The terms under which Senly processes personal data on behalf of your agency (Article 28 GDPR).
This is a courtesy translation. The Dutch version is the legally binding original. View the Dutch version →
This data processing agreement forms part of the Terms & Conditions and applies as soon as you use Senly as an agency. Senly is the processor; your agency is the controller. In the event of conflict, the EU Standard Contractual Clauses prevail, followed by this agreement.
Senly processes personal data on behalf of your agency when providing the platform (hosting, storage, content planning and publishing, CRM, reporting, support), for as long as the agreement is in force.
Data subjects: your agency’s end clients and their contacts, plus the social media accounts you connect. Data: name and contact details, notes, content and captions, CRM leads, connected account IDs with encrypted access tokens, and statistics.
Senly processes personal data solely on your documented instructions (your use of the platform), unless required by law.
Everyone with access to personal data is bound by a duty of confidentiality.
Senly takes appropriate technical and organisational measures: encryption at rest (AES-256-GCM) and in transit (TLS 1.3), strict separation per agency with a dedicated key per tenant, access control and roles, two-step verification, audit logging and rate limiting.
You give general authorisation for engaging sub-processors. A current overview is available at /subverwerkers. When a sub-processor is added or replaced, we inform you in good time so you can object. Every sub-processor is bound by the same obligations.
Senly helps you with requests for access, rectification, erasure and portability through the export and delete functions in the platform.
Senly informs you without undue delay (target: within 24 hours of discovery) of a data breach affecting your data; your agency reports it to the supervisory authority where required.
After termination, Senly deletes the personal data within 90 days, except where a statutory retention obligation applies (such as invoices, which are kept in anonymised form).
On request, Senly makes available the information needed to demonstrate compliance, including the sub-processor overview and the security measures.
Transfers outside the EU (including hosting in the United States via Railway) take place on the basis of the EU-US Data Privacy Framework and/or the EU Standard Contractual Clauses.
This agreement is governed by the Terms & Conditions and Dutch law.
Questions? Contact us via the details in our privacy statement.