This agreement applies where we process personal data on your behalf. You are the controller and we are the processor. Article 28 of the GDPR requires this to be in writing, which is what this is.
1. Subject matter and duration
We process personal data for as long as we are providing the services under your engagement, and for the retention period set out in the privacy notice afterwards.
2. Nature and purpose
Depending on what you have engaged us for, processing may include: mapping how work moves through your organisation; reviewing systems that hold personal data; building and running automations that move personal data between systems; and administering AI tooling used by your staff.
3. Categories of data and data subjects
Typically your staff, and where your systems contain them, your customers and suppliers. Categories are ordinary business contact and employment data. We do not require special-category data and ask you not to provide it unless it is genuinely necessary, in which case tell us first.
4. Our obligations
- We process personal data only on your documented instructions, including the instruction contained in your engagement, and including on any transfer to a country outside the EEA. Where EU or Irish law requires us to process without your instruction, we will tell you what the law requires before we process, unless that law forbids us from telling you.
- Everyone with access is bound by confidentiality.
- We apply appropriate technical and organisational measures, set out in the information security statement below.
- We help you respond to data subject requests, by appropriate technical and organisational measures and so far as it is possible for us to do so.
- We help you meet your obligations on security, breach notification and impact assessments, taking account of the nature of the processing and what we know.
- We notify you without undue delay on becoming aware of a personal data breach, with what we know at the time and the rest as we learn it.
- On the end of the engagement, we delete or return personal data at your choice, including copies, except where EU or Irish law requires us to keep it.
- We make available the information you need to demonstrate compliance with Article 28, and we allow for and contribute to audits and inspections carried out by you or by an auditor you appoint.
- If we think an instruction from you breaks data protection law, we will tell you immediately. We may pause that instruction until it is resolved.
5. Sub-processors
You give us general authorisation to use the sub-processors listed below. We will give you notice before adding or replacing one, and you may object on reasonable grounds, in which case we will work out an alternative or you may end the affected service.
Each is bound by obligations no less protective than these, and we remain fully liable to you for their performance.
Anthropic is on that list only if you use Notus. It is a genuine sub-processor, because the passages go from our systems to theirs on our account rather than yours. Two limits worth knowing: only passages from documents you have marked ready are ever sent, and only in response to a question somebody in your organisation asked. Nothing is sent on a schedule, nothing is sent in bulk, and the content is not used to train a model.
6. International transfers
We do not transfer personal data outside the EEA except as set out in the table above, and only under an adequacy decision or standard contractual clauses with the additional measures those clauses require. If a transfer basis we rely on is struck down or withdrawn, we will tell you and agree a replacement before continuing.
7. Information security
The measures we apply under Article 32, so that the reference above points at something you can actually read:
- Personal data is encrypted in transit and at rest by the platforms named above.
- Access to client data is limited to the people who need it, through named individual accounts. Nobody reaches client data through a shared login. Multi-factor authentication is set at whichever identity provider you sign in with, so your own policy is what applies; the portal does not enforce a second factor of its own, and we would rather say that than imply a control we do not operate. The shared demo accounts on the sign-in page are the one exception, and they hold invented data belonging to no client.
- The database enforces access at row level, so an account can only reach the organisation it belongs to, and that is enforced by the database rather than by the application asking nicely.
- Credentials we store for automations are encrypted with a key held outside the database, and cannot be read back out through the portal by anybody, including us. The automation engine decrypts one at the moment it needs it to call the system it belongs to, and never writes it to a log.
- Access is removed on the day someone leaves.
- Backups are held by the database platform on its own schedule.
- We keep a record of processing under Article 30(2) and will produce it on request.
This is a statement of what we do, not a certification. We are not ISO 27001 certified and do not claim to be.
8. Precedence
Where this agreement conflicts with the terms of service on the processing of personal data, this agreement wins.