HexaSentra← Home

Data Processing Addendum

Last updated: 1 September 2026
Draft for review. A signed DPA is typically executed as part of an enterprise order form; have counsel review before relying on it.

This Addendum ("DPA") forms part of the agreement between the customer ("Controller") and HexaSentra ("Processor") and governs the processing of personal data under the EU/UK GDPR and comparable laws.

1. Roles & scope

The Controller determines the purposes and means of processing. HexaSentra processes personal data only on documented instructions from the Controller to provide the Service.

2. Nature of processing

3. Processor obligations

4. Sub-processors

The Controller authorizes the use of vetted sub-processors under equivalent obligations. We maintain a current list and give notice of intended changes, allowing reasonable objection.

5. International transfers

Where personal data leaves its region, transfers rely on Standard Contractual Clauses or another valid mechanism.

6. Security measures

Row-level tenant isolation; encryption in transit; secret management with access controls; least-privilege access; audit logging; append-only, content-addressed evidence storage; and a documented incident-response process.

7. Return & deletion

On termination, and on request, HexaSentra deletes or returns personal data, subject to legal retention requirements. Tenant purge tooling is available to the Controller in-product.

8. Audit

HexaSentra makes available information necessary to demonstrate compliance and will support audits on reasonable notice, subject to confidentiality.