Legal
Data Processing Agreement
When you give us access to a system or documents for an audit, you remain the controller of that data and we act solely on your instructions.
Last updated: 21 August 2026
When this applies
These terms apply from the moment you give us, as part of an assessment, personal data of which you are the controller: database access, configuration exports, documents, screenshots, test accounts.
You remain the controller. Custom Service Arleta Marczyńska is the processor and acts solely on your documented instructions, which are the confirmed scope of the assessment.
Scope of processing
| Item | Arrangement |
|---|---|
| Purpose | Performing a security assessment within the confirmed scope. |
| Duration | The time needed to carry out the assessment and the evidence retention period agreed in the contract. |
| Type of data | Only the data necessary to demonstrate the findings. By default, masked or test data. |
| Categories of data subjects | Determined by the client’s system, most often its customers and employees. |
| Nature of processing | Reading, analysis, recording evidence in masked form. We do not modify data in the client’s system. |
Our commitments
- We process data solely on your instructions, that is, within the limits of the confirmed scope.
- Persons with access are bound by confidentiality.
- We use encryption in transit and at rest, read-only access wherever reading is enough, and short-lived credentials.
- We help you meet your obligations towards data subjects and towards the supervisory authority.
- We make available the information needed to demonstrate compliance and allow audits on agreed terms.
Data minimization
This is the point that protects you most in practice, so we take it seriously.
- By default we ask for test accounts and masked data, not production data.
- Evidence in the report contains as much data as needed to demonstrate the problem, and not one record more.
- Identifiers and sensitive content in evidence are masked before they are stored.
- We do not copy databases or document collections if the schema and policies are enough to establish a finding.
- We do not send your data to external language models.
Subprocessors
We use the subprocessors listed on the subprocessors page. We give 30 days’ notice of any change, and you may then terminate the agreement without consequences.
Each subprocessor is bound by the same obligations that we have towards you.
Personal data breach
If a breach affecting your data occurs, we notify you without undue delay, and no later than 24 hours after becoming aware of it, and tell you: what it concerns, what scope of data, what the likely consequences are and what we are doing to limit the damage.
Return and deletion
After the assessment ends we delete the data or return it to you, depending on your decision. We keep only what is necessary to demonstrate that the service was properly performed, in masked form, for the period agreed in the contract.
At your request we confirm deletion in writing.
Signing
We send the agreement ready for signature together with the quote. If you have your own template, send it to arlets@yesfor.ai and we will review it and respond to the differences.