Data processing agreement

GDPR Article 28 terms, signable as they are. Most customers do not need to negotiate this; if yours does, the changes usually concern audit rights and sub-processor notice.

VERSION 2.1Effective 3 June 2026 Request signable copy
ROLE
Processor
You remain controller
TRANSFERS
None
No SCCs required
SUB-PROCESSOR NOTICE
30 days
With right to object
BREACH NOTICE
72 hours
Partial information first

1 · Subject matter and duration

Provena processes personal data on your instructions solely to provide marking, signing, verification, ledger and reporting functions. Processing lasts for the term of the main agreement plus the 90-day export window.

2 · Nature of the data

Assets may contain personal data — faces, voices, names in a document. Provena does not index or analyse content beyond what marking and verification require. Categories:

  • Asset content (Cloud)in memory, discarded
  • Asset content (self-hosted)never reaches us
  • Manifest metadatastored, DE
  • Operator identity in audit logstored, DE

3 · Security measures

Annex II measures are the controls published on the Trust & Security page, which is incorporated by reference and versioned. Reducing a control requires notice to you; adding one does not.

4 · Sub-processors

You give general authorisation for the sub-processors listed publicly. We give 30 days notice of additions or replacements; you may object on reasonable data protection grounds, and if we cannot resolve the objection you may terminate the affected service without penalty.

5 · Data subject requests

Requests reaching us directly are forwarded to you within five working days and not answered on your behalf. Where a request requires deletion, the ledger retains hashes and identifiers rather than content; we will explain that distinction to a supervisory authority in writing if asked.

6 · Audit

You may audit compliance once per year on 30 days notice, or more often if a supervisory authority requires it. We provide our penetration test summary and control documentation first, since that satisfies most audits without an on-site visit.

7 · Return and deletion

On termination you export manifests, ledger and reports in the documented format within 90 days. After that we delete all personal data, including backups, within a further 30 days, and confirm the deletion in writing on request.

Sub-processor listAnnex II controlsPrivacy statement