Data processing agreement
The processor terms that come with every pilot: roles, instructions, sub-processors, security measures, deletion, audits.
Summary of the agreement signed with every pilot. The signed document is the binding one.
Roles. The customer is the controller of its end users' personal data; Digital Current SRL, Romania, the company that operates Actessia, is the processor. It is a controller only for its own account data about the customer's staff.
Instructions. Actessia processes personal data only to provide the service as configured by the customer in its dashboard (which documents are indexed, which tools are enabled, which fields are allowed in responses, how long transcripts are kept) and on documented instruction.
Sub-processors. Listed on the sub-processors page, with the country and purpose of each. The customer is notified 30 days before a change and may object; if the objection cannot be resolved the customer may terminate.
Transfers. Storage is in the EU. Model inference and embeddings are performed in the United States under standard contractual clauses and the providers' data processing terms; the content sent is limited to the conversation turn and the retrieved passages, never a credential.
Security measures. Row-level tenancy isolation enforced in the database and in every service; per-tenant encryption keys wrapped by a key-encryption key; redaction of transcripts before storage with audited reveal; an append-only audit log; the broker model for actions, with confirmation for writes and destructive actions off by default; origin allowlists, rate limits and spend caps; least-privilege access for Actessia staff, with impersonation of a customer's dashboard requiring a written reason and appearing in the customer's own audit log.
Retention and deletion. Per-tenant retention (90 days by default) with hard deletion; a deletion endpoint for individual end users; deletion of all customer data within 30 days of the end of the contract, with an export first on request.
Breach notification. Without undue delay and within 48 hours of becoming aware.
Audit. Once a year on reasonable notice, or after a breach, the customer or its auditor may review the measures above; Actessia answers security questionnaires as part of the pilot.
Data subject requests. Forwarded to the customer within 5 working days; assistance provided.