Legal

Attestari Data Processing Agreement

Effective 2026-09-23

This Data Processing Agreement ("DPA") forms part of the Attestari Terms of Service (the "Terms") between The Elite360 Corporation ("Processor") and the business customer that accepts the Terms ("Customer") for a Small business or Enterprise account, or any other account that processes personal data of people other than the account holder. It applies automatically; no signature is needed. A countersigned copy is available on request to contact@elite360.ai.

1. Definitions

"Data Protection Law" means every law on the processing of personal data that applies to a party, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws including the California Consumer Privacy Act as amended ("CCPA"). "Customer Personal Data" means personal data Processor processes on Customer's behalf in providing Attestari. "Controller", "processor", "data subject", "personal data breach" and "processing" have the meanings in the GDPR; "service provider" and "sell" and "share" have the meanings in the CCPA.

2. Roles and instructions

Customer is the controller and Processor the processor of Customer Personal Data. Processor processes it only on Customer's documented instructions, which are the Terms, this DPA, and Customer's configuration and use of Attestari. Processor informs Customer if it believes an instruction breaks Data Protection Law. Details of the processing are in Annex I.

3. Processor's obligations

Processor will:

  1. ensure that everyone authorised to process Customer Personal Data is bound by confidentiality;
  2. implement the technical and organisational measures in Annex II;
  3. use sub-processors only as section 4 allows;
  4. taking into account the nature of the processing, help Customer respond to data subject requests, in the first place through the export, correction and deletion functions of the web app;
  5. help Customer with security, breach notification, data protection impact assessments and prior consultation, as far as the information available to Processor allows;
  6. at the end of the service, delete Customer Personal Data within 30 days, after making it available for export, unless law requires it to be kept;
  7. make available the information needed to show compliance with this DPA, as set out in section 7.

4. Sub-processors

Customer gives general authorisation for the sub-processors listed at attestari.ai/subprocessors. Processor gives at least 30 days' notice on that page, and by email to Customers who subscribe, before adding or replacing a sub-processor. Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected service and receive a pro-rata refund of prepaid fees for it. Processor imposes data protection obligations on each sub-processor no less protective than this DPA and remains responsible for its sub-processors.

5. Personal data breaches

Processor notifies Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice describes the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Processor updates Customer as more becomes known.

6. International transfers

Customer Personal Data is processed in the United States. For transfers from the European Economic Area, the EU Standard Contractual Clauses (Commission Decision 2021/914), Module Two (controller to processor), are incorporated by reference, with Customer as data exporter and Processor as data importer: clause 7 (docking) applies; clause 9 option 2 (general authorisation, 30 days' notice); the option in clause 11 does not apply; clauses 17 and 18 choose the law and courts of Ireland; Annexes I and II of this DPA complete the clauses' annexes. For the United Kingdom, the UK International Data Transfer Addendum (version B1.0) applies to those clauses; for Switzerland, the clauses apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection and the Federal Data Protection and Information Commissioner as the competent authority. If Processor certifies under the EU-US Data Privacy Framework, that certification may be relied on instead, to the extent Data Protection Law allows.

7. Audits

Processor answers Customer's reasonable written security questionnaires once a year and provides its current description of security measures. Where Data Protection Law requires more, or a supervisory authority requests it, Processor will co-operate with an audit by Customer or an independent auditor bound by confidentiality, on 30 days' notice, at Customer's cost, no more than once a year.

8. CCPA

Processor is a service provider. It does not sell or share Customer Personal Data; does not retain, use or disclose it for any purpose other than providing Attestari under the Terms; does not combine it with personal data from other sources except as the CCPA permits; and will notify Customer if it can no longer meet its CCPA obligations.

9. AI analysis

Where Customer submits a private artifact for examination, its contents are sent to the AI sub-processor listed for analysis. Processor has contractual commitments that such content is not used to train models. Customer Personal Data other than submitted artifacts is never sent to an AI provider.

10. General

Liability under this DPA is subject to the limits in the Terms. If this DPA and the Terms conflict, this DPA governs as to personal data; if the Standard Contractual Clauses conflict with either, the clauses govern. Processor may update this DPA to reflect changes in Data Protection Law or its sub-processors, with 30 days' notice; an update never reduces the protection given to Customer Personal Data.

Annex I: Details of processing

  • Parties: Customer (controller, data exporter); The Elite360 Corporation, contact@elite360.ai (processor, data importer).
  • Data subjects: Customer's employees, contractors and other people whose devices or accounts Customer adds to Attestari.
  • Categories of personal data: name, work email, identity-provider identifiers; device names, operating systems and inventories of agent tools (names, versions, sources, configuration hashes); protect and policy records; admin actions and audit log; API keys (stored hashed) and lookup records; contents of artifacts submitted for private examination; IP addresses and service logs.
  • Special categories: none intended. Customer does not submit special category data.
  • Frequency: continuous for the term of the Terms.
  • Nature and purpose: hosting, analysis, grading, policy enforcement, alerting, reporting and support, as the Terms describe.
  • Retention: as set out in the Attestari Privacy Policy, and in any case deleted within 30 days after the end of the service.
  • Competent supervisory authority: the authority of the EU member state where Customer is established, or where its EU representative is.

Annex II: Technical and organisational measures

  • Encryption in transit (TLS 1.2 or higher) and at rest (AES-256, provider-managed keys).
  • Database on a private network with no public IP; services run with least-privilege identities.
  • Sign-in through a managed identity platform with single sign-on (SAML and OIDC) for Enterprise.
  • API keys shown once and stored only as hashes; secrets held in a managed secret store; deployments run through CI with short-lived federated credentials, no long-lived keys.
  • Administrative access only through an identity-aware proxy, logged.
  • Logical separation of each Customer's data; private-artifact results visible only to that Customer, kept in a separate store from public results.
  • Signed releases of the device app with public provenance.
  • Backups of the database with point-in-time recovery; tested restores.
  • Monitoring, alerting and an incident response procedure covering breach notification under section 5.
  • Deletion on schedule per the Privacy Policy retention table, carried out automatically.