In plain English
- Published ungated — you can review it before a sales call.
- Incorporates the 2021 Standard Contractual Clauses and the UK International Data Transfer Addendum.
- Includes DORA Article 30 ICT third-party clauses (audit, exit, sub-contracting) for EU financial entities.
- Security incidents notified without undue delay and within 48 hours of confirmation.
1. Scope and roles
Customer is controller; alt.qa is processor for personal data contained in run evidence and workspace content. Processing is limited to providing the service as instructed in the Test Authorization and settings.
2. Security measures
- Encryption in transit (TLS 1.2+) and at rest, per-workspace keys for evidence.
- Role-based access, least privilege, logged administrative access.
- Per-origin rate limits, stop-before-pay, kill switch.
- Annual penetration test (first scheduled month 3); SOC 2 Type I in progress.
3. Sub-processors
Listed at /legal/subprocessors. 30 days’ notice of changes with a right to object.
4. Audits
Customer may audit once a year on 30 days’ notice, or rely on our third-party reports once issued. Regulators of EU financial entities retain unrestricted audit rights (DORA).
5. Incidents
We notify without undue delay and within 48 hours of confirming a personal-data breach, with the information needed for your regulatory notifications.
6. Return and deletion
On termination we return or delete customer personal data within 30 days, unless law requires retention. Exit assistance is provided for EU financial entities.
This document is provided for transparency. Where a signed order form or master agreement exists, it controls. Previous versions are available on request.