Data Processing Agreement

Last updated: 28 June 2026

This Data Processing Agreement ("DPA") forms part of the Subscriber Agreement between Attaché Desk Ltd ("Attaché Desk", "Processor") and the subscribing organization ("Subscriber", "Controller") and governs the processing of personal data by Attaché Desk on behalf of the Subscriber in connection with the Services.

Where the Subscriber Agreement refers to this DPA, or where Attaché Desk processes personal data on behalf of the Subscriber in providing the Services, this DPA applies. In the event of conflict, this DPA prevails over the Subscriber Agreement with respect to data processing matters.

Capitalized terms not defined here have the meaning given in the Subscriber Agreement or in the Terms of Service.

1. Definitions

For the purposes of this DPA:

"Applicable Data Protection Law" means the GDPR (Regulation (EU) 2016/679) and any supplementary national implementing legislation, together with any applicable data protection law in the Subscriber's jurisdiction.

"Controller" means the Subscriber, as the entity that determines the purposes and means of processing personal data included in Subscriber Content.

"Customer Data" means any personal data contained in or derived from Subscriber Content that the Processor processes on behalf of the Controller under the Subscriber Agreement.

"GDPR" means the General Data Protection Regulation (EU) 2016/679.

"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data.

"Processor" means Attaché Desk Ltd.

"Services" has the meaning given in the Terms of Service.

"Sub-processor" means a third party engaged by the Processor to process Customer Data on the Processor's behalf.

2. Scope and Roles

2.1 Processor acting on Controller's behalf

Attaché Desk processes Customer Data solely in its capacity as data processor acting on the documented instructions of the Controller. The Controller determines the purposes and means of processing Customer Data.

2.2 Subscriber Content

This DPA governs the processing of personal data contained in or derived from Subscriber Content — including drafts, dossiers, counterpart profiles, uploaded documents, agreed-language libraries, and any other material the Controller submits to or generates within the Services. It does not govern Attaché Desk's processing of personal data for its own controller-level purposes (such as account management and billing), which is described in the Privacy Policy.

2.3 Specification of processing

The following describes the processing carried out under this DPA:

Subject matter: Providing AI-assisted diplomatic drafting, research, and document management Services

Duration: For the term of the Subscriber Agreement, subject to the deletion and return provisions in Section 11.

Nature of processing: Storage, retrieval, processing by AI models, analysis, export, and transmission of Customer Data within the Services.

Purpose: To enable the Controller's authorized users to draft, research, review, and manage diplomatic documents and related materials.

Categories of data: Professional correspondence, diplomatic positions, counterpart information, treaty and resolution references, dossier materials; may include personal data of individuals referenced in official communications.

Categories of data subjects: The Controller's authorized users; third-party individuals referenced in Subscriber Content, including diplomatic counterparts and public officials.

3. Controller Instructions

3.1 Documented instructions

Attaché Desk will process Customer Data only on the Controller's documented instructions. The Subscriber Agreement and this DPA constitute the Controller's initial documented instructions. The Controller may issue further instructions in writing consistent with the Subscriber Agreement.

3.2 Compliance with instructions

If Attaché Desk reasonably believes that an instruction would require processing that infringes Applicable Data Protection Law, Attaché Desk will promptly inform the Controller and may suspend execution of that instruction until it receives lawful documented instructions.

3.3 Legal requirements

If Attaché Desk is required by applicable law or a binding governmental order to process Customer Data in a manner inconsistent with the Controller's instructions, Attaché Desk will, to the extent permitted by law, notify the Controller before complying with such requirement.

4. Sub-processors

4.1 Authorized sub-processors

The Controller authorizes Attaché Desk to engage sub-processors to assist in providing the Services. Attaché Desk's current list of approved sub-processors is published at [attachedesk.ai/legal/sub-processors] and is updated when sub-processors are added or removed.

4.2 AI model providers — no-training commitment

Sub-processors engaged as AI model providers (currently including Anthropic, Mistral AI, Google, and Perplexity) are engaged under contractual no-training terms. Customer Data processed through model APIs is not used to train, fine-tune, or improve any AI model. Model API calls are governed by data processing agreements with each provider.

4.3 Notification of changes

Attaché Desk will provide the Controller with at least 14 days' prior written notice of any intended addition or replacement of a sub-processor that processes Customer Data. If the Controller reasonably objects to a new sub-processor, the parties will work in good faith to resolve the objection. If no resolution is reached within 30 days, either party may terminate the affected portion of the Services on written notice, without liability for early termination.

4.4 Sub-processor obligations

Attaché Desk ensures that each sub-processor is bound by data protection obligations at least as protective as those in this DPA. Attaché Desk remains responsible to the Controller for the performance of sub-processors' obligations.

