Data Processing Agreement (DPA)

This Data Processing Agreement (“DPA”) supplements the Sinas.co Terms and Conditions between Pulsr B.V. (acting as the “Data Processor”) and the Customer (acting as the “Data Controller”).

1. Definitions & Scope

1.1. Applicable Data Protection Law: Means the EU General Data Protection Regulation (GDPR - Regulation 2016/679), the UK GDPR, and Swiss FADP, as applicable.

1.2. Subject Matter: The Processor provides managed AI execution infrastructure, serverless runtimes, and state persistence services to the Controller.

1.3. Nature & Purpose of Processing: Processing prompt inputs, custom code execution payloads, agent state data, and system logs solely to operate, execute, and secure the Managed Services as instructed by Controller.

2. Processor Obligations

2.1. Instructions: The Processor shall process Customer Personal Data strictly on documented instructions from the Controller, including with respect to transfers outside the EEA/UK/Switzerland.

2.2. Confidentiality: The Processor ensures that personnel authorized to process Customer Personal Data are bound by strict obligations of confidentiality.

2.3. No Training on Customer Data: The Processor explicitly guarantees that Customer Personal Data and execution payloads will not be used to train, fine-tune, or improve any public or foundational AI models.

3. Technical & Organizational Measures (TOMs)

The Processor implements appropriate security measures, including:

  • Encryption in Transit & At Rest: TLS 1.3 for all API/data flows and AES-256 encryption for persisted database states and secrets.

  • Tenant Isolation: Logical network and container isolation per tenant environment.

  • Access Control: Role-based access control (RBAC) and mandatory multi-factor authentication (MFA) for production environment access.

  • Vulnerability Management: Regular system patching, log monitoring, and automated container security scans.

4. Sub-processors

4.1. Authorized Sub-processors: The Controller grants general authorization for the engagement of sub-processors to deliver core infrastructure:

Sub-processor

Purpose

Location

Scaleway

Cloud Infrastructure & Hosting

EU (France)

Stripe, Inc.

Billing & Payment Processing

EU / USA (SCCs)

Postmark / SendGrid

Transactional Service Emails

USA (SCCs)

4.2. Notification of Changes: Processor will notify Controller at least 14 days prior to adding or replacing any sub-processors, giving Controller the right to object on reasonable data protection grounds.

5. Incident Management & Breach Notification

5.1. In the event of a confirmed Personal Data Breach affecting Customer data, Processor shall notify Controller without undue delay and no later than 36 hours after becoming aware of the incident.

5.2. Processor shall provide prompt assistance and details regarding the nature of the breach, affected records, and mitigation steps taken.

6. Data Deletion & Export

6.1. Upon termination of the Managed Services, Processor shall, at Controller’s choice, delete or return all Customer Personal Data within 30 days, unless retention is required by EU or Netherlands law.

6.2. System execution logs and transient telemetry are automatically purged on a 30- to 90-day rolling retention cycle.

Annex I: Details of Processing

A. LIST OF PARTIES

  • Data Exporter: Customer (acting as Data Controller / Business).

  • Data Importer: Pulsr B.V., trading as Sinas (“Sinas”) (acting as Data Processor / Service Provider).

B. CATEGORIES OF DATA SUBJECTS

  1. Customer Personnel: Employees, contractors, administrators, and software engineers accessing the Sinas control plane and dashboard.

  2. Customer End-Users: Individuals whose personal data or prompt payloads are processed by Customer's applications, AI agents, or serverless execution pipelines running on Sinas infrastructure.

C. CATEGORIES OF PERSONAL DATA

  • Account & Profile Data: First and last names, business email addresses, billing/payment records, authentication credentials (passwords, single sign-on tokens), and organization roles.

  • Transient Execution Payloads: Prompt text, response outputs, structured JSON parameters, function arguments, and code runtime inputs passed dynamically through agent orchestrators.

  • Persistent State Data: Vector embeddings, key-value state persistence tables, custom agent memory stores, and database index records configured by Customer.

  • Telemetry & System Logs: Source IP addresses, user-agent strings, API endpoint access logs, execution timestamps, container error traces, and usage metrics.

D. SENSITIVE DATA (SPECIAL CATEGORIES)

  • Sinas does not require Special Categories of Personal Data (GDPR Art. 9) to operate its infrastructure. Customer determines whether sensitive data is sent in execution payloads and remains responsible for maintaining an appropriate legal basis.

E. NATURE AND PURPOSE OF PROCESSING

  • Provisioning, running, and maintaining managed AI execution infrastructure, serverless Python/Node.js runtime containers, vector database proxies, and persistent agent state pipelines.

F. DURATION OF PROCESSING

  • For the duration of the underlying Subscription Agreement plus the standard data retention window (30 days for data return/erasure post-termination; 30–90 days rolling for system runtime logs).

Annex II: Technical & Organizational Measures (TOMs)

Pulsr B.V. maintains the following technical, physical, and organizational security measures:

1. Confidentiality & Isolation
  • Tenant Sandboxing: Serverless functions and agent workflows run in isolated container environments or microVMs. Tenants cannot access memory or persistent storage across isolation boundaries.

  • Role-Based Access Control (RBAC): Strict least-privilege access model applied to production environments. Access to production systems requires mandatory Multi-Factor Authentication (MFA) and hardware tokens where applicable.

  • Secrets Management: Customer API keys and external integration tokens are encrypted using hardware-backed key management vaults and injected into execution containers only at runtime.

2. Data Integrity & Encryption
  • Encryption in Transit: All incoming and outgoing network traffic across public networks is secured using TLS 1.3 (with fallback to TLS 1.2 minimum).

  • Encryption at Rest: All persisted data stores, vector indexes, key-value state databases, and backup snapshots are encrypted using AES-256 standard encryption.

3. Availability & Resilience
  • Redundancy: Core control planes and infrastructure components are deployed across multiple availability zones within secure EU cloud provider facilities (AWS / Hetzner EU).

  • Backups: Automated daily backups of database state with continuous point-in-time recovery capabilities, tested quarterly for integrity.

  • DDoS Mitigation: Automated upstream DDoS protection and rate limiting at the edge API gateways.

4. Incident Response & Governance
  • Continuous Monitoring: Automated 24/7 logging and threat monitoring of system execution endpoints, container runtime health, and authentication anomalies.

  • Patch Management: Continuous automated vulnerability scanning of container base images and immediate deployment of critical security patches.

  • Vendor Risk Management: Annual security evaluation of all underlying third-party sub-processors.

Table of content

Table of content

On this page

Title