- Definitions
- Roles of the parties
- Subject matter and duration
- Nature of processing
- Categories of personal data
- Data subjects
- Sub-processors
- Security measures (Article 32)
- Data subject rights assistance
- Breach notification
- Data deletion and return
- Audit rights
- International transfers
- Governing law
- Contact
1. Definitions
In this DPA, the following terms have the meanings set out below. Capitalised terms not defined here have the meanings given to them in the UK GDPR or in the Terms and Conditions.
- "Controller" means the natural or legal person who determines the purposes and means of processing personal data. In the context of this DPA, the Customer is the Controller.
- "Processor" means the natural or legal person who processes personal data on behalf of the Controller. In the context of this DPA, Prosader Ltd. is the Processor.
- "Personal Data" means any information relating to an identified or identifiable natural person, as defined in Article 4(1) UK GDPR.
- "Processing" means any operation performed on personal data, including collection, storage, retrieval, analysis, and deletion.
- "Sub-processor" means any third party appointed by Prosader to process personal data on Prosader's behalf in connection with providing the Service.
- "Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
- "UK GDPR" means the General Data Protection Regulation as it forms part of the law of England and Wales, Scotland, and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018.
2. Roles of the parties
The Customer is the Controller of personal data processed through the Prosader gateway. Prosader is the Processor and processes personal data only on the documented instructions of the Customer (as set out in this DPA and the applicable subscription terms).
Prosader will not process personal data for any purpose other than delivering the Service, unless required to do so by applicable law, in which case Prosader will inform the Customer before processing unless prohibited by law.
Prosader ensures that persons authorised to process personal data are subject to appropriate confidentiality obligations.
3. Subject matter and duration
The subject matter of processing is the operation of the Prosader AI agent runtime security gateway, including: evaluating AI agent tool call requests against policy rules, generating and storing cryptographically signed audit receipts, recording session activity, and facilitating human step-up approval workflows.
Processing commences on the date the Customer first uses the Service and continues for the duration of the subscription. Upon termination or expiry of the subscription, processing ceases and data is deleted in accordance with Section 11.
4. Nature of processing
Processing activities carried out by Prosader on behalf of the Customer include:
- Receiving and evaluating AI agent tool call requests in real time
- Applying the Customer's configured policy rules to each request
- Generating Ed25519-signed audit receipts recording enforcement decisions
- Storing audit receipts and session logs for retrieval and compliance review
- Routing step-up approval requests to designated human reviewers
- Providing analytics and reporting on agent activity to the Customer via the dashboard
5. Categories of personal data
Depending on how the Customer configures and uses the Service, the personal data processed may include:
- Agent identifiers and session identifiers assigned by the Customer's systems
- Employee or contractor identifiers and usernames of persons interacting with AI agents
- The content of AI agent tool call requests and responses (which may contain personal data depending on the tools used and their parameters)
- IP addresses of agents or users initiating requests
- Timestamps of all enforcement decisions
- Step-up approval decisions and the identity of the approving reviewer
The Customer is responsible for ensuring that any personal data submitted to the Service is processed in accordance with applicable data protection law.
6. Data subjects
The data subjects whose personal data may be processed include:
- The Customer's employees and contractors operating or overseeing AI agents
- Human reviewers designated by the Customer for step-up approval workflows
- AI agents acting on behalf of the Customer (to the extent agent identifiers constitute personal data)
- Third parties whose personal data may appear in the content of AI agent tool calls, depending on the Customer's use case
7. Sub-processors
Prosader uses the following sub-processors to provide the Service. By agreeing to this DPA, the Customer provides general authorisation for Prosader to engage sub-processors as listed below. Prosader will notify the Customer of any intended changes to this list at least 14 days in advance, providing the Customer an opportunity to object.
| Sub-processor | Role | Location | Transfer mechanism |
|---|---|---|---|
| Hetzner Online GmbH | Cloud infrastructure hosting — servers, storage, databases | Germany (EU) | EU adequacy (no transfer from UK — data stored in EU) |
| Cloudflare, Inc. | CDN, DDoS protection, and network traffic routing | United States (global CDN) | UK International Data Transfer Agreement (IDTA) and Cloudflare's Standard Contractual Clauses |
Prosader imposes data protection obligations on all sub-processors equivalent to those set out in this DPA. Prosader remains fully liable to the Customer for the performance of sub-processors.
