Data Processing Agreement
This Data Processing Agreement (“DPA”) supplements the Terms of Service and sets out the terms required by Art. 28(3) GDPR under which we process personal data contained in tenant-submitted calculation data on behalf of the tenant. It forms part of the subscription for every tenant.
1. Parties and roles#
Processor: ArgonGate Ltd, registered with Companies House (England and Wales) under company no. 16771850 — full contact details in the Impressum (the “Provider”).
Controller: the tenant — the declarant organisation that holds the FastCBAM subscription and submits data to the service (the “Tenant”).
- This DPA covers tenant-submitted calculation data (installation and activity data, CN codes, emission inputs and the traces generated from them) to the extent it contains personal data, as described in Privacy Policy §1. For that data the Tenant is controller and the Provider is processor.
- For account, billing, support and website data the Provider acts as an independent controller; that processing is governed by the Privacy Policy, not by this DPA.
- Boundary. Where the same individual appears in both
scopes, the capacity is determined by the record: identity and
activity data appearing within the Tenant's workspace records
(submissions, traces, audit events,
declarant_subidentifiers) is processed under this DPA as processor; the Provider's own account, billing and support relationship with that individual remains independent-controller scope.
2. Subject-matter, duration, nature and purpose#
- Subject-matter: operation of the FastCBAM service — a deterministic CBAM emissions calculation engine, REST API and MCP tool surface — on data submitted by the Tenant.
- Nature and purpose: CBAM emissions calculation and trace generation; validation, storage, replay and export of declaration-related records on the Tenant's behalf.
- Duration: the term of the Tenant's subscription, plus the statutory CBAM retention window that applies to declaration-related records after termination (see §8).
3. Data subjects and categories of personal data#
Categories of data subjects:
- The Tenant's authenticated users and service-account operators.
- Verifier personnel acting on declarations.
- Individuals whose identifiers appear incidentally in tenant-submitted installation or activity data.
Categories of personal data:
- Authenticated user identity — subject id and, where supplied, name and email, held in the EU identity provider.
- Verifier personnel identity — name, accreditation body, role.
- Audit-log subject identifiers —
declarant_subvalues in audit events. - Technical request metadata — route, status, duration, content hash and hash-chain fields of audit events; access logs.
The commercial/industrial calculation data itself (production, energy and emissions inputs, CN codes, traces) is commercially sensitive but generally not personal data. Where tenant-submitted calculation data nonetheless contains personal data — for example sole-trader installation details or contact persons embedded in activity data — that data is processed under this DPA on the Tenant's documented instructions. No special categories of personal data (Art. 9 GDPR) are processed.
4. Controller instructions#
- The Provider processes personal data only on the Tenant's documented instructions, including with regard to transfers to third countries, unless required to do so by Union or Member State law; in that case the Provider informs the Tenant of the legal requirement before processing, unless that law prohibits it (Art. 28(3)(a) GDPR).
- The service's documented interfaces — the REST API, the MCP tool surface and the associated documentation — together with the data the Tenant submits through them, constitute the Tenant's documented instructions. Additional instructions must be agreed in writing.
- Persons authorised to process the personal data are bound by contractual or statutory obligations of confidentiality (Art. 28(3)(b) GDPR).
- The Provider informs the Tenant immediately if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.
5. Sub-processors#
The Tenant grants a general written authorisation (Art. 28(2) GDPR) for the following sub-processors, engaged as at the date of this DPA:
- Amazon Web Services — compute, database, object storage; region eu-central-1 (Frankfurt).
- Cloudflare — edge, DNS, TLS and DDoS protection for the MCP endpoint, with the EU Data Localization Suite applied.
- ZITADEL (ZITADEL Cloud EU) — OIDC identity provider for user and service-account authentication.
- Stripe Payments Europe, Ltd. — payment processing for online checkout (active once online checkout launches; card data is processed by Stripe, not by us).
The maintained sub-processor list is published at Privacy Policy §4. The Provider gives notice of any intended addition or replacement of a sub-processor at least 30 days before the change takes effect, by email to the Tenant's registered account contact and by updating the published list. The Tenant may object in writing on reasonable data-protection grounds within that 30-day window; if the parties cannot agree a solution before the change takes effect, the Tenant may terminate the affected subscription with effect no later than the date the change takes effect, and prepaid fees for the period after termination are refunded pro rata. The Provider imposes on each sub-processor the same data protection obligations as set out in this DPA (Art. 28(4) GDPR) and remains fully liable to the Tenant for the sub-processor's performance.