5. Security Measures

Attaché Desk will implement and maintain the technical and organizational security measures described in its Security Policy, including:

  • AES-256 encryption at rest; TLS 1.2 or higher in transit;

  • Tenant isolation via row-level security at the database layer;

  • Principle of least privilege and multi-factor authentication for personnel access;

  • Append-only audit logging;

  • EU data residency for all Customer Data;

  • Annual penetration testing by independent third parties;

  • Contractual no-training terms with all AI model providers;

  • Classification-based routing that disables live external retrieval for Restricted and Confidential sessions.

Attaché Desk may update security measures over time and will not materially reduce the overall security level without prior notice.

6. Data Subject Rights

6.1 Assistance to Controller

Attaché Desk will, taking into account the nature of the processing, provide reasonable assistance to the Controller in responding to data subject rights requests under Applicable Data Protection Law (including requests for access, rectification, erasure, restriction, portability, and objection).

6.2 Forwarding of requests

Where a data subject submits a rights request directly to Attaché Desk in respect of Customer Data processed under this DPA, Attaché Desk will promptly forward it to the Controller and refrain from responding substantively without the Controller's authorization.

7. Data Protection Impact Assessments

Where required by Applicable Data Protection Law, Attaché Desk will provide reasonable assistance to the Controller in conducting data protection impact assessments (DPIAs) and in prior consultations with supervisory authorities, to the extent that such assessment or consultation relates to processing by Attaché Desk under this DPA.

8. Personal Data Breach Notification

8.1 Notification timeline

In the event of a Personal Data Breach affecting Customer Data, Attaché Desk will notify the Controller without undue delay, and in any case within 72 hours of becoming aware of the breach, to the security contact address specified in the Subscriber Agreement.

8.2 Notification content

To the extent available, the notification will include:

  • A description of the nature of the breach, including the categories and approximate number of data subjects affected;

  • The categories and approximate volume of Customer Data affected;

  • The name and contact details of the Attaché Desk data protection contact;

  • The likely consequences of the breach;

  • The measures taken or proposed by Attaché Desk to mitigate or remedy the breach

Where full information is not available at the time of initial notification, Attaché Desk will provide available information promptly and supplement it as soon as practicable.

8.3 Scope limitation

Where Attaché Desk personnel cannot access the content of Customer Data (e.g., due to application-layer encryption), we may not be able to confirm the type or extent of Customer Data affected and will clearly state this limitation.

9. Audits and Documentation

9.1 Documentation

Attaché Desk will maintain records of processing activities carried out under this DPA as required by Article 30(2) GDPR and will make them available to the Controller or its designated auditor on written request.

9.2 Audit rights

Upon at least 30 days' prior written notice, the Controller (or a qualified third-party auditor under confidentiality obligation) may conduct an audit or inspection to verify Attaché Desk's compliance with this DPA, at the Controller's cost and during normal business hours and in a manner that does not unreasonably disrupt Attaché Desk's operations. Audit reports produced by independent third parties engaged by Attaché Desk (where available) satisfy this requirement unless the Controller identifies a reasonable specific concern not addressed by such reports.

10. International Transfers

Where Customer Data is transferred outside the European Economic Area (including in connection with sub-processors or AI model API calls), Attaché Desk ensures that appropriate safeguards are in place in accordance with Chapter V GDPR, including Standard Contractual Clauses adopted by the European Commission. On request, Attaché Desk will provide Controller with a copy of applicable transfer mechanisms.

This DPA, and the Standard Contractual Clauses incorporated herein by reference (Controller-to-Processor module), shall serve as the legal basis for any transfer of Customer Data from the EEA by the Controller to Attaché Desk where required by applicable law.

11. Deletion and Return of Data

Upon termination or expiry of the Subscriber Agreement, Attaché Desk will, at the Controller's election, delete or return all Customer Data within 30 days, unless retention for a longer period is required under applicable law. Attaché Desk will certify deletion in writing upon request. Backup copies will be deleted within Attaché Desk's regular backup rotation cycle, typically within 90 days.

12. Liability

Each party's liability under this DPA is subject to the limitations set out in the Subscriber Agreement and Terms of Service. Nothing in this DPA limits a party's liability to data subjects under Applicable Data Protection Law.

13. Updates to This DPA

Attaché Desk may update this DPA to reflect changes in Applicable Data Protection Law, guidance from supervisory authorities, or material changes to sub-processors. We will provide at least 14 days' notice of material updates.

14. Contact and Data Protection Officer

For data protection enquiries related to this DPA:

Attaché Desk Ltd
Dublin, Ireland
European Union

Data protection contact: privacy@attachedesk.ai

DPA requests and legal matters: legal@attachedesk.ai

To request a countersigned copy of this DPA, or to submit a formal DPA request for enterprise procurement, contact legal@attachedesk.ai.