Data Processing Agreement
1. Definitions
- "Controller": the SentientIQ customer (dealership, retailer, or other business) that determines the purposes and means of processing personal data collected through its website and customer channels.
- "Processor" / "we": SentientIQ, Inc., which processes personal data on behalf of the Controller to deliver the SentientIQ service.
- "Personal Data": any information relating to an identified or identifiable natural person, including name, email address, and phone number voluntarily submitted through the SentientIQ chat interface or a connected customer channel.
- "Processing": any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
- "Data Subject": the website visitor or customer whose Personal Data is processed under this DPA.
- "Sub-processor": a third party engaged by the Processor to assist in processing Personal Data on behalf of the Controller.
2. Scope and nature of processing
The Processor processes the following categories of Personal Data on behalf of the Controller:
Data categories
- Name (first and last)
- Email address
- Phone number
- Unit or product of interest (as stated by the visitor)
- Conversation content submitted through the chat interface or a connected customer channel
Purpose of processing
To deliver the SentientIQ conversational AI service; specifically, to capture and transmit lead contact information to the Controller so the Controller can follow up with the Data Subject regarding their expressed interest.
Processing activities
- Collection via the chat interface on the Controller's website and via customer channels the Controller connects
- Storage in a secure, Controller-isolated database partition
- Transmission to the Controller via email notification and dashboard
- Retention for the duration specified in Section 5
- Deletion per Section 5 or upon Controller request
3. Processor obligations
The Processor agrees to:
- 3.1 Process only on documented instructions. Process Personal Data solely for the purposes described in Section 2, or as otherwise instructed in writing by the Controller. Not process Personal Data for any other purpose, including the Processor's own commercial benefit.
- 3.2 No sale or sharing. Not sell, rent, share, or otherwise disclose Personal Data to any third party for cross-context behavioral advertising, the Processor's own marketing, or any purpose outside the contracted service. This prohibition survives termination of the agreement.
- 3.3 Confidentiality. Ensure that all personnel authorized to process Personal Data are bound by confidentiality obligations no less protective than those in this DPA.
- 3.4 Security. Implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized access, disclosure, alteration, or destruction. Current measures include TLS 1.3 encryption in transit, AES-256 encryption at rest, row-level security, and role-based access control.
- 3.5 Sub-processors. Not engage sub-processors without the Controller's general authorization. Current authorized sub-processors are listed in Section 7. The Processor will notify the Controller of any intended changes to sub-processors with reasonable advance notice, providing an opportunity to object.
- 3.6 Data subject rights assistance. Assist the Controller in fulfilling obligations to respond to Data Subject rights requests (access, deletion, portability, correction) within the timeframes required by applicable law.
- 3.7 Breach notification. Notify the Controller without undue delay, and in no event later than 72 hours, after becoming aware of a personal data breach affecting data processed under this DPA.
- 3.8 Deletion on termination. Upon termination or expiration of the service agreement, delete or return all Personal Data within 30 days, at the Controller's election, unless applicable law requires continued retention.
- 3.9 Audit rights. Provide the Controller with information reasonably necessary to demonstrate compliance with this DPA upon written request. The Processor may satisfy this obligation through security questionnaires, certifications, or documentation in lieu of on-site audits.
4. Controller obligations
The Controller agrees to:
- 4.1 Ensure there is a lawful basis for collecting and processing the Personal Data of its website visitors and customers under applicable law.
- 4.2 Maintain an accurate and current privacy policy on its website that discloses the use of AI chat and the collection of visitor contact information.
- 4.3 Promptly notify the Processor of any Data Subject rights requests that require the Processor's assistance to fulfill.
- 4.4 Not instruct the Processor to process Personal Data in a manner that would violate applicable law.
5. Data retention and deletion
- Standard retention. Personal Data is retained for the duration of the Controller's active service agreement with the Processor, then deleted within 30 days of termination.
- California tenants (CCPA). For Controllers whose primary business location is in California, the Processor implements an automated monthly purge of contact PII (name, email, phone) that is more than 30 days old, consistent with CCPA service provider retention limitations.
- On-demand deletion. The Controller may request deletion of specific Data Subject records at any time by contacting info@sentientiq.app. The Processor will complete deletion within 30 days of a verified request. Data Subjects may also request deletion directly; see Data deletion.
- Anonymized analytics. Aggregated, non-identifiable behavioral analytics data may be retained indefinitely for model training and platform improvement. This data cannot be linked to any individual and is not subject to this DPA's deletion requirements.
6. CCPA service provider provisions
For purposes of the California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq.), the Processor acts as a "service provider" to the Controller. The Processor certifies that it:
- Processes Personal Data only for the business purpose of providing the contracted SentientIQ service
- Does not sell Personal Data
- Does not retain, use, or disclose Personal Data for any commercial purpose other than providing the service
- Does not combine Personal Data received from the Controller with Personal Data received from other sources, except as permitted by CCPA regulations
- Will notify the Controller if it determines it can no longer meet its obligations under CCPA
7. Authorized sub-processors
The Controller grants general authorization for the Processor to engage the following sub-processors. Each sub-processor is bound by data protection obligations no less protective than those in this DPA.
- Amazon Web Services (AWS) · United States · Infrastructure hosting and storage
- Supabase · United States · Database hosting and access control
- Anthropic · United States · AI inference for conversation processing
- Cloudflare · United States · CDN and network security
- Resend · United States · Transactional email delivery
The Processor will provide at least 10 days' written notice of any intended addition or replacement of sub-processors. The Controller may object within that period by contacting info@sentientiq.app. If the parties cannot resolve the objection, the Controller may terminate the service agreement without penalty.
8. International data transfers
All Personal Data processed under this DPA is stored and processed in the United States. For Controllers subject to GDPR who transfer Personal Data from the European Economic Area, the parties agree that the Standard Contractual Clauses (EU Commission Decision 2021/914, Module 2, Controller to Processor) are incorporated by reference and form part of this DPA. A copy of the applicable SCCs is available upon request at info@sentientiq.app.
9. Liability
Each party's liability under this DPA is subject to the limitations and exclusions set forth in the SentientIQ Terms of Service. Where applicable law prohibits such limitations in the context of data protection obligations, those limitations shall not apply to the extent of the prohibition.
The Processor shall be liable to the Controller for damages caused by processing that does not comply with this DPA or applicable data protection law, except where the Processor can demonstrate that it is not in any way responsible for the event giving rise to the damage.
10. Governing law
This DPA is governed by the laws of the State of Delaware, United States, consistent with the SentientIQ Terms of Service. For matters specifically governed by GDPR or CCPA, the applicable statutory requirements shall control to the extent of any conflict with Delaware law.
11. Term and termination
This DPA is effective upon acceptance of the SentientIQ Terms of Service and remains in effect for the duration of the service agreement. Sections 3.2 (No sale or sharing), 3.3 (Confidentiality), 5 (Retention and deletion), and 6 (CCPA) survive termination.
12. Amendments
The Processor may amend this DPA to reflect changes in applicable law or sub-processor arrangements. Material amendments will be communicated via email or dashboard notification with at least 30 days' advance notice. Continued use of the service after the notice period constitutes acceptance of the amended DPA.
For DPA inquiries, data subject rights requests, sub-processor objections, or breach notifications:
SentientIQ, Inc. · info@sentientiq.app