Data processing addendum
Last updated 29 September 2026. This addendum forms part of the licence terms and applies where we process personal data on your behalf.
1. The starting position
In a standard ActaSeal deployment, we are not a processor of your data at all. The software runs on infrastructure you control, the evidence it produces stays there, and it makes no outbound call by default. There is no hosted service holding your records. Most of what a data processing addendum normally governs therefore does not arise.
We state this rather than staying silent about it because it changes the risk assessment your privacy team is about to do, and because it is verifiable: the exact set of things the software can send is enumerated in our privacy policy and each one is off unless you turn it on.
2. Where we do become a processor
We process personal data on your behalf only in these cases:
- Support material you send us. If you send a log extract, a configuration file, a diagnostic bundle or an evidence packet so that we can investigate a problem, and it contains personal data, we process it for the sole purpose of resolving that issue.
- Onboarding or review sessions. If we work inside your environment during onboarding or a compliance review and encounter personal data while doing so.
We do not become a processor through the licence revocation check, the transparency-log anchoring, or the usage export, because none of those carries personal data.
3. Our obligations where we do process
Where clause 2 applies we will: process only on your documented instructions; ensure anyone we allow to process it is bound by confidentiality; apply appropriate technical and organisational measures; assist you with data subject requests and with security incident notification; not engage a sub-processor without listing it at /legal/subprocessors.html and giving you notice of changes; and delete or return the material when the purpose is complete, at your choice.
The subject matter is the support or review activity you asked for; the duration is the time needed to complete it; the nature and purpose are diagnosis and resolution; the categories of data subject and personal data are whatever your material contains, which is within your control and not ours.
4. Security measures
Material sent to us for support is held in our mailbox and on the device of the person handling it, encrypted at rest and in transit, accessible only to that person, and deleted when the issue is closed. We do not copy it into a ticketing system or an AI service.
ActaSeal has not been audited under SOC 2 Type II. If your vendor qualification requires a SOC 2 report by name, we do not meet that requirement today and will confirm so in writing rather than pointing at a substitute.
5. International transfers
We are based in India. Where you are subject to the UK or EU GDPR and clause 2 applies, transfers are made under the European Commission's standard contractual clauses, which we will execute on request. The simplest way to avoid the question entirely is not to send us material containing personal data; the product does not require it.
6. Audit
You may ask us, once a year, for the information reasonably necessary to demonstrate compliance with this addendum. Given the narrow scope in clause 2, that will normally be a written response rather than an on-site audit. Where your regulator requires an on-site audit we will not refuse it.