Template document.This is a template document. Final legal review by a qualified data protection counsel is recommended before signing commercial agreements. Contact support@cindera.eu for the signed version.

Cindera · DPA (GDPR Art. 28)

Data Processing Agreement

Last updated · 2026-06-03

Section 01

Parties

This Data Processing Agreement (the "DPA") is entered into between:

  • The Customer, identified in the relevant order or subscription, acting as the controllerof personal data within the meaning of Regulation (EU) 2016/679 ("GDPR"); and
  • Yassin Mahouti BV("Cindera"), with registered office at [registered address placeholder], Belgium, company number [enterprise number placeholder], acting as processor.

This DPA supplements the Terms of Service and forms an integral part of the agreement between the parties. It implements Article 28 GDPR.

Section 02

Subject, duration and nature of processing

  • Subject: the processing of personal data by Cindera on behalf of the Customer for the purpose of providing the Cindera service.
  • Duration: for as long as the Customer maintains an active subscription, plus the retention periods set out below.
  • Nature and purpose:read-only analysis of the Customer's Microsoft 365 / Entra ID configuration to produce identity security and compliance findings, scores, reports and remediation guidance.

Section 03

Categories of personal data and data subjects

Categories of personal data

  • Directory identifiers (user object ID, principal name, email address, display name).
  • Account state and configuration: account status, last sign-in, registered authentication methods (the fact, not the secrets), directory role assignments and group memberships.
  • Application registrations, service principals and consented permissions in the Customer's tenant.
  • Audit-log entries produced by the Cindera application itself (actor, action, target, timestamp).

Categories of data subjects

  • Employees of the Customer.
  • Guest users invited into the Customer's tenant, including contractors and external collaborators.
  • Service accounts and application identities present in the Customer's tenant.

Section 04

Cindera's obligations as processor

Cindera will:

  • Process personal data only on documented instructions from the Customer, including with regard to transfers of personal data to a third country or international organisation. The Customer's instructions are reflected in this DPA, the Terms of Service, and the configuration of the Cindera application.
  • Ensure that persons authorised to process the personal data have committed themselves to confidentiality.
  • Implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Art. 32 GDPR). These include: TLS in transit and encryption at rest by the sub-processor database, ephemeral handling of Microsoft Graph access tokens (never persisted), tenant-scoped access in every database query, tamper-evident audit logging, strict security headers and a Content Security Policy, rate limiting, soft deletes on compliance data, and primary customer data is stored in EU-hosted infrastructure.
  • Assist the Customer, taking into account the nature of the processing, by appropriate technical and organisational measures insofar as possible, for the fulfilment of the Customer's obligation to respond to requests for exercising data subject rights.
  • Notify the Customer without undue delay and in any event within 72 hours after becoming aware of a personal data breach affecting the Customer's data.
  • Assist the Customer in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, impact assessments, prior consultation), taking into account the nature of processing and information available to Cindera.
  • At the choice of the Customer, delete or return all personal data at the end of the provision of services and delete existing copies, as described in "Return and deletion" below.
  • Make available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits as set out below.

Section 05

Sub-processors

The Customer provides a general authorisation for Cindera to engage the sub-processors listed below. Cindera will inform the Customer of any intended changes concerning the addition or replacement of sub-processors, giving the Customer the opportunity to object on reasonable grounds.

For the authoritative, up-to-date list including hosting regions and compliance certifications, see our current Sub-processors list at /subprocessors. The summary below is retained for backward compatibility with previously signed counterparts of this DPA.

  • Supabase — PostgreSQL hosting, EU region. Primary customer database.
  • Vercel — application hosting, EU region. Runs the Cindera web application and serverless functions.
  • Inngest — background jobs and scheduled scans (US-hosted; Standard Contractual Clauses in place for any personal-data transfer).
  • Resend — transactional email (US, SCCs in place).
  • Upstash — Redis used solely for rate-limit counters (EU region). No directory or scan data is stored here.

The current list also appears in the Privacy Policy. Cindera will impose data-protection obligations on each sub-processor that are no less protective than those set out in this DPA.

Section 06

International transfers

Where personal data is transferred to a sub-processor outside the EEA and no adequacy decision applies, the parties rely on the European Commission's Standard Contractual Clauses (Module 2 — controller to processor — or Module 3 — processor to processor — as appropriate) together with supplementary measures where required by the recipient country.

Section 07

Return and deletion at termination

On termination of the provision of services, Cindera will, at the Customer's choice, return all Customer personal data or delete it and certify deletion. Deletion will be completed within 30 daysof the Customer's instruction, save for copies that Cindera is required to retain under EU or member state law. Audit logs are retained as described in the Privacy Policy.

Statutory retention obligations (such as accounting records under Belgian law) take precedence over deletion obligations and will be retained for the legally required period.

Section 08

Audit rights

Cindera will make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 GDPR. Once per twelve-month period (and additionally where required by a competent supervisory authority), the Customer may request an audit on reasonable prior written notice. Audits will be conducted during normal business hours, will respect the confidentiality obligations of any third parties, and will be limited in scope to what is reasonably necessary to verify compliance with this DPA.

The Customer bears its own audit costs, and audits shall not unreasonably disrupt the Processor's operations.

Section 09

Governing law

This DPA is governed by Belgian law. Disputes are subject to the exclusive jurisdiction of the courts of Brussels, Belgium, without prejudice to mandatory provisions of GDPR or other directly applicable EU law.

Signing the DPA

Sign DPA

Contact support@cindera.eu to receive the signed DPA. We will return a countersigned PDF following review of the controller details provided in your request.