Data Processing Agreement
These terms govern personal data that Decisimo processes on your behalf when you use the platform. They form part of our Terms & Conditions, and where the two differ on a data protection question, this document governs.
Roles
For personal data contained in what you send to an execution endpoint, in your decision logic and in your test data, you are the controller and Decisimo is your processor. That is true even though endpoint payloads are not retained: evaluating data to produce a decision is processing, whether or not anything is kept afterwards.
For the account, billing and security records we keep in order to run the business — the names and business email addresses of your people, invoices, access logs — Decisimo is the controller. Those are described in the privacy policy, not here.
"Controller", "processor", "personal data", "processing", "data subject" and "personal data breach" carry the meanings given to them in the UK GDPR and, where it applies to your use, the EU GDPR.
What is processed (Annex 1)
The processing has the following characteristics:
- Subject matter. Providing the Decisimo Decision Management Platform under the Terms & Conditions.
- Duration. For as long as your account is open, plus the retention periods in section 10.
- Nature and purpose. Executing decision logic you have built, against data you submit, and returning the result. Storing and versioning that decision logic. Operating, securing and billing the service.
- Types of personal data. Whatever you choose to send. Typically identity and contact details, financial and credit data, employment and income data, and any other attribute your decision logic evaluates. You decide this; we do not require any particular field.
- Categories of data subject. Typically your applicants, customers and the people they are connected to, together with the users you give portal access.
- Storage. Endpoint payloads pass through to produce the decision and are not retained. Decision logic, configuration and version history are stored. Access logs, performance logs and usage metrics are retained to operate and bill the service.
Our instructions from you
We process personal data only on your documented instructions, which are these terms, the Terms & Conditions, the configuration you set in the portal, and any further written instruction you give. We also process where UK or EU law requires it, in which case we tell you first unless the law prohibits that.
If we consider an instruction to breach data protection law, we will tell you. We do not sell personal data, we do not use it for our own purposes, and we do not train models on it.
Confidentiality
Everyone we authorise to process personal data is bound by an appropriate duty of confidentiality, and access is limited to those who need it to do their work.
Security
We implement technical and organisational measures appropriate to the risk, as required by Article 32. Decisimo Ltd is certified to ISO 27001 and registered with the Information Commissioner’s Office under ZA920573. The controls are described on the security page, which forms Annex 2 to this document, and include encryption in transit and at rest, role-based access control, segregation of environments, logging of portal activity, and regular review of access rights.
Not retaining endpoint payloads is itself a control: data that is never stored cannot be taken from storage.
Subprocessors
You give us general authorisation to appoint subprocessors. We maintain a current list, which is available on request and whose main entries are named in the privacy policy.
- We will tell you before adding or replacing a subprocessor, giving you at least thirty (30) days’ notice.
- You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the service without penalty and we refund the fees you have paid for the unused period.
- Every subprocessor is engaged under written terms imposing obligations no less protective than these, and we remain responsible to you for what our subprocessors do.
Where processing happens, and transfers
Execution endpoints run in the region attached to your plan. Trials run on our European endpoint. Decision logic and account data are held in the United Kingdom or the European Economic Area.
Where providing the service means transferring personal data outside the UK or the EEA to a country without an adequacy decision, we do so under an appropriate safeguard — the UK International Data Transfer Addendum, or the European Commission’s standard contractual clauses — and, where the transfer calls for one, a transfer risk assessment. If you enable an integration with an externally hosted machine learning or large language model provider, data goes to that provider on your instruction and under the terms of your relationship with them; that transfer is yours, not ours.
Helping you meet your obligations
Data subject requests. Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures in responding to requests to access, rectify, erase, restrict, port or object. Where a data subject contacts us directly about data we process for you, we forward the request to you and do not respond to its substance ourselves.
Articles 32 to 36. We assist you, taking into account what we know and the means available to us, with security, breach notification, data protection impact assessments and prior consultation with a supervisory authority.
Information and audits. We make available the information you reasonably need to demonstrate compliance with Article 28, and we allow and contribute to audits or inspections conducted by you or an auditor you appoint, on reasonable notice, no more than once a year unless a supervisory authority or a breach requires otherwise, and subject to confidentiality.
Personal data breach
If a personal data breach affecting your personal data occurs, we notify you without undue delay and in any event within seventy-two (72) hours of becoming aware of it. The notification describes what we know of the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We cooperate with you in investigating and remediating it. Statutory notifications to a supervisory authority or to affected individuals remain yours to make.
Deletion and return
At the end of your account you choose whether we delete or return the personal data we process for you. Unless you tell us to return it, we delete it, along with existing copies, except where UK or EU law requires us to keep it. Your decision logic is exported on request as a human-readable Markdown file, as set out in the Terms & Conditions.
Where an account has been frozen for non-payment, deletion follows the timetable in section 7 of the Terms & Conditions. Data in routine backups is overwritten on the normal backup cycle, and remains subject to these terms until it is.
Liability, changes and law
Liability under these terms is governed by the liability section of the Terms & Conditions. We may update this document, and will give at least thirty (30) days’ notice of a material change in the same way as for the Terms & Conditions. Nothing here reduces an obligation that data protection law places on either party directly.
These terms are governed by English law and subject to the exclusive jurisdiction of the English courts. Published in English and Spanish; if the versions differ, the English version governs.