Arctic Parade LTD / BUSINESS DOCUMENTS
Data-processing agreement
Customer workspace processing schedule and obligations. Version 2026-09-18-v1.
These are early-access drafts awaiting final fact checks and legal review before public contracting. Outstanding details: Final legal review of processing and commercial terms, Postmark account-specific agreement/transfer review.
Parties and scope
Arctic Parade LTD. Contact address: 9 Haigh Road, Huddersfield, England, HD3 2AE. Email: arran@arcticparade.com. Company registration: 17033806; England and Wales. Registered office: 9 Haigh Road, Huddersfield, England, HD3 2AE. This agreement supplements the early-access terms between us and the organisation creating or administering the workspace (the Customer). It applies to personal data processed for the Customer, including where an MSP instructs us as a sub-processor. The Customer confirms authority from any upstream controller. It does not replace our controller privacy notice for business/account administration.
Processing schedule
Subject: customer inventory and lifecycle operations. Purpose: import or authorised discovery, catalogue comparison, action tracking, evidence history, customer reports and enabled review emails. Operations: collection, organisation, storage, retrieval, authorised disclosure, export and deletion. Duration: while the workspace/service exists plus the protected 14-day backup expiry period. Categories: customer/contact labels, resource identifiers, technology/version/environment context, owner/reviewer names, notes, action dates and evidence supplied by authorised members. Data subjects: the Customer’s or its clients’ staff, contractors and contacts whose information appears in those records. Special-category data and criminal-offence data are not intended inputs.
Customer instructions and obligations
Uploads, authorised connector configuration, workspace settings and written support instructions form the documented instructions. We process only on those instructions unless law requires otherwise, notifying the Customer where permitted. The Customer chooses lawful inputs, informs relevant individuals and authorises its members. We flag instructions we believe unlawful. We do not sell workspace data, use it to train AI models or send customer marketing on the Customer’s behalf under this agreement.
Confidentiality and security
Authorised personnel must be bound by confidentiality. We maintain proportionate security, including workspace checks, roles, password hashing, encrypted connector secrets, restricted operator configuration, audit history and tested recovery procedures. Current technical measures and pre-launch gaps are listed on the security page. Public HTTPS and secure sign-in cookies are deployed. External monitoring and off-host recovery arrangements remain outstanding. This release has no customer-specific role boundaries, independent penetration-test certification or availability SLA.
Sub-processors
The Customer generally authorises the vendors listed in the supplier register for the stated purposes when the relevant feature is enabled. We impose equivalent processing obligations and remain responsible for our sub-processors. We provide advance notice of planned additions/replacements and an opportunity to object on data-protection grounds. Our proposed normal notice period is 30 days through the account contact route. We agree an alternative or allow the affected service to end if a reasonable objection cannot be resolved. No new host or AI provider is silently added through this agreement.
Transfers
International transfers require the Customer’s documented instructions and an applicable UK safeguard or adequacy route, with any required assessment. We provide information on the recorded mechanism on request. Postmark account email is enabled; its published processing terms describe transfer safeguards, but the account-specific agreement and UK transfer assessment record remain outstanding. This agreement does not substitute for that vendor review.
Rights, assistance and breach notification
We assist with individual rights, security obligations, breach assessment/notification and impact assessments, taking account of the service. We notify the Customer of a personal data breach without undue delay after awareness, provide available facts and updates, and cooperate in containment. We do not make the Customer’s regulatory reporting decision for it.
Return, deletion and backup handling
At the Customer’s choice on ending the service, return workspace data in the supported JSON export format or delete it. Active deletion removes inventory, evidence, history, member access, tokens, pending jobs and encrypted credentials. Backup copies remain protected, beyond ordinary use, and expire within 14 days; any recovery must reapply recorded deletion instructions before resumed use. Where law requires a limited record to be retained, we identify the obligation and limit further use. Azure role revocation and files exported by members require separate action. Written data-removal instructions are not conditional on paying a new fee.
Information, audits and precedence
We provide compliance information and allow/contribute to audits or inspections, including legally required urgent checks, while protecting other customers’ data. Contact arran@arcticparade.com to arrange scope and access. This processing agreement prevails over conflicting commercial terms about personal-data processing; applicable transfer clauses prevail where required. Security or transfer commitments are not waived by early-access status.
Related documents and guidance
Keep a copy using your browser's Print / Save as PDF. Workspace administrators can export the version and snapshot accepted by their organisation.