Sestaro Sestaro

Data Processing Agreement (DPA)

Last updated: June 25, 2026

Template. Have this reviewed by your legal counsel before signing. It describes how Sestaro actually processes data, but is not legal advice.

Purpose

This agreement governs the processing of personal data carried out by Sestaro (processor) on behalf of the Client (controller) when the Client uploads its own data for enrichment or verification, within the meaning of art. 28 GDPR. For the prospecting database it sells, Sestaro acts as controller.

Nature and purpose

Enrichment of Client-provided contacts, email verification, and search over the Client's data, solely to deliver the Sestaro service.

Categories of data

Professional identity (name, job title), professional contact details (email, phone), and company information.

Categories of data subjects

The Client's professional contacts and prospects.

Duration

The processing lasts for the duration of the service contract. On termination, data is deleted or returned at the Client's choice.

Processor obligations

Process only on documented instructions from the Client; ensure confidentiality of authorised staff; implement the security measures of art. 32; assist with data-subject requests (access, erasure...); notify personal-data breaches without undue delay; delete or return data at the end.

Sub-processors

The Client authorises the following sub-processors: Stripe (payment processing), the EU hosting provider (server infrastructure), and the outbound mail service. Sestaro remains liable for their compliance.

Security

Encryption in transit (TLS), hashing of credentials and secrets, restricted access, admin audit logs, storage-limitation purge.

Location

Data is hosted within the European Union.

Audit

Sestaro makes available the information necessary to demonstrate compliance with this agreement and art. 28 GDPR.