The Article 28 terms on which White Label Consultancy AS processes personal data for a customer of Pritect Sonar.
Version
0.1
Drafted
15 Sep 2026
In force from
Not in force
Draft for review
This is a draft for review. It has not been through legal review, and the sub-processor references and transfer bases in Annex III are open. It is published so that a data protection officer can read the position, and the open items, before it is offered as a contract.
1
Roles, scope and what this agreement is part of
This agreement applies whenever White Label Consultancy AS ("the processor") processes personal data on behalf of a customer ("the controller") in providing Pritect Sonar. It forms part of the terms of service and prevails over them where the two could be read differently.
The controller determines the purposes and means of the processing: it chooses which tenants to connect, what is in scope, what is retained and for how long, and what is disclosed within its own organisation. The processor acts only on the controller's instructions.
Where the controller is itself acting as a processor for another controller, for example an adviser operating a workspace for a client, this agreement applies as though the references to the controller were to that adviser, and the adviser confirms it has the authority to give the instructions it gives.
2
Subject matter, duration, nature, purpose and categories
The subject matter, the duration, the nature and purpose of the processing, the categories of personal data and the categories of data subjects are described in Annex I. Annex I is part of this agreement and is written to be the description a controller can put straight into its own record of processing activities.
The processing lasts for as long as the controller keeps a workspace open, and ends as section 10 describes.
3
Instructions
The processor processes personal data only on the controller's documented instructions, including on transfers, unless required to do otherwise by Union or member state law. Where such a law applies, the processor tells the controller before processing unless the law prohibits it.
The controller's instructions are: this agreement, the terms of service, the choices the controller makes in the product (the tenants connected, the scope selected, the settings, the retention periods, the exports requested and any link to the Pritect platform), and any further written instruction the parties agree.
The processor tells the controller if, in its opinion, an instruction infringes the General Data Protection Regulation or another data protection provision. It may suspend the affected processing until the instruction is withdrawn or changed.
The processor does not use personal data processed under this agreement for any purpose of its own. In particular it does not use it to train or improve a model, to benchmark, or to produce statistics about anyone other than the controller, whether identified or in aggregate.
4
Confidentiality of personnel
The processor ensures that every person it authorises to process personal data under this agreement is bound by an appropriate duty of confidentiality that survives the end of their engagement.
Access is granted on the principle of least privilege and only where it is needed to provide or support the service. Administrative access to production is limited to named individuals, is authenticated with multiple factors, and is recorded.
The processor's personnel cannot read a controller's content, because no content is stored. Where support requires access to a workspace's records, the controller is asked first and the access is written to the controller's own audit log.
5
Security of processing
The processor implements the technical and organisational measures set out in Annex II, taking account of the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks to the rights and freedoms of natural persons.
Annex II lists measures that are implemented rather than intended. Where a measure is planned and not yet in place, it says so, because an annex that mixed the two would be useless to a controller assessing risk.
The processor may change a measure, provided the change does not reduce the overall level of security. Where a change materially affects the description in Annex II, the processor updates it and the updated version is published.
6
Sub-processors
The controller gives general written authorisation for the processor to engage the sub-processors listed in Annex III. The processor imposes on each sub-processor data protection obligations no less protective than those in this agreement, and remains fully liable to the controller for a sub-processor's performance.
The processor tells the controller at least thirty days before adding or replacing a sub-processor, by notifying the workspace and updating the published register. The controller may object on reasonable data protection grounds within that period. If the objection cannot be resolved, the controller may terminate the affected part of the service and receive a refund of the unused prepaid portion.
7
Assisting with data subject rights
The processor assists the controller, by appropriate technical and organisational measures and insofar as possible, in fulfilling its obligation to respond to requests to exercise data subject rights. If a data subject contacts the processor directly, the processor does not respond on the merits and refers them to the controller, telling the controller promptly.
The processor can, on the controller's instruction, delete findings relating to a container or an item, and can delete the container owner fields the service holds. It cannot erase personal data from the controller's own Microsoft 365 or Google Workspace tenant, because it has no write access to it.
