Legal
Data processing note
A plain-language summary of the controller/processor relationship for the personal data you put into your workspace about other people. A signed DPA is available on request.
- Version
- 0.1-draft
- In effect from
- —
Draft — not yet in force. This text has not been reviewed by a lawyer and is published for transparency during the invite-only beta, not as a binding agreement. The following still have to be supplied before it can take effect: registered company name, company registration number, registered office address, governing law, jurisdiction for disputes, data-protection contact address, EU representative (where required). The operative terms during the beta are the ones issued on request — ask us.
1.Who is what
Two different relationships run in parallel, and confusing them is the usual source of trouble.
- Your own account data — your name, email, country, billing details. We are the controller. Covered by the privacy policy.
- Data you enter about other people — colleagues you invite, sales contacts, investor contacts, candidates. You are the controller; we are your processor and act on your instructions. This note covers that.
2.What we do with it
We process it only to provide the service to you: storing it, showing it back to the people in your workspace who are permitted to see it, running the product’s calculations over it, and — only for a specific action you approve — sending the necessary part to the provider performing that action.
We do not use it for our own purposes, we do not sell it, and we do not train models on it. Using it any other way would make us a controller of it, which we are not.
3.Your responsibilities
- Having a lawful basis for the personal data you enter about other people.
- Telling those people how their data is used, where the law requires it.
- Handling requests they make to you about their data — you can use the product’s own export and deletion tools, and we will help where we can.
- Not entering special-category data. The product is not designed for it and we do not want it.
- Managing who in your workspace can see what, using the roles available to you.
4.Our commitments as processor
- Process only on your documented instructions, which the product’s own interface constitutes.
- Keep it confidential and require the same of anyone with access.
- Apply the technical measures described on the security page — per-workspace isolation enforced in the database, private file storage, hashed share tokens, step-up verification for sensitive actions.
- Use only the sub-processors listed in the privacy policy, each under equivalent terms, and tell you before adding one.
- Help you respond to data-subject requests and to regulators.
- Notify you without undue delay if we become aware of a breach affecting your data.
- Delete or return the data at the end of the agreement, subject to records we must retain by law.
5.Sub-processors and transfers
The full list is in the privacy policy, which also covers where processing happens and the transfer mechanism relied on when data crosses a border.
6.Getting a signed agreement
This note is a summary, not the agreement itself. If you need a signed DPA — including Standard Contractual Clauses, a sub-processor list as an annex, or a security schedule for your own compliance review — request one through the contact form, or write to [not yet registered — see the notice at the top of this page].
During the invite-only beta these are issued on request rather than published, so that what you sign is the reviewed version rather than a draft.
Questions about this document go to our contact form. To exercise a data-protection right, use the data request form.