Separate website inquiries from customer data
The public website’s Privacy Policy covers browsing and inquiries. A customer deployment can involve security logs, identifiers, user activity, assets, and other sensitive operational information. That processing requires a deployment-specific assessment and agreement.
This page is an overview of contracting topics. It is not a signed data-processing agreement and does not establish terms for an unconfigured deployment.
Define roles, scope, and instructions
The agreement should identify the contracting entities, controller and processor roles where applicable, the service purpose, processing duration, categories of data, categories of individuals, and documented customer instructions.
Only connect systems and data that your organization is authorized to process. Choose the minimum telemetry needed for the agreed security workflow.
Review technical and organizational measures
Review access controls, encryption, logging, administrative access, data separation, incident handling, and response authorization for the actual deployment. Security design principles on this website are not a substitute for a verified description of implemented controls.
Identify any AI services involved, what information they receive, and their applicable data-use and retention terms.
Agree on providers and transfers
Obtain the relevant subprocessor list, service functions, processing locations, and applicable change-notification procedure. Assess international transfers and required safeguards under the laws that apply to the customer.
See subprocessor information for the distinction between public website providers and product processing.
Specify lifecycle and assistance
Establish retention and deletion instructions, end-of-service handling, assistance with applicable data-subject requests, breach notification requirements, and the process for reviewing evidence of compliance.
Do not infer a retention period, data residency commitment, audit right, or incident notification deadline from a marketing description. These requirements should be agreed in the relevant contract.
Start the review
Use Book a meeting to discuss your deployment and data requirements. Privacy correspondence should use the contact channel provided in your service agreement. Share detailed security or personal information only after a suitable secure channel is agreed.