6. Technical and organisational measures#
Taking into account the state of the art and the risks of the processing, the Provider implements the following measures (Art. 32 GDPR), verified against the deployed service:
- Tenant isolation — ZITADEL org-scoped JWTs;
declarant_subscoping in the data layer; S3 object keys prefixed per authenticated subject. - Access control — API Gateway JWT authorizer
rejects missing, malformed,
alg=none, wrong-audience and tampered tokens; MCP requests without a bearer token are rejected. - Secret management — no secrets in the code repository; database credentials held in AWS Secrets Manager; the engine host carries no third-party or AI credentials.
- Evidence integrity — the
audit_eventsstore is insert-only (updates and deletes raise errors) with a per-row hash chain; chain and tamper status are monitored. - Reproducibility — deterministic calculation engine with byte-identical trace replay.
- Web hardening — strict Content-Security-Policy, HSTS preload and X-Frame-Options DENY on the serving path; CORS is not opened.
- EU-only processing — calculation data is processed and stored exclusively in eu-central-1 (Frankfurt).
- Encryption — TLS in transit; encryption at rest on managed AWS storage.
The Provider may update these measures as the service and the threat landscape evolve, provided the overall level of security does not fall below the level described here.
7. Assistance and breach notification#
- Data-subject requests — taking into account the nature of the processing, the Provider assists the Tenant with appropriate technical and organisational measures in fulfilling the Tenant's obligation to respond to data-subject requests under Arts. 12–23 GDPR. Requests received directly by the Provider that concern data processed under this DPA are routed to the responsible Tenant without undue delay, and at the latest within five business days of receipt.
- Security, breach and DPIA assistance — the Provider assists the Tenant in ensuring compliance with Arts. 32–36 GDPR, taking into account the nature of the processing and the information available to the Provider.
- Personal data breach — the Provider notifies the Tenant without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data processed under this DPA, and provides the information reasonably required for the Tenant's own notifications under Arts. 33/34 GDPR as it becomes available; the initial notice is not delayed pending complete information and may be supplemented in phases (Art. 33(4) GDPR by analogy).
8. Audit rights, liability, deletion and return#
- Information and audit — the Provider makes available to the Tenant all information necessary to demonstrate compliance with Art. 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Tenant or an auditor mandated by the Tenant (Art. 28(3)(h) GDPR), subject to reasonable prior notice, at most once per contract year absent a supervisory-authority requirement or a personal data breach, and under confidentiality obligations protecting other tenants.
- Deletion and return — on termination of the subscription the Provider, at the Tenant's choice, deletes or returns all personal data processed under this DPA and deletes existing copies (Art. 28(3)(g) GDPR) — except that declaration-related records and traces remain stored for the CBAM statutory retention period of 4 years (Reg. (EU) 2023/956 Arts. 7(6) and 9(3)), Union law requiring their storage within the meaning of the Art. 28(3)(g) exception. After the retention window, erasure is executed through the GOVERNANCE-mode audited deletion path of the object store, leaving an audit record of the erasure itself.
- Liability — liability between the parties follows Art. 82 GDPR and the liability provisions of the Terms of Service. Nothing in this DPA or the Terms limits or excludes the rights of data subjects under Art. 82 GDPR, or either party's liability towards data subjects under Art. 82(1)–(4) GDPR. As between the parties, compensation paid to data subjects is apportioned according to each party's part of the responsibility (Art. 82(5) GDPR), and the Terms' liability provisions apply to such inter-party recourse to the maximum extent permitted by law.
9. International transfers#
Calculation data is processed and stored exclusively in the EU (eu-central-1, Frankfurt). The MCP edge runs under Cloudflare's EU Data Localization Suite and never parses calculation payloads; it forwards them to the EU backend.
The Provider is established in the United Kingdom. UK-side access to personal data processed under this DPA is treated as a transfer under Chapter V GDPR and takes place on the basis of the European Commission's adequacy decision for the United Kingdom, renewed on 19 December 2025 with effect until 27 December 2031 (unless earlier amended, suspended or repealed). Should that adequacy decision be suspended, invalidated or expire without renewal, the parties agree that the Standard Contractual Clauses of Commission Implementing Decision (EU) 2021/914 (Module Two: controller to processor), with the Tenant as data exporter and the Provider as data importer and completed with the processing details set out in this DPA and the published sub-processor list, are deemed incorporated into this DPA with effect from the date the adequacy basis ceases. No personal data is transferred to any other third country without a valid transfer mechanism under Chapter V GDPR and the Tenant's documented instructions.
10. Order of precedence and governing law#
- In case of conflict concerning the processing of personal data, this DPA prevails over the Terms of Service; mandatory provisions of the GDPR and other applicable data protection law prevail over both.
- This DPA is governed by the laws of England and Wales, in line with Terms §11. This choice of law does not limit the application of the GDPR or of mandatory EU or Member State data protection law to the processing, nor the competence of EU supervisory authorities or the rights of data subjects to bring claims in their own jurisdiction under Arts. 77–79 GDPR.