Data Processing Addendum
This Data Processing Addendum (DPA) forms part of the agreement between the customer (controller) and Sentrix (processor) and governs the processing of personal data that the customer submits to or generates through the Services.
Last updated: 22 July 2026 · Governing law: United Arab Emirates
1. Roles of the parties & applicable law
For personal data relating to the customer's end users that is processed through the Services, the customer is the controller (or a processor acting for its own controller) and Sentrix is the processor. For account and relationship data, Sentrix acts as an independent controller as described in the Privacy Policy. This DPA applies to Sentrix's processing as processor.
This DPA is written against UAE Federal Decree-Law No. 45 of 2021 (PDPL) as its baseline. Where the customer or its end users are subject to another regime — the DIFC Data Protection Law 2020, the ADGM Data Protection Regulations 2021, or the EU/UK GDPR — the corresponding controller/ processor obligations apply and the mechanisms in Section 10 are used for cross-border transfers.
2. Processing details
- Instructions: Sentrix processes personal data only on the customer's documented instructions, including as set out in the agreement and its configuration of the Services, unless required by law (in which case it notifies the customer where permitted).
- Duration: for the term of the agreement plus any legally required retention.
- Nature & purpose: real-time risk decisioning, screening orchestration and case operations.
- Categories of data: identifiers, risk and transaction signals, screening inputs and results, case notes and decisions — as determined by the customer.
- Data subjects: the customer's end users and other individuals the customer chooses to submit.
3. Confidentiality of personnel
Sentrix ensures that personnel authorised to process personal data are bound by appropriate obligations of confidentiality and are granted access on a need-to-know, least-privilege basis.
4. Security measures
Sentrix implements appropriate technical and organisational measures to protect personal data, as summarised in Annex B and described on our Security page, including encryption in transit and at rest, access controls, tenant isolation, and logging and monitoring.
5. Sub-processing
The customer provides a general authorisation for Sentrix to engage sub-processors to deliver the Services. A current list is maintained on our Sub-processors page. Sentrix imposes data-protection obligations on sub-processors no less protective than this DPA, remains responsible for their performance, and gives advance notice of intended changes so the customer may object on reasonable data-protection grounds.
6. Data-subject requests
Taking into account the nature of the processing, Sentrix assists the customer with appropriate technical and organisational measures, insofar as possible, to respond to data-subject requests. Where a request is made directly to Sentrix, we refer it to the relevant customer.
7. Personal-data-breach notification
Sentrix notifies the customer without undue delay after becoming aware of a personal-data breach affecting the customer's data, and provides information reasonably available to help the customer meet its own notification obligations.
8. Deletion or return on termination
On termination or expiry, and at the customer's choice, Sentrix deletes or returns the personal data it processes on the customer's behalf and deletes existing copies, unless retention is required by law. Export is available for a defined window following termination.
9. Audits & information
Sentrix makes available information reasonably necessary to demonstrate compliance with this DPA and contributes to audits, including inspections, conducted by the customer or an auditor it mandates, subject to reasonable confidentiality, security, scheduling and frequency safeguards. Where available, third-party reports and our Security and Compliance documentation may be used to satisfy audit requirements.
10. International & cross-border transfers
Where processing involves transfers of personal data outside the UAE, the parties rely on the transfer grounds in Articles 22–23 of the PDPL — a destination offering an adequate level of protection, or, absent adequacy, appropriate contractual safeguards, the data subject's consent, or another permitted ground. For personal data subject to the EU/UK GDPR, the parties additionally rely on the Standard Contractual Clauses, the UK International Data Transfer Addendum, or an applicable adequacy decision, together with supplementary measures as appropriate.
11. Annexes
Annex A — Details of processing
Subject matter, duration, nature and purpose, categories of data and data subjects are as set out in Section 2 and the agreement.
Annex B — Technical & organisational measures
- Encryption of personal data in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access control and least privilege (SSO/SAML on eligible plans is on our roadmap).
- Logical tenant isolation and per-workspace data separation.
- Append-only audit logging of decisions and overrides.
- Vulnerability management, monitoring and incident response.
- Backups and business-continuity measures.
For questions about this DPA, contact privacy@sentrix.world.
Company details
The operating entity for the Sentrix service is identified below. Fields marked “to be confirmed on execution” are completed with the contracting entity's registered particulars in the executed Order Form or master agreement.
This document forms part of the agreement between the customer and the Sentrix contracting entity. It is provided for information and does not itself constitute legal advice; customers should obtain their own advice on how it applies to their circumstances and regulatory obligations.