8
Assisting with Articles 32 to 36
Taking into account the nature of the processing and the information available to it, the processor assists the controller in ensuring compliance with the obligations in Articles 32 to 36 of the General Data Protection Regulation.
Security: Annex II, and the trust page, which states what is stored and what is not in the terms a controller can verify.
Data protection impact assessment: a template is published, pre-filled with the product facts a controller needs and leaving the assessment itself to the controller.
Workforce information: a notice a controller can send to its own people, and an explainer written for a works council, are published alongside the template.
Prior consultation: the processor provides, on request, the information about the processing that a controller needs in order to consult its supervisory authority.
9
Personal data breach
The processor tells the controller without undue delay, and in any event within twenty four hours of becoming aware, of a personal data breach affecting personal data processed under this agreement.
The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned insofar as known, the likely consequences, the measures taken or proposed, and a point of contact. Where the information cannot all be given at once, it is given in phases without undue further delay.
The processor does not notify a supervisory authority or a data subject on the controller's behalf unless the controller instructs it in writing to do so.
10
Deletion and return
At the controller's choice, the processor deletes or returns personal data processed under this agreement at the end of the provision of services, and deletes existing copies, unless Union or member state law requires storage.
Return means export: the inventory, the findings and the audit records in the documented export formats, available to the controller for as long as the workspace is open.
Within a live workspace, retention is the controller's setting: resolved findings, scan records and audit records each have a period the controller chooses, and the purge runs against those periods automatically.
11
Audits and information
The processor makes available to the controller the information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the controller or an auditor it mandates.
In the first instance the processor answers with the published material: this agreement and its annexes, the trust page, the limits page and the sub-processor register, which together describe what is processed, what is stored, where, and by whom. Where that is not sufficient, the controller may request further information, and an on-site inspection may be arranged on reasonable notice, at most once a year unless a breach or a supervisory authority's instruction gives cause.
The processor does not yet hold an independent security certification or a published penetration test summary. It says so here rather than referring a controller to an assurance report that does not exist, and it will publish one when it does.
12
International transfers
The processor processes personal data under this agreement in the European Union. A workspace is pinned to one region when it is created and cannot be moved: EU Frankfurt, or EU Stockholm by arrangement. The database, the web application and the scanning worker all run in that region, and contextual classification is called on an EU endpoint.
The processor does not transfer personal data outside the European Economic Area in the course of providing the service. Where a sub-processor is incorporated outside the EEA, the transfer position for that sub-processor is governed by the terms recorded in Annex III, which are open and are marked as open.
Where the Standard Contractual Clauses apply to a sub-processor, the processor relies on the module appropriate to the relationship and on the supplementary measures the supplier operates, and records both in Annex III once they are confirmed. This agreement is not offered as final until that record exists.
Annex I
The parties and the description of processing
Role
Party
Details
Controller
The customer organisation that creates the workspace
As identified in the order form or on sign-up. The controller's contact for this agreement is the workspace owner.
Processor
White Label Consultancy AS
Registration number [to be completed before signature], registered at [to be completed before signature]. Data protection contact [to be completed before signature].
The parties.
Item
Description
Subject matter
Discovery and mapping of personal data in the controller's Microsoft 365 and Google Workspace tenants, and the exposure findings derived from it.
Duration
For as long as the controller keeps a workspace open, and then as section 10 provides.
Nature of the processing
Reading content in memory, classifying it, discarding it, and storing a record about it. Collection, structuring, storage and erasure of that record; no alteration of the source.
Purpose
Enabling the controller to know where personal data lives in its own systems, how much of it there is, how it is shared, and where that presents a risk.
Categories of data subjects
Any person whose personal data appears in the content of the controller's tenants, which typically includes the controller's employees, customers, suppliers and correspondents. Separately, the holders of the accounts that own sites, drives and mailboxes.
