Data Processing Addendum
For business customers who need a processor agreement covering personal data inside their documents.
Roles
Where you upload documents containing personal data, you are the controller and Senithu Software Solutions is the processor. We process that data only on your documented instructions, which are given by your use of the service.
Scope of processing
Subject matter: optical character recognition and structured extraction from documents you submit. Duration: for as long as your account is active, plus the retention period. Categories of data: whatever appears in the documents you upload, which may include names, addresses, financial details and identification numbers.
Confidentiality
Everyone we authorise to process customer data is bound by confidentiality, contractually or by statute, before they touch it. In practice access is held by the small team that operates the service, on named accounts with two-factor authentication.
Security measures
We maintain encryption in transit, key-only server access with password authentication disabled, default-deny network filtering, automated intrusion banning, least-privilege service accounts, and default-deny database rules.
Assistance to the controller
Taking the nature of the processing into account, we assist you in meeting your own obligations: if a data subject sends a request to us that belongs to you, we forward it without undue delay rather than answering in your place; and we provide reasonable assistance with your security, breach-notification and impact-assessment obligations insofar as they concern our processing.
Personal data breaches
If we become aware of a personal data breach affecting your documents or account data, we notify you without undue delay with what we know: what happened, what data is affected, what we have done, and what we recommend you do. We do not wait for a complete picture before the first notice.
Sub-processing
We use the sub-processors listed on the Sub-processors page. We will give notice before adding a new sub-processor, and you may object on reasonable data-protection grounds.
International transfers
Document processing and storage take place in Frankfurt, Germany. Where a sub-processor transfers data outside the EEA, that transfer relies on Standard Contractual Clauses or an adequacy decision.
Return and deletion
Documents are deleted automatically on the published retention schedule. On termination you may export your data, after which we delete it within 30 days except where law requires us to keep a record.
Demonstrating compliance
On request we make available the information reasonably necessary to demonstrate compliance with this addendum — this page, the Security page, the sub-processor list, and written answers to a security questionnaire. Where that is genuinely insufficient for your regulator, we will discuss an audit, at your cost, scoped so it does not expose other customers’ data.
Contact
Questions about this document, or a request relating to your data, go to VisionParse@senithu.lk. We answer data requests within 30 days.