Data Processing Agreement

Last updated: July 19, 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between you (the “Customer”) and Sinonfor use of the Sinon platform (the “Service”). It governs personal data that Sinon processes on the Customer’s behalf — principally the employee data uploaded to run simulations. For data Sinoncontrols directly, see our Privacy Policy.

1. Roles of the parties

For the personal data covered by this DPA, the Customer is the data controller and Sinon is the data processor. The Customer determines the purposes and means of the processing; Sinon processes personal data only to provide the Service and only on the Customer’s documented instructions.

2. Subject matter, nature, and purpose

Sinon processes personal data to deliver simulated phishing-awareness campaigns and reporting: generating campaign content, sending simulated emails, recording interaction events, and producing metrics and reports. Processing continues for the duration of the Customer’s subscription and this DPA.

3. Categories of data subjects and personal data

Data subjects

The Customer’s employees, contractors, or other members it is authorized to test.

Categories of personal data

  • Identifiers: name and email address.
  • Organizational attributes: department, position, and locale.
  • Interaction data: send / delivered / open / click / submit / report events, timestamps, hashed IP address, and browser user-agent.

Excluded by design: Sinon does not collect or store the credentials or form values a data subject enters into a simulated page — only the fact that a submission occurred. Sinon does not require or process special-category data.

4. Customer responsibilities

  • The Customer warrants it has a lawful basis and all necessary authorization to test the data subjects it uploads, and has provided any legally required notices to them.
  • The Customer will only upload personal data it is entitled to process, and no more than is necessary for the simulations.
  • The Customer’s instructions to Sinon are given through its use of the Service and this DPA.

5. Our obligations as processor

  • Process personal data only on the Customer’s documented instructions, including for international transfers, unless required by law (in which case we will inform the Customer where permitted).
  • Ensure personnel authorized to process the data are bound by confidentiality.
  • Implement the technical and organizational security measures described in Annex A.
  • Assist the Customer, taking into account the nature of processing, in responding to data-subject requests and in meeting its security, breach-notification, and impact-assessment obligations.
  • Notify the Customer without undue delay after becoming aware of a personal-data breach affecting their data.
  • On termination, delete or return the Customer’s personal data at the Customer’s choice, except where retention is required by law.

6. Sub-processors

The Customer authorizes Sinon to engage the sub-processors below to provide the Service. Each is bound by data-protection terms no less protective than this DPA.

Sub-processorRole
SupabaseDatabase, authentication, and file storage
OpenAIGeneration of simulated content and report drafts
Amazon Web Services (SES)Delivery of simulated campaign emails
PaddleSubscription billing (merchant of record)

We will give the Customer reasonable notice of any intended addition or replacement of a sub-processor, giving the Customer the opportunity to object on reasonable data-protection grounds.

7. International transfers

Where processing involves transferring personal data across borders, including to the sub-processors above, Sinon will ensure an appropriate transfer mechanism is in place, such as the European Commission’s Standard Contractual Clauses, together with any supplementary measures required.

8. Audit

On reasonable written request, Sinon will make available information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, subject to reasonable confidentiality and security conditions.

9. Deletion and return

The Customer can update or delete personal data at any time through the Service. On expiry or termination of the subscription, Sinon will delete the Customer’s personal data within a reasonable period, unless a limited retention is required by law.

Annex A — Security measures

  • Encryption of personal data in transit and at rest.
  • Row-level tenant isolation so one customer’s data is never accessible to another.
  • Authentication and least-privilege access controls for administrative access.
  • An audit trail recording authorizations and sensitive actions.
  • A design that never stores credentials or values submitted to simulated pages.

Contact

Questions about this DPA, or to give instructions or notices under it, contact us at [contact email — add before launch].