Agreements
Two contractual documents govern your organization’s relationship with Sencai as a data processor and as a service provider: the Data Processing Agreement (DPA) and the Master Service Agreement (MSA). Both can be reviewed and signed directly in the app, per organization.
Find them under Legal in the app: Data Processing Agreement
(/gravity/settings/dpa) and Master Service Agreement (/gravity/settings/msa).
Data Processing Agreement (GDPR Art.28)
Section titled “Data Processing Agreement (GDPR Art.28)”Article 28 of the GDPR requires a data processing agreement between a controller (your organization, for the data in your infrastructure) and a processor (Sencai) before Sencai can lawfully process personal data on your organization’s behalf. The DPA wizard walks through this in three steps:
- Review - the current DPA document’s version, effective date, and summary, with a link to the full text.
- Sign - enter your full name and job title, and confirm you’re an authorized representative of your organization.
- Status - shows the signature status: signed and awaiting Sencai’s countersignature, or fully executed once both parties have signed.
If your organization already has a signed or fully executed DPA, the wizard opens directly on the status step.
Master Service Agreement
Section titled “Master Service Agreement”The MSA governs the commercial relationship between your organization and Sencai. Unlike the DPA (a standard document every organization reviews), MSA documents are individually negotiated and uploaded by your account manager - the review step won’t show a document, and signing isn’t available, until your account manager has prepared one for your organization. Once it’s available, signing follows the same three-step review → sign → status flow as the DPA.
Who may sign
Section titled “Who may sign”Signing either document - DPA or MSA - requires the Admin role or above (Admin or Owner) in the organization the agreement belongs to. A Member can view the current signature status but can’t sign on the organization’s behalf; this matches the weight of the action - you’re confirming your organization agrees to a legally binding document.
Where signed copies live
Section titled “Where signed copies live”There’s no separate document library for signed agreements - the signature record (who signed, their name and title, when, and the countersignature date once Sencai has countersigned) lives on the same DPA or MSA page, under the status step. Sencai typically countersigns within 5 business days of your signature; you’ll see the status update once that happens.
Sub-processors
Section titled “Sub-processors”If your organization needs a list of Sencai’s sub-processors for its own due diligence, that information isn’t currently exposed as a dedicated in-app screen - check the DPA document’s own text (via the “Read full DPA text” link on the review step) or contact sales@sencai.space.
Signing is organization-scoped
Section titled “Signing is organization-scoped”Every signature - DPA or MSA - applies to one organization. If you’re a member of more than one organization, each has its own independent agreement and its own signature status; signing on behalf of one organization doesn’t cover any other organization you belong to.
How this relates to the public legal pages
Section titled “How this relates to the public legal pages”Sencai’s marketing site publishes its general privacy policy, terms of service, and cookie policy publicly. The DPA and MSA are different: they’re customer-specific contractual documents, reviewed and signed per organization through this in-app flow rather than published as static pages. If your organization needs a DPA before becoming a customer (for example, during a security review ahead of signing up), the public marketing site directs that request to sales@sencai.space - the in-app flow described here is for existing customers actively reviewing and signing on their own organization’s behalf.
What’s next
Section titled “What’s next”- Compliance overview - how agreements fit into the rest of the compliance area
- Privacy & data - your own personal GDPR rights, a separate mechanism from your organization’s DPA
- Getting started: roles - the Admin/Owner requirement for signing
- Getting started: organizations - how organization membership and roles work