Categories of personal data in content
Whatever the controller's own content contains. The service classifies it into the categories in its published taxonomy, which includes identifiers, contact details, financial identifiers and the special categories of Article 9.
Personal data that is stored
Filenames and paths; the identifiers, counts, confidences and position references that make up a finding; sharing state and labels; the display name, address and account status of a container owner, which is returned only where the controller has turned the owner view on.
Personal data that is not stored
Document text, message bodies, attachments, matched values and snippets. None of these is written anywhere that outlives the job that read it.
Special category data
Content may contain it and the service classifies and counts it. It is never stored as a value: what persists is the category, the count and the position.
Frequency
Continuous while a scan runs, and on the schedule the controller sets thereafter.
Competent supervisory authority
[to be completed before signature], determined by the processor's place of establishment once it is recorded.
The description of processing, written to be copied into a record of processing activities.
Annex II
Technical and organisational measures
The measures below are implemented. Where one is planned and not yet in place, the row says so, because an annex that mixed the two would be useless to a controller assessing risk.
Measure
What it is
State
Content is never persisted
Content is read into memory, classified and discarded. A test suite plants known values, runs them through the pipeline, then searches the database dump, the queue tables, the realtime payloads and the worker's temporary filesystem for every planted value.
Implemented, and enforced in continuous integration
No personal data in logs
Log records carry identifiers, counts, enumerations and durations. Values pass through an allowlisting serialiser, a lint rule bans direct console calls, and a test feeds sensitive values through every field position to assert they are replaced.
Implemented
Tenant isolation
Every table carries the workspace identifier and row level security through shared membership helpers. Cross-tenant denial is tested for an anonymous caller, a member of another workspace and an adviser without access.
Implemented
Encryption in transit and at rest
Transport security on every connection. Storage encryption at the database. Tenant credentials encrypted under a per-workspace key.
Implemented
Per-workspace key, wrapped under a master key
Each workspace's key is wrapped under a master key held outside the database. The worker refuses to start without it. Deleting a workspace destroys its key.
Implemented
Least privilege and strong authentication
Four roles with ranked powers. Multi-factor authentication available to every account and required for administrative access to production.
Implemented
Outbound allowlist
The worker may reach only the hosts it needs, named explicitly, and fails loudly at connect for anything else.
Implemented
Append-only audit
Audit records, finding events and connection scope events cannot be updated or deleted by anyone, including the processor. Audit content is identifiers, counts, enumerations and durations by contract, never a name, an address, a filename or an excerpt.
Implemented
Controlled state transitions
A status changes only through a function that validates the change against a fixed table of legal transitions, so an impossible state cannot be written by any caller.
Implemented
Fail closed
An item the engine could not classify with confidence is marked for review, never clean. An item it could not read is recorded as not read, with the reason.
Implemented
Independent security testing
An external penetration test with a published summary.
Planned before public launch, not yet done
Certification
An independent information security certification.
Not held
Measures, and their state.
Annex III
Sub-processors
The sub-processors engaged for every workspace. Microsoft and Google are not listed, for the reason section 1 gives: they are the controller's own processors.
Sub-processor
Contracting entity
Purpose
Processing location
Content reaches it
Contract reference
Supabase
Supabase, Inc., United States
Database, authentication and job queue for the workspace.
EU, Frankfurt (eu-central-1, Frankfurt)
No
Open, see the register
Vercel
Vercel Inc., United States
Hosts the web application.
EU, Frankfurt (fra1, Frankfurt)
No
Open, see the register
Fly.io
Fly.io, Inc., United States
Runs the scanning worker that reads content in memory.
EU, Frankfurt (fra, Frankfurt)
Yes, in memory only
Open, see the register
Mistral AI
Mistral AI SAS, France
Contextual classification of short passages. No prompt or completion is stored.
EU (EU endpoint, api.mistral.ai)
Yes, in memory only
Open, see the register
The sub-processors engaged for every workspace. The contract reference and transfer basis for each are open and are marked as such on the register page.