ACTA
Legal

Data Processing Agreement

Effective date: 26/09/2206

This Data Processing Agreement (“DPA”) forms part of the agreement between ACTA (“Customer”) and ACTA.LLC, operating ACTA (“ACTA”).

It applies when ACTA processes personal data on behalf of the Customer while providing the ACTA platform, simulations, reports, integrations, support, or pilot services.

1. Roles

The Customer acts as the Controller of Customer Personal Data.

ACTA acts as the Processor and processes Customer Personal Data only on the Customer's documented instructions.

Where ACTA processes information for its own account management, security, billing, or legal obligations, ACTA may act as an independent Controller for that limited purpose.

2. Customer instructions

ACTA will process Customer Personal Data only to:

  • Provide the contracted ACTA services
  • Configure and run authorised simulations
  • Generate reports and outputs
  • Provide support and maintenance
  • Maintain security and service reliability
  • Follow written instructions from the Customer

ACTA will not sell Customer Personal Data or use it for unrelated advertising.

3. Customer responsibilities

The Customer is responsible for:

  • Establishing a lawful basis for processing
  • Providing required notices to individuals
  • Obtaining consents where necessary
  • Ensuring uploaded data is accurate and lawful
  • Avoiding unnecessary sensitive or identifiable information
  • Confirming that ACTA's processing instructions are appropriate
  • Responding to data-subject requests where required

4. Confidentiality

ACTA will ensure that people authorised to process Customer Personal Data are bound by confidentiality obligations.

5. Security measures

ACTA will maintain reasonable security controls appropriate to the nature of the data and services, including:

  • Access management
  • Authentication controls
  • Encryption where appropriate
  • Logging and monitoring
  • Secure infrastructure
  • Vulnerability and incident management
  • Backup and recovery procedures
  • Personnel confidentiality obligations
  • Logical separation of customer environments where applicable

6. Subprocessors

The Customer authorises ACTA to use subprocessors required to provide the service, including hosting, infrastructure, authentication, analytics, support, and AI/API providers.

ACTA will maintain a list of relevant subprocessors and will require them to provide appropriate data-protection commitments.

Current subprocessors may include:

  • [Cloud provider]
  • [Database provider]
  • [LLM/API provider]
  • [Authentication provider]
  • [Monitoring provider]

ACTA will provide notice of material changes to subprocessors where required by applicable law or contract.

7. Data-subject requests

If ACTA receives a request from an individual relating to Customer Personal Data, ACTA will, where legally permitted:

  • Notify the Customer
  • Not respond independently unless instructed
  • Provide reasonable assistance
  • Help locate, correct, export, or delete relevant information

8. Security incidents

ACTA will notify the Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer Personal Data.

The notice will include, where available:

  • Nature of the incident
  • Categories of affected information
  • Likely consequences
  • Containment and remediation steps
  • Contact details for the incident-response team

9. Audits and compliance information

Upon reasonable request, ACTA will provide information necessary to demonstrate compliance with this DPA. Audits must be:

  • Reasonably scheduled
  • Limited to relevant systems and records
  • Conducted without compromising other customers' confidentiality
  • Subject to appropriate confidentiality obligations

10. International transfers

Where Customer Personal Data is transferred internationally, ACTA will use legally recognised transfer mechanisms and appropriate safeguards required by applicable data-protection law.

11. Retention and deletion

At the end of the services, ACTA will delete or return Customer Personal Data according to the Customer's instructions, unless retention is required by law.

Backups may remain temporarily until overwritten under ACTA's standard retention procedures.

12. AI and model usage

ACTA may use third-party AI models or APIs to process Customer-approved inputs for the purpose of delivering the service.

Unless expressly authorised in writing:

  • Customer Personal Data will not be used to train public or general-purpose models
  • Customer content will not be combined with another customer's confidential content
  • ACTA will apply reasonable controls to limit unauthorised disclosure
  • ACTA will maintain traceability for material simulation outputs where technically feasible

ACTA outputs are decision-support material and must be reviewed by the Customer before operational use.

13. Liability

The liability provisions in the main agreement apply to this DPA. Where required by applicable law, the parties will comply with mandatory data-protection obligations.

14. Governing law

This DPA is governed by the law specified in the main agreement between the parties, unless applicable data-protection law requires otherwise.