Data processing addendum (draft — counsel to review before the first EU/UK customer)

This addendum forms part of the terms of service for customers subject to the GDPR or UK GDPR ("Customer").

1. Roles. For the customer data listed in section 3, Customer is controller and Openwake is processor. For the public registry (facts about vendors extracted from their public documents) Openwake is an independent controller.

2. Instructions. Openwake processes customer data only to provide the Service — alerts, digests, reports, counterparty checks and receipts — and on Customer's documented instructions given through the Service's settings and API. Openwake does not use customer data to train any model and does not sell it.

3. Data and subjects. Business contact data of Customer's staff (names, work email addresses); organisational metadata (the vendors Customer watches; the data classes Customer's systems declare in counterparty checks; the decisions returned; timestamps); alert channel configuration. No content of Customer's communications or files: the Service has no field for it. Subjects: Customer's employees and contractors.

4. Confidentiality and personnel. Access to customer data is limited to personnel who need it to operate the Service, bound by confidentiality obligations.

5. Security. Encryption in transit; encryption at rest by the database provider; alert channels and contact addresses additionally sealed at the application layer with AES-256-GCM; API keys stored as hashes; every record appended to an Ed25519-signed, hash-chained ledger with a publicly anchored head; nightly backups with a monthly restore test; deep health monitoring. Full description at /docs/security.

6. Subprocessors. Customer authorises the subprocessors listed at /legal/subprocessors. Openwake gives 30 days' notice by email of any addition; Customer may object within that period, and if the objection cannot be resolved may terminate the affected plan without penalty and receive a pro-rata refund of prepaid fees.

7. Transfers. Data is hosted in the EU. Where a subprocessor processes data outside the EU/UK (see the list), transfers rely on the EU Standard Contractual Clauses (module 3) and the UK Addendum, incorporated by reference.

8. Assistance. Openwake assists Customer with data-subject requests, security assessments and data-protection impact assessments to the extent the request concerns Openwake's processing, using the evidence packs, ledger proofs and this documentation.

9. Personal data breach. Openwake notifies Customer without undue delay and within 72 hours of confirming a breach affecting customer data, with the information available at the time and updates as known.

10. Deletion and return. On termination, or on request, Openwake deletes customer data within 30 days. Ledger entries retain hashes and timestamps only, no personal data. Customer may export watchlists, checks and reports through the API at any time.

11. Audit. Openwake provides this documentation, its security description, evidence packs and ledger proofs on request, and any third-party audit report once available. On-site audits are limited to once per year, on 30 days' notice, at Customer's cost, where the documentation is insufficient to demonstrate compliance.

12. Liability. As set out in the terms of service.

Contact. privacy@openwake.ai