Inyanza SystemsSentinelCore v1.x
PlatformHow it worksSolutionsSecurityPricingAboutResources
Live DemoRequest a Pilot
PlatformHow it worksSolutionsSecurityPricingAboutResources
Live DemoRequest a Pilot

Legal

Data Processing Agreement

Effective date: August 3, 2026

1. Purpose and application

This Data Processing Agreement, or DPA, is a standard form provided by Inyanza Systems. It applies only when it is incorporated into a signed Master Services Agreement, order form, statement of work, or other written agreement between Inyanza Systems and a customer.

This DPA applies when Inyanza Systems processes Personal Data on behalf of a customer while providing SentinelCore, security assessments, implementation, support, or related professional services.

2. Roles of the parties

The customer is the controller or business responsible for determining the purposes and means of processing Personal Data. Inyanza Systems acts as the processor or service provider and processes Personal Data only on the customer's documented instructions, except where applicable law requires otherwise.

3. Definitions

"Personal Data" means information relating to an identified or identifiable individual. "Processing" includes collecting, accessing, storing, organizing, using, transmitting, securing, deleting, or otherwise handling Personal Data.

"Security Incident" means a confirmed unauthorized access to, acquisition of, disclosure of, alteration of, or destruction of Personal Data processed by Inyanza Systems on behalf of the customer.

4. Processing details

  • Subject matter: Providing SentinelCore, assessments, onboarding, configuration, support, reporting, security operations, and related services.
  • Duration: The term of the applicable agreement and any limited retention period required for security, continuity, legal, or contractual purposes.
  • Data subjects: Customer personnel, authorized users, contractors, business contacts, and individuals whose information is included in customer-provided records.
  • Personal Data: Names, business contact information, account identifiers, roles, authentication and audit information, system metadata, and information submitted through the services.
  • Purpose: Delivering, securing, supporting, and improving the contracted services and meeting documented legal or compliance requirements.

Customers must not submit special-category, highly sensitive, or regulated Personal Data unless the applicable agreement expressly permits it and appropriate safeguards have been agreed.

5. Customer instructions and responsibilities

The customer's agreement, configuration choices, support requests, and documented instructions constitute its processing instructions. The customer is responsible for ensuring that its instructions and use of the services comply with applicable law and that it has a lawful basis for providing Personal Data to Inyanza Systems.

6. Confidentiality

Inyanza Systems will limit access to Personal Data to personnel and approved service providers who require access to perform the services. Those persons are subject to confidentiality obligations appropriate to their roles.

7. Security measures

Inyanza Systems will maintain reasonable administrative, technical, and organizational safeguards appropriate to the services and the risks presented by the processing. Depending on the contracted service, these safeguards may include:

  • Tenant isolation and role-based access controls.
  • Authentication, session controls, and account management.
  • Encryption in transit and appropriate storage protections.
  • Audit logging, monitoring, and incident-management controls.
  • Secure development, vulnerability management, and testing.
  • Backup, restoration, and service-continuity procedures.
  • Personnel access restrictions and confidentiality controls.

8. Subprocessors

The customer authorizes Inyanza Systems to use subprocessors necessary to provide the services, including infrastructure, hosting, communications, monitoring, and support providers. Inyanza Systems will require subprocessors that process Personal Data to provide protections consistent with this DPA.

Upon reasonable request, Inyanza Systems will provide information about material subprocessors used for the customer's contracted services.

9. Assistance with data-subject requests

Taking into account the nature of the processing, Inyanza Systems will provide reasonable assistance so the customer can respond to valid requests involving access, correction, deletion, restriction, portability, or objection. Inyanza Systems will not independently respond to a request concerning customer-controlled data unless authorized or legally required.

10. Security Incident notification

Inyanza Systems will notify the customer without undue delay after confirming a Security Incident affecting Personal Data processed on the customer's behalf. Notification will include available information reasonably necessary for the customer to evaluate the incident and meet its legal obligations.

Notification does not constitute an admission of fault or liability.

11. International transfers

Where Personal Data is transferred across national borders, Inyanza Systems will use a legally recognized transfer mechanism when required. Additional transfer terms may be included in the customer's signed agreement.

12. Return and deletion

At the end of the services, Inyanza Systems will return or delete customer Personal Data in accordance with the applicable agreement, documented customer instructions, operational requirements, backup cycles, and applicable law.

13. Compliance information and audits

Upon reasonable written request, Inyanza Systems will provide information reasonably necessary to demonstrate compliance with this DPA. Any audit must be proportionate, protect confidential information, avoid unreasonable disruption, and comply with the applicable agreement.

14. Order of precedence

If this DPA conflicts with another agreement between the parties concerning the processing of Personal Data, the signed, customer-specific agreement controls. All other terms of the applicable agreement remain in effect.

15. Contact

Questions about this DPA may be sent to legal@inyanzasystems.com. Security matters may be sent to security@inyanzasystems.com.

Inyanza Systems

AI Security Posture Management for organizations operating modern AI applications, models, and agents.

PlatformSentinelCoreHow it worksLive DemoPricingManaged Pilot
CompanySolutionsAboutResourcesGlossarySecurityContact
Contactsales@inyanzasystems.comsecurity@inyanzasystems.comsupport@inyanzasystems.com
© 2026 Inyanza Systems. All rights reserved.
Site MapPrivacyTermsMaster Services AgreementData Processing AgreementRefund PolicyCookiesAcceptable UseResponsible Disclosure