Legal

Data Processing Addendum

Last updated: May 24, 2026

Draft. This template is structurally complete and reflects how Auctores Helm actually processes data, but it has not yet been reviewed by counsel. Use this as the starting point for procurement discussions. The version each customer signs is countersigned by Auctores Helm and supersedes this draft. Email connect@theauctores.in for an executable PDF.

This Data Processing Addendum (the "DPA") forms part of the Auctores Helm Subscription Agreement (the "Agreement") between Auctores Helm (a product of The Auctores, "Processor" or "Auctores Helm") and the customer identified in the Agreement ("Controller") and applies whenever Auctores Helm processes Controller Personal Data on Controller's behalf.

1. Definitions

Terms not defined here have the meanings given in the GDPR (Regulation (EU) 2016/679), the UK GDPR, and, where applicable, the CCPA. "Personal Data" means any information relating to an identified or identifiable natural person Controller submits to the Auctores Helm service.

2. Scope and Roles

Controller is the data controller of Controller Personal Data processed via the Auctores Helm service. Auctores Helm is the data processor. Each party will comply with the obligations applicable to its role under applicable data protection laws.

3. Processing Details

  • Subject matter: provision of the Auctores Helm service (tasks, time tracking, client management, credential vault, invoicing, client portal, optional AI features).
  • Duration: for the term of the Agreement plus the 30-day soft-delete grace period thereafter.
  • Nature and purpose: hosting, storing, and processing Controller Personal Data solely to provide the service and as documented in the Privacy Policy.
  • Categories of data subjects: Controller's employees, contractors, clients, and stakeholders.
  • Categories of Personal Data: name, email, authentication data, time-tracking entries, task content, comments, file attachments, billing contact info, and any other Personal Data Controller chooses to submit.

4. Sub-processors

Auctores Helm uses the following sub-processors to deliver the service. Controller authorises this list on subscription. Auctores Helm will give at least 30 days' notice (via the public changelog and in-app admin notification) before adding or replacing a sub-processor; Controller may object in writing.

  • Neon, Inc., managed Postgres database hosting (US/EU regions).
  • Vercel Inc., application hosting, edge CDN, serverless functions, blob storage.
  • Anthropic, PBC, AI inference for optional features (Gmail-to-task parsing, daily briefs, summarisation). Disabled at the workspace level by the admin.
  • Resend, Inc., transactional email (invitation, password reset, trial-expiring notices).
  • PayPal Holdings, Inc., subscription billing.
  • Backblaze, Inc., encrypted nightly database backups (US region).

5. Security Measures

Auctores Helm implements technical and organisational measures appropriate to the risk, including: TLS 1.2+ in transit; AES-256 at rest for the credential vault; bcrypt for password hashes; SSO and TOTP 2FA for the operator admin console; least-privilege access controls; per-organisation data isolation enforced at the application layer with automated tests; audit logging of every super-admin action; encrypted nightly backups with 30-day retention; per-workspace AI spend caps and admin-controllable kill switch. The current detailed list is maintained at /security.

6. International Transfers

Where Controller Personal Data is transferred outside the EEA/UK, Auctores Helm relies on the European Commission's Standard Contractual Clauses (Module Two, controller-to-processor) and the UK International Data Transfer Addendum, incorporated by reference. Auctores Helm will not transfer Personal Data to a jurisdiction without an adequacy decision unless an equivalent safeguard applies.

7. Data Subject Rights

Controller is responsible for responding to data subject requests. Auctores Helm will assist Controller by:

  • providing per-user data export (CSV) and per-user erasure (anonymisation of the user record) through the in-app Settings surface;
  • providing organisation-level data export (CSV across tasks, time entries, clients, credentials metadata) on demand;
  • providing organisation-level deletion (soft-delete with 30-day restore window, followed by permanent erasure via the scheduled cron job).

8. Personal Data Breach

Auctores Helm will notify Controller without undue delay and in any event within 72 hours after becoming aware of a Personal Data Breach affecting Controller Personal Data, with the information required by Article 33(3) GDPR to the extent then available. Auctores Helm will provide reasonable assistance in Controller's notifications to supervisory authorities and affected data subjects.

9. Audit Rights

Auctores Helm will make available all information reasonably necessary to demonstrate compliance with Article 28 GDPR, including the Security Measures in Section 5 and an annually-updated security questionnaire on request. Controller may conduct an audit no more than once per year, on 30 days' written notice, during business hours, at Controller's expense, subject to a confidentiality agreement. Third-party audit reports (SOC 2 once available) will be accepted in lieu of direct audits where they cover the relevant controls.

10. Deletion or Return on Termination

On termination of the Agreement, Controller may export its Personal Data via the in-app CSV export for up to 30 days. After that grace period Auctores Helm will permanently erase all Controller Personal Data from the production database (and within 60 days from backups), except where retention is required by law.

11. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement.

12. Governing Law

This DPA is governed by the law specified in the Agreement. Where the Agreement does not specify, English law applies.


Questions or redline requests? Reply to your account email or contact connect@theauctores.in. Auctores Helm will return a countersigned DPA reflecting agreed modifications.

See also: Privacy Policy · Security · Terms of Service