1. Roles and instructions
For Store Contact information, Store assignments, Protocol Notifications and Protocol Submissions, the organization that requested the work is the controller. ASAI Labs processes that information as its processor under Article 28 GDPR.
ASAI Labs processes customer data only on documented instructions to provide, secure and support the Auditing System. The customer remains responsible for its purposes, lawful basis, transparency to people and any special-category data assessment it needs to complete.
2. Data and duration
The service may process identity and business contact data, account and authentication data, Store and operational data, notification records, Protocol Submissions, coordinates, comments, privacy-ready images, analysis results and technical security records.
Processing continues for the customer service relationship and for the documented purpose of the relevant Protocol data. Customer instructions, legal holds and applicable legal obligations can require a shorter or longer restricted retention period.
3. Confidentiality and security
ASAI Labs applies technical and organizational measures appropriate to the risk, including organization-scoped access, role-based authorization, protected sessions, restricted object storage and processing paths, face blurring before authorized image delivery, minimized audit records, security telemetry and tested recovery processes.
People authorized by ASAI Labs to process customer data are subject to confidentiality obligations. ASAI Labs will maintain reasonable procedures for identifying, containing and communicating personal-data incidents.
4. Subprocessors
ASAI Labs may use the providers listed in the current subprocessor register to host, store, process and deliver the service. Each processor or subprocessor is required to provide protections appropriate to Article 28 GDPR and to process data only for the agreed service purpose.
5. International transfers
Where a provider or its support personnel process data outside the EEA, ASAI Labs uses an applicable adequacy decision or an Article 46 safeguard, such as the European Commission Standard Contractual Clauses, with supplementary security and contractual measures where required.
The current transfer descriptions, destinations and safeguards are set out in the provider register. Customers may request additional transfer information from privacy@asailabs.com.
6. Assistance with rights and compliance
ASAI Labs will provide reasonable assistance for access, correction, erasure, restriction, portability and objection requests relating to customer-controlled data. It will also support reasonable assistance with security assessments, impact assessments and regulator enquiries, taking into account the nature of processing and the information available to ASAI Labs.
Customers remain responsible for responding to individuals as controller. ASAI Labs can receive a request at privacy@asailabs.com and route it to the relevant organization when the controller is unclear.
7. Return and deletion
At the end of the service or on documented instruction, customer data will be deleted, returned or anonymized, subject to legal retention, claim periods and restricted backup cycles. Temporary unblurred, failed and superseded images are removed under the approved object-lifecycle rule after the secured validation and processing path completes.
Need a signed DPA?
Email the privacy team with your organization name and service contact.
Request DPA