Data processing agreement
The written contract required by Article 28 of the UK GDPR, governing personal data that CYBERROCK LTD processes on your behalf. Last updated 18 August 2026.
1. Definitions
In this agreement:
"UK GDPR" means Regulation (EU) 2016/679 (the General Data Protection Regulation) as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, and as amended.
"DPA 2018" means the Data Protection Act 2018.
"Data Protection Laws" means the UK GDPR and the DPA 2018, together with any other data protection or privacy law applicable to the Processor's provision of Unwhisper, each as amended, replaced or superseded from time to time.
"ICO" means the Information Commissioner's Office, the United Kingdom's supervisory authority for data protection.
References to Articles are to Articles of the UK GDPR. This agreement is the written contract required by Article 28(3) of the UK GDPR, which obliges a controller to put such a contract in place before a processor processes personal data on its behalf, and prescribes the terms it must contain.
"controller", "processor", "data subject", "personal data", "processing" and "personal data breach" have the meanings given in Article 4 of the UK GDPR.
2. Scope and roles
This agreement supplements the terms of service and applies where CYBERROCK LTD ("Processor") processes personal data on behalf of the customer ("Controller") in providing Unwhisper.
The Controller is the controller of any personal data contained in content submitted for scanning; the Processor processes that data only to return a verdict. Separately, the Processor is an independent controller of account, billing and usage data, which is governed by the privacy policy and is outside the scope of this agreement.
3. Processing on documented instructions
The Processor will process personal data only on the Controller's documented instructions, which comprise this agreement, the terms of service, and the parameters of each API request. The Processor will not process personal data for any other purpose, and in particular will not use it to train, fine-tune or evaluate its models.
The Processor will tell the Controller if, in its opinion, an instruction infringes the Data Protection Laws.
4. Confidentiality
The Processor ensures that persons authorised to process personal data are bound by confidentiality obligations and are granted access only to the extent necessary.
5. Security
The Processor implements appropriate technical and organisational measures under Article 32 (security of processing), set out in Schedule 2. The most significant of these is architectural: submitted content is not retained, so it cannot be exposed by a later breach of storage.
6. Sub-processors
The Controller gives general authorisation for the sub-processors listed in Schedule 3. The Processor will give at least 30 days' notice before adding or replacing a sub-processor, during which the Controller may object on reasonable data-protection grounds; if the objection cannot be resolved, the Controller may terminate the affected service without penalty.
The Processor imposes data protection obligations on each sub-processor no less protective than those in this agreement, and remains liable for their performance.
7. Assistance with data subject rights
Taking account of the nature of the processing, the Processor will assist the Controller by appropriate technical and organisational measures in responding to requests from data subjects exercising the rights in Chapter III of the UK GDPR (Articles 12 to 23). In practice this assistance is limited by design: because submitted content is not retained, the Processor will ordinarily hold no personal data to which such a request could attach.
8. Personal data breach
The Processor will notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Controller's personal data, and will provide the information reasonably required for the Controller to meet its own notification obligations under Articles 33 and 34 (notification to the ICO and, where required, to affected data subjects).
9. Data protection impact assessments
The Processor will provide reasonable assistance with data protection impact assessments under Article 35 and prior consultations with the ICO under Article 36, taking account of the nature of the processing and the information available to it.
10. Deletion and return
Submitted content is deleted in the ordinary course of processing, as described in Schedule 1; there is no separate deletion step at the end of the agreement because nothing is retained. On termination the Processor will delete or return any residual personal data processed on the Controller's behalf, except where the Data Protection Laws or other UK law require it to be kept.
11. Audit and information
The Processor will make available to the Controller the information reasonably necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates. Audits are limited to once in any 12-month period unless a breach has occurred or the ICO requires otherwise, are subject to reasonable notice and confidentiality, and must not compromise the security of other customers.
12. International transfers
Scanning is performed in the United Kingdom. Where a sub-processor processes personal data outside the UK, the Processor ensures a lawful transfer mechanism is in place under Chapter V of the UK GDPR: either adequacy regulations made under section 17A of the DPA 2018, or the ICO's International Data Transfer Agreement (IDTA), or the International Data Transfer Addendum to the European Commission's standard contractual clauses.
Schedule 1, details of the processing
Subject matter: detection of prompt-injection content in material submitted by the Controller.
Duration: the term of the terms of service. Each individual processing operation lasts only as long as the scan.
Nature and purpose: automated inspection, extraction, decoding and classification of submitted content in order to return a pass or fail verdict.
Type of personal data: determined entirely by the Controller. The Processor does not select, request or control what is submitted, and any personal data present is incidental to the security purpose.
Categories of data subjects: determined entirely by the Controller.
Retention: content is held only for the duration of the scan. Text is processed in memory; file uploads are written to a temporary file which is deleted immediately after the scan completes, including on error. No copy is retained afterwards. Where the Controller explicitly requests a forensic report, extracts of the analysed content are written to a report which is retrievable through a signed link for five minutes and is then deleted automatically.
Schedule 2, technical and organisational measures
- Non-retention by design. Submitted content is not stored, logged or used for training. This is the primary control.
- Encryption in transit for all API and console traffic.
- Access control. Production access is restricted, authenticated and logged.
- Credential handling. API keys are stored so they cannot be read back and can be revoked immediately.
- Tenant isolation. Scans are processed independently; no customer content is shared between accounts.
- Time-limited forensic artefacts. Reports expire after five minutes and are pruned automatically.
- Resource limits. Per-scan work budgets and rate limits protect availability.
Schedule 3, authorised sub-processors
- Amazon Web Services, hosting and compute, London region, United Kingdom.
- Stripe (Payment provider), card processing and invoicing. Processes billing data only; never receives submitted content.
- Transactional email provider, account verification and service messages. Processes account data only; never receives submitted content.
Named current providers are available on request. Only the hosting sub-processor is involved in scanning; the others handle account and billing data exclusively.
Contact
CYBERROCK LTD, 128 City Road, London EC1V 2NX, United Kingdom
Document version 1.1.0 · published 18 August 2026
