Legal

Data Processing Addendum

For customers with GDPR, UK GDPR, or similar obligations.

Last updated August 10, 2026 Effective August 10, 2026 Version 0.1 (draft)
Draft — not yet reviewed by counsel

untactit is pre-launch. This document describes how we intend to operate and is published so you can see it early. It has not been through legal review and is not yet a binding agreement. If you need executed terms before that review completes, contact us and we will handle it directly.

English is the governing version

Translations of this page may be provided for convenience. Where a translation conflicts with the English text, the English text controls.

1. Scope and roles

This addendum forms part of the Terms of Service. It applies where we process personal data on your behalf in providing the service.

For workspace content, you are the controller and we are the processor. You determine what personal data enters the workspace and why. We process it only on your documented instructions, which include the Terms, this addendum, and your use of product features.

For account, billing, and product analytics data we act as an independent controller under our Privacy Policy.

2. Details of processing

Subject matterProvision of the untactit agent asset management platform
DurationThe term of your subscription, plus the deletion window in section 9
Nature and purposeHosting, storage, indexing, transmission, and display of workspace content; authentication; audit logging
Categories of dataIdentity and contact data of your users; any personal data you choose to include in assets you upload
Categories of data subjectsYour personnel, contractors, and anyone whose personal data you include in workspace content
Special categoriesNot permitted without a separate written agreement

3. Our obligations

  • Process personal data only on your documented instructions, including for transfers, unless required otherwise by law — in which case we will inform you first unless the law forbids it.
  • Ensure personnel authorized to process personal data are bound by confidentiality.
  • Implement the technical and organizational measures described in section 4.
  • Assist you, taking into account the nature of processing, with data subject requests, security, breach notification, and impact assessments.
  • Make available the information needed to demonstrate compliance with this addendum.

4. Security measures

We maintain measures including:

  • Access control — role-based permissions enforced server-side; single sign-on only, with no password storage; least-privilege internal access reviewed periodically.
  • Encryption — TLS 1.2 or higher in transit; encryption at rest; application-level encryption with separate keys for credentials and other sensitive fields.
  • Isolation — every record carries its tenant identifier and queries are scoped at the data layer, so a missing filter fails closed rather than exposing data.
  • Logging — append-only audit records of access and change, which cannot be edited after the fact.
  • Resilience — encrypted backups, documented restore procedures, and regular testing.

5. Subprocessors

You give general authorization for us to engage subprocessors. Our current list is published at untactit.com/subprocessors.

We will give at least 30 days' notice before adding or replacing a subprocessor. You may object on reasonable data protection grounds within that period; if we cannot resolve your objection, you may terminate the affected part of the service without penalty.

Each subprocessor is bound by written terms offering at least the same protection as this addendum. We remain fully liable for their performance.

6. Data subject requests

The product lets you access, correct, export, and delete workspace content directly. Where a data subject contacts us instead of you, we will refer them to you rather than respond on your behalf, unless legally required otherwise. We will assist you with requests you cannot fulfil through product features.

7. Personal data breach

We will notify you without undue delay and in any case within 72 hours of becoming aware of a personal data breach affecting your data. Notice will describe the nature of the breach, the categories and approximate volume of data and data subjects affected, likely consequences, and the measures taken or proposed.

We will not delay notification in order to complete our investigation. Reports go to your designated security contact and account administrators.

8. Audits

On request, and no more than once in any twelve months unless required by a supervisory authority, we will provide information reasonably necessary to demonstrate compliance. Where documentation is insufficient, you may conduct an audit yourself or through an independent auditor, on 30 days' notice, during business hours, subject to confidentiality and without unreasonably disrupting our operations.

9. Return and deletion

You can export workspace content at any time during your subscription, in an open format, at no charge.

On termination we will delete workspace content within 30 days, including from backups on their normal rotation cycle, except where retention is required by law. On request we will confirm deletion in writing.

10. International transfers

Where processing involves transferring personal data outside the EEA, UK, or Switzerland without an adequacy decision, the Standard Contractual Clauses are incorporated into this addendum by reference, with untactit as data importer, together with the UK International Data Transfer Addendum where applicable.

We conduct transfer impact assessments and maintain supplementary technical measures including encryption in transit and at rest.

11. Signing this addendum

This addendum takes effect on acceptance of the Terms of Service. If your procurement process requires a countersigned copy, write to legal@untactit.com and we will execute one.