Skip to content

Agreements

Two contractual documents govern your organization’s relationship with Sencai as a data processor and as a service provider: the Data Processing Agreement (DPA) and the Master Service Agreement (MSA). Both can be reviewed and signed directly in the app, per organization.

Find them under Legal in the app: Data Processing Agreement (/gravity/settings/dpa) and Master Service Agreement (/gravity/settings/msa).

Article 28 of the GDPR requires a data processing agreement between a controller (your organization, for the data in your infrastructure) and a processor (Sencai) before Sencai can lawfully process personal data on your organization’s behalf. The DPA wizard walks through this in three steps:

  1. Review - the current DPA document’s version, effective date, and summary, with a link to the full text.
  2. Sign - enter your full name and job title, and confirm you’re an authorized representative of your organization.
  3. Status - shows the signature status: signed and awaiting Sencai’s countersignature, or fully executed once both parties have signed.

If your organization already has a signed or fully executed DPA, the wizard opens directly on the status step.

The MSA governs the commercial relationship between your organization and Sencai. Unlike the DPA (a standard document every organization reviews), MSA documents are individually negotiated and uploaded by your account manager - the review step won’t show a document, and signing isn’t available, until your account manager has prepared one for your organization. Once it’s available, signing follows the same three-step review → sign → status flow as the DPA.

Signing either document - DPA or MSA - requires the Admin role or above (Admin or Owner) in the organization the agreement belongs to. A Member can view the current signature status but can’t sign on the organization’s behalf; this matches the weight of the action - you’re confirming your organization agrees to a legally binding document.

There’s no separate document library for signed agreements - the signature record (who signed, their name and title, when, and the countersignature date once Sencai has countersigned) lives on the same DPA or MSA page, under the status step. Sencai typically countersigns within 5 business days of your signature; you’ll see the status update once that happens.

If your organization needs a list of Sencai’s sub-processors for its own due diligence, that information isn’t currently exposed as a dedicated in-app screen - check the DPA document’s own text (via the “Read full DPA text” link on the review step) or contact sales@sencai.space.

Every signature - DPA or MSA - applies to one organization. If you’re a member of more than one organization, each has its own independent agreement and its own signature status; signing on behalf of one organization doesn’t cover any other organization you belong to.

Section titled “How this relates to the public legal pages”

Sencai’s marketing site publishes its general privacy policy, terms of service, and cookie policy publicly. The DPA and MSA are different: they’re customer-specific contractual documents, reviewed and signed per organization through this in-app flow rather than published as static pages. If your organization needs a DPA before becoming a customer (for example, during a security review ahead of signing up), the public marketing site directs that request to sales@sencai.space - the in-app flow described here is for existing customers actively reviewing and signing on their own organization’s behalf.