Data processing
The plain version, before the signed one.
A data processing agreement is a contract, and this page is not it. This is what ours says in language somebody can read in one sitting, so your legal team knows what they are opening and your technical reviewer can check it against what we actually hold before anybody drafts anything.
The executable agreement is provided on request and is signed alongside the commercial contract. Where the two differ, the signed agreement governs and this page is wrong.
The shape of it
Who is who, and what that decides.
| Term | Who | What follows from it |
|---|---|---|
| Controller | You | You decide why your people's data is handled and on what basis. You also decide who among your own people may reach which systems, because that is a grant your administrators write rather than a setting we configure. |
| Processor | Us | We act on your documented instructions and not on our own judgement about your data. In practice the instruction set is small, because the product's whole design is that we hold the decision and the record and none of the data. |
| Sub-processor | Microsoft | Hosting, the database and the key vault, in one region. The complete list with what each could see is published rather than attached as an annex nobody reads. |
| Data subjects | Your people | The individuals named in grants and in the access record, listed field by field in the privacy notice. Not your customers: no copy of your business data is stored, so the people inside your systems never become data subjects in our keeping. |
The commitments
What the agreement commits us to.
-
01
Process only on your instructions, and only for the service
No secondary use. Nothing of yours is used to build a product, improve a model, benchmark anything, or produce statistics we publish. We run no model at all, which makes this the easiest commitment on the page to keep.
-
02
Confidentiality and access on our side
The people who can reach production are named, few, and bound to confidentiality. At a company this size that is a short list rather than a policy framework, and we would rather describe it accurately than dress it as a programme.
-
03
Notice before a new sub-processor, with a right to object
In writing, before it handles anything of yours, with what it does and what it could see. The published list changes at the same time.
-
04
Breach notification without undue delay
With what we know, what we do not yet know, and what we are doing. The access record is part of what makes that answerable rather than speculative: only three of the twenty reason codes may ever be described as a breach, and that mapping is fixed in code rather than decided during an incident.
-
05
Deletion or return on termination
Your structure, your people, your grants and your written rules are removed or returned on your instruction. The access record follows whatever retention you agreed, and if you want it back rather than deleted, it exports in a form you can keep.
-
06
Assistance with your own obligations
Subject requests, impact assessments and regulator questions. Because we hold four fields about any individual, most of this is short, and your administrators can answer much of it themselves from the console without asking us.
Audit rights
What you can actually inspect, and what you cannot.
Audit clauses are usually the part where a vendor grants a right that is impractical to exercise. Here the useful inspection is continuous and needs no clause at all.
Available to you at any time
- The complete access record for your organization, exportable by your own administrators without asking us, refusals included.
- Every configuration change your administrators made, and who made it.
- The published limits and status pages, which are written to be read by somebody looking for a reason to say no.
Not available, and stated plainly
- No third-party audit report, because there is none. See certification status for the full row-by-row position.
- No on-site inspection of a shared environment without a specific arrangement, since one service serves several clients and an inspection cannot be allowed to reach another client's data.
- No penetration test report, because none has been commissioned. If your agreement requires one, say so during negotiation rather than assuming it exists.
Standard contractual clauses. Processing happens in one region and nothing is replicated outside it, so no transfer mechanism is engaged for the service itself. If your own circumstances need the clauses in place regardless, they are available and it is a normal request rather than an exception.
Ask for the executable version.
It comes with the review pack rather than after a call, because the slow part of this is your side and it should start first.