Legal
Data Processing Addendum.
When SageTensor handles personal data on behalf of a client, this addendum governs how. It also lists the sub-processors used and the safeguards for international transfers — the questions procurement and data-protection teams ask first.
Data Processing Addendum
Controller and processor roles.
For its own website and mandate intake, SageTensor is the data controller; that processing is described in the Privacy Policy . When SageTensor builds or operates a system for a client and, in doing so, processes personal data on that client's behalf, the client is the controller and SageTensor is the processor. This addendum governs that processor relationship and is intended to satisfy Article 28 of the UK and EU GDPR and comparable requirements.
Scope and instructions.
SageTensor processes personal data only to provide the engagement and only on the client's documented instructions, including the engagement agreement, statement of work, and this addendum. The subject matter, duration, nature, and purpose of the processing, the types of personal data, and the categories of data subjects are set out in the relevant engagement agreement. We will tell you if, in our view, an instruction breaches data-protection law.
Our obligations as processor.
- Process personal data only on the controller's documented instructions.
- Ensure that personnel authorized to process the data are bound by confidentiality.
- Implement and maintain appropriate technical and organizational security measures (below).
- Engage sub-processors only under the conditions in this addendum, and remain responsible for them.
- Assist the controller, as far as reasonably possible, with data-subject requests and with security, breach-notification, and impact-assessment obligations.
- Delete or return personal data at the end of the engagement, as instructed.
- Make available the information reasonably needed to demonstrate compliance, and allow for and contribute to audits, subject to reasonable confidentiality and security limits.
Sub-processors.
SageTensor uses a small, deliberate set of sub-processors to run this website and its intake service. We remain responsible for their compliance, engage each under a written contract with data-protection terms at least as protective as this addendum, and will give notice of any intended addition or replacement so a controller can object on reasonable grounds.
| Sub-processor | Role | Processing | Location |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, edge network, and application platform | Serves the website and runs the mandate service (Workers), the database (D1), session and rate-limit storage (KV), the notification queue, and the anti-abuse challenge (Turnstile). Processes request metadata, IP addresses, and submitted mandate data at rest and in transit. | United States, with a global edge network |
| Transactional email provider | Outbound notification delivery | Delivers a short internal notification when a mandate is received. The message carries only a non-confidential reference code and route — never the words you wrote or your contact details. Engaged only once notification credentials are configured. | United States or European Union, per the configured provider |
A client engagement may introduce additional, client-specific sub-processors (for example, a cloud region or service the client asks us to use). Those are named in the engagement documentation.
International transfers.
Our infrastructure provider operates globally, and personal data may be processed in the United States. Where personal data protected by UK or EU law is transferred outside those regions, the transfer is made under an appropriate safeguard — the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, or another valid mechanism — together with any additional measures needed for the transfer. A copy of the relevant clauses is available on request.
Security measures.
SageTensor maintains technical and organizational measures appropriate to the risk. For this website and intake service these include:
- Encryption of data in transit over TLS, and a strict set of HTTP security headers (HSTS, no-sniff, frame-deny, a strict content-security policy, and a restrictive permissions policy).
- Data-store access exclusively through parameterized statements and atomic transactions, so a partial or injected record cannot exist.
- Data minimization by design: only what is needed is collected, free-text avoids secrets by instruction, and there is no public file upload.
- Operational logs and audit records that carry only a route, a reference code, an event type, and timestamps — never the content you submit, secrets, or IP addresses in the clear.
- Abuse controls that protect availability without profiling: a human-verification challenge, a minimum-time check, and a rate limit keyed on a salted, one-way hash of the IP address.
- Purpose-based retention enforced automatically, with the ability to place a legal hold and to delete per field.
- Least-privilege access to production systems and secrets, held in the platform's secret store rather than in code.
SageTensor does not claim certifications it does not hold. Where an engagement requires a specific control framework or certification, that is agreed and evidenced as part of the engagement rather than implied here.
Assisting with data-subject requests and breaches.
SageTensor will, taking into account the nature of the processing, assist the controller with appropriate technical and organizational measures in responding to data-subject requests (access, rectification, erasure, restriction, portability, and objection). We will notify the controller without undue delay after becoming aware of a personal-data breach affecting the controller's data, and provide the information reasonably needed for the controller to meet its own notification duties.
Return and deletion.
On termination or expiry of an engagement, SageTensor will, at the controller's choice, return or delete the personal data it processes on the controller's behalf, and delete existing copies unless the law requires retention. For SageTensor's own intake data, the retention schedule in the Privacy Policy applies.
Putting a signed DPA in place.
This page states SageTensor's standard processor terms and sub-processor list. To execute a signed Data Processing Agreement (including the Standard Contractual Clauses where relevant) for an engagement, contact legal@sagetensor.com . For privacy questions, contact privacy@sagetensor.com .