Data Processing Addendum (DPA)
Effective date: 22 September 2026 · Last updated: 22 September 2026
Download as textPrevious versions
1. Parties and incorporation
This Data Processing Addendum forms part of the SENRIKO Terms or an applicable Order Form between the Customer and Individual Entrepreneur Izotov Aleksandr Olegovich (“SENRIKO”). It applies automatically when SENRIKO processes Customer Personal Data as a processor on the Customer’s behalf.
The Customer is the controller or another processor lawfully authorised to appoint SENRIKO. SENRIKO is the processor/subprocessor for Customer Personal Data. Capitalised terms not defined here have the meaning in the Terms.
2. Definitions
- Customer Personal Data means personal data contained in Customer Data that SENRIKO processes solely to provide the Service on documented Customer instructions.
- Data Protection Law means the Digital Code of the Kyrgyz Republic and any other privacy/data-protection law mandatorily applicable to the processing.
- Personal Data Breach means a security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to Customer Personal Data.
- Subprocessor means a third party appointed by SENRIKO to process Customer Personal Data for the Service.
3. Subject, duration, nature and purpose
SENRIKO processes Customer Personal Data to perform website checks, store configured evidence and history, deliver alerts/reports, operate integrations, provide support, secure the Service and carry out other documented functions selected by the Customer.
Processing begins when the Customer configures a function involving Customer Personal Data and continues until deletion or return under the Terms, this DPA and applicable law. Details are in Annex 1.
4. Documented instructions
The Terms, Order Form, Account configuration, support instructions and this DPA are the Customer’s documented instructions. SENRIKO processes Customer Personal Data only on those instructions, unless law requires other processing. Where legally permitted, SENRIKO will inform the Customer of that requirement before processing.
SENRIKO will inform the Customer if it reasonably believes an instruction infringes Data Protection Law and may suspend the affected instruction until clarified or corrected. SENRIKO is not required to give legal advice.
5. Customer obligations
The standard Service is not designed for special-category, children’s, cardholder, medical, biometric or other highly regulated Customer Personal Data. The Customer must not submit such data unless a separate written order identifies the lawful basis, security controls, locations, retention, subprocessor authority and any sector-specific terms.
The Customer warrants that it:
- has authority over each monitored Site and connected system;
- has a lawful basis for the processing and has given required notices;
- will minimise data and not use real sensitive, children’s or regulated data in synthetic checks;
- will configure retention, recipients, public links and access appropriately;
- will respond to data subjects and regulators as controller;
- will not instruct SENRIKO to violate law or third-party rights; and
- will maintain reasonable security for credentials, integrations and exported data.
6. Confidentiality and personnel
SENRIKO limits Customer Personal Data access to personnel and contractors who need it for the Service, support, security or legal compliance. They are bound by confidentiality and receive appropriate security/privacy instructions. Access is reviewed and removed when no longer needed.
Where legally permitted, SENRIKO will notify the Customer before disclosing Customer Personal Data in response to a government, law-enforcement or third-party demand, reasonably challenge an overbroad demand, and disclose only the minimum information legally required.
7. Security measures
SENRIKO implements measures appropriate to risk, including those in Annex 2. The Customer acknowledges that security evolves and that SENRIKO may replace a measure with an equivalent or stronger control without materially reducing overall protection.
The Customer is responsible for assessing whether the Service and configured functions are appropriate for the categories and risk of data it chooses to process.
8. Subprocessors
The Customer gives general written authorisation for the Subprocessors listed at https://senriko.com/legal/subprocessors. SENRIKO imposes data-protection obligations that are materially protective for the relevant service.
SENRIKO will provide at least 15 days’ advance notice before a new Subprocessor begins materially processing Customer Personal Data, normally by updating the list and notifying the Account owner. The Customer may object during that period on reasonable documented data-protection grounds.
The parties will attempt a reasonable solution, such as configuration change or alternative provider. If none is commercially reasonable, either party may terminate only the affected function or the Service, and SENRIKO will provide any refund required by the Terms or mandatory law. SENRIKO remains responsible for its Subprocessor duties to the extent required by law.
Customer-directed destinations, a Customer’s Site/CRM/analytics property, Paddle acting independently as Merchant of Record, and public DNS/RDAP operators are not automatically SENRIKO Subprocessors.
9. Assistance with individual rights
Taking account of the processing and information available, SENRIKO will reasonably assist the Customer with access, copy, correction, deletion, restriction, portability, objection and consent-withdrawal requests relating to Customer Personal Data.
If SENRIKO receives a request clearly relating to Customer-controlled data, it will direct the person to the Customer or forward the request where appropriate, unless prohibited. The Customer remains responsible for the decision and response. Excessive or technically bespoke assistance may be charged at an agreed reasonable rate where law permits.
10. Compliance assistance
SENRIKO will reasonably assist with security, breach notifications, data-protection impact assessments and regulator consultations, taking account of the Service and information available. Assistance beyond standard documentation may require an Enterprise Order Form or reasonable fee, except where the need results from SENRIKO’s breach.
11. Personal Data Breach
SENRIKO will notify the Customer without undue delay after discovering a Personal Data Breach affecting Customer Personal Data and, where the 48-hour processor rule under applicable Kyrgyz law applies, no later than 48 hours after discovery. The first notice may be preliminary; SENRIKO will supplement it as material facts become available.
