Draft for solicitor review — published for transparency. Not legal advice. Enterprise customers should execute the MSA and DPA. Last updated: 2026-07-23.

Data Processing Agreement — Public Overview

When ACQI processes **personal data on your behalf** in connection with the Platform (for example, IT-estate discovery data containing employee identifiers), ACQI acts as a **processor** and you (or your client) act as **controller**, under Article 28 UK GDPR / EU GDPR.

Placeholders pending
  • {{LEGAL_EMAIL}} — to be confirmed before final publication
  • {{PRIVACY_EMAIL}} — to be confirmed before final publication

Page is published for transparency; founder will fill these before the final version goes out under counsel review.

# Data Processing Agreement (DPA)

For enterprise customers of ACQI.AI LTD

When ACQI processes personal data on your behalf in connection with the Platform (for example, IT-estate discovery data containing employee identifiers), ACQI acts as a processor and you (or your client) act as controller, under Article 28 UK GDPR / EU GDPR.

A full executable DPA is provided with the Master Services Agreement (not as a pure click-through for production workloads containing real estate data).

Request the current DPA PDF: {{LEGAL_EMAIL}} Privacy questions: {{PRIVACY_EMAIL}}

---

1.When a DPA is required

Scenario DPA needed?
Evaluation with synthetic data only Usually no processor relationship for estate PII
Production discovery / migration / governance with real employee or end-user personal data processed by ACQI systems Yes — execute DPA before processing
Desktop-only processing where personal data never leaves your environment and ACQI never receives it Processor terms may not be triggered for that data; confirm architecture with your counsel and ACQI

---

2.What the ACQI DPA covers (summary)

Aligned to incorporation-pack doc 19 (subject to solicitor finalisation):

  1. Subject matter: M&A / IT discovery, cataloguing, analysis, reporting, migration planning/execution support, governance.
  2. Duration: Term of MSA/SOW + deletion/return period.
  3. Nature of processing: Collection via authorised connectors/modules, storage, structuring, analysis, display, export, deletion.
  4. Categories of data (typical): directory identities, mailbox metadata (not full mail bodies unless in-scope), device inventory, license/app assignments, network identifiers, security posture metadata, audit logs.
  5. Data subjects: employees, contractors, admins, and other individuals reflected in the scanned estate.
  6. Instructions: process only on documented instructions.
  7. Confidentiality: personnel bound by confidentiality.
  8. Security (TOMs): technical and organisational measures (encryption, access control, logging, etc.) — scaled to what is actually implemented; not over-claimed certifications.
  9. Subprocessors: list with notice and objection rights — see Subprocessors.
  10. International transfers: UK IDTA / UK Addendum / EU SCCs / adequacy as applicable.
  11. Assistance: data subject rights, DPIA support, breach notice.
  12. Breach notice: without undue delay (target within 24 hours of ACQI becoming aware, to help controllers meet 72-hour regulatory clocks).
  13. Deletion/return: on termination or request (typical 30 days), subject to legal retention and backup windows.
  14. Audits: reasonable audit rights as set out in the DPA.
  15. No secondary use: no sale of personal data; no training of models on customer personal data for other customers (see AI disclosure).

---

3.Controller responsibilities (you)

  • Establish a lawful basis for processing data subjects in target/acquired environments
  • Provide required privacy notices to data subjects where applicable
  • Ensure authorisation to scan systems
  • Configure least-privilege access
  • Issue clear processing instructions (SOW / configuration)
  • Decide retention beyond platform defaults

---

4.Desktop-first and data minimisation

ACQI’s architecture aims to:

  • Keep credentials on the endpoint
  • Minimise unnecessary transfer of personal data to ACQI-hosted infrastructure
  • Support customer-controlled storage of discovery outputs where configured

Where optional cloud or AI features transfer data off-endpoint, those flows are described in the Privacy Policy, Subprocessors list, and AI disclosure.

---

5.Standard Contractual Clauses / IDTA

EU/UK transfer tools are attached or incorporated in the full DPA package when transfers require them. Public summary pages do not replace signed SCCs/IDTA modules.

---

6.How to execute

  1. Complete commercial discussion / order form
  2. Execute MSA + DPA (and SOW)
  3. Confirm subprocessors and transfer mechanism
  4. Complete security questionnaire if required
  5. Only then process live personal data through any ACQI-hosted path

Design-partner programmes should use synthetic data until DPA execution — consistent with incorporation-pack LOI guidance.

---

---

Public overview only. Full legal text: incorporation-pack 19-dpa-gdpr-art28.md (DRAFT) — solicitor must finalise before customer signature.

Entity block
ACQI.AI LTD
Private limited company registered in England and Wales
Company number: [to be confirmed]
Registered office: [to be confirmed]
Contact: hello@acqi.ai

The ACQI platform intellectual property is owned by ACQI HOLDINGS LTD and licensed to ACQI.AI LTD for customer delivery.