The data processing agreement
The legal framework of processing
It is not a commercial accessory. It is the condition of entry into the working relationship and, in our view, the minimum condition under which a professional bound by professional secrecy can outsource the processing of a case file.
The roles of the parties
You are the data controller. SCANALYTIX.AI is the processor and processes exclusively on your documented instructions. We do not use the data for our own purposes, we do not use it to train AI models, and we do not make it available to any third party not authorised by contract.
The processing agreement
Signed before the first document is handed over, in the form of Annex 5. It covers the nature and purpose of processing, the categories of data and data subjects, duration, security measures, sub-processors, assistance with data-subject rights, incident notification, audit and deletion at termination. The assessment stage and pilot projects fall under the same agreement: signature precedes them, and the Client receives the handover reports and certificates for each stage.
Who actually accesses the content
Data is encrypted in transit (TLS 1.2/1.3) and at rest (AES-256). The encryption keys of the final archive are held by your organisation; without them, stored content is unreadable to any third party. Operator access is least-privilege, with RBAC and multi-factor authentication, logged by name in the audit trail, available in full on request.
Sub-processors
We use no undeclared sub-processors. The full list, with each one’s role and processing location, is annexed to the contract (Annex C). Using an external language model (AI) is optional and your decision. You choose the model from a list of models that cumulatively meet three conditions: the provider is named in the contract as a sub-processor, processing takes place on infrastructure in the European Union, and the data is not used for training. Personal or free accounts of consumer AI applications do not meet these conditions. Models currently available: Claude (Anthropic) and Gemini (Google). We recommend pseudonymisation before any dialogue with an external model.
Retention and deletion
Raw data is kept for the duration of the project and a further 30 days after delivery, for remediation. On expiry or at your request it is permanently deleted, with a deletion certificate. Physical documents are returned against a handover report, or destroyed to DIN 66399, protection class 3, with a destruction certificate.
Conflict of interest
We keep a register of the cases and parties we have served; we check for conflicts before accepting any new project and notify you in writing of any overlap; we do not accept a case in which we have served the opposing party without the written consent of both parties. Technical separation between files is effective: isolated instances, distinct keys, teams with no cross-access.
Your relationship with your own client
The data processing agreement governs the relationship between you and SCANALYTIX.AI. Your obligations towards your own client (professional secrecy and informing the client about the use of a processor and of AI tools) remain yours. To support you, we provide, on request, a model clause for the legal services agreement and a model client information notice.
Information-security procedures are built on the ISO/IEC 27001 structure and on GDPR requirements.
Annex 1
Secure transfer of physical and digital documents
Applies exclusively to delivery Model B. A secure transfer means an unbroken chain of custody: data (whatever its format) is not compromised, lost or accessed without authorisation at any point: collection, processing, storage and destruction/return.
The physical archive
Inventory and sealing
Before leaving the client’s premises, documents are inventoried and placed in special archive boxes closed with uniquely serialised, tamper-evident seals.
Secure transport
Dedicated vehicles with GPS monitoring and alarm systems. Drivers and handling staff are vetted and have signed confidentiality agreements.
Chain of custody
At every step (client handover, carrier, reception) handover reports are signed and the integrity of seals and serial numbers is verified.
The scanning area
Boxes are stored and unsealed only in restricted-access areas (access cards or biometrics), under 24/7 video surveillance.
Equipment memory
Scanners are configured to wipe their cache memory automatically after every session.
The digital archive
Encrypted transfer channels
No e-mail attachments or public platforms. Exclusively SFTP, secure APIs or a dedicated client portal, encrypted with TLS 1.2/1.3.
Encryption in transit and at rest
Data is encrypted during transfer and in storage (AES-256): even if a server is compromised, files cannot be read without the decryption key.
Access control
Least privilege (RBAC): each operator sees only the data required for their task. Authentication is mandatory through MFA.
Traceability
Every action (who uploaded, who viewed, who ran OCR/AI) is recorded automatically in immutable system logs.
Closing the cycle
Return or secure destruction
Physical documents are returned against a handover report or shredded to DIN 66399, protection class 3, with a destruction certificate.
Digital wiping
Raw digital data is permanently deleted according to the agreed retention policies, with a deletion certificate issued.
Annex 2
AUDIT TRAIL procedures
The audit trail is a chronological, secure and unalterable record of every action, decision and change a document goes through, from the moment it enters the system until the data is exported. It explains how the final result was reached and separates decisions made by the algorithm from those made by human users.
Ingestion
The exact moment the document entered the system, its source and who uploaded it.
AI/OCR extraction
Which fields the algorithm extracted and the confidence level for each field.
Human intervention
What the operator changed (old value vs. new value) the user’s identity and the moment of the change.
Document-level actions
Deletions, page additions, rotations, splits or merges of files.
Queries
Who queried the case file, when and what they asked.
Export
The moment the final structured data was sent onward and who triggered the action.
Storage, retention and destruction
Entry into the archive, the retention period applied, the moment of deletion and the certificate issued.
Liability, insurance and continuity
What happens if something goes wrong, settled in the contract, not afterwards.
Limit of liability
Set by contract, relative to the value of the project.
Professional liability insurance
The insurer, policy number and ceiling are named in the contract, relative to the value of the project.
Business continuity
Should SCANALYTIX.AI cease operations, your data is returned in full, in original and processed formats, within 30 days, and our copies are deleted with a certificate. As the encryption keys are yours, the archive remains accessible regardless of our situation.
Provider dependency
Tiers 0–2 depend on no external language-model provider. If such a provider becomes unavailable, Tiers 3 and 4 are affected, and the processed archive remains fully usable.
The encryption keys are yours: the archive remains accessible to your organisation, regardless of our situation.