Data Processing Agreement
Last updated: April 27, 2026 Draft prepared for legal review — not yet reviewed by counsel.
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between THEL (“Processor”, “we”) and the Customer (“Controller”, “you”) for the Sinra application (app.sinra.dev). It applies whenever THEL processes personal data on the Customer’s behalf as a result of the Customer’s use of the Service, in accordance with Article 28 of the GDPR.
1. Subject matter and duration
The Processor processes personal data on behalf of the Controller for the duration of the Customer’s subscription to the Service, and thereafter only as needed to comply with Section 8 (deletion and retention) or legal obligations.
2. Nature and purpose of processing
The Processor hosts and processes the data the Controller and its authorized users submit into the Service (creating, storing, displaying, searching, exporting) so that the Controller can use Sinra’s project management features: capabilities, issues, cycles, releases, testing, and related workflows. The Processor does not use Customer Data for any purpose other than providing, maintaining, and improving the Service, and does not sell Customer Data or use it for advertising.
3. Categories of data and data subjects
Categories of personal data processed:
- Account and team-member data: names, work email addresses, and role/permission information of the Controller’s users.
- Content data: text, comments, attachments, and metadata that the Controller’s users choose to enter into issues, capabilities, specifications, cycles, releases, and tests. This may incidentally include names or contact details of other individuals mentioned in that content (e.g., a colleague or a contact named in a ticket).
- Technical/log data: login timestamps, IP addresses, and basic usage logs needed to operate and secure the Service.
Categories of data subjects: the Controller’s employees, contractors, and other authorized users of the Service, and any third parties whose names or details the Controller’s users choose to include in Content data.
Special categories of data (GDPR Article 9) and other sensitive data (health data, financial account credentials, criminal records, etc.): the Service is not designed, certified, or intended to process these categories. The Controller agrees not to submit such data into the Service. If the Controller has a specific, documented need to do so (for example a regulated customer that must reference sensitive test data), it must contact the Processor first at support@sinra.dev to assess feasibility; absent such prior written agreement, the Processor has no obligation to apply safeguards specific to special-category data.
4. Sub-processors
The Processor uses the following sub-processors to provide the Service:
| Sub-processor | Purpose | Location |
|---|---|---|
| OVH SAS (2 Rue Kellermann, 59100 Roubaix, France) | Infrastructure hosting | France (EU) |
The Processor will not engage a new sub-processor that processes Customer Data without giving the Controller at least 30 days’ notice, during which the Controller may object on reasonable data-protection grounds. All data covered by this DPA is hosted in France; the Processor will not transfer Customer Data outside the European Union without the Controller’s prior written consent and appropriate safeguards (e.g., Standard Contractual Clauses).
5. Processor obligations
The Processor shall:
- process Customer Data only on the Controller’s documented instructions (including as set out in this DPA and the Terms of Service), unless required otherwise by EU or member-state law, in which case the Processor will inform the Controller before processing, unless prohibited from doing so;
- ensure that persons authorized to process Customer Data are bound by confidentiality obligations;
- implement appropriate technical and organizational measures to protect Customer Data, proportionate to the risk (see Section 6);
- assist the Controller, insofar as reasonably possible given the nature of the processing, in responding to data subject requests (access, rectification, erasure, portability, objection) submitted regarding data held in the Service;
- notify the Controller without undue delay, and in any event within 72 hours of becoming aware, after confirming a personal data breach affecting Customer Data, with the information reasonably available at that time;
- assist the Controller with data protection impact assessments and prior consultations with supervisory authorities where required, to the extent the information is available to the Processor;
- at the Controller’s choice, delete or return all Customer Data at the end of the provision of services, subject to Section 8;
- make available to the Controller the information reasonably necessary to demonstrate compliance with this DPA, and allow for audits (including inspections) conducted by the Controller or an auditor mandated by the Controller, on reasonable notice and at the Controller’s expense, limited to once per 12-month period absent a confirmed security incident.
6. Security measures
The Processor applies measures appropriate to the risk, including: encryption of data in transit (TLS); access controls restricting internal access to Customer Data to personnel who need it to operate or support the Service; logging of administrative access; regular security updates of infrastructure; and hosting exclusively on EU-based infrastructure (OVH, France). Given the size of the team operating the Service, these measures are those reasonably achievable by a small software company; they do not constitute certification against a specific security standard (e.g. ISO 27001, SOC 2) unless separately stated in writing.
7. Controller obligations
The Controller warrants that it has a valid legal basis for the personal data it submits to the Service and that its instructions to the Processor comply with applicable data protection law. The Controller is responsible for the accuracy of Customer Data and for configuring user permissions within the Service appropriately.
8. Deletion and retention
On termination of the subscription, the Controller may export Customer Data for 30 days. After this period, Customer Data is deleted from active production systems within 30 additional days, and from encrypted backups within 90 days of that deletion, except where retention is required by law (e.g., invoicing records) or for the establishment, exercise, or defense of legal claims.
9. Liability
Liability under this DPA is subject to the limitations set out in Section 8 of the Terms of Service. Nothing in this DPA limits either party’s liability for infringement of data subjects’ rights to the extent such liability cannot lawfully be limited.
10. Precedence
In case of conflict between this DPA and the Terms of Service on matters of personal data processing, this DPA prevails.
11. Contact
Data protection questions: support@sinra.dev