addressed evidence storage; and a documented incident-response process.
On termination, and on request, HexaSentra deletes or returns personal data, subject to legal retention requirements. Tenant purge tooling is available to the Controller in-product.
HexaSentra makes available information necessary to demonstrate compliance and will support audits on reasonable notice, subject to confidentiality.