Data processing addendum

Last updated 29 September 2026. This addendum forms part of the licence terms and applies where we process personal data on your behalf.

1. The starting position

In a standard ActaSeal deployment, we are not a processor of your data at all. The software runs on infrastructure you control, the evidence it produces stays there, and it makes no outbound call by default. There is no hosted service holding your records. Most of what a data processing addendum normally governs therefore does not arise.

We state this rather than staying silent about it because it changes the risk assessment your privacy team is about to do, and because it is verifiable: the exact set of things the software can send is enumerated in our privacy policy and each one is off unless you turn it on.

2. Where we do become a processor

We process personal data on your behalf only in these cases:

We do not become a processor through the licence revocation check, the transparency-log anchoring, or the usage export, because none of those carries personal data.

3. Our obligations where we do process

Where clause 2 applies we will: process only on your documented instructions; ensure anyone we allow to process it is bound by confidentiality; apply appropriate technical and organisational measures; assist you with data subject requests and with security incident notification; not engage a sub-processor without listing it at /legal/subprocessors.html and giving you notice of changes; and delete or return the material when the purpose is complete, at your choice.

The subject matter is the support or review activity you asked for; the duration is the time needed to complete it; the nature and purpose are diagnosis and resolution; the categories of data subject and personal data are whatever your material contains, which is within your control and not ours.

4. Security measures

Material sent to us for support is held in our mailbox and on the device of the person handling it, encrypted at rest and in transit, accessible only to that person, and deleted when the issue is closed. We do not copy it into a ticketing system or an AI service.

ActaSeal has not been audited under SOC 2 Type II. If your vendor qualification requires a SOC 2 report by name, we do not meet that requirement today and will confirm so in writing rather than pointing at a substitute.

5. International transfers

We are based in India. Where you are subject to the UK or EU GDPR and clause 2 applies, transfers are made under the European Commission's standard contractual clauses, which we will execute on request. The simplest way to avoid the question entirely is not to send us material containing personal data; the product does not require it.

6. Audit

You may ask us, once a year, for the information reasonably necessary to demonstrate compliance with this addendum. Given the narrow scope in clause 2, that will normally be a written response rather than an on-site audit. Where your regulator requires an on-site audit we will not refuse it.