8. Security measures (Article 32)
Prosader implements and maintains the following technical and organisational measures to ensure a level of security appropriate to the risk:
Encryption
- All data in transit is encrypted using TLS 1.2 or higher
- Database storage is encrypted at rest
- All audit receipts are cryptographically signed using Ed25519 and chained to detect tampering
Access controls
- Access to production systems is restricted to authorised Prosader personnel only
- Multi-factor authentication is required for all administrative access
- Role-based access controls are enforced for all internal systems
- Customer data is isolated by tenant identifier; cross-tenant access is prevented at the application and database level
Monitoring and logging
- All administrative actions on production systems are logged and audited
- Security events are monitored and alerted in real time
Resilience and testing
- Regular automated backups are performed and tested for restorability
- Penetration testing is conducted periodically by qualified security professionals
- An incident response plan is maintained and reviewed regularly
9. Data subject rights assistance
Prosader will, taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures to respond to requests from data subjects exercising their rights under UK GDPR (including rights of access, rectification, erasure, restriction, portability, and objection).
Where Prosader receives a data subject request directly relating to Customer Data, Prosader will promptly notify the Customer and will not respond to the request without the Customer's instruction, except where required by applicable law.
Prosader will use commercially reasonable efforts to provide such assistance within 72 hours of receiving a request from the Customer.
10. Breach notification
Prosader will notify the Customer without undue delay, and in any event within 72 hours of becoming aware, of any Data Breach affecting Customer Data. Notification will be made to the primary contact email address associated with the Customer's account.
The notification will include, to the extent known at the time:
- A description of the nature of the breach, including the categories and approximate number of data subjects and records affected
- The name and contact details of Prosader's data protection contact
- The likely consequences of the breach
- The measures taken or proposed to address the breach and mitigate its effects
The Customer remains responsible for determining whether to notify relevant supervisory authorities (including the ICO) or affected data subjects in accordance with applicable law.
11. Data deletion and return
Upon termination or expiry of the subscription, Prosader will:
- Delete or anonymise all Customer Data held in live production systems within 30 days of the termination date
- Delete Customer Data from all backup systems within 90 days of the termination date
- Provide a written confirmation of deletion to the Customer upon request
If the Customer requires export of their data before deletion, they must request this via legal@prosader.com within 30 days of termination. Prosader will provide an export in a standard machine-readable format (JSON) within 14 days of the request.
12. Audit rights
Prosader will make available to the Customer all information necessary to demonstrate compliance with this DPA and, upon the Customer's written request, will allow for and contribute to audits conducted by the Customer or an auditor appointed by the Customer.
The following conditions apply to any audit:
- The Customer must provide at least 30 days' prior written notice
- Audits are limited to once per calendar year, except where required by a supervisory authority or following a Data Breach
- The Customer must treat all information obtained during an audit as Confidential Information
- The Customer is responsible for all costs associated with any audit
As an alternative to an on-site audit, Prosader may provide a summary audit report prepared by an independent qualified security professional. The Customer may accept such a report in lieu of a direct audit at its discretion.
13. International transfers
Customer Data is stored on Hetzner servers located in Germany within the EU/EEA. The EU is covered by the UK's adequacy regulations (SI 2021/1256), meaning transfers of personal data from the UK to EU-hosted infrastructure are lawful without additional safeguards.
Where data passes through Cloudflare's global CDN infrastructure (a US company), this is governed by the UK International Data Transfer Agreement (IDTA) and Cloudflare's applicable Standard Contractual Clauses. Cloudflare processes only network-level routing data and does not have access to the decrypted content of Customer Data.
Prosader will not transfer Customer Data to any additional countries without first ensuring an appropriate transfer mechanism is in place and notifying the Customer.
14. Governing law
This DPA and any disputes arising out of or in connection with it shall be governed by and construed in accordance with the laws of England and Wales. The courts of England and Wales shall have exclusive jurisdiction.
This DPA supersedes any prior data processing agreements between the parties relating to the Service and forms part of the overall contract between Prosader and the Customer.
15. Contact
For any questions relating to this DPA, data protection matters, or to request a countersigned copy of this DPA:
Email: legal@prosader.com
Post: Prosader Ltd., 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
To request a signed copy of this DPA for your records (as required for your own compliance documentation), please email legal@prosader.com with the subject line "DPA countersignature request" and include your company name and registered address.