Data Processing Addendum
The terms under which Asrar processes personal data on behalf of customers, in line with Article 28 of the GDPR, including security measures, subprocessors, breach notification and international transfers.
On this page (17 sections)
- 1. Definitions
- 2. Roles and scope
- 3. Instructions
- 4. Confidentiality
- 5. Security
- 6. Subprocessors
- 7. Data subject requests
- 8. Personal Data Breaches
- 9. Impact assessments and consultations
- 10. Deletion and return
- 11. Audits
- 12. International transfers
- 13. Liability and precedence
- 14. Duration
- Annex 1 — Details of processing
- Annex 2 — Technical and organisational measures
- Annex 3 — Subprocessors
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Asrar SAS (“Processor”) and the customer that controls a Playfair workspace (“Controller”). It applies whenever the Processor processes Personal Data on behalf of the Controller in providing the Service. No signature is required; the DPA applies automatically. Customers who need a countersigned copy can request one at legal@asrar.example.
1. Definitions
Terms such as “Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject”, “Personal Data Breach” and “Supervisory Authority” have the meanings given in Regulation (EU) 2016/679 (“GDPR”). “Customer Personal Data” means Personal Data contained in the data sources connected to, or files uploaded into, the Controller’s workspaces, and in content created there. “Subprocessor” means any processor engaged by the Processor to process Customer Personal Data.
2. Roles and scope
The Controller determines the purposes and means of processing Customer Personal Data. The Processor processes it only to provide the Service. The subject matter, nature, purpose, duration, categories of data and data subjects are described in Annex 1.
3. Instructions
The Processor processes Customer Personal Data only on the Controller’s documented instructions. The Terms, this DPA and the Controller’s configuration and use of the Service (for example, connecting a source, asking a question or scheduling a report) constitute those instructions. The Processor will inform the Controller if, in its opinion, an instruction infringes applicable data-protection law.
4. Confidentiality
The Processor ensures that personnel authorised to process Customer Personal Data are bound by confidentiality obligations and access it only as needed to provide, secure and support the Service.
5. Security
The Processor implements the technical and organisational measures described in Annex 2, appropriate to the risk. The Processor may update these measures provided the overall level of protection is not reduced.
6. Subprocessors
The Controller gives general authorisation for the Processor to engage the Subprocessors listed on the Subprocessors page. The Processor will notify the Controller of any intended addition or replacement at least 30 days in advance (by email to workspace Owners and on that page). The Controller may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, the Controller may terminate the affected Service with a pro-rata refund of prepaid fees. The Processor imposes data-protection obligations on each Subprocessor that are no less protective than this DPA and remains liable for their performance.
7. Data subject requests
Taking into account the nature of the processing, the Processor assists the Controller by appropriate measures — including the export and deletion features of the Service — in responding to requests from Data Subjects. If the Processor receives a request directly, it will redirect the Data Subject to the Controller without responding substantively, unless required by law.
8. Personal Data Breaches
The Processor notifies the Controller without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification describes, as far as known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences and the measures taken or proposed. The Processor provides further information as it becomes available.
9. Impact assessments and consultations
The Processor provides reasonable assistance with data-protection impact assessments and prior consultations with Supervisory Authorities that relate to the Service, to the extent the Controller does not otherwise have access to the relevant information.
10. Deletion and return
During the subscription, the Controller can export and delete Customer Personal Data using the Service. Within 30 days after the closure of a workspace, the Processor deletes the Customer Personal Data it holds for that workspace, except where retention is required by law. Backups are overwritten within 35 days. Cached query results expire according to their configured lifetime.
11. Audits
The Processor makes available the information necessary to demonstrate compliance with this DPA, including security documentation and third-party certifications or reports where available. Where that information is insufficient, the Controller may conduct an audit, once per year, on 30 days’ written notice, during business hours, at its own cost and under confidentiality obligations, in a manner that does not compromise the security of other customers.
12. International transfers
Customer Personal Data is hosted in the European Union (Frankfurt, Germany). Where a Subprocessor processes Customer Personal Data outside the European Economic Area, the Processor ensures an adequate level of protection through an adequacy decision or the Standard Contractual Clauses adopted by the European Commission (Module 3, processor to processor), supplemented where necessary by additional measures.
13. Liability and precedence
Each party’s liability under this DPA is subject to the limitations in the Terms, except where the law does not allow such limitations. In case of conflict between this DPA and the Terms regarding the processing of Customer Personal Data, this DPA prevails.
14. Duration
This DPA applies for as long as the Processor processes Customer Personal Data on behalf of the Controller.
Annex 1 — Details of processing
| Subject matter | Provision of the Playfair analytics service |
| Nature of processing | Hosting, storage, querying (read-only), transformation into charts and tables, caching, transmission to authorised recipients (share links, scheduled reports), deletion |
| Purpose | Answering the Controller’s questions about its data, building dashboards and reports |
| Duration | The term of the subscription plus the deletion periods in §10 |
| Categories of Data Subjects | Determined by the Controller; typically the Controller’s customers, prospects, employees, suppliers and users of its services |
| Categories of Personal Data | Determined by the Controller; typically identifiers and contact details, transaction and order data, usage data |
| Special categories | Not intended. The Controller must not connect or upload special categories of data without appropriate safeguards and prior written agreement |
Annex 2 — Technical and organisational measures
- Access to customer databases: read-only roles required and verified; queries executed in read-only transactions with statement validation, timeouts and row caps; no write statements accepted.
- Encryption: TLS 1.2+ in transit; encryption at rest for databases, backups and object storage; database credentials and integration tokens encrypted with AES-256-GCM using a dedicated key.
- Access control: role-based access in the product; least-privilege staff access with multi-factor authentication; access to customer content only for support requested by the customer, security or legal reasons, and logged.
- Tenant isolation: every record is scoped to a workspace; authorisation is enforced server-side on every request.
- Logging and monitoring: audit logs for source changes, permission changes, exports and share links; query log for every executed query; alerting on anomalous activity.
- Resilience: daily encrypted backups retained for 35 days; restoration tested regularly.
- Secure development: code review, dependency scanning, secrets management, separate environments.
- Personnel: confidentiality undertakings and security training.
- Minimisation: sample values from columns identified as personal data are redacted; AI providers receive only the minimum context needed.
Annex 3 — Subprocessors
See the Subprocessors page.