Cindera · DPA (GDPR Art. 28)
Data Processing Agreement
Last updated · 2026-08-23
Section 01
Parties
This Data Processing Agreement (the "DPA") is entered into between:
- The Customer, identified in the relevant order or subscription, acting as the controllerof personal data within the meaning of Regulation (EU) 2016/679 ("GDPR"); and
- YM Group BV("Cindera"), with registered office at Giervalkenlaan 34/10, 1170 Watermaal-Bosvoorde, Belgium, company number BE 1021.794.535, acting as processor.
This DPA supplements the Terms of Service and forms an integral part of the agreement between the parties. It implements Article 28 GDPR.
Section 02
Subject, duration and nature of processing
- Subject: the processing of personal data by Cindera on behalf of the Customer for the purpose of providing the Cindera service.
- Duration: for as long as the Customer maintains an active subscription, plus the retention periods set out below.
- Nature and purpose:read-only analysis of the Customer's Microsoft 365 / Entra ID configuration to produce identity security and compliance findings, scores, reports and remediation guidance.
Section 03
Categories of personal data and data subjects
Categories of personal data
- Directory identifiers (user object ID, principal name, email address, display name).
- Account state and configuration: account status, last sign-in, registered authentication methods (the fact, not the secrets), directory role assignments and group memberships.
- Application registrations, service principals and consented permissions in the Customer's tenant.
- Audit-log entries produced by the Cindera application itself (actor, action, target, timestamp).
Categories of data subjects
- Employees of the Customer.
- Guest users invited into the Customer's tenant, including contractors and external collaborators.
- Service accounts and application identities present in the Customer's tenant.
Section 04
Cindera's obligations as processor
Cindera will:
- Process personal data only on documented instructions from the Customer, including with regard to transfers of personal data to a third country or international organisation. The Customer's instructions are reflected in this DPA, the Terms of Service, and the configuration of the Cindera application.
- Ensure that persons authorised to process the personal data have committed themselves to confidentiality.
- Implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Art. 32 GDPR). These include: TLS in transit and encryption at rest by the sub-processor database, ephemeral handling of Microsoft Graph access tokens (never persisted), tenant-scoped access in every database query, tamper-evident audit logging, strict security headers and a Content Security Policy, rate limiting, soft deletes on compliance data, and primary customer data is stored in EU-hosted infrastructure.
- Assist the Customer, taking into account the nature of the processing, by appropriate technical and organisational measures insofar as possible, for the fulfilment of the Customer's obligation to respond to requests for exercising data subject rights.
- Notify the Customer without undue delay and in any event within 72 hours after becoming aware of a personal data breach affecting the Customer's data.
- Assist the Customer in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, impact assessments, prior consultation), taking into account the nature of processing and information available to Cindera.
- At the choice of the Customer, delete or return all personal data at the end of the provision of services and delete existing copies, as described in "Return and deletion" below.
- Make available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits as set out below.
Section 05
Sub-processors
The Customer provides a general authorisation for Cindera to engage the sub-processors listed below. Cindera will inform the Customer of any intended changes concerning the addition or replacement of sub-processors, giving the Customer the opportunity to object on reasonable grounds.
For the authoritative, up-to-date list including hosting regions and compliance certifications, see our current Sub-processors list at /subprocessors. The summary below is retained for backward compatibility with previously signed counterparts of this DPA.
- Supabase: PostgreSQL hosting, EU region. Primary customer database.
- Vercel: application hosting. Serverless functions run in the EU (Frankfurt); the global delivery network in front of them may handle connection metadata such as an IP address outside the EU under SCCs, and does not execute application logic or see scan data.
- Inngest: background jobs and scheduled scans (US-hosted; Standard Contractual Clauses in place). Receives pseudonymous record identifiers only, not names, titles, email addresses or domains.
- Resend: transactional email (US, SCCs in place). Receives the recipient address and a generic subject line; no report content and no directory data.
- Sentry: application error monitoring, EU region (Germany). Exception messages and stack traces only.
- Upstash: Redis used solely for rate-limit counters (EU region). No directory or scan data is stored here.
- Stripe: subscription billing (US-hosted with EU processing for European customers, SCCs in place). Receives billing contact details, company name and VAT number. No directory data and no scan results; card details are captured by Stripe directly and never reach Cindera's systems.
The current list also appears in the Privacy Policy. Cindera will impose data-protection obligations on each sub-processor that are no less protective than those set out in this DPA.
Section 06
International transfers
Where personal data is transferred to a sub-processor outside the EEA and no adequacy decision applies, the parties rely on the European Commission's Standard Contractual Clauses (Module 2 for controller to processor, or Module 3 for processor to processor, as appropriate) together with supplementary measures where required by the recipient country.
Section 07
Return and deletion at termination
On termination of the provision of services, Cindera will, at the Customer's choice, return all Customer personal data or delete it and certify deletion. Deletion will be completed within 30 daysof the Customer's instruction, save for copies that Cindera is required to retain under EU or member state law. Audit logs are retained as described in the Privacy Policy.
Deletion covers generated report PDFs held in EU object storage as well as the database records. They are removed in the same operation as the scan data they came from, and any outstanding download link stops working at the same moment.
Statutory retention obligations (such as accounting records under Belgian law) take precedence over deletion obligations and will be retained for the legally required period.
Section 08
Audit rights
Cindera will make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 GDPR. Once per twelve-month period (and additionally where required by a competent supervisory authority), the Customer may request an audit on reasonable prior written notice. Audits will be conducted during normal business hours, will respect the confidentiality obligations of any third parties, and will be limited in scope to what is reasonably necessary to verify compliance with this DPA.
The Customer bears its own audit costs, and audits shall not unreasonably disrupt the Processor's operations.
Section 09
Governing law
This DPA is governed by Belgian law. Disputes are subject to the exclusive jurisdiction of the courts of Brussels, Belgium, without prejudice to mandatory provisions of GDPR or other directly applicable EU law.
Signing the DPA
Sign DPA
Contact support@cindera.eu to receive the signed DPA. We will return a countersigned PDF following review of the controller details provided in your request.
