This Data Processing Addendum (“DPA”) supplements the PDigger Terms of Service and Privacy Policy. It applies when eprojac Ltd processes personal data on behalf of a customer as a processor in the course of providing signed-in VLM assistance.
1. Definitions
“Customer Data” means personal data processed by eprojac on behalf of the customer in providing the service, including selected images and text submitted for Ask, skill, checkpoint, refinement, or screening.
“Data Protection Laws” means laws applicable to that processing, including the UK GDPR and the Data Protection Act 2018, the EU GDPR, and, where applicable, US state privacy laws.
“controller”, “processor”, “data subject”, “personal data”, and “processing” have the meanings in those laws.
“Subprocessor” means a third party engaged by eprojac to process Customer Data. “Terms” means the PDigger Terms of Service.
2. Scope, term, and precedence
This DPA applies where the customer is a controller (or a processor acting for another controller) of Customer Data and eprojac processes it as the customer’s processor. It forms part of the Terms, starts when the customer first sends Customer Data, and lasts for as long as eprojac processes Customer Data for the customer. For data protection matters this DPA takes precedence over the Terms; for everything else the Terms apply.
3. Processing on instructions
eprojac shall process Customer Data only on the documented instructions of the customer, which are the Terms, this DPA, and the customer’s use of the service, unless required to do otherwise by law that applies to eprojac. In that case eprojac will inform the customer before processing, unless the law prohibits it. If eprojac believes an instruction infringes Data Protection Laws, it will inform the customer promptly.
Subject matter: VLM assistance for PDigger. Duration: the period of the request plus any short-lived upload needed to deliver it (uploads are deleted as soon as they are read; an object that is uploaded but never submitted expires under a one-day S3 lifecycle rule, which removes it within about two days). Bodies are not retained in the database or application logs. Nature and purpose: transmit bounded evidence to the inference provider and return the result; operate quotas and keep the record of each request. Types of data: images and text the customer chooses to send, which may include personal data visible on screen, together with counts of input events. Keystroke codes and typed text are never sent. Data subjects: persons whose information appears in that content.
4. Confidentiality
eprojac ensures that every person it authorises to process Customer Data is bound by a contractual or statutory duty of confidentiality and processes Customer Data only as instructed.
5. Security
eprojac implements appropriate technical and organisational measures for the risk, including TLS in transit, encryption at rest for AWS-managed stores, access limited to operators who need it, and confidentiality obligations.
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, eprojac maintains the measures described on the Security contact page and reviews them as the service changes. These measures satisfy eprojac’s obligations under Article 32.
6. Subprocessors
The customer gives general authorisation for eprojac to engage the Subprocessors listed on the Subprocessors page. eprojac imposes on each Subprocessor data protection obligations equivalent to those in this DPA, by written contract, and remains fully liable to the customer for the Subprocessor’s performance.
eprojac will give at least 14 days’ notice before adding or replacing a Subprocessor, by updating the Subprocessors page; the customer is responsible for checking that page. The customer may object on reasonable data protection grounds within that period. If eprojac cannot resolve the objection, the customer may terminate the affected service by stopping sending Customer Data and signing out, without penalty.
7. Assistance and data-subject rights
Taking into account the nature of the processing, eprojac will assist the customer by appropriate technical and organisational measures, insofar as possible, in responding to requests from data subjects to exercise their rights. Because request bodies are not stored, eprojac ordinarily holds no Customer Data to which such a request could relate; local history remains on the customer’s Mac under the customer’s control. If eprojac receives a request directly it will, where lawful, forward it to the customer without responding on the customer’s behalf.
eprojac will also assist the customer, taking into account the information available to it, in meeting the customer’s obligations under Articles 32 to 36 of the UK GDPR and EU GDPR: security, breach notification, data protection impact assessments, and prior consultation with a supervisory authority. Assistance beyond current documentation may be charged at a reasonable rate.
8. Personal-data breaches
eprojac will notify the customer without undue delay after becoming aware of a personal-data breach affecting Customer Data. The notice will describe, as far as known, the nature of the breach, the likely consequences, the measures taken or proposed, and a contact point, and eprojac will provide further information as it becomes available so the customer can meet its own notification duties.
9. Transfers
Customer Data may be transferred to and processed in the United States by the Subprocessors. eprojac relies on the following mechanisms:
- For transfers from the EEA to eprojac in the United Kingdom: the European Commission’s adequacy decision for the United Kingdom.
- For onward transfers from the United Kingdom to the United States: the UK Extension to the EU-US Data Privacy Framework where the Subprocessor is certified, and otherwise the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (or the IDTA), as incorporated in each Subprocessor’s data processing terms.
- For transfers from the EEA to the United States: the EU-US Data Privacy Framework where the Subprocessor is certified, and otherwise the EU Standard Contractual Clauses, Module 3 (processor to processor), as incorporated in each Subprocessor’s data processing terms.
The mechanism relied on for each Subprocessor is stated on the Subprocessors page. Where a mechanism is invalidated, eprojac will adopt a replacement without undue delay.
10. Deletion or return
Because request bodies are not stored, there is ordinarily no Customer Data for eprojac to return after a request completes. Upload objects are deleted as soon as they are read; an object that is uploaded but never submitted expires under a one-day S3 lifecycle rule, which removes it within about two days. On termination of the service, or on a verified request, eprojac will delete controller-side account and ledger data as described in the Privacy Policy and Data requests page, unless law requires retention, and will confirm deletion on request. In any case, ledger rows expire within 7 days, and sign-in profiles, together with the matching Amazon Cognito user record, expire 12 months after the last signed-in use of VLM assistance (the last authenticated request the app made to local.pdigger.com).
11. Audits
eprojac will make available the information reasonably necessary to demonstrate compliance with this DPA, starting with the Security contact and Subprocessors pages and, on request, further written answers. Where Data Protection Laws require an audit or inspection beyond that, the customer (or an independent auditor it mandates who is bound by confidentiality) may conduct one, at the customer’s cost, no more than once in any 12-month period, on at least 30 days’ written notice, remotely and on the basis of documentation wherever that is sufficient, during normal business hours, without disrupting the service, and subject to reasonable confidentiality and security requirements. eprojac may object to an auditor who is a competitor.
12. Liability and governing law
Each party’s liability under this DPA is subject to the exclusions and limits in the Terms, and the aggregate liability of both parties under the Terms and this DPA together is limited to the amount set out in the Terms. This DPA is governed by the law and courts stated in the Terms.