Skip to main content

Data Processing Agreement

Version 22 August 2026 · effective and last updated 22 August 2026 · last reviewed 22 August 2026

How this applies to you

This Data Processing Agreement (“DPA”) forms part of our Terms of Service (see Terms § 6) and applies automatically, without a separate signature, to every organisation registered for a Sacred Logic™ Charter Mark account (the “Customer”) and Sacred Logic Ltd., Kilkeedy, Tubber, Co. Clare, Ireland (“Sacred Logic”). It governs Sacred Logic's processing of personal data as a processor on the Customer's instructions — the role allocation and scope are set out in “Background and roles” below. It takes effect from registration.

Background and roles

Sacred Logic provides a voluntary AI-certification service (the “Charter Mark”) and related website (the “Services”), described in the Terms of Service and Privacy Policy.Role allocationSacred Logic's role under data protection law depends on the type of processing. The following sets out each activity and the applicable role.Certification application data — Processor (this DPA). When processing personal data that the Customer submits in connection with a certification application — including application materials, evidence, personnel contact details, and the internal records of the assessment and certification decision — Sacred Logic acts as a processor on the Customer's documented instructions (“Customer Personal Data”). This DPA governs that relationship.Account and registration data — Controller (Privacy Policy). Sacred Logic acts as an independent controller for personal data it collects when an organisation registers an account (including organisation name, billing contact, and account-holder details). Governed by the Privacy Policy; not this DPA.Public registry and certificate data — Controller (Privacy Policy). Sacred Logic acts as an independent controller for the information it publishes on the public register (organisation name, certification status, tier, framework version, and assessment route). This publishing is carried out for Sacred Logic's own legitimate purposes as operator of the certification scheme. Governed by the Privacy Policy; not this DPA.Site usage, analytics, and chat logs — Controller (Privacy Policy). Processing of visitor and user data for site operation, security, and improvement is conducted by Sacred Logic as an independent controller. Governed by the Privacy Policy; not this DPA.Consumer lead-sharing (B2C portal) — separate Controllers. When a consumer opts in through the Sacred Logic consumer portal to share their contact details with a specific organisation, Sacred Logic acts as an independent controller for its own collection and transfer of that consent signal. The receiving organisation is a separate, independent controller for its own subsequent use of the shared lead. Sacred Logic is not acting as a processor on the organisation's behalf in that flow, and this DPA does not apply to it. Each party is responsible for its own lawful basis and data-subject notices. Sacred Logic's consumer-facing obligations are set out in the Privacy Policy.This DPA governs only Sacred Logic's processing as Processor of Customer Personal Data (the first item above) and forms part of the agreement between the parties (the “Principal Agreement”). Where they conflict on data protection in relation to that processing, this DPA prevails over the Principal Agreement.

1. Definitions

“Data Protection Law” means the EU GDPR (Regulation (EU) 2016/679), the UK GDPR and Data Protection Act 2018, the Data Protection Act 2018 of the Republic of Ireland, and the ePrivacy rules, each as applicable. “Controller”, “Processor”, “Personal Data”, “Processing”, “Data Subject”, “Personal Data Breach” and “Sub-processor” have the meanings in Data Protection Law. “SCCs” means the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant).

2. Processing details

Subject matter: provision of the Charter Mark certification Services.Duration: the term of the Principal Agreement, plus any legally required retention.Nature and purpose: receiving, storing, and reviewing certification application materials to assess an AI system against the Human Values Framework; operating the associated records.Types of personal data: contact details of the Customer's personnel/representatives, and any personal data contained within the Customer's submitted documentation — the Customer should minimise what it includes.Categories of data subjects: the Customer's staff, representatives, and any individuals referenced in submitted materials.Special-category data: none is intended or required for certification. If a submission would include it, contact us before including it.

