Skip to main content
DATA PROCESSING

Data Processing Addendum

These processor terms apply to Customer Content when this Data Processing Addendum is incorporated into an order or written agreement for Siglata.

1. Scope and roles

This Data Processing Addendum (DPA) applies when Customer and Estirpia Technologies Pte. Ltd. incorporate it into an order or other written agreement for the Siglata Service. Customer is the controller, business, or equivalent decision-maker for personal data in Customer Content, and Estirpia is the processor, service provider, or equivalent provider, as those terms apply under the relevant law.

The subject matter is Estirpia's provision of the Service, including hosting, organizing, transforming, storing, securing, supporting, and returning Customer Content. The duration is the applicable Service term plus the period needed to complete return, deletion, legal, security, and dispute obligations. The data subjects, data types, and processing activity are those Customer places in or directs through the Service, including people represented in files, account and Organization members, and people whose data appears in Content.

  • Account, contact, support, security, and independent service-operation processing can remain governed by the Privacy Policy as Estirpia's own controller activity.
  • The DPA does not make Estirpia a controller for Customer's purposes or authorize Estirpia to use Content for unrelated purposes.

2. Documented instructions and limits

Estirpia will process Customer Content only on Customer's documented instructions: this DPA, the applicable order or written agreement, the Terms of Use, Customer's configuration and use of the Service, and later written instructions accepted through the designated contact. Estirpia will inform Customer if an instruction appears to violate applicable data-protection law and may suspend the affected instruction until the parties resolve it.

The instructions authorize processing needed to provide the requested Service, authenticate and authorize users and agents, maintain Organization boundaries, create revisions and outputs, provide support, maintain security, investigate abuse, comply with law, and follow Customer's retention or deletion directions. Estirpia does not use Customer Content, prompts, or agent instructions to train general-purpose AI models.

  • Customer must ensure its instructions and use of the Service have a lawful basis and satisfy required notices and rights.
  • Customer must not direct Estirpia to process data outside the Service, DPA, order, or written agreement without a documented change accepted by the parties.

3. Confidentiality

Estirpia will ensure that personnel and subprocessors authorized to process Customer Content are bound by confidentiality obligations appropriate to the data and task. Access is limited to people and systems that need it for the documented processing, security, support, or legal purpose.

Estirpia may disclose Customer Content when required by law. Where legally permitted and reasonably practicable, Estirpia will notify Customer before disclosure and cooperate with a lawful effort to limit it.

  • Confidentiality duties continue after personnel change and after the DPA or Service ends.
  • A lawful disclosure does not become a permitted secondary use of Customer Content.

4. Security measures

Estirpia will implement and maintain technical and organizational measures appropriate to the risk, state of the art, cost, processing context, and likely impact of a security incident. Measures include Organization-scoped authorization, role and client identity checks, controlled service access, content-addressed storage and integrity checks, audit records for applicable operations, and restricted computation boundaries. This DPA also sets the incident-notification and cooperation obligations that apply when a personal-data breach is confirmed.

The Security Practices document describes the current public security posture. Security measures may change as the Service changes, provided the resulting measures continue to be appropriate to the processing risk. No security measure is an absolute guarantee against every incident or failure.

  • Estirpia will protect Customer Content against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and unauthorized access to the extent required by applicable law.
  • Customer is responsible for its credentials, agent scopes, instructions, endpoints, and any security control it operates outside Siglata.

5. Subprocessors

Customer authorizes Estirpia to use subprocessors and other service providers needed for the documented processing, including providers for cloud hosting and edge delivery, object storage, managed databases and authentication, email delivery, server-side analytics and telemetry, workflow execution, support, and security monitoring. Estirpia will impose written data-protection obligations appropriate to the processing and remains responsible for the subprocessor's performance to the extent required by applicable law.

Estirpia will make relevant subprocessor information available and provide notice of material additions or replacements where required by law or the applicable agreement. Customer may raise a reasonable, documented objection based on data-protection grounds; the parties will work in good faith on a lawful alternative or mitigation.

  • Customer's own connected agents, hosts, model providers, and integrations are not Estirpia subprocessors merely because Customer connects them.
  • Subprocessor locations and functions can change; the applicable notice or agreement controls the available detail.

6. Assistance and data-subject requests

Considering the nature of the processing and information available to Estirpia, Estirpia will reasonably assist Customer with requests from data subjects and with Customer's obligations concerning security, impact assessments, consultations, and regulator requests. Customer remains responsible for determining the response, communicating with the data subject, and giving the documented instruction needed for Estirpia to act.

Customer will send processor-assistance requests to support@mail.siglata.com with enough context to identify the Organization, data, request, and deadline. Estirpia may request verification, restrict a response that would expose another customer, and charge only where the applicable agreement or law permits reasonable assistance costs.

