MAISIGHT REV 01

BLUEPRINT · LEGAL / DPA

Data Processing Addendum

Effective 2026-08-15. Back to the legal pack.

This document has not yet been reviewed by counsel and is not legal advice.

It is drafted from a standard SaaS template. It is not a signed or executed agreement: the operating entity, its notice address, and the Standard Contractual Clauses module selections still need a counsel pass before this can be countersigned. To request an executable copy, email codeblackwell@gmail.com.

This Addendum applies where mAiSight processes personal data on a customer's behalf. It forms part of the Terms of Service.

1. Definitions

"Data Protection Law" means the EU General Data Protection Regulation, the UK GDPR, and any other data protection law that applies to a party's processing under this Addendum. Controller, processor, data subject, personal data, processing, and personal data breach have the meanings given in the GDPR. "Customer Personal Data" means personal data within Customer Content that we process under the Terms.

2. Roles

The customer is the controller of Customer Personal Data. mAiSight is the processor. We act only on the customer's documented instructions, which are: the Terms, this Addendum, the configuration the customer sets in the product, and any further written instruction the customer gives that is consistent with them. If we believe an instruction breaches Data Protection Law, we will tell you.

For our own account and billing records we act as a controller, and the Privacy Policy governs that.

3. Scope of processing

Subject matter Provision of the mAiSight documentation reading layer: ingestion, glossary extraction and review, publishing, and aggregate reading analytics.
Duration The term of the customer's subscription, plus the deletion window in section 9.
Nature and purpose Storage, parsing, machine extraction of terminology, rendering, and aggregation — solely to deliver the Service.
Types of personal data Any personal data the customer chooses to include in submitted documentation, plus customer account contact details. The Service is not designed to process personal data and customers are asked not to submit it as document content (Acceptable Use Policy).
Categories of data subject The customer's personnel, and any individual referenced in submitted documentation. Readers of published documentation are not a category here, because no personal data about them is collected — see section 4.
Special category data None. The Service must not be used for it.

4. Reader analytics are not personal data

The widget sets no cookies, stores no persistent identifier, and does not retain IP addresses, raw User-Agent strings, or Referer headers. Reading events are aggregated on write and cannot be attributed to an individual; the dashboard has no access to individual events. We therefore do not consider reader analytics to be personal data, and there is no reader-level record for us to retrieve or erase in response to a data subject request.

5. Our obligations

6. Subprocessors

The customer gives general written authorization for us to engage subprocessors. The current list, with the purpose and region of each, is published and dated at /legal/subprocessors.

We will give 30 days' notice before adding or replacing a subprocessor. The customer may object on reasonable data protection grounds within that window; if we cannot resolve the objection, the customer may terminate the affected part of the Service and receive a pro-rata refund of the unused prepaid term. We remain liable for our subprocessors' acts and omissions as for our own, and impose data protection obligations on them no less protective than these.

Where the customer configures extraction against a model it hosts itself, no model-provider subprocessor is engaged for that customer's extraction.

7. International transfers

Application data is hosted in the European Union. Some subprocessors operate in the United States, as identified on the subprocessors page. Where personal data is transferred outside the EEA or UK, the transfer relies on the European Commission's Standard Contractual Clauses, with the UK Addendum where the UK GDPR applies, together with any supplementary measures the transfer assessment identifies. The specific SCC modules and annexes are to be completed with counsel before execution.

8. Security

We maintain measures appropriate to the risk, including: encryption of data in transit; encryption at rest of customer-issued source credentials, held separately from their decryption key and rotated on a fixed cadence; access to production restricted to personnel who need it; redaction of secrets from logs; and destruction of credentials when a source is deleted. The threat model behind these choices, and its explicit limits, is published at /security.

We hold no third-party security certification. mAiSight is not SOC 2 audited and not ISO 27001 certified, and this Addendum does not represent otherwise.

9. Breach notification

We will notify the customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe the nature of the breach, the categories and approximate number of records affected so far as known, the likely consequences, and the measures taken or proposed. We will assist the customer with its own notification obligations.

10. Deletion and return

On termination the customer may export Customer Content for 30 days. After that we delete it, with backups cycling out on their normal schedule, except where retention is required by law. Deleting a document in the product removes it and its aggregates. On written request we will confirm deletion.

11. Audit

On reasonable written notice, and no more than once a year unless required by a supervisory authority or following a breach, we will respond to a reasonable security questionnaire and make available documentation sufficient to demonstrate compliance with this Addendum. Given our size we do not offer on-site audits by default; where Data Protection Law entitles the customer to one, we will agree a proportionate arrangement in good faith.

12. Liability and precedence

Each party's liability under this Addendum is subject to the limitations in the Terms. In the event of conflict, this Addendum prevails over the Terms as to the processing of Customer Personal Data, and the Standard Contractual Clauses prevail over both.

13. Requesting a signed copy

Email codeblackwell@gmail.com with your entity name and notice address. Note the banner at the top of this page: a countersigned version needs the counsel pass to be complete first, and we will tell you where that stands rather than stalling.