Provena processes personal data on your instructions solely to provide marking, signing, verification, ledger and reporting functions. Processing lasts for the term of the main agreement plus the 90-day export window.
Assets may contain personal data — faces, voices, names in a document. Provena does not index or analyse content beyond what marking and verification require. Categories:
Annex II measures are the controls published on the Trust & Security page, which is incorporated by reference and versioned. Reducing a control requires notice to you; adding one does not.
You give general authorisation for the sub-processors listed publicly. We give 30 days notice of additions or replacements; you may object on reasonable data protection grounds, and if we cannot resolve the objection you may terminate the affected service without penalty.
Requests reaching us directly are forwarded to you within five working days and not answered on your behalf. Where a request requires deletion, the ledger retains hashes and identifiers rather than content; we will explain that distinction to a supervisory authority in writing if asked.
You may audit compliance once per year on 30 days notice, or more often if a supervisory authority requires it. We provide our penetration test summary and control documentation first, since that satisfies most audits without an on-site visit.
On termination you export manifests, ledger and reports in the documented format within 90 days. After that we delete all personal data, including backups, within a further 30 days, and confirm the deletion in writing on request.