AnchorMark

Data Processing Addendum (summary)

Last updated: May 1, 2026. Version 1.0. We notify customers of material changes by email and update this date.

This page summarizes our Data Processing Addendum (DPA). The executable DPA, including Standard Contractual Clauses and the UK International Data Transfer Addendum, is available on request from [email protected] and is offered to all paying customers.

Roles

For Customer Data, the customer is the controller and AnchorMark is the processor. For account, billing, and usage data, AnchorMark is an independent controller as described in our Privacy Policy.

Scope and subject matter

We process personal data only to provide the Service in accordance with the customer's documented instructions, the Order, and the DPA.

Sub-processors

Our current sub-processors are listed at /sub-processors. We notify customers of new sub-processors at least 30 days in advance and offer a reasonable objection mechanism.

International transfers

Where personal data is transferred outside the EEA, UK, or Switzerland, we rely on the EU SCCs (modules as appropriate) and the UK IDTA, plus supplementary technical and organizational measures.

Security

TLS 1.2+ in transit, AES-256 at rest, KMS-managed keys, tenant isolation enforced at the route/query/row level, immutable audit logging, role-based access, and documented incident response. Annex II of the DPA describes our security measures in detail.

Data subject rights

We assist controllers in responding to data subject requests through in-product self-serve tools and, where needed, manual support.

Breach notification

We notify customers of a personal-data breach without undue delay and in any case within 72 hours of becoming aware, with the information required by Article 33 GDPR to the extent available.

Audit

We provide our latest third-party audit report on request under NDA. Customers may conduct on-site audits no more than once per 12 months with reasonable notice and in coordination with our team.

Return and deletion

On termination we return or delete Customer Data within 30 days, subject to legal retention obligations, after which residual backups are rotated within 35 days.