← Back to Senshin

Senshin

Data Processing Agreement
Last updated: 21 September 2026 · Version 2.2 · UK GDPR / Data Protection Act 2018 / Article 28
This DPA is the processor terms for personal data you put into Senshin. It is not labelled as solicitor-approved. If a limited company is formed, the processor name and Companies House number will be updated here in the same change.

Contents

  1. Parties
  2. Definitions
  3. Scope and purpose
  4. Processor obligations
  5. Sub-processors
  6. International transfers
  7. Security measures
  8. Breach notification
  9. Data subject rights
  10. Retention and deletion
  11. Audit rights
  12. Liability
  13. Termination

1. Parties

Controller: the organisation (or person) that has a Senshin subscription and determines the purposes of processing project personal data ("Customer").

Processor: Alex Sakpoba, trading as Senshin (senshin.io) ("Senshin").

Account data about the person who signs up (name, email, billing) is described in the Privacy Policy — Senshin is controller of that. This DPA covers personal data the Customer uploads or types into projects (people, stakeholders, files, and similar).

2. Definitions

Words used here have the meanings in UK GDPR and the Data Protection Act 2018: Personal Data, Processing, Controller, Processor, Data Subject, Supervisory Authority.

3. Scope and purpose

Senshin processes Personal Data only to provide the Senshin service described in the Terms — hosting the workspace, Sensei analysis, the Brief, exports, and support you ask for.

Data subjects: the Customer's staff, contractors, stakeholders, guests, and anyone the Customer records in the workspace.

Types of Personal Data: names, emails, job titles, organisation, project role, and whatever the Customer chooses to enter or upload. Senshin does not need special-category data to run the product; do not upload it unless you have a lawful basis and have told us.

Duration: the subscription plus the retention in section 10.

Industry picture (controller, not processor): separately from this DPA, if an authorised user allows it, Senshin as controller may keep a staging row of banded numbers and outcome codes (still Personal Data, so it can be deleted on objection) and, once five similar programmes exist, mix those numbers into an anonymous pool. That pool is not Personal Data (UK GDPR Recital 26) and cannot be unwound. Workspace content — names, RAID text, files, exact pounds — is not used for that picture. Details are in the Privacy Policy.

4. Processor obligations

Senshin shall:

5. Sub-processors

The Customer gives Senshin general written authorisation to use sub-processors on these terms. Senshin uses sub-processors for hosting and storage, content delivery and security, sign-in, payments, email and messaging, and AI processing. Each is engaged under written terms that require it to protect Personal Data and to process it only to provide its service to Senshin.

Senshin will make its current sub-processor information available to the Customer on request (privacy@senshin.io).

AI. Project Personal Data may be included in a model request to generate written analysis. Deterministic checks run on Senshin's own infrastructure first. Senshin's main AI route is configured to use only providers that do not keep or train on the request.

Senshin will tell the Customer, by email or notice in the product, before adding a sub-processor that will process Customer Personal Data, with reasonable time to object. If we cannot resolve the objection, the Customer may end the subscription; unused whole months on an annual plan are refunded as on the Refunds page.

6. International transfers

If a sub-processor handles Personal Data outside the UK, Senshin relies on an adequacy decision or appropriate safeguards, such as the UK Addendum to the EU Standard Contractual Clauses.

7. Security measures

We do not claim a SOC 2 or ISO 27001 certificate we do not hold.

8. Breach notification

If Senshin becomes aware of a Personal Data breach affecting Customer Personal Data, Senshin will notify the Customer without undue delay and in any event within 72 hours of becoming aware, with enough fact for the Customer to meet its own ICO duties, then contain, remediate, and cooperate.

That 72 hours is the UK GDPR notification clock for a personal-data breach. It is not a promise about how fast we fix a product incident, and it is not a customer-support reply time.

9. Data subject rights

Senshin will help the Customer respond to access, rectification, erasure, restriction, portability and objection requests. The product includes export and account-delete for the Customer's own users. Requests about people who only appear inside project records should come from the Customer; we will not second-guess the Customer's instructions without a legal reason.

10. Retention and deletion

During the subscription: data stays until the Customer deletes it or the account.

After the subscription ends: 30 days to export, then deletion of Customer workspace data. Backup copies fall out of rotation within 90 days. Audit records required for tax or security may be kept up to 24 months, then deleted or stripped of identifiers.

The Customer may request earlier deletion; we will do it unless the law requires us to keep a copy.

11. Audit rights

12. Liability

Liability under this DPA follows the Terms. Nothing here limits liability that English law does not allow to be limited, or for a breach caused by wilful misconduct.

13. Termination

This DPA lasts for the subscription and then for as long as section 10 requires processing to finish.

Enterprise customers who need extra clauses: legal@senshin.io — we will say honestly what a sole trader can sign.