  • Assistance can include search, access, correction, export, restriction, deletion, and information about processing operations.
  • Customer must not send unnecessary sensitive data in a request and must protect any export it receives.

7. Personal-data incidents

Estirpia will notify Customer without undue delay after confirming a personal-data breach affecting Customer Content, to the extent required by applicable law and the information reasonably available. Notice will describe the nature of the incident, affected processing where known, likely consequences, mitigation or response steps, and a contact channel for follow-up.

Estirpia will take reasonable steps to contain, investigate, remediate, and document the incident and will reasonably cooperate with Customer's legally required notifications. Customer remains responsible for deciding whether and how to notify data subjects or authorities.

  • Security notices and vulnerability reports should be sent to security@mail.siglata.com.
  • Estirpia will not treat a routine failed request or unsuccessful attack with no confirmed compromise as a personal-data breach, while it may still investigate and document the event.

8. Return and deletion

At Customer's choice and subject to the Service's available export and account controls, Estirpia will make Customer Content available for return during the Service term or at termination. After Customer instructs deletion, or when the applicable agreement ends, Estirpia will delete or return Customer Content and delete remaining copies within a commercially reasonable period appropriate to the systems and processing, unless law requires retention or a security, audit, dispute, or legal-hold need permits limited retention.

Where data remains in a backup or immutable audit record that cannot be removed immediately without compromising integrity or continuity, Estirpia will isolate it from further processing except for the purpose requiring retention and will delete it when that purpose ends. This DPA does not promise a single fixed deletion deadline.

  • Customer should export needed Content before closing an Organization or ending the Service.
  • Customer's deletion instruction does not require Estirpia to delete a record that applicable law requires it to keep.
  • Estirpia will provide reasonable confirmation of completed deletion when the applicable agreement or law requires it.

9. International transfers

Estirpia may transfer Customer Content to Singapore, the European Union, the United States, or other countries where Estirpia or an authorized subprocessor operates. The parties will comply with applicable cross-border transfer requirements and will use the transfer mechanism required for the relevant data and destination, including an adequacy decision, contractual safeguards, or comparable-protection arrangement where applicable.

If a required transfer mechanism changes, becomes unavailable, or is held insufficient, the parties will cooperate on a lawful alternative or supplementary measure. Customer's instruction to use a connected third-party agent or provider remains Customer's responsibility and does not make that recipient an Estirpia subprocessor.

  • For EU or EEA data, the parties may use the then-current standard contractual clauses or another valid mechanism where required.
  • For Singapore data, the parties will address the comparable-protection requirement applicable to the transfer.

10. Information and audit

Estirpia will make available information reasonably necessary to demonstrate compliance with its processor obligations and will reasonably support an audit where Customer is entitled to conduct one under applicable law or the written agreement. Customer should first use security information, written responses, and available reports; a direct audit must be scoped to the processing, protect confidential information, and avoid disrupting the Service or exposing another customer's data.

Audits will occur during normal business hours with reasonable advance coordination unless an urgent legal or security circumstance requires otherwise. Customer bears its own audit costs, and any additional cost caused by an unusually broad or repeated audit may be allocated as the applicable agreement permits.

  • Estirpia may satisfy a request through an independent audit report, certification, questionnaire, or comparable evidence where it addresses the requested obligation.
  • Audit information remains confidential and may not be used to test or attack the Service.

11. Precedence and limitations

If this DPA is incorporated into an order or written agreement, it controls over the public Privacy Policy or Terms only to the extent of a conflict about processing Customer Content. The order or written agreement controls commercial terms, scope, fees, and service commitments. Mandatory law controls where it cannot be changed by contract.

Nothing in this DPA expands Customer's rights in Estirpia systems, changes the responsibility of a connected third party, or requires Estirpia to follow an instruction that is unlawful, technically impossible, or inconsistent with the applicable Service without an agreed change.

  • The DPA is processor terms, not a promise that every privacy law applies to every Customer or data subject.
  • If a provision is unenforceable, the remaining provisions continue to the extent permitted by law.

12. Term and contact

This DPA is effective on September 3, 2026 when incorporated into an applicable order or written agreement and continues for the processing term and any permitted retention period. Changes to processing scope, subprocessors, transfer mechanisms, or security measures may require an updated DPA or written notice under the applicable agreement.

Processor questions and assistance requests belong at support@mail.siglata.com. Personal-data incident and vulnerability notices belong at security@mail.siglata.com.

  • Customer should identify its authorized privacy and security contacts in the applicable commercial relationship.
  • The parties will cooperate in good faith to keep processor terms usable as the Service and applicable law evolve.