Draft pending legal review
This document is a working draft prepared from our internal framework. It has not yet been reviewed by a solicitor and is not the final wording.
Data Processing Agreement
Last updated July 2026
This Data Processing Agreement forms Schedule 1 to the Terms of Service and is incorporated into them. It applies where ValConAI processes personal data on a customer's behalf.
1. Roles and instructions
For interview transcripts, expert personal data and generated content, the customer is the controller and ValConAI is the processor. We process this personal data only on the customer's documented instructions, which include operating the service as described in the Terms.
2. Subject matter, duration, nature and purpose
The subject matter is the provision of the ValConAI service. Processing continues for the life of the account. The nature and purpose is interviewing an expert and generating content from the answers. The personal data covers the expert's name, role and answers and any expert email used for delivery. The data subjects are the customer's experts and interview subjects.
3. Security
We apply appropriate technical and organisational measures, including encryption in transit, encryption at rest for sensitive fields, tenant isolation, access controls and audit logging. Interview content is never written to logs or error reports.
4. Confidentiality
Personnel authorised to process personal data are bound by confidentiality.
5. Sub-processors
The customer authorises the sub-processors below. We will give notice of any intended change so the customer may object.
- Anthropic - AI content generation. No training on API data; a zero retention option is available.
- Stripe - payments and billing.
- Postmark - transactional email delivery.
- Hetzner - server hosting.
- Cloudflare - content delivery, edge and object storage (including R2).
- Sentry - error monitoring (personal data scrubbed).
- Meta, TikTok and Google - consent gated advertising measurement events only. These receive data only where the customer or visitor has given advertising consent.
6. International transfers
Some sub-processors are located in, or transfer personal data to, the United States and other countries outside the UK and EEA, including Anthropic, Stripe, Cloudflare, Sentry and the advertising recipients Meta, TikTok and Google. Each transfer is covered by an appropriate safeguard under the UK GDPR and EU GDPR: the Standard Contractual Clauses and the UK International Data Transfer Addendum, or an adequacy decision where one applies, through each provider's data processing agreement.
7. Assistance and data subject rights
We assist the customer in responding to data subject requests, including access, portability and erasure. Expert rights requests received by us are routed to the customer as controller, and we provide the admin tools (transcript export and an anonymise expert action, both audit logged) to action them.
8. Personal data breach
We will notify the customer without undue delay after becoming aware of a personal data breach affecting their data.
9. Deletion and return
On termination, or on the customer's instruction, we delete or return the personal data, subject to the 14 day deletion grace period and any retention we are legally required to keep (for example anonymised billing ledger records).
10. Audit
We make available the information needed to demonstrate compliance with this agreement.