sincerely

Data Processing Agreement

For customers who need a signed DPA, email [email protected] and we'll countersign this standard agreement. Summary below; the full text is incorporated into our Terms.

Roles

For employee data managed through Sincerely (names, titles, contact details, photos), the customer is the controller and Sincerely is the processor, acting only on documented instructions expressed through the product.

Subprocessors

ProviderPurposeRegion
SupabaseDatabase, auth, file storageLondon, UK
VercelApplication hostingEU/UK edge, London functions
StripePaymentsEU/US (SCCs)
ResendTransactional emailEU/US (SCCs)
UpstashRate limiting, cachingEU
PostHogProduct analyticsEU
SentryError monitoringEU

We give 30 days' notice before adding a subprocessor.

Security, breach, deletion

Technical measures are described on the security page: encryption in transit and at rest, row-level access isolation, least-privilege secrets. We notify affected customers of a personal data breach without undue delay and within 72 hours of becoming aware. On termination we delete customer data within 30 days, subject to legal retention duties.