Sinapsi
ItalianoSign in

Data Processing Agreement (DPA)

Last updated: 8 July 2026

If you use Sinapsi for your organisation, you are the controller of the personal data inside your spaces and Salesmart S.r.l. acts as your processor (art. 28 GDPR). The DPA covers what you would expect, because the architecture already works that way:

  • Scope: processing limited to providing the service — chunking, indexing, retrieval, weighting — per isolated tenant, on your documented instructions.
  • Confidentiality: no human access to private content in normal operation; personnel bound by confidentiality.
  • Location: all processing in the EU (Google Cloud, europe-west8, Milan). Subprocessors limited to the public list; changes announced in advance with right to object.
  • Security: tenant isolation, per-section permissions, signed HttpOnly sessions, no third-party scripts.
  • Data subject rights & breach: assistance with requests; notification of personal data breaches without undue delay.
  • Return & deletion: one-click full export at any time; on termination, the export → 60 days read-only → deletion policy applies. Never silent.

The signable DPA document is available on request — write to privacy@sinapsi.wiki and we will send it for countersignature.