The notice will, as available, describe the nature and approximate scope, affected data and persons, likely consequences, containment and remediation, contact point and information reasonably needed for the Customer’s notification. Information may be supplied in phases. Notification is not an admission of fault.
The Customer is responsible for notifying regulators and individuals unless law assigns that duty directly to SENRIKO. SENRIKO will preserve appropriate incident evidence and cooperate reasonably.
12. Deletion and return
During the Service the Customer may use available export and deletion controls. At termination or on lawful instruction, SENRIKO will delete or return Customer Personal Data, at the Customer’s choice where technically available and required by law, unless law requires retention.
Ordinary active copies are removed through the published process. Disaster-recovery copies age out within up to 14 days and remain inaccessible for ordinary processing. Records retained for a binding duty or claim are restricted to that purpose.
The Plan retention schedule applies to monitoring history. The Customer must export records before expiry or downgrade.
13. Audit and information
SENRIKO will provide information reasonably necessary to demonstrate compliance, including this DPA, the Subprocessors list, relevant security descriptions and incident information. No more than once per 12 months, or after a material confirmed breach, the Customer may request a reasonable audit.
The parties will first use independent reports, questionnaires or remote evidence. An on-site or bespoke audit requires reasonable prior notice, must protect other customers and security, occur during business hours and be paid by the Customer unless it identifies a material SENRIKO breach. Auditors must be independent and confidential.
14. International transfers
SENRIKO will use a lawful transfer mechanism where required by Data Protection Law. Depending on the applicable regime, this may include an adequacy decision, contract necessity, valid consent, approved contractual safeguards, or standard contractual clauses with supplementary measures.
Before a restricted transfer governed by the EU GDPR or UK GDPR begins, the parties will execute the applicable EU Standard Contractual Clauses and module, UK Addendum/IDTA, or another valid mechanism, together with required supplementary measures. Those instruments are not deemed automatically completed or signed where law or the official form requires party details, choices or signature. Where Kyrgyz law requires prescribed contractual transfer terms, the parties will execute them before the transfer. This DPA does not declare any country adequate without a competent decision.
15. Controller processing by SENRIKO
This DPA does not apply to data for which SENRIKO independently determines purposes, including Account administration, subscription metadata, fraud/security logs, public-Site analytics, legal evidence and direct support correspondence. That processing is governed by the Privacy Policy.
SENRIKO may create and use statistics that have been irreversibly aggregated or de-identified so that neither the Customer nor a person is reasonably identifiable. Such information is not Customer Personal Data, but SENRIKO will not attempt to re-identify it.
16. Liability and precedence
Liability under this DPA is subject to the Terms, except a limitation cannot override liability or data-subject rights that law does not permit the parties to limit.
For personal-data processing, this DPA prevails over conflicting general Terms. An Order Form prevails only if it expressly identifies and lawfully changes a DPA provision. Mandatory law prevails over all documents.
17. Term and changes
This DPA remains effective while SENRIKO processes Customer Personal Data. Material changes follow the notice process in the Terms. A change required by binding law or security may take effect sooner with prompt notice and no reduction of mandatory rights.
Annex 1 - Processing details
Subject matter: Website monitoring and related SaaS functions configured by the Customer.
Duration: For the Account/Subscription term and the applicable deletion, backup and legal-retention periods.
Nature/operations: Collection from public/customer-controlled Sites; automated requests; browser operation; synthetic submissions; recording, organisation, storage, analysis, comparison, retrieval, reporting, alert delivery, export, restriction, deletion and backup.
Purposes: Availability and integrity monitoring, form and analytics-signal verification, incident evidence, alerts, reports, support, security and documented Customer-selected integrations.
Data subjects: Customer users and alert recipients; Site owners/personnel; visitors or other people incidentally visible in monitored content; people represented in a Customer-controlled autoresponder subject, URL or screenshot.
Data categories: Business contact details; online identifiers; Site/URL content; synthetic test values; screenshots; autoresponder sender/subject metadata; monitoring results; Customer-connected aggregated GA4 metrics; support material. Special-category, children’s and payment-card data are prohibited unless a separate written lawful arrangement expressly allows them.
Frequency: Continuous or periodic according to Customer configuration.
Return/deletion: Account controls, Plan retention, termination process and 14-day backup cycle.
Annex 2 - Technical and organisational measures
- encrypted transport through HTTPS/TLS and HSTS;
- scrypt password hashing; hashing of session, one-time and share-link tokens;
- role-based and need-to-know access; restricted administrator enablement;
- administrator and security audit logging;
- encrypted alert addresses with separated key management;
- isolated browser sessions and separated browser-check processes;
- SSRF, private-network, blocked-domain and rate-limit controls;
- synthetic markers and authority verification for active checks;
- log redaction and data minimisation;
- regular backup and restoration controls with 14-day cycle;
- vulnerability/patch and infrastructure-health processes;
- incident assessment, containment and notification procedure;
- vendor confidentiality, processor terms and change review;
- retention and deletion jobs; and
- Customer export, deletion, revocation and access controls.