Data Processing Addendum

The GDPR and UK-GDPR position. Unusually short, because the architecture removes most of what a DPA normally has to govern.

Version 1.0 · effective 2 August 2026

The core point

For your business data we are NOT a processor — we never receive it. FactRule runs inside your network, so your databases, documents, questions, and derived knowledge are structurally out of our reach rather than merely out of scope by policy. You remain the controller, and there is no processor for us to be.

Where we do process

We are a controller for account data: company name, contact email, plan and billing state, and closed-schema health pulses from connected deployments (counts and status values, never content). If you use a hosted trial workspace, we process what you load into it for the trial period, as a processor, on your documented instructions.

Sub-processors

Listed on the Sub-processors page. We give at least 30 days notice before adding one, and you may object.

International transfers

Account data is stored in the region named on the Sub-processors page. Where a transfer mechanism is required we rely on the UK IDTA or the EU Standard Contractual Clauses.

Security measures

Described on the Security page: encryption in transit and at rest, least-privilege access, tamper-evident audit logging, and documented incident response.

Your rights and our assistance

Because we hold so little, most data-subject requests about your business data are answerable by you alone inside your own deployment — the product ships an erasure cascade for exactly that. For account data we assist with access, correction, and deletion within 30 days.

Breach notification

We notify you without undue delay, and within 72 hours at the latest, of any personal-data breach affecting data we process for you, with what we know and what we are doing about it.

Deletion and return

On termination we delete account records within 30 days and pulse data within 90, keeping only what tax law requires. Hosted trial workspaces are deleted at trial end. Your self-hosted data is never ours to return — it never left.

Audit

We answer security questionnaires and provide our documentation. On-site audits can be arranged under an enterprise agreement.

To execute a countersigned DPA, email privacy@factrule.com with your entity details and we will return a signed copy.