Ir para o conteúdo principal

Legal

Data Processing Agreement

Last updated: August 20, 2026

This agreement applies when we process personal data on your behalf — for example, if your organization provisions users over SCIM, queries SecureStamp Signal on behalf of your brand, or uses MCP Guard with delegated sessions. It forms part of the Terms of Service and needs no separate signature: accepting the Terms accepts this agreement.

1. Parties and subject matter

This agreement is entered into between Arche Software Studio Inc., a company incorporated in Delaware, United States, trading as SecureStamp (the “Processor”), and the legal entity subscribing to the services (the “Controller”).

It governs the processing of personal data carried out by the Processor on the Controller’s behalf, and is to be read in accordance with Article 28 GDPR and equivalent applicable rules.

2. Role of each party

The Controller determines the purposes and means of processing. The Processor processes personal data only on the Controller’s documented instructions, including as to international transfers, unless legally required otherwise; in that case the Processor will inform the Controller before processing, unless that notice is prohibited on important grounds of public interest.

The Processor will inform the Controller without delay if, in its opinion, an instruction infringes data protection law.

3. Scope of processing

Details are set out in Annex I. In summary:

  • Subject matter and nature: provision of the SecureStamp digital-trust services subscribed to by the Controller
  • Duration: the term of the service contract, plus the deletion periods in clause 9
  • Purpose: solely to provide the service. The Processor does not use Controller data for its own purposes, does not train models on it, and does not sell or otherwise transfer it

4. Confidentiality

The Processor ensures that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Internal access is role-restricted on a least-privilege basis and recorded in an audit log.

5. Security measures

The Processor implements the technical and organizational measures described in Annex II, appropriate to the risk under Article 32 GDPR, and reviews them periodically.

6. Sub-processors

The Controller gives general authorization for the sub-processors published at securestamp.online/subprocessors.

The Processor will give at least 30 days notice of the addition or replacement of a sub-processor. The Controller may object on reasonable data protection grounds within that period; if the objection cannot be resolved, the Controller may terminate the affected part of the service without penalty.

The Processor imposes on each sub-processor data protection obligations no less protective than those in this agreement, and remains liable to the Controller for their performance.

7. Assistance to the Controller

Taking into account the nature of the processing, the Processor will assist the Controller:

  • In responding to data subject rights requests. If a data subject contacts the Processor directly, the Processor will not respond on the merits and will forward the request to the Controller without undue delay
  • In meeting the security, breach-notification and impact-assessment obligations of Articles 32 to 36 GDPR

8. Personal data breaches

The Processor will notify the Controller without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting data processed on the Controller’s behalf, with the available information on its nature, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken.

9. Deletion and return

On termination of the services, and at the Controller’s election, the Processor will delete or return the personal data and delete existing copies, unless applicable law requires retention. Deletion completes within 90 days of termination, or sooner on the Controller’s request.

During the term, the Controller may export its data at any time from the admin dashboard.

10. Audit

The Processor will make available to the Controller the information necessary to demonstrate compliance with this agreement and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates.

Audits are to be requested on reasonable notice, limited to once per year unless required by a supervisory authority or following a substantiated security breach, conducted during business hours, and carried out without compromising the confidentiality of other customers.

11. International transfers

Production infrastructure is located in the United States (AWS, us-east-1 region). Where processing involves a transfer of data from the European Economic Area, the United Kingdom or Switzerland, that transfer relies on the Standard Contractual Clauses adopted by the European Commission in 2021, which are incorporated into this agreement by reference, with the Controller as data exporter and the Processor as data importer.

Our infrastructure and payment sub-processors likewise incorporate those clauses into their own data processing agreements, and Stripe is additionally certified under the EU-U.S. Data Privacy Framework.

12. Term and precedence

This agreement takes effect on acceptance of the Terms of Service and continues for as long as the processing lasts. In case of conflict with the Terms of Service on data protection matters, this agreement prevails.

Annex I — Details of processing

Categories of data subjects

  • Employees and collaborators of the Controller holding a service account
  • Individuals appearing as a counterparty in a Signal or Action Trust lookup made by the Controller
  • End users of the Controller, where it integrates SecureStamp into its own flows

Categories of personal data

  • Identity and account: display name, email address, user identifier, active or deactivated status, role and permissions
  • Directory (SCIM): the attributes the Controller chooses to synchronize from its identity provider
  • Usage and audit: timestamps, IP address, requested action type, risk level, verdict issued, and signed receipts
  • Origin metadata: domains, authorized senders, SPF/DKIM/DMARC results, declared channels

Data expressly excluded

The service is designed not to receive message bodies. Analysis runs on the user’s device and only an abstract description of the requested action is transmitted. In MCP Guard, a one-way cryptographic fingerprint of the instruction is transmitted, never its content.

The service is not intended for special categories of data under Article 9 GDPR, nor for health data, nor for data of children under 16. The Controller undertakes not to introduce such data into the service.

Annex II — Technical and organizational measures

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • End-to-end encryption with post-quantum cryptography (ML-KEM) in Confidential Mail; private keys never leave the user’s device
  • Key custody in AWS KMS, with rotation and usage logging
  • Role-based access control on a least-privilege basis, with multi-factor authentication available on all accounts and enforceable by organization policy
  • Tamper-evident audit logging of critical operations
  • Logical isolation of each organization’s data
  • Distributed rate limiting and anti-abuse controls
  • Periodic penetration testing with documented remediation of findings
  • Privacy invariants enforced by automated tests on every deployment, including the one preventing a message body from leaving the device
  • Encrypted backups and a tested restore procedure

Contact

Processor: Arche Software Studio Inc. (Delaware, USA)

Privacy: privacy@securestamp.online

Security: security@securestamp.online

Data Processing Agreement — SecureStamp | SecureStamp