Data Processing Addendum
This Data Processing Addendum (\u201cDPA\u201d) forms part of the Terms of Service between the customer (\u201cController\u201d) and JLM Solutions (\u201cProcessor\u201d) governing the processing of Personal Data in Sentinel Vault.
Last reviewed: August 2026
1. Definitions
Terms such as "Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Supervisory Authority" have the meanings given in the EU General Data Protection Regulation 2016/679 ("GDPR"). "Customer Data" means the data submitted by Controller or its users to the Service.
2. Roles and scope
Controller determines the purposes and means of Processing Customer Data. Processor Processes Customer Data solely on Controller's documented instructions, which are the Terms of Service, the Service's configuration options, and this DPA.
3. Subject matter and duration
- Subject matter: provision of the Sentinel Vault Service.
- Duration: the term of the underlying subscription plus any post-termination retention permitted or required by law.
- Nature and purpose: hosting, transmitting, storing, and securing Customer Data as necessary to deliver the Service.
- Types of Personal Data: account identifiers, authentication data, item metadata, and encrypted secret values.
- Categories of Data Subjects: Controller's employees, contractors, and other authorized end users.
4. Processor obligations
- Process Personal Data only per Controller's documented instructions.
- Ensure that personnel authorized to Process Personal Data are bound by confidentiality.
- Implement the technical and organizational measures described in the Security Overview.
- Assist Controller, insofar as possible, in responding to Data Subject requests and in fulfilling its GDPR obligations (Articles 32-36).
- Notify Controller without undue delay of any confirmed Personal Data Breach affecting Customer Data.
5. Subprocessors
Controller grants general authorization for Processor to engage the Subprocessors listed on the Subprocessors page. Processor will notify Controller of intended additions or replacements with at least 15 days' notice, giving Controller the opportunity to object on reasonable data-protection grounds.
6. International transfers
Where the Processing of Personal Data involves transfers outside the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, the parties agree that the applicable Standard Contractual Clauses issued by the European Commission (Module Two, Controller-to-Processor) are incorporated by reference and apply to such transfers, together with any additional safeguards required by law.
7. Audit
Processor will make available to Controller information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party assessments where available. Where mandatory audit rights under Article 28(3)(h) GDPR apply, they will be exercised on reasonable advance notice, no more than once per year (unless required by a Supervisory Authority), at Controller's expense, and subject to confidentiality and to Processor's operational security requirements.
8. Return and deletion
On termination of the Service, Controller may export Customer Data via the built-in export for up to 30 days. Thereafter, Processor will delete Customer Data from active systems in accordance with the retention schedule in the Privacy Policy, subject to legal-hold obligations.
9. Liability
Each party's liability under this DPA is subject to the limitation of liability in the underlying Terms of Service, except as prohibited by applicable law.
10. Order of precedence
In the event of conflict, this DPA prevails over the Terms of Service with respect to the Processing of Personal Data. The Standard Contractual Clauses prevail over both where they apply.
11. Signing
Customers who require a signed copy of this DPA may email privacy@sentinelvault.appwith the legal entity name and address. Absent a signed copy, this DPA applies to all customers subject to the Terms of Service.
