Ascripto

Data Processing Agreement

Last reviewed 6 October 2026

When your organisation connects its directory, signatures and mail to Ascripto, we process personal data on your behalf. This agreement sets out how, as Article 28 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) requires. It forms part of our Terms of Service and needs no separate signature.

1. Parties and roles

The customer that accepted the Terms of Service is the controller. The processor is Gyrus Solutions sp. z o.o. w organizacji, a company in the course of registration in Poland. Registration details are published here as soon as the entry is issued. Terms defined in the GDPR have the same meaning here. Where the UK GDPR applies, references to the GDPR include it.

2. Subject matter, duration, nature and purpose

We process customer personal data only to provide Ascripto to you: reading your directory, auditing and deploying email signatures, adding signatures to mail routed through our relay, keeping the message log, hosting brand assets, measuring campaigns, and supporting you. Processing lasts as long as the Terms of Service, plus the deletion period in section 10. The categories of data and data subjects are in Annex 1.

3. Your instructions

We process customer personal data only on your documented instructions. The Terms of Service, this agreement, and your configuration and use of the service are those instructions. If we believe an instruction infringes data protection law, we tell you. If the law requires us to process data otherwise, we tell you first unless the law forbids it.

4. Confidentiality

Everyone we authorise to process customer personal data is bound by confidentiality. Our staff do not access customer data except through a support grant that is limited in time, carries a reason, is recorded, and is visible to you.

5. Security

We implement the technical and organisational measures in Annex 2, and keep them appropriate to the risk as the service develops. We may change them as long as the overall level of protection does not fall.

6. Sub-processors

You give us general authorisation to engage the sub-processors in Annex 3. We tell you at least 30 days before adding or replacing one, by email to your workspace owner and by updating Annex 3. If you object on reasonable data-protection grounds, we will discuss it in good faith; if we cannot resolve it, you may end the agreement for the affected service and receive a refund of any prepaid fees for the unused period. We bind every sub-processor to data protection obligations no less protective than these, and remain responsible to you for their performance.

Google and Microsoft, whose platforms you connect, are your providers, not our sub-processors.

7. International transfers

Customer personal data is stored and processed in the European Economic Area. We do not transfer it outside the EEA except as Annex 3 states, and then only with a lawful transfer mechanism such as the European Commission’s Standard Contractual Clauses or an adequacy decision.

8. Helping you

Taking into account the nature of the processing, we help you respond to data subjects exercising their rights, mainly through the service itself; if a request reaches us directly, we pass it to you without undue delay and do not answer it ourselves unless you ask. We also give you the information you reasonably need for data protection impact assessments and consultations with a supervisory authority.

9. Personal data breaches

We notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting customer personal data. We tell you what we know — its nature, the data and people likely affected, its likely consequences, and the measures taken or proposed — and add to it as we learn more. Notifying you is not an admission of fault.

10. Deletion and return

When the Terms of Service end you can export your data for 30 days. After that we delete customer personal data, unless the law requires us to keep it. Backups are nightly, kept for 30 days and then deleted, and are not restored except to recover the service.

11. Demonstrating compliance and audits

We make available the information needed to demonstrate compliance with this agreement, and answer reasonable security questionnaires. If that does not suffice, you, or an independent auditor bound by confidentiality, may audit our compliance once a year on 30 days’ notice, during business hours and without disrupting the service or other customers’ data, at your cost. A supervisory authority may always audit as the law provides.

12. Liability and precedence

The liability provisions of the Terms of Service apply to this agreement, except where the GDPR provides otherwise. If this agreement conflicts with the Terms of Service on the processing of personal data, this agreement prevails.

Annex 1 — Data subjects and categories of data

Data subjectsPersonal dataKept for
Your employees and other people in your directoryNames, email addresses, directory identifiers, and the other directory fields signatures use (such as job title, department, phone numbers, office); administrators’ changes to them; their current and approved signatures; audit findings about themWhile they are in your directory; 7 days in the recycle bin after they leave it, or as you set
Your administrators and users of AscriptoNames, email addresses, and the actions they take in your workspaceAudit of actions: 13 months
Senders and recipients of mail routed through our relaySender and recipient addresses, Message-ID, time, and delivery outcome. Message content passes through in transit and is not stored10 days searchable; an archive you control may keep it longer
Recipients who click a tracked link or load a bannerThe event, its time, the campaign and the sender, the recipient as a one-way hash, and the kind of client (browser, mail proxy or scanner). No IP address is stored90 days; monthly totals for 25 months
Anyone shown in your brand assetsImages you upload, served publicly so recipients’ mail clients can load themUntil you delete them

We do not ask for special categories of personal data. Do not put them in signatures or directory fields that Ascripto reads.

Annex 2 — Technical and organisational measures

Annex 3 — Sub-processors

Sub-processorWhat it doesWhere
Microsoft Ireland Operations Limited (Microsoft Azure)Hosting: servers, databases, storage, key managementGermany (Frankfurt)

Transactional email is sent through a mail server we operate ourselves, so it involves no sub-processor.