Data Processing Agreement
This agreement governs personal data about the people who are investigated using NACRE Intel. You are the controller of that data. We process it on your instructions. It forms part of the Terms of Service and is accepted when you open an account.
1. Parties
The processor is Nacre, SAS, registered under RCS Paris 941 938 839, SIRET 941 938 839 00011, whose registered office is at 50 avenue des Champs-Élysées, 75008 Paris, France (“we”, “us”).
The controller is the organisation holding the account under which an investigation is run (“you”). This agreement takes effect when you accept it on opening that account, and applies for as long as we process personal data on your behalf.
Data protection contact: privacy@nacre.edda.cloud.
2. Roles
You determine who is investigated and for what purpose, so you are the controller within the meaning of Article 4(7) GDPR. We provide the means of carrying out that research, so we are the processor under Article 4(8). We do not decide whose data is processed or why, and we cannot: those facts sit with you.
For personal data about your own users — names, email addresses, sign-in records — we are the controller, and the Privacy Policy applies instead.
3. Your obligations as controller
You warrant that:
- you have a lawful basis under Article 6 for each investigation, and can evidence it;
- where an investigation involves data relating to criminal convictions or offences — sanctions listings, litigation, regulatory action, adverse media — you are authorised to process it under Article 10, by Union or Member State law applicable to you;
- you will meet your own transparency obligations under Articles 13 and 14, or can properly rely on an exemption from them;
- your instructions to us do not require us to breach the GDPR or any other data protection law.
Selecting a subject and starting an investigation is your documented instruction to us, and the scope of that instruction is the research described in clause 5. We do not collect your purpose and hold no record of it: the basis on which you gave the instruction is yours to document and retain.
4. Our obligations as processor
We will:
- process the data only on your documented instructions, including as to transfers, unless we are required to do otherwise by law — in which case we will tell you first, unless the law forbids it;
- tell you promptly if, in our opinion, an instruction infringes data protection law;
- ensure that everyone authorised to process the data is bound by an obligation of confidentiality;
- implement the security measures described in Annex C;
- respect the conditions in clause 6 for engaging another processor;
- assist you, by appropriate technical and organisational measures and insofar as possible, in responding to requests to exercise rights under Chapter III;
- assist you with your obligations under Articles 32 to 36 — security, breach notification and data protection impact assessments — taking into account what we know and what you do not;
- delete or return the data at the end of the service, as set out in clause 8;
- make available the information needed to demonstrate compliance with Article 28 and allow for audits as set out in clause 9.
5. Nature of the processing
Annex A — subject matter and detail.
| Subject matter | Automated open-source research on named individuals, and production of a structured report |
| Duration | The term of your account, subject to the retention period in clause 8 |
| Nature and purpose | Retrieval from publicly accessible sources; screening against public registers; extraction, structuring, summarisation and risk indication |
| Categories of data subject | Individuals selected by you, and third parties publicly connected to them who appear in sources or in the relationship graph |
| Categories of personal data | Identity and biographical data; professional history and affiliations; publicly listed contact identifiers and social handles; photographs where openly licensed or publicly published; public statements and press coverage; relationships to other people and organisations; dated events; an automatically generated risk indication |
| Article 10 data | Where public sources report them: sanctions and watchlist entries, litigation, regulatory action, and adverse media concerning alleged offences. Processed only on your instruction and on your warranty under clause 3 that you are authorised to receive it. |
| Special categories | Not sought. The service is instructed not to seek data revealing racial or ethnic origin, political opinion, religion, trade union membership, health, sex life or sexual orientation. Such data may nonetheless appear incidentally in a public source that is read. |
6. Sub-processors
You give general authorisation for us to engage the sub-processors listed on the Sub-processors page. We will give at least thirty days’ notice by email before a new one begins processing. If you reasonably object on data protection grounds, you may terminate the affected part of the service and receive a refund of unused credits.
Each sub-processor is bound by written terms imposing obligations no less protective than these, and we remain fully liable to you for their performance.
7. International transfers
All data is stored in Frankfurt, Germany. The material transfer outside the EEA is to our language model provider in the United States, which receives the subject’s name and the content of pages retrieved, in order to analyse and summarise them.
That transfer is made under the European Commission’s Standard Contractual Clauses. The provider is contractually prohibited from training models on the content. Content is transmitted over encrypted connections, is not retained by the provider for its own purposes, and — because it is drawn from already-public sources — the incremental risk from onward access is materially lower than for confidential data.
8. Retention, deletion and return
An investigation and everything belonging to it — findings, sources, stored page text, images and snapshots — is deleted automatically 12 months after it completes. This is enforced by a scheduled process, not by policy alone.
You may delete an investigation at any time before then, and must do so where your own retention obligations are shorter. On termination of your account we delete all investigation data within thirty days, unless you ask in writing for an export first, in which case we provide it and then delete.
We may retain data for longer only where law requires it, and only for as long as it requires.
9. Audit
We will make available the information reasonably necessary to demonstrate compliance with Article 28, and will respond to a reasonable written security questionnaire once in any twelve-month period. Where that is genuinely insufficient, you may audit on thirty days’ notice, at your cost, no more than once a year unless a supervisory authority or a personal data breach requires otherwise, subject to confidentiality and to not disrupting the service or the data of other customers.
10. Personal data breach
We will notify you without undue delay, and in any event within seventy-two hours, after becoming aware of a personal data breach affecting your data, with what we know of its nature, the categories and approximate number of people and records concerned, the likely consequences and the measures taken. Notification is not an admission of fault.
11. Assisting with rights requests
Where an investigated person contacts us directly, we will not answer for you: we will pass the request to you promptly and support you in responding within the statutory deadline. Where the request is one we can act on ourselves — deleting what we hold, or adding a name to the exclusion list so no further investigation of that person can be run — we may act on it directly and will tell you that we have.
12. Precedence and liability
Where this agreement conflicts with the Terms of Service on the processing of personal data, this agreement prevails. Liability under it is subject to the limitations in the Terms, except where the GDPR does not permit that.
Annex B — sub-processors
Published and maintained at https://nacre.edda.cloud/legal/subprocessors.
Annex C — technical and organisational measures
- Encryption in transit. All access over TLS; all calls to sub-processors over TLS.
- Access control. Investigation data is reachable only by the account that owns it, enforced at the controller layer. Stored images and page snapshots are held on a private disk with no public URL and are served only through an authenticated route, which answers a request for another account’s file with “not found” rather than “forbidden”, so that the existence of an investigation is not disclosed.
- Credentials. Passwords stored only as salted hashes. Sign-in attempts rate-limited.
- Segregation. Each customer’s data is logically separated and queries are scoped to the owning account.
- Source integrity. A page is stored only where it was actually retrieved or actually cited, so the record reflects what was read rather than what was merely listed. Citations pointing at pages never retrieved are flagged.
- Identity separation. Findings carry an attribution verdict, and material judged to concern a different person of the same name is excluded from the report while being retained as evidence that the check was made.
- Auditability. Every stage of every investigation is recorded in an append-only journal with timestamps, including the queries run and the pages read.
- Hosting. European Union (Frankfurt), on infrastructure with physical and environmental controls operated by the hosting provider.
- Administrative access. Restricted to named administrators, over authenticated channels.