Data Processing Addendum
Last approved: Pending configuration · Version 1.0
Scope
This addendum covers personal data processed by the service on documented customer instructions for account administration, evidence management, optional AI assistance, security, support and contracted service delivery.
Roles, duration and instructions
The customer acts as controller and the service operator acts as processor for customer personal data. Processing continues for the subscription term and any documented return or deletion period. The operator processes data only on documented customer instructions, including the service configuration and authorised user actions, unless applicable law requires otherwise.
Data subjects and data categories
Data subjects may include authorised users, customer personnel, reviewers, contractors and people referenced in customer-submitted evidence. Data may include account identifiers, professional contact details, organisation and system records, content metadata, review records, audit information, technical identifiers and customer-selected files or URLs.
Security measures
Access control, tenant isolation, audit logging, encrypted transport, encrypted production storage, malware scanning, integrity-checked backups, vulnerability management and incident response are required technical and organisational measures. Personnel authorised to process customer data are subject to confidentiality obligations.
Subprocessors and transfers
The current hosting region and subprocessors are published below. The operator must impose equivalent data-protection duties on subprocessors, maintain appropriate transfer safeguards, provide advance notice of material subprocessor changes and offer a reasonable objection process where required by the customer agreement.
Assistance and incidents
The service supports data export and deletion workflows. Taking account of the nature of processing, the operator will assist with data-subject requests, security obligations, impact assessments and regulator consultations. The operator will notify the customer without undue delay after becoming aware of a personal-data breach and provide available information needed for the customer response.
Return, deletion and audits
At termination or on documented instruction, the operator will return or delete customer personal data unless retention is required by law. The operator will provide information reasonably necessary to demonstrate compliance and support proportionate audits under confidentiality, security and non-disruption conditions agreed by the parties.