Data processing agreement

The terms under which Senly processes personal data on behalf of your agency (Article 28 GDPR).

Version: 18 September 2026

This data processing agreement forms part of the Terms & Conditions and applies as soon as you use Senly as an agency. Senly is the processor; your agency is the controller. In the event of conflict, the EU Standard Contractual Clauses prevail, followed by this agreement.

1. Subject matter, nature and duration

Senly processes personal data on behalf of your agency when providing the platform (hosting, storage, content planning and publishing, CRM, reporting, support), for as long as the agreement is in force.

2. Categories of data and data subjects (Annex A)

Data subjects: your agency’s end clients and their contacts, plus the social media accounts you connect. Data: name and contact details, notes, content and captions, CRM leads, connected account IDs with encrypted access tokens, and statistics.

3. Instructions

Senly processes personal data solely on your documented instructions (your use of the platform), unless required by law.

4. Confidentiality

Everyone with access to personal data is bound by a duty of confidentiality.

5. Security

Senly takes appropriate technical and organisational measures: encryption at rest (AES-256-GCM) and in transit (TLS 1.3), strict separation per agency with a dedicated key per tenant, access control and roles, two-step verification, audit logging and rate limiting.

6. Sub-processors (Annex B)

You give general authorisation for engaging sub-processors. A current overview is available at /subverwerkers. When a sub-processor is added or replaced, we inform you in good time so you can object. Every sub-processor is bound by the same obligations.

7. Assistance with data subject rights

Senly helps you with requests for access, rectification, erasure and portability through the export and delete functions in the platform.

8. Data breaches

Senly informs you without undue delay (target: within 24 hours of discovery) of a data breach affecting your data; your agency reports it to the supervisory authority where required.

9. Return and deletion

After termination, Senly deletes the personal data within 90 days, except where a statutory retention obligation applies (such as invoices, which are kept in anonymised form).

10. Audits and information

On request, Senly makes available the information needed to demonstrate compliance, including the sub-processor overview and the security measures.

11. International transfers

Transfers outside the EU (including hosting in the United States via Railway) take place on the basis of the EU-US Data Privacy Framework and/or the EU Standard Contractual Clauses.

12. Governing law

This agreement is governed by the Terms & Conditions and Dutch law.

Questions? Contact us via the details in our privacy statement.