3. Processor obligations

Sacred Logic shall:3.1 Instructions. Process Customer Personal Data only on the Customer's documented instructions (including this DPA and the Principal Agreement), unless required by law, in which case it will inform the Customer first unless legally prohibited.3.2 Confidentiality. Ensure persons authorised to process Customer Personal Data are bound by confidentiality.3.3 Security. Implement appropriate technical and organisational measures under Article 32, having regard to the state of the art and the risk — see the security-measures summary below.3.4 Sub-processors. Not engage a new sub-processor without the Customer's general written authorisation. The Customer authorises the sub-processors listed below. Sacred Logic will give at least 30 days' notice of any intended addition or replacement, allowing the Customer to object on reasonable data-protection grounds, and will impose data-protection obligations on each sub-processor no less protective than this DPA.3.5 Data-subject rights. Taking into account the nature of the processing, assist the Customer by appropriate measures to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection).3.6 Assistance. Assist the Customer in ensuring compliance with Articles 32–36 (security, breach notification, DPIAs, prior consultation), taking into account the information available to Sacred Logic.3.7 Breach. Notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, with the information reasonably available.3.8 Deletion or return. At the Customer's choice, delete or return all Customer Personal Data at the end of the Services and delete existing copies, unless retention is required by law.3.9 Audits. Make available information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, by the Customer or its auditor, on reasonable notice, subject to confidentiality and no more than once per year unless a breach or regulator requires otherwise.

4. International transfers

Sacred Logic shall not transfer Customer Personal Data outside the EEA/UK except under an appropriate safeguard (an adequacy decision such as the EU–US Data Privacy Framework where the recipient is certified, or the SCCs/UK Addendum). Relevant transfers by authorised sub-processors are identified in the table below.

5. Controller obligations

The Customer warrants that it has a lawful basis and any necessary notices/consents for the personal data it provides, and that its instructions comply with Data Protection Law.

6. Liability, term, and law

6.1 Liability under this DPA is subject to the limitations/exclusions in the Principal Agreement, except where Data Protection Law does not allow such limitation.6.2 This DPA takes effect with the Principal Agreement (from registration) and continues while Sacred Logic processes Customer Personal Data.6.3 This DPA, and any dispute or claim arising out of or in connection with it (including non-contractual disputes or claims), is governed by and construed in accordance with the laws of the Republic of Ireland. The parties irrevocably agree that the courts of the Republic of Ireland shall have exclusive jurisdiction to settle any such dispute or claim, without prejudice to any mandatory data-subject rights or regulator competence.

Authorised sub-processors

ClerkAuthentication / account identity. Location: US. Safeguard: Standard Contractual Clauses.ConvexApplication database & serverless functions. Location: US. Safeguard: SCCs (expected — Convex's own DPA/sub-processor list should be confirmed directly before relying on this row).VercelWebsite hosting / CDN. Location: US and other locations where Vercel or its sub-processors operate. Safeguard: Standard Contractual Clauses + UK Addendum.StripePayment processing (billing data only). Location: Outside the EEA — Stripe Technology Company Limited is the EMEA/APAC controller entity. Safeguard: EU–US Data Privacy Framework + Standard Contractual Clauses.Google (Gemini API)AI chat-assistant replies (site-wide assistant — Application Data does not pass through this). Location: US / global. Safeguard: Google's Gemini API terms — included for completeness as a site-wide sub-processor, not because it touches Customer Personal Data under this DPA.

Security measures (summary)

Authentication is delegated to Clerk; access to privileged data and functions is enforced server-side against a cryptographically-verified identity, never a client-supplied value. Traffic is encrypted in transit (TLS). Payment card data is handled directly by Stripe and never stored by Sacred Logic. Access is least-privilege, with an append-only audit log of administrative actions. Retention limits apply, with deletion or anonymisation on request subject to legal and audit obligations. See the Security page for more detail.

This DPA is a good-faith standard agreement prepared by Sacred Logic Ltd. in accordance with Article 28 GDPR. It is not a substitute for legal advice specific to your situation. If you need a bespoke, individually-executed DPA — for example with terms specific to your organisation — contact [email protected].