Data Processing Addendum
Last updated: July 26, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Stolz Telecom ("Processor," "we") and the customer ("Controller," "Customer") and applies whenever we process personal data on the Customer's behalf in providing Sentinel RF.
1. Roles and scope
The Customer is the controller of personal data contained in its account data and customer content (for example, names and work email addresses of its staff, and any personal data that appears in uploaded documents or questions). We act as processor of that data and process it only to provide the service. We act as an independent controller for our own billing records and for prospect data collected on the marketing site.
2. Nature and purpose of processing
- Hosting, parsing, indexing, and retrieving uploaded documents.
- Answering questions submitted by the Customer's seats, including sending relevant document excerpts to model-inference providers under no-logging policies.
- Operating accounts, seats, usage reporting, and the admin console.
- Sending transactional email connected to the service.
Duration: the subscription term plus the 30-day post-cancellation retention window, after which customer content is permanently deleted.
3. Instructions
We process personal data only on the Customer's documented instructions, which consist of the Terms, this DPA, and the Customer's use of the service's controls, unless processing is required by law, in which case we will inform the Customer unless the law prohibits it.
4. Confidentiality
Personnel authorized to process personal data are bound by confidentiality obligations and access production systems on a least-privilege basis.
5. Security measures
- Encryption of data in transit (TLS).
- Per-tenant isolation of documents and indexed content, enforced in the retrieval layer and verified by automated cross-tenant leakage tests that run on every code change.
- Role-based access control within the service (owner, admin, member) and a distinct, separately gated operations role for our staff.
- Support access to a customer's account is read-only and is recorded in that customer's own audit log.
- Key-based authentication and hardened access for production infrastructure.
- Rate limiting, input validation, and structured audit logging.
- Operational logs designed to exclude document content and conversation text.
6. Subprocessors
We engage a limited set of subprocessors to provide the service. We remain responsible for their performance. The current list of subprocessors is available on request by emailing [email protected]. We will give at least 30 days' notice by email before adding or replacing a subprocessor that processes customer personal data; if the Customer reasonably objects, it may terminate the affected service and receive a pro-rated refund of prepaid fees.
7. Data subject requests
We will refer data-subject requests concerning customer-controlled data to the Customer and, taking into account the nature of the processing, provide reasonable assistance so the Customer can respond within required timelines. Operation admins can handle most requests directly through the admin console (user management and data export).
8. Personal data breach
We will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting customer personal data, and will provide information reasonably required for the Customer to meet its own notification obligations.
9. Deletion and return
The Customer can export its data from the admin console at any time. Following the end of the subscription and the 30-day retention window, we delete customer content, including uploaded documents and indexed excerpts. Residual copies in operational logs and backups age out on their own retention schedules.
10. Audits
On written request, no more than once per year, we will provide a written summary of our security measures and complete a reasonable security questionnaire. Where that is insufficient to meet a legal obligation, the parties will agree on the scope, timing, and cost of a further audit.
11. International transfers
The service stores and processes customer data in the United States. Customers subject to EEA, UK, or similar transfer rules should contact us; where required, the parties will enter into standard contractual clauses or an equivalent mechanism.
12. Contact
Questions about this DPA or requests for a countersigned copy: [email protected].