# Data Processing Agreement — template

**Provael · template version 2026-08-04**

> **This is a template, not executed terms, and not legal advice.** It is published so your legal
> team can read the position before a call rather than after one. Redline it. Where your own
> paper is required, this document tells you which clauses actually bite, which is usually the
> faster route.

---

## 0. The scope note that shortens this document

Most of a DPA governs how a processor protects personal data it holds. **In the ordinary use of
Provael, the supplier holds none.**

The tool is a Python package that runs inside the customer's environment. It has no telemetry, no
phone-home, no account and no licence check. Policy weights, checkpoints, run outputs and evidence
artifacts are produced on the customer's machines and remain there. There is no transfer to secure,
no store to encrypt and no deletion obligation to perform, because nothing arrives.

This agreement therefore governs the two narrow cases where personal data genuinely is processed:

1. **Contact details** submitted through the provael.com website.
2. **Material shared during a booked assessment**, which may incidentally contain personal data
   (for example, names inside a log, a task description or a video frame).

If you are only using the open-source tool, clauses 3–8 are unlikely to apply to you at all.

---

## 1. Parties and roles

| Role | Party |
| --- | --- |
| Controller | The Customer |
| Processor | Provael (the supplier named in the engagement contract) |

The Customer determines the purposes and means of processing. The Processor acts only on
documented instructions from the Customer, which for the avoidance of doubt include the
engagement contract and the rules-of-engagement letter.

## 2. Subject matter, duration, nature and purpose

- **Subject matter.** Adversarial evaluation of a vision-language-action robot policy in
  simulation, and the production of evidence artifacts describing that evaluation.
- **Duration.** The term of the engagement, plus the retention period in clause 6.
- **Nature and purpose.** Security testing and evidence generation. Not profiling, not automated
  decision-making about individuals, not marketing.
- **Categories of data subject.** Customer personnel who contact the supplier or participate in
  an engagement.
- **Categories of personal data.** Business contact details. Incidentally, any personal data the
  Customer chooses to include in material shared for an assessment.
- **Special category data.** None is requested, required, or knowingly processed. The Customer
  should not share it.

## 3. Processor obligations

The Processor shall:

1. Process personal data only on the Customer's documented instructions, including for transfers,
   unless required otherwise by law (in which case it will inform the Customer unless legally
   prohibited).
2. Ensure persons authorised to process the data are bound by confidentiality.
3. Implement the technical and organisational measures described in clause 5.
4. Respect the conditions in clause 4 for engaging another processor.
5. Assist the Customer, by appropriate measures, in responding to data-subject rights requests.
6. Assist the Customer with security, breach notification, impact assessments and prior
   consultation, taking into account the nature of processing and the information available.
7. At the Customer's choice, delete or return all personal data at the end of the engagement, and
   delete existing copies unless retention is legally required.
8. Make available the information necessary to demonstrate compliance with this clause and allow
   for and contribute to audits, including inspections, conducted by the Customer or an auditor
   the Customer mandates.

## 4. Sub-processors

The Customer grants general written authorisation for the sub-processors listed at
**https://www.provael.com/trust/**, which names each one and what it touches. The Processor shall
inform the Customer of any intended addition or replacement, giving the Customer the opportunity to
object.

**Note on scope:** the listed sub-processors serve the website and the supplier's own operations.
None of them receives assessment material or policy weights.

## 5. Security measures

Measures in force are published in full — including the ones that are absent — in the pre-answered
security questionnaire at **https://www.provael.com/trust/**. Summarised:

- Transport encryption (TLS, HSTS) for all website and lead-capture traffic; encryption at rest for
  the lead store.
- Multi-factor authentication on source, CI and package-publishing accounts; release publishing via
  OIDC rather than a stored long-lived credential.
- Dependency vulnerability scanning, static analysis and strict type checking enforced on every
  change, failing the build on a known advisory.
- Least-privilege access during an engagement, scoped and time-boxed by the rules-of-engagement
  letter.

**Stated plainly:** there is no SOC 2, no ISO/IEC 27001, no third-party penetration test and no
cyber-liability policy in force as of the template date above. If any of these is a condition of
your purchase, raise it at the scoping call.

## 6. Retention and deletion

- **Contact details:** retained for the period stated in the privacy notice at
  https://www.provael.com/privacy/ and deleted on request.
- **Assessment material:** deleted within **30 days** of delivery of the final report, unless the
  Customer instructs otherwise in writing. Evidence artifacts the Customer receives are theirs and
  are not held by the Processor.

## 7. International transfers

Where personal data is transferred outside the UK/EEA, the transfer relies on an adequacy decision
where one applies, and otherwise on the Standard Contractual Clauses, which are incorporated by
reference. The sub-processor list at /trust states the location of each recipient.

## 8. Breach notification

The Processor shall notify the Customer without undue delay, and in any event within **48 hours**,
of becoming aware of a personal-data breach affecting Customer data, and shall provide the
information the Customer reasonably requires to meet its own notification obligations.

## 9. Liability and precedence

Liability is as set out in the engagement contract. Where this agreement and the engagement contract
conflict on the processing of personal data, this agreement prevails.

---

**Signature blocks**

| | Customer | Processor |
| --- | --- | --- |
| Name | | |
| Title | | |
| Date | | |
| Signature | | |

---

*Provael — evidence, not certification. Simulation only. This template is published at
https://www.provael.com/trust/ and is not legal advice; have your own counsel review it.*
