Data Processing Agreement
For customers who need a signed DPA, email [email protected] and we'll countersign this standard agreement. Summary below; the full text is incorporated into our Terms.
Roles
For employee data managed through Sincerely (names, titles, contact details, photos), the customer is the controller and Sincerely is the processor, acting only on documented instructions expressed through the product.
Subprocessors
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Database, auth, file storage | London, UK |
| Vercel | Application hosting | EU/UK edge, London functions |
| Stripe | Payments | EU/US (SCCs) |
| Resend | Transactional email | EU/US (SCCs) |
| Upstash | Rate limiting, caching | EU |
| PostHog | Product analytics | EU |
| Sentry | Error monitoring | EU |
We give 30 days' notice before adding a subprocessor.
Security, breach, deletion
Technical measures are described on the security page: encryption in transit and at rest, row-level access isolation, least-privilege secrets. We notify affected customers of a personal data breach without undue delay and within 72 hours of becoming aware. On termination we delete customer data within 30 days, subject to legal retention duties.