Data Processing Agreement — Public Overview
When ACQI processes **personal data on your behalf** in connection with the Platform (for example, IT-estate discovery data containing employee identifiers), ACQI acts as a **processor** and you (or your client) act as **controller**, under Article 28 UK GDPR / EU GDPR.
{{LEGAL_EMAIL}}— to be confirmed before final publication{{PRIVACY_EMAIL}}— to be confirmed before final publication
Page is published for transparency; founder will fill these before the final version goes out under counsel review.
# Data Processing Agreement (DPA)
For enterprise customers of ACQI.AI LTD
When ACQI processes personal data on your behalf in connection with the Platform (for example, IT-estate discovery data containing employee identifiers), ACQI acts as a processor and you (or your client) act as controller, under Article 28 UK GDPR / EU GDPR.
A full executable DPA is provided with the Master Services Agreement (not as a pure click-through for production workloads containing real estate data).
Request the current DPA PDF: {{LEGAL_EMAIL}} Privacy questions: {{PRIVACY_EMAIL}}
---
1.When a DPA is required
| Scenario | DPA needed? |
|---|---|
| Evaluation with synthetic data only | Usually no processor relationship for estate PII |
| Production discovery / migration / governance with real employee or end-user personal data processed by ACQI systems | Yes — execute DPA before processing |
| Desktop-only processing where personal data never leaves your environment and ACQI never receives it | Processor terms may not be triggered for that data; confirm architecture with your counsel and ACQI |
---
2.What the ACQI DPA covers (summary)
Aligned to incorporation-pack doc 19 (subject to solicitor finalisation):
- Subject matter: M&A / IT discovery, cataloguing, analysis, reporting, migration planning/execution support, governance.
- Duration: Term of MSA/SOW + deletion/return period.
- Nature of processing: Collection via authorised connectors/modules, storage, structuring, analysis, display, export, deletion.
- Categories of data (typical): directory identities, mailbox metadata (not full mail bodies unless in-scope), device inventory, license/app assignments, network identifiers, security posture metadata, audit logs.
- Data subjects: employees, contractors, admins, and other individuals reflected in the scanned estate.
- Instructions: process only on documented instructions.
- Confidentiality: personnel bound by confidentiality.
- Security (TOMs): technical and organisational measures (encryption, access control, logging, etc.) — scaled to what is actually implemented; not over-claimed certifications.
- Subprocessors: list with notice and objection rights — see Subprocessors.
- International transfers: UK IDTA / UK Addendum / EU SCCs / adequacy as applicable.
- Assistance: data subject rights, DPIA support, breach notice.
- Breach notice: without undue delay (target within 24 hours of ACQI becoming aware, to help controllers meet 72-hour regulatory clocks).
- Deletion/return: on termination or request (typical 30 days), subject to legal retention and backup windows.
- Audits: reasonable audit rights as set out in the DPA.
- No secondary use: no sale of personal data; no training of models on customer personal data for other customers (see AI disclosure).
---
3.Controller responsibilities (you)
- Establish a lawful basis for processing data subjects in target/acquired environments
- Provide required privacy notices to data subjects where applicable
- Ensure authorisation to scan systems
- Configure least-privilege access
- Issue clear processing instructions (SOW / configuration)
- Decide retention beyond platform defaults
---
4.Desktop-first and data minimisation
ACQI’s architecture aims to:
- Keep credentials on the endpoint
- Minimise unnecessary transfer of personal data to ACQI-hosted infrastructure
- Support customer-controlled storage of discovery outputs where configured
Where optional cloud or AI features transfer data off-endpoint, those flows are described in the Privacy Policy, Subprocessors list, and AI disclosure.
---
5.Standard Contractual Clauses / IDTA
EU/UK transfer tools are attached or incorporated in the full DPA package when transfers require them. Public summary pages do not replace signed SCCs/IDTA modules.
---
6.How to execute
- Complete commercial discussion / order form
- Execute MSA + DPA (and SOW)
- Confirm subprocessors and transfer mechanism
- Complete security questionnaire if required
- Only then process live personal data through any ACQI-hosted path
Design-partner programmes should use synthetic data until DPA execution — consistent with incorporation-pack LOI guidance.
---
7.Related pages
---
Public overview only. Full legal text: incorporation-pack 19-dpa-gdpr-art28.md (DRAFT) — solicitor must finalise before customer signature.