CDR API terms of service


The terms behind our Content Disarm and Reconstruction API - written to be read, not buried in small print.


About this agreement

These terms of service (the "Agreement") set out the terms on which Red Eagle Tech Ltd provides its Content Disarm and Reconstruction API, purchased online at redeagle.tech/products/content-disarm-reconstruct-api. Red Eagle Tech Ltd is registered in England and Wales with company number 15496321 and VAT registration number 470867070 (registered office: Prospect House, Suite 26, 2 Athenaeum Road, London, N20 9AE), and is registered with the Information Commissioner's Office under reference ZB763188.

These terms are effective from 30 July 2026 (version 1.0).

In this Agreement, "we", "us" and "our" mean Red Eagle Tech Ltd, and "you" and "your" mean the business customer that registered the account. We have deliberately written this Agreement in plain English. It is still a contract, but you should not need a law degree to understand what you are buying and what we have promised.


Contents


1. The parties, definitions and interpretation

1.1 This Agreement is between Red Eagle Tech Ltd and the business customer named on the account registered in the account portal.

1.2 In this Agreement, the following words have the following meanings:

  • "Service" - our Content Disarm and Reconstruction API: the hosted API that accepts Submissions, processes them to remove potentially malicious content, and returns Sanitised Output, together with the account portal and the Documentation.

  • "Submission" - a file you send to the Service for sanitisation.

  • "Accepted Submission" - a Submission the Service accepts for processing, acknowledged by a success response from the API. Submissions the API rejects (for example for failed validation, failed authentication, an exhausted allowance or rate limiting) are not Accepted Submissions.

  • "Sanitised Output" - the processed copy of a Submission that the Service makes available for download.

  • "Credit" - prepaid balance purchased for pay-as-you-go use of the Service, denominated in pounds sterling and drawn down per Accepted Submission.

  • "Plan" - a monthly subscription size for the Service (each with an included allowance of documents), or the pay-as-you-go option, as published on the Product Page.

  • "Product Page" - the CDR API page at redeagle.tech/products/content-disarm-reconstruct-api, including its published pricing, allowances, rate limits and file-size limits.

  • "Documentation" - the technical documentation for the Service published by us, including the API reference and integration guides.

  • "Customer Data" - the content of your Submissions and Sanitised Output, and any other data belonging to you that we process in providing the Service.

  • "Malicious Content" - software or content designed to harm, exploit or gain unauthorised access to systems or data, including malware, exploits and weaponised documents.

1.3 Headings are for convenience and do not affect interpretation. "Including" