Sentrix

Privacy · DPA

Data processing agreement (DPA)

Sentrix's commitments as the service provider for your data in app.sentrix.ca: instructions, security, sub-processors, hosting in Canada, incidents and exit.

Last updated on 2026-10-02. When your organization uses the app.sentrix.ca platform for its compliance programme, it remains accountable for the personal information it places there, and Sentrisques Cybersécurité Inc. processes it on its behalf, as its service provider. This page summarizes the commitments we make in that role. The data processing agreement signed with your organization prevails; request it at privacy@sentrix.ca.

The parties and their roles

  • Your organization is the accountable enterprise under Law 25, or the controller under the GDPR. It determines the purposes for which the information is processed.
  • Sentrix is the service provider, or the processor under the GDPR. It processes the information only to deliver the service, on your documented instructions.

Subject matter and duration

Processing serves to deliver the platform: collecting evidence from your connected systems, assessing your controls, managing your vendors and policies, producing your deliverables. It lasts for the subscription term, then until the return and deletion described below.

Our commitments

  1. Instructions. We process your information only on your documented instructions, which include your use of the platform and your agreement. We tell you if an instruction appears to us to infringe the law.
  2. Confidentiality. Only team members whose role requires it have access to your data; they are bound by confidentiality commitments.
  3. Security. We maintain security measures suited to the sensitivity of the information: encryption in transit and at rest, keys in a managed vault, limited and logged access, platform monitoring.
  4. Sub-processors. We entrust your data only to sub-processors bound by a contract that imposes equivalent obligations on them. We notify you at least 30 days before adding one.
  5. Assistance. We help you answer requests from the persons concerned, carry out your privacy impact assessments and manage an incident.
  6. Incidents. We notify you without undue delay of any confidentiality incident affecting your data, with the information available to assess the risk.
  7. Return and deletion. At the end of the service, you have 30 days to export your data; active data is then deleted within 90 days, and backups expire on their cycle, at most seven years.
  8. Transparency. We make available the information needed to demonstrate compliance with these commitments.

Hosting and transfers

Your data is hosted on Microsoft Azure, in the Canada Central region, in Canada. This hosting is outside Québec: Law 25 governs it, and a privacy impact assessment was carried out for it. Requests to the application pass through a network protection service with a global reach.

For customers subject to the GDPR, Canada is the subject of an adequacy decision of the European Commission for organizations subject to PIPEDA. Where a transfer to another country is necessary, we rely on appropriate safeguards such as the standard contractual clauses.

Going further

The detail of the information processed, our sub-processors and retention is in the section Law 25 and the app.sentrix.ca platform. Our security measures are described on the Security and trust page.

Frequently asked questions

Q01
Do we need a data processing agreement to use Sentrix?
If your organization places personal information in the platform, yes: Law 25 requires a written contract with any service provider, and the GDPR requires the agreement set out in its Article 28. We sign one with every customer. Write to privacy@sentrix.ca to obtain our standard agreement or have your legal team review it before signing.
Q02
Does this page replace the signed agreement?
No. This page summarizes the commitments Sentrix makes as a service provider. The data processing agreement signed with your organization, and your subscription agreement, prevail in case of difference. They set out the details specific to your contract, such as the security schedules, the named list of sub-processors and the audit terms.
Q03
Can we object to a new sub-processor?
We notify you at least 30 days before adding a sub-processor that will process your data. You may raise a reasoned objection during that period. We then discuss it with you and, if no reasonable solution is found, the agreement sets out the options available, including termination of the affected service.
Q04
How can we verify Sentrix's security measures?
On request, we provide the documentation that describes our security and privacy measures, and we answer our customers' security questionnaires. Our ISO/IEC 27001 certification is in progress. Audit or inspection terms specific to your organization are set out in the signed agreement.

Last updated: 2026-10-02