Data Processing Agreement

This is Asqav's standard Data Processing Agreement. To request a signed counterpart, contact info@asqav.com. A signed version takes precedence over this standard form.

1. Roles

2. Subject matter

Cryptographic signing and storage of action records from the Customer's AI agents, optional anchoring of those records to public timestamping authorities, policy enforcement, and audit reporting.

3. Duration

This DPA runs for the term of the Customer's underlying subscription agreement and survives termination for as long as Asqav continues to hold Customer personal data.

4. Nature and purpose of processing

5. Categories of data subjects

6. Categories of personal data

The categories depend on deployment mode.

Cloud SaaS (hash-only, default):

Cloud SaaS (full-payload, opt-in only): any personal data the Customer chooses to include in the action context, subject to the Customer's redaction policies.

Self-hosted: Customer-defined. Asqav does not process data in this mode.

7. Sub-processors

Customer authorizes Asqav to engage sub-processors. The current sub-processor list is published at https://www.asqav.com/security and is kept current there. Asqav gives the Customer at least 30 days written notice by email to the account administrator of any intended addition or replacement, and the Customer may object on reasonable data-protection grounds. If the objection cannot be resolved, the Customer may terminate the affected service with a pro-rata refund of prepaid fees.

8. Security measures

These are the technical and organizational measures Asqav implements as a processor under GDPR Article 32.

9. Sub-processor authorization and notification

The Customer grants general authorization to engage sub-processors per Section 7. Asqav remains liable for sub-processor performance under this DPA.

10. Data subject requests

Asqav will, taking into account the nature of the processing, assist the Customer with appropriate technical and organizational measures to fulfill the Customer's obligations to respond to data subject requests under Articles 15 to 22 GDPR. Requests forwarded by data subjects directly to Asqav will be redirected to the Customer.

11. International transfers

Where personal data is transferred outside the European Economic Area, the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) are incorporated by reference and apply between the parties. The current hosting region for Customer Data is Falkenstein, Germany (EU), as published at https://www.asqav.com/security. Customer Data is processed in the EU; Asqav gives 30 days notice before any change of hosting region.

12. Audit rights

The Customer may audit Asqav's compliance with this DPA on reasonable prior written notice and no more than once per 12 months, except where required by a supervisory authority or following a personal data breach. Asqav will provide the Customer with audit reports as available. Asqav does not hold SOC 2 or ISO 27001 certifications; if such reports become available, they will be shared on request under NDA.

13. Personal data breach notification

Asqav will notify the Customer without undue delay and within 72 hours of becoming aware of a personal data breach affecting Customer Data. The notice will describe the nature of the breach, categories and approximate number of affected data subjects and records, likely consequences, and measures taken or proposed. This notification clock applies to Asqav as processor notifying the customer-controller. If a personal-data breach affecting your account data (where Asqav acts as controller) occurs, we notify affected customers without undue delay.

14. Return or deletion on termination

On termination of the underlying subscription, Asqav will, at the Customer's choice, return or delete the Customer's personal data in line with the retention terms of the Privacy Policy, unless a legal hold or regulatory mandate requires longer retention. Hashes that remain in immutable anchoring sources (Bitcoin, public timestamping authorities) cannot be removed by Asqav. What gets anchored is a digest over the receipt's signed bytes, not over the action context. Those bytes carry a 128-bit random action identifier and server-assigned timestamps, so the anchored value is not open to the guessing attack that an unsalted digest over a predictable action context is. The two receipt modes anchor different bytes: the default anchors the signed message, and compliance-mode receipts anchor the envelope form that also covers the signature object.

15. Confidentiality

Asqav personnel processing Customer Data are subject to written confidentiality obligations.

16. Liability

Liability under this DPA is governed by the limitations and exclusions set out in the underlying subscription agreement.

17. Order of precedence

Where this DPA conflicts with the underlying subscription agreement, this DPA prevails for matters of personal data processing. A signed counterpart of this DPA prevails over this standard form.

18. Contact

For DPA execution, sub-processor list requests, breach notifications, or audit coordination: info@asqav.com.