Data Processing Agreement
Last updated: 11 June 2026
This is Asqav's standard Data Processing Agreement. To request a signed counterpart, contact info@asqav.com. A signed version takes precedence over this standard form.
1. Roles
- Cloud SaaS deployment: the Customer is the Data Controller. Asqav acts as the Data Processor for the personal data the Customer routes through the platform. Processor details: Asqav, info@asqav.com.
- Self-hosted deployment: the Customer remains both Data Controller and Operator. Asqav is not a processor for self-hosted instances because no Customer Data leaves the Customer's infrastructure unless the Customer enables cloud telemetry.
2. Subject matter
Cryptographic signing and storage of action records from the Customer's AI agents, optional anchoring of those records to public timestamping authorities, policy enforcement, and audit reporting.
3. Duration
This DPA runs for the term of the Customer's underlying subscription agreement and survives termination for as long as Asqav continues to hold Customer personal data.
4. Nature and purpose of processing
- Integrity protection of agent action records via ML-DSA signatures.
- Audit trail retention and retrieval.
- Compliance reporting (EU AI Act, DORA, and customer-defined frameworks).
- Operation of the Customer dashboard and support.
5. Categories of data subjects
- End users of the Customer's AI agents whose interactions are signed.
- The Customer's own personnel using the Asqav dashboard and APIs.
6. Categories of personal data
The categories depend on deployment mode.
Cloud SaaS (hash-only, default):
- Action hashes (SHA-256 over the canonical action context, or HMAC-SHA-256 where the Customer supplies its own salt). Asqav treats these hashes, including the ones transmitted to timestamping services, as pseudonymized personal data in scope of this DPA when they relate to identifiable agent activity. An unsalted hash over a predictable action context can be guessed by a party holding the hash, so Asqav makes no claim that such hashes are beyond recovery or that they stop being personal data in a recipient's hands.
- Whitelisted metadata:
agent_id,org_id,session_id,action_type,timestamp,model_name,tool_name. - Account data: email, name, hashed credentials, usage metrics.
Cloud SaaS (full-payload, opt-in only): any personal data the Customer chooses to include in the action context, subject to the Customer's redaction policies.
Self-hosted: Customer-defined. Asqav does not process data in this mode.
7. Sub-processors
Customer authorizes Asqav to engage sub-processors. The current sub-processor list is published at https://www.asqav.com/security and is kept current there. Asqav gives the Customer at least 30 days written notice by email to the account administrator of any intended addition or replacement, and the Customer may object on reasonable data-protection grounds. If the objection cannot be resolved, the Customer may terminate the affected service with a pro-rata refund of prepaid fees.
8. Security measures
- Encryption in transit: TLS 1.2 or higher (TLS 1.3 preferred) for every connection.
- Encryption at rest: application-level AES-256-GCM for agent signing keys and sensitive secrets. Database storage is hosted on dedicated EU infrastructure with network isolation; it is not separately disk-encrypted today.
- Authentication: API keys stored hashed; passwords hashed with Argon2id.
- Integrity: ML-DSA (FIPS 204) signatures; chained record hashes.
- Optional RFC 3161 timestamps where enabled.
- Optional Bitcoin anchoring via OpenTimestamps.
- Logical isolation per Customer organization: PostgreSQL row-level security, forced on 42 tenant tables, keyed to the organization bound on each connection and failing closed when none is set.
- Access control: role-based, least privilege, audited admin actions.
These are the technical and organizational measures Asqav implements as a processor under GDPR Article 32.
9. Sub-processor authorization and notification
The Customer grants general authorization to engage sub-processors per Section 7. Asqav remains liable for sub-processor performance under this DPA.
10. Data subject requests
Asqav will, taking into account the nature of the processing, assist the Customer with appropriate technical and organizational measures to fulfill the Customer's obligations to respond to data subject requests under Articles 15 to 22 GDPR. Requests forwarded by data subjects directly to Asqav will be redirected to the Customer.
11. International transfers
Where personal data is transferred outside the European Economic Area, the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) are incorporated by reference and apply between the parties. The current hosting region for Customer Data is Falkenstein, Germany (EU), as published at https://www.asqav.com/security. Customer Data is processed in the EU; Asqav gives 30 days notice before any change of hosting region.
12. Audit rights
The Customer may audit Asqav's compliance with this DPA on reasonable prior written notice and no more than once per 12 months, except where required by a supervisory authority or following a personal data breach. Asqav will provide the Customer with audit reports as available. Asqav does not hold SOC 2 or ISO 27001 certifications; if such reports become available, they will be shared on request under NDA.
13. Personal data breach notification
Asqav will notify the Customer without undue delay and within 72 hours of becoming aware of a personal data breach affecting Customer Data. The notice will describe the nature of the breach, categories and approximate number of affected data subjects and records, likely consequences, and measures taken or proposed. This notification clock applies to Asqav as processor notifying the customer-controller. If a personal-data breach affecting your account data (where Asqav acts as controller) occurs, we notify affected customers without undue delay.
14. Return or deletion on termination
On termination of the underlying subscription, Asqav will, at the Customer's choice, return or delete the Customer's personal data in line with the retention terms of the Privacy Policy, unless a legal hold or regulatory mandate requires longer retention. Hashes that remain in immutable anchoring sources (Bitcoin, public timestamping authorities) cannot be removed by Asqav. What gets anchored is a digest over the receipt's signed bytes, not over the action context. Those bytes carry a 128-bit random action identifier and server-assigned timestamps, so the anchored value is not open to the guessing attack that an unsalted digest over a predictable action context is. The two receipt modes anchor different bytes: the default anchors the signed message, and compliance-mode receipts anchor the envelope form that also covers the signature object.
15. Confidentiality
Asqav personnel processing Customer Data are subject to written confidentiality obligations.
16. Liability
Liability under this DPA is governed by the limitations and exclusions set out in the underlying subscription agreement.
17. Order of precedence
Where this DPA conflicts with the underlying subscription agreement, this DPA prevails for matters of personal data processing. A signed counterpart of this DPA prevails over this standard form.
18. Contact
For DPA execution, sub-processor list requests, breach notifications, or audit coordination: info@asqav.com.