Data Processing Agreement (DPA)
Last updated: June 25, 2026
Purpose
This agreement governs the processing of personal data carried out by Sestaro (processor) on behalf of the Client (controller) when the Client uploads its own data for enrichment or verification, within the meaning of art. 28 GDPR. For the prospecting database it sells, Sestaro acts as controller.
Nature and purpose
Enrichment of Client-provided contacts, email verification, and search over the Client's data, solely to deliver the Sestaro service.
Categories of data
Professional identity (name, job title), professional contact details (email, phone), and company information.
Categories of data subjects
The Client's professional contacts and prospects.
Duration
The processing lasts for the duration of the service contract. On termination, data is deleted or returned at the Client's choice.
Processor obligations
Process only on documented instructions from the Client; ensure confidentiality of authorised staff; implement the security measures of art. 32; assist with data-subject requests (access, erasure...); notify personal-data breaches without undue delay; delete or return data at the end.
Sub-processors
The Client authorises the following sub-processors: Stripe (payment processing), the EU hosting provider (server infrastructure), and the outbound mail service. Sestaro remains liable for their compliance.
Security
Encryption in transit (TLS), hashing of credentials and secrets, restricted access, admin audit logs, storage-limitation purge.
Location
Data is hosted within the European Union.
Audit
Sestaro makes available the information necessary to demonstrate compliance with this agreement and art. 28 GDPR.

