Legal

Data Processing Agreement

Our GDPR / UK GDPR data processing agreement, published ungated, with 2021 SCCs, the UK Addendum and DORA ICT third-party clauses for EU financial services.

Version 1.0Effective 25 Sep 2026Draft — pending counsel reviewQuestions? [email protected]

In plain English

  • Published ungated — you can review it before a sales call.
  • Incorporates the 2021 Standard Contractual Clauses and the UK International Data Transfer Addendum.
  • Includes DORA Article 30 ICT third-party clauses (audit, exit, sub-contracting) for EU financial entities.
  • Security incidents notified without undue delay and within 48 hours of confirmation.

1. Scope and roles

Customer is controller; alt.qa is processor for personal data contained in run evidence and workspace content. Processing is limited to providing the service as instructed in the Test Authorization and settings.

2. Security measures

  • Encryption in transit (TLS 1.2+) and at rest, per-workspace keys for evidence.
  • Role-based access, least privilege, logged administrative access.
  • Per-origin rate limits, stop-before-pay, kill switch.
  • Annual penetration test (first scheduled month 3); SOC 2 Type I in progress.

3. Sub-processors

Listed at /legal/subprocessors. 30 days’ notice of changes with a right to object.

4. Audits

Customer may audit once a year on 30 days’ notice, or rely on our third-party reports once issued. Regulators of EU financial entities retain unrestricted audit rights (DORA).

5. Incidents

We notify without undue delay and within 48 hours of confirming a personal-data breach, with the information needed for your regulatory notifications.

6. Return and deletion

On termination we return or delete customer personal data within 30 days, unless law requires retention. Exit assistance is provided for EU financial entities.


This document is provided for transparency. Where a signed order form or master agreement exists, it controls. Previous versions are available on request.