Data Processing Agreement
Last reviewed 6 October 2026
When your organisation connects its directory, signatures and mail to Ascripto, we process personal data on your behalf. This agreement sets out how, as Article 28 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) requires. It forms part of our Terms of Service and needs no separate signature.
1. Parties and roles
The customer that accepted the Terms of Service is the controller. The processor is Gyrus Solutions sp. z o.o. w organizacji, a company in the course of registration in Poland. Registration details are published here as soon as the entry is issued. Terms defined in the GDPR have the same meaning here. Where the UK GDPR applies, references to the GDPR include it.
2. Subject matter, duration, nature and purpose
We process customer personal data only to provide Ascripto to you: reading your directory, auditing and deploying email signatures, adding signatures to mail routed through our relay, keeping the message log, hosting brand assets, measuring campaigns, and supporting you. Processing lasts as long as the Terms of Service, plus the deletion period in section 10. The categories of data and data subjects are in Annex 1.
3. Your instructions
We process customer personal data only on your documented instructions. The Terms of Service, this agreement, and your configuration and use of the service are those instructions. If we believe an instruction infringes data protection law, we tell you. If the law requires us to process data otherwise, we tell you first unless the law forbids it.
4. Confidentiality
Everyone we authorise to process customer personal data is bound by confidentiality. Our staff do not access customer data except through a support grant that is limited in time, carries a reason, is recorded, and is visible to you.
5. Security
We implement the technical and organisational measures in Annex 2, and keep them appropriate to the risk as the service develops. We may change them as long as the overall level of protection does not fall.
6. Sub-processors
You give us general authorisation to engage the sub-processors in Annex 3. We tell you at least 30 days before adding or replacing one, by email to your workspace owner and by updating Annex 3. If you object on reasonable data-protection grounds, we will discuss it in good faith; if we cannot resolve it, you may end the agreement for the affected service and receive a refund of any prepaid fees for the unused period. We bind every sub-processor to data protection obligations no less protective than these, and remain responsible to you for their performance.
Google and Microsoft, whose platforms you connect, are your providers, not our sub-processors.
7. International transfers
Customer personal data is stored and processed in the European Economic Area. We do not transfer it outside the EEA except as Annex 3 states, and then only with a lawful transfer mechanism such as the European Commission’s Standard Contractual Clauses or an adequacy decision.
8. Helping you
Taking into account the nature of the processing, we help you respond to data subjects exercising their rights, mainly through the service itself; if a request reaches us directly, we pass it to you without undue delay and do not answer it ourselves unless you ask. We also give you the information you reasonably need for data protection impact assessments and consultations with a supervisory authority.
9. Personal data breaches
We notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting customer personal data. We tell you what we know — its nature, the data and people likely affected, its likely consequences, and the measures taken or proposed — and add to it as we learn more. Notifying you is not an admission of fault.
10. Deletion and return
When the Terms of Service end you can export your data for 30 days. After that we delete customer personal data, unless the law requires us to keep it. Backups are nightly, kept for 30 days and then deleted, and are not restored except to recover the service.
11. Demonstrating compliance and audits
We make available the information needed to demonstrate compliance with this agreement, and answer reasonable security questionnaires. If that does not suffice, you, or an independent auditor bound by confidentiality, may audit our compliance once a year on 30 days’ notice, during business hours and without disrupting the service or other customers’ data, at your cost. A supervisory authority may always audit as the law provides.
12. Liability and precedence
The liability provisions of the Terms of Service apply to this agreement, except where the GDPR provides otherwise. If this agreement conflicts with the Terms of Service on the processing of personal data, this agreement prevails.
Annex 1 — Data subjects and categories of data
| Data subjects | Personal data | Kept for |
|---|---|---|
| Your employees and other people in your directory | Names, email addresses, directory identifiers, and the other directory fields signatures use (such as job title, department, phone numbers, office); administrators’ changes to them; their current and approved signatures; audit findings about them | While they are in your directory; 7 days in the recycle bin after they leave it, or as you set |
| Your administrators and users of Ascripto | Names, email addresses, and the actions they take in your workspace | Audit of actions: 13 months |
| Senders and recipients of mail routed through our relay | Sender and recipient addresses, Message-ID, time, and delivery outcome. Message content passes through in transit and is not stored | 10 days searchable; an archive you control may keep it longer |
| Recipients who click a tracked link or load a banner | The event, its time, the campaign and the sender, the recipient as a one-way hash, and the kind of client (browser, mail proxy or scanner). No IP address is stored | 90 days; monthly totals for 25 months |
| Anyone shown in your brand assets | Images you upload, served publicly so recipients’ mail clients can load them | Until you delete them |
We do not ask for special categories of personal data. Do not put them in signatures or directory fields that Ascripto reads.
Annex 2 — Technical and organisational measures
- Location: the service runs in Microsoft Azure’s Germany West Central region (Frankfurt).
- Encryption: TLS for all traffic to and between our services; data encrypted at rest by the storage platform. Mail between Exchange Online and our relay uses TLS and is authenticated by certificate.
- Credentials: directory tokens, signing keys and service account keys are kept in Azure Key Vault and never in a database or in code. A workspace’s records hold only a reference to them.
- Separation: every workspace’s data is scoped by its identifier on every read and write. Applications reach the databases only through defined routines, never through direct table access.
- Access: staff access requires multi-factor authentication. Access to a customer’s data needs a time-limited, reasoned and recorded support grant visible to the customer. Production access is limited to the people who operate the service.
- Accounts: passwords stored only as one-way hashes; second factors supported for every account; sessions listed and revocable by their owner.
- Minimisation: the relay never stores message content or subjects; tracking stores no IP addresses; access to Google and Microsoft directories is read-only.
- Records: administrative actions in a workspace and staff actions are recorded in audit logs that the actions themselves cannot alter.
- Resilience: health of every part of the service is monitored; databases are backed up nightly and kept for 30 days; the relay’s behaviour when it cannot sign mail is set per workspace.
Annex 3 — Sub-processors
| Sub-processor | What it does | Where |
|---|---|---|
| Microsoft Ireland Operations Limited (Microsoft Azure) | Hosting: servers, databases, storage, key management | Germany (Frankfurt) |
Transactional email is sent through a mail server we operate ourselves, so it involves no sub-processor.