Data processing agreement
You are the controller of the personal data inside the documents you upload; we are your processor and act only on your instructions. This page is that agreement, and it applies automatically — no signature needed.
Last updated . Applies to frisket.robomiri.com, operated by Robomiri.
1. Scope and roles
This agreement forms part of the terms of service and applies whenever we process personal data on your behalf. You are the controller. We are the processor. Where we determine our own purposes — your account and billing records, security logs — we are a controller and the privacy policy governs instead.
It applies automatically to every customer, so there is nothing to sign. If your organisation needs a countersigned copy on its own paper, email privacy@robomiri.com.
2. Subject matter, duration, nature and purpose
- Subject matter: processing of documents you submit, to produce the output the product exists to produce.
- Duration: for as long as your account is active, plus the retention windows in section 6.
- Nature and purpose: storage, extraction, conversion, validation, generation and delivery of results — nothing else.
- Types of personal data: whatever your documents contain. Typically names, addresses, account identifiers, transaction descriptions, and case or matter references.
- Categories of data subjects: your clients, customers, employees and counterparties, as determined by you.
3. Our obligations
- We process personal data only on your documented instructions, which include using the service as intended.
- We ensure that people authorised to process it are bound by confidentiality.
- We implement the technical and organisational measures in section 5.
- We assist you, so far as we reasonably can, with data-subject requests, breach notification, and data protection impact assessments.
- We tell you without undue delay if we become aware of a personal data breach affecting your data, with what we know and what we are doing about it.
- We tell you if an instruction from you appears to infringe data protection law, and we may pause that processing until it is resolved.
4. Subprocessors
You give general authorisation for the subprocessors below. Each is bound by written terms no less protective than this agreement, and we remain liable to you for their performance.
| Subprocessor | What they do for us | Where | Can they see document content? |
|---|---|---|---|
| Hetzner Online GmbH | Application hosting, database, and object storage | Germany (EU) | Yes |
| Stripe Payments Europe, Ltd. | Payment processing and billing records | Ireland (EU), with transfers to the United States under Stripe’s SCCs | No |
| Anthropic PBC | Model inference for extraction steps that need it | United States, under standard contractual clauses | Yes |
We publish additions on this page at least 30 days before the new subprocessor begins processing. If you reasonably object on data protection grounds, tell us within those 30 days; if we cannot resolve it, you may terminate the affected service and receive a pro-rata refund.
Transfers outside the UK and EEA are made under the European Commission’s standard contractual clauses together with the UK International Data Transfer Addendum, with a transfer risk assessment on file.
5. Security measures
- Encryption in transit for all traffic, and encryption at rest for stored documents.
- Access to production limited to named operators, over authenticated channels, with per-request identifiers that make access traceable.
- Documents reachable only through short-lived signed links scoped to the requesting account.
- Automated deletion on the schedule in section 6, run as a job rather than by hand.
- Encrypted backups with a fixed rotation, and a restore drill that is actually run.
- Separation of environments; production data is not copied into development.
6. Deletion and return
Documents and results are deleted automatically on the windows below. You may delete them sooner from your account, and on termination you may export what you still need before the windows expire.
| What | Deleted after | Why that long |
|---|---|---|
| Files you upload | 2 hours | A job has to be able to read the file while it runs, and you have to be able to retry a failed conversion without re-uploading. Neither needs longer. |
| Converted files and generated documents | 24 hours | Long enough that a download link still works the next morning, short enough that we are not a copy of your records. |
| Verification reports and their reference numbers | 30 days | A report is evidence: whoever you sent it to must be able to check it against the reference number for a reasonable period. Reports contain the check result and the document hash, not the document. |
Uploaded files are removed within 2 hours of the job finishing, and copies in encrypted backups expire with the backup, within 30 days.
7. Audits
We will answer reasonable written questions about our processing and provide the documentation we hold. An on-site audit is available once in any twelve-month period, on 30 days’ notice, at your cost, subject to confidentiality and to not disrupting other customers.
8. Precedence
If this agreement conflicts with the terms of service on the processing of personal data, this agreement wins. It is governed by the law of England and Wales.