1. Roles and processing particulars
The customer acts as controller, or as processor on behalf of its controller, and EIGENVECTOR LTD acts as processor or subprocessor for personal data processed solely under the customer’s documented instructions. Each party remains responsible for any processing it independently determines as controller.
The order and its processing schedule must specify the subject matter, duration, nature and purpose of processing; categories of data subjects and personal data; approved models and components; locations; access arrangements; retention; and customer contacts. Typical operations may include receiving requests, running inference, temporarily storing inputs and delivering outputs. Special-category or criminal-offence data is outside scope unless expressly assessed and agreed.
2. Documented instructions
We process customer personal data only on documented instructions, including approved configurations, except where law requires otherwise. We will inform the customer of such a legal requirement before processing unless the law prohibits that notice. We will inform the customer if, in our opinion, an instruction infringes applicable data protection law.
We do not use customer prompts, files or outputs for our own model training under these terms. Any different processing purpose requires a separate lawful agreement and appropriate notices.
3. Confidentiality and security
We ensure that authorised personnel are subject to confidentiality duties and only access customer personal data where required for their role and the agreed service.
We implement technical and organisational measures appropriate to the processing risks and the agreed architecture. The order’s security schedule addresses access control, authentication, network boundaries, configuration management, logging, retention, incident handling, recovery and any encryption or backup requirements. Measures must be assessed for the actual deployment; these terms do not certify a particular standard.
4. Subprocessors
Subprocessors for customer inference processing require the customer’s specific or general written authorisation. Before processing begins, the customer receives the relevant list, functions and locations. Where general authorisation applies, we give at least 30 days’ notice of an intended material addition or replacement so the customer can object on reasonable data protection grounds.
We impose equivalent data protection obligations on subprocessors and remain responsible to the customer for their relevant performance under these terms. If a reasonable objection cannot be resolved, the parties will agree an alternative or terminate the affected processing before the change takes effect, subject to the order.
5. Assistance and incidents
Taking into account the nature of processing and information available, we assist the customer with data subject requests, security obligations, breach reporting, impact assessments and prior consultation as required by applicable law. We refer requests received directly from data subjects to the customer unless otherwise instructed or required by law.
We notify the customer without undue delay after becoming aware of a personal data breach affecting its data. We provide available information about the nature, affected data, likely consequences and remedial measures, and supplement it as the investigation develops. This is not a promise that every incident will be fully understood within a fixed number of hours.
6. International transfers
Customer personal data is processed only in the locations and access arrangements permitted by the order. A restricted international transfer requires a valid mechanism and any necessary supplementary measures under applicable law. The relevant transfer instrument, where needed, is incorporated into the customer agreement.
Customer approval of a deployment location does not by itself satisfy all legal transfer requirements. Each party performs the responsibilities applicable to its role.
7. Accountability and audit
We make available information reasonably necessary to demonstrate compliance with these processing obligations and allow proportionate audits, including inspections where required by law. Audit arrangements protect other customers’ information, system security and confidential material, and avoid unnecessary disruption. Reasonable advance notice applies unless a regulator or urgent incident requires otherwise.
The customer may use supplied documentation and independent assurance where relevant, without waiving a legally required audit right. We do not imply that a named certification or audit report exists unless it is expressly provided.
8. Return and deletion
At the customer’s choice, we return or delete customer personal data at the end of the relevant processing service, and delete existing copies unless applicable law requires retention. The order specifies a practical export, deletion and backup-expiry process. Data retained by law remains protected and is not used for unrelated purposes.
9. General
These terms are intended to address the applicable controller–processor requirements of Article 28 UK GDPR and, where applicable, EU GDPR. A completed order and processing schedule are essential to define the actual service; this published text alone does not create an operational deployment or establish compliance with every legal requirement.
If these terms conflict with general service terms on personal-data protection, these terms prevail. Mandatory rights of data subjects and powers of regulators are unaffected. Contact hi@eigenvector.app for processing-related communications.
Official resources
ICO — Controller and processor contractsQuestions about this policy?
Contact EIGENVECTOR LTD at hi@eigenvector.app or through our enquiry form.
Get in touch