Legal

Data processing addendum

The terms that apply when the content you upload contains personal data about other people. You are the controller, this service is your processor, and this page says what that means in practice rather than in defined terms.

Sub-processorsPrivacy policy

Forms part of the terms of service. If you need it as a signed document, ask on the contact page.

A note on this document. It is a plain language template written by the operator of this site, not by a lawyer, and it has not been reviewed for any particular jurisdiction. It follows the shape that Article 28 of the UK and EU General Data Protection Regulation requires, but it is not yet a lawyer approved instrument, and the operator must have it reviewed before relying on it. If your counsel needs a specific form of words or a signed copy, ask.

Roles, subject matter and duration

Who is who

You are the controller. You decide what to upload, why, and for how long. The operator of this service is the processor, acting on your documented instructions, which in practice are the instructions you give by using the product: upload this, parse it, build a twin, run this scenario, delete that source.

Where you self host, none of this applies to anybody else, because you are both controller and operator and no third party is processing anything.

Subject matter and purpose

The subject matter is the processing needed to provide the service: storing your files, extracting text and facts from them, building a knowledge graph and an assumption ledger, generating agents, running simulations and returning results. The purpose is to run the product for you and for nothing else.

Duration

Processing lasts as long as your account holds the content. It ends when you delete the content, when you delete the account, or thirty days after a subscription lapses without being restored, whichever comes first.

Instructions

Processing happens only on your instructions, except where a law requires otherwise, in which case you will be told before the processing happens unless that law forbids telling you. If an instruction from you appears to breach data protection law, you will be told.

Scope

Categories of data and of data subject

The product does not require personal data to work. It models sizes and relationships, so a customer list with labels instead of names produces the same answer. This table describes what may be present if you choose to include it.

Category of data subjectCategories of personal data that may appearHow it arrives
Your own usersName, email address, company, plan, sign in recordsGiven directly at signup and on the profile
Your employeesNames, roles, departments, reporting lines, salaries where a file includes themInside an organisational chart, a payroll summary or a strategy document you upload
Your customers' contactsNames, job titles, email addresses, account ownershipInside a customer list, a CRM export or a contract you upload
Your suppliers' contactsNames, job titles, contact detailsInside a supplier list or a contract you upload
Your salespeopleNames, quota, attainment, account assignmentsInside a pipeline export or a sales report you upload
Anybody named in free textWhatever the document says about themInside strategy notes, reviews or meeting records you upload

No special category data is required by the product and uploading it is not recommended. If a file you upload contains it, that is your decision as controller, and the processing terms here still apply.

Sub-processors, security and assistance

Sub-processors

You give general authorisation for the sub-processors listed on the sub-processor page. Each is engaged under written terms no less protective than these, and the operator remains responsible for what they do.

Notice of a new or replaced sub-processor is given at least thirty days before it starts processing, by email to account holders and by a dated entry on that page. If you object on reasonable data protection grounds within that window, the operator will work with you to find an alternative, and if there is none you may terminate the affected part of the service and be refunded for any period paid for and not used.

The optional language model provider is a sub-processor only if a key is configured. With no key, no content reaches it at all. If you supply your own key, the relationship with that provider is yours rather than the operator's.

Security measures

Content is stored outside the media library in a directory carrying a deny rule, under randomised filenames. Every record is scoped to one twin and one owner, and every API route resolves the twin and checks the caller before reading or writing. Access to the production environment is limited to the people who need it, which today is one person. Transport security, disk encryption and backups are properties of the hosting provider and are described on their own terms.

What is not in place is stated on the security page in the same detail: no SOC 2, no penetration test yet, no encryption added by the plugin on top of what the host provides. Those statements are part of this document by reference, because a security schedule that quietly omits the gaps is worse than none.

Confidentiality

Anybody with access to your content is bound to keep it confidential. Today that is the operator alone, and that will be updated here rather than left vague if it changes.

Assistance

You will get reasonable help with requests from data subjects, with data protection impact assessments, and with consultations with a supervisory authority, taking into account the nature of the processing and what is available. In practice most access, correction, export and deletion requests you receive can be answered by you directly inside the product without asking anybody.

Breach notification

If a personal data breach affecting your content is discovered, you will be told without undue delay and in any event within seventy two hours of it becoming known, with what is known at the time, what is being done, and what you may need to do. There is no formal incident response process written down yet, which is named on the security page as one of the things worth building next.

Deletion, return, audit and transfers

Deletion and return

You can delete content yourself at any time, and deletion is immediate and complete: a deleted source takes its file, its chunks and its facts with it. You can export facts, assumptions, graph nodes, run results and briefs through the API while the account is open.

At the end of the service, all content is deleted after the thirty day window, unless a law requires a copy to be kept, in which case what is kept and why will be stated. Deletion at your request during the term happens within thirty days and covers backups as they rotate.

Audit

You may ask for the information needed to show that these obligations are met, and it will be provided. There is no audit report to hand over, because no audit has happened, and the honest version of an audit clause for a business this size is a commitment to answer questions in writing and to let a reasonable inspection happen at your cost, on notice, no more than once a year, without disrupting other customers.

When a penetration test has been done, its summary will replace part of this paragraph. Until then, this is what there is.

International transfers

Where the hosting region, the email provider or an optional language model provider means content is processed outside your own region, that transfer relies on an appropriate safeguard, normally the standard contractual clauses or the UK addendum to them. The sub-processor page names the region each one operates in, so you can see where content actually sits before you sign anything.

If your policy requires processing to stay inside one region, say so before you subscribe. Self hosting solves it completely, and that is a legitimate reason to choose it.

Need this signed, or in your own paper?

Ask. A specific redline is easier to deal with than a general concern, and a clause that needs changing will be changed rather than argued about.

ContactSecurity