Data processing terms
What a procurement team usually asks for as a DPA. It is short because the architecture makes it short: the product runs in your cluster and your data never reaches us, so the only processing to govern is the account you hold with us.
Last updated 28 August 2026
1. Who is what
For the data inside your cluster — images, findings, verdicts, evidence, your own users — you are the controller and we are nothing at all. Not a processor: a processor receives data, and we do not. There is no channel by which that data could reach us, which the privacy notice sets out field by field.
For the account you hold with us — the address you sign in with, your licences, the cluster fingerprints bound to them — we are the controller, because we decide what is needed to run a licensing service and we answer for it.
That leaves one narrow case where we act as your processor: personal data of your staff that you send us in a support request, or that you ask us to enter on your behalf. Sections 3 to 11 govern that case, and it is the only one they govern.
2. What is processed
| Subject matter | Supporting your use of Attestkeep and administering your account at your request |
|---|---|
| Duration | For as long as the agreement is in force, plus the deletion period in section 9 |
| Nature and purpose | Receiving, reading, answering and storing correspondence; making a change to your account when you ask for one |
| Categories of data | Business contact details, and whatever your staff choose to include in a message |
| Categories of person | Your employees and contractors who contact us or are named by those who do |
| Special categories | None. Do not send them; if they arrive, we delete them and say so. |
3. Instructions
We process that data only on your documented instructions, of which this document and the terms of service are the standing set, and a support ticket is a specific one. If an instruction would put us in breach of a law we are subject to, we tell you rather than following it quietly.
4. People
Everyone with access is bound to confidentiality, is few in number and is named in the audit trail when they act on an account. Access is granted for a job and removed when the job ends.
5. Security
The measures are the ones in the privacy notice: Argon2id password hashing, encryption of activation keys at rest, hashed session and e-mail tokens, TLS in transit, an admin surface on a separate restricted hostname, an audit trail for every administrative action, and a standing rule that secrets are never written to a log. We keep them at least at this level for as long as we process anything for you.
6. Sub-processors
You give general authorisation for the sub-processors listed on the sub-processors page, which is the current list and not a category. A new one is announced there and by e-mail at least 30 days before it starts. If you object on reasonable data protection grounds and we cannot resolve it, you may cancel the affected part of the agreement without penalty and we refund the unused term.
Each sub-processor is engaged under written terms imposing obligations no weaker than these, and we remain answerable to you for what they do.
7. Helping you meet your obligations
If one of your people exercises a right against you — access, correction, erasure, portability, objection — and the answer sits in something we hold, we help you answer it within 15 days and at no charge. The same applies to an impact assessment or a prior consultation that reasonably needs information only we have.
If a request comes to us directly, we do not answer it on your behalf. We tell the person to ask you, and we tell you it happened.
8. If something goes wrong
We notify you without undue delay and in any case within 48 hours of becoming aware of a personal data breach affecting data we process for you, with what we know at the time: what happened, which data and roughly how many people, the likely consequences and what we are doing. We do not wait for a complete picture before the first message, and we follow up as it fills in.
Where we are the controller instead, we notify the competent authority within 72 hours and tell affected people directly where the risk to them is high.
9. Return and deletion
When the agreement ends, you may ask for a copy of what we hold for you in a machine-readable form. We delete the rest within 30 days of the request, or within 90 days of the agreement ending if you ask for nothing — except records a law requires us to keep, which we name rather than describe vaguely: commercial and tax records, for their statutory period, containing nothing beyond what an invoice needs.
Backups fall out on their own rotation, which does not exceed 30 days, and nothing is restored from them for any purpose other than recovering from a failure.
10. Audit
You may ask for the information needed to show that these terms are being met, and we answer in writing within 30 days. Where a written answer is genuinely not enough, we accept one on-site or remote audit a year, on 30 days' notice, at your cost, by you or an auditor who is not a competitor of ours and who signs a confidentiality undertaking. A regulator exercising its own powers needs none of this.
11. Transfers
Data we hold for you stays on a server in Türkiye. The two sub-processors outside Türkiye and the safeguards that cover them are named on the sub-processors page. Where a transfer needs standard contractual clauses, they are in place before the transfer, not after.
12. Signing this
These terms apply to every customer as they stand, without signing anything: accepting the terms of service accepts them. If your procurement needs a signed copy, or your own DPA reviewed, write to legal@attestkeep.com and you will get an answer from a person, usually the same week.
Where these terms and the terms of service disagree about processing, this document wins. Where this document and a law that applies to you disagree, the law wins and we will change this document rather than argue with it.