Data Processing Agreement
1. Roles
The Controller decides the purposes and means of processing personal data collected through IRIS on its website and in its console. The Processor processes that data only on the Controller's documented instructions, including this agreement.
2. Duration
For the term of the services agreement and the wind-down period in section 11.
3. Nature and purpose
Operating an investor concierge and presentation viewer; recording visits; linking activity to contacts who identify themselves or arrive through personalised links; presenting engagement to the Controller's team; sending email on the Controller's behalf; producing aggregate analytics.
4. Data subjects
Visitors to the Controller's investor website, recipients of its investor emails, and contacts the Controller adds (current and prospective investors, advisers, analysts and similar).
5. Personal data
Name, email address, phone number and notes where provided; concierge questions and answers; pages and presentation pages viewed; approximate location and network name derived from IP address (the IP address itself is not stored; abuse limits use a one-way fingerprint that rotates daily); referrer, campaign tag and device type; a pseudonymous browser identifier; email engagement events. No special category data is intended to be processed.
6. Processor obligations
- Process personal data only on documented instructions.
- Ensure persons with access are bound by confidentiality.
- Apply the security measures in section 9.
- Engage sub-processors only under section 7.
- Assist the Controller with data subject requests, security, breach notification and impact assessments. Access, export and deletion requests are completed within 30 days.
- Delete or return personal data at the end of the engagement under section 11.
- Make available the information needed to demonstrate compliance.
7. Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, database, security, location lookup | USA and global edge |
| OpenAI, L.L.C. | Concierge and voice answers (non-training API) | USA |
| Anthropic, PBC | Drafting assistance (non-training API) | USA |
| Resend (Plus Five Five, Inc.) | Email delivery | USA |
The Processor gives 30 days' notice of a new or replacement sub-processor, and the Controller may object on reasonable data protection grounds. The Processor remains responsible for its sub-processors.
8. International transfers
Transfers outside the country of collection rely on a lawful mechanism, including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum where required.
9. Security measures
- Encryption in transit and at rest, with field-level encryption (AES-256-GCM) of phone numbers and contact notes.
- Automatic removal of payment card, government ID and bank account numbers from concierge messages before processing or storage.
- Automatic deletion of visit, presentation and concierge records after 24 months, and of sign-in attempt logs after 90 days.
- Per-client logical separation enforced on the server; a Client's credentials reach only that Client's data.
- Named logins with lockout, single-use reset links and optional two-step verification; role-based access.
- Secrets held server-side; IP addresses not stored.
- Rate limiting on public endpoints; automated release checks covering tenant separation.
- Retention limits: visit, presentation and concierge records deleted after 24 months.
10. Personal data breach
The Processor notifies the Controller without undue delay, and within 72 hours of becoming aware, of a breach affecting the Controller's personal data, with the information available to support the Controller's own notifications.
11. Return or deletion
On termination the Processor, at the Controller's choice, returns or deletes all personal data within 90 days, except where law requires retention.
12. Audit
The Processor answers reasonable written requests for information to verify compliance, not more than once a year unless a regulator requires or a breach has occurred.
13. Precedence
This agreement is subject to the services agreement, including its liability provisions. On data protection matters this agreement prevails.