Data Processing Agreement
Effective date: 26/09/2206
This Data Processing Agreement (“DPA”) forms part of the agreement between ACTA (“Customer”) and ACTA.LLC, operating ACTA (“ACTA”).
It applies when ACTA processes personal data on behalf of the Customer while providing the ACTA platform, simulations, reports, integrations, support, or pilot services.
1. Roles
The Customer acts as the Controller of Customer Personal Data.
ACTA acts as the Processor and processes Customer Personal Data only on the Customer's documented instructions.
Where ACTA processes information for its own account management, security, billing, or legal obligations, ACTA may act as an independent Controller for that limited purpose.
2. Customer instructions
ACTA will process Customer Personal Data only to:
- Provide the contracted ACTA services
- Configure and run authorised simulations
- Generate reports and outputs
- Provide support and maintenance
- Maintain security and service reliability
- Follow written instructions from the Customer
ACTA will not sell Customer Personal Data or use it for unrelated advertising.
3. Customer responsibilities
The Customer is responsible for:
- Establishing a lawful basis for processing
- Providing required notices to individuals
- Obtaining consents where necessary
- Ensuring uploaded data is accurate and lawful
- Avoiding unnecessary sensitive or identifiable information
- Confirming that ACTA's processing instructions are appropriate
- Responding to data-subject requests where required
4. Confidentiality
ACTA will ensure that people authorised to process Customer Personal Data are bound by confidentiality obligations.
5. Security measures
ACTA will maintain reasonable security controls appropriate to the nature of the data and services, including:
- Access management
- Authentication controls
- Encryption where appropriate
- Logging and monitoring
- Secure infrastructure
- Vulnerability and incident management
- Backup and recovery procedures
- Personnel confidentiality obligations
- Logical separation of customer environments where applicable
6. Subprocessors
The Customer authorises ACTA to use subprocessors required to provide the service, including hosting, infrastructure, authentication, analytics, support, and AI/API providers.
ACTA will maintain a list of relevant subprocessors and will require them to provide appropriate data-protection commitments.
Current subprocessors may include:
- [Cloud provider]
- [Database provider]
- [LLM/API provider]
- [Authentication provider]
- [Monitoring provider]
ACTA will provide notice of material changes to subprocessors where required by applicable law or contract.
7. Data-subject requests
If ACTA receives a request from an individual relating to Customer Personal Data, ACTA will, where legally permitted:
- Notify the Customer
- Not respond independently unless instructed
- Provide reasonable assistance
- Help locate, correct, export, or delete relevant information
8. Security incidents
ACTA will notify the Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer Personal Data.
The notice will include, where available:
- Nature of the incident
- Categories of affected information
- Likely consequences
- Containment and remediation steps
- Contact details for the incident-response team
9. Audits and compliance information
Upon reasonable request, ACTA will provide information necessary to demonstrate compliance with this DPA. Audits must be:
- Reasonably scheduled
- Limited to relevant systems and records
- Conducted without compromising other customers' confidentiality
- Subject to appropriate confidentiality obligations
10. International transfers
Where Customer Personal Data is transferred internationally, ACTA will use legally recognised transfer mechanisms and appropriate safeguards required by applicable data-protection law.
11. Retention and deletion
At the end of the services, ACTA will delete or return Customer Personal Data according to the Customer's instructions, unless retention is required by law.
Backups may remain temporarily until overwritten under ACTA's standard retention procedures.
12. AI and model usage
ACTA may use third-party AI models or APIs to process Customer-approved inputs for the purpose of delivering the service.
Unless expressly authorised in writing:
- Customer Personal Data will not be used to train public or general-purpose models
- Customer content will not be combined with another customer's confidential content
- ACTA will apply reasonable controls to limit unauthorised disclosure
- ACTA will maintain traceability for material simulation outputs where technically feasible
ACTA outputs are decision-support material and must be reviewed by the Customer before operational use.
13. Liability
The liability provisions in the main agreement apply to this DPA. Where required by applicable law, the parties will comply with mandatory data-protection obligations.
14. Governing law
This DPA is governed by the law specified in the main agreement between the parties, unless applicable data-protection law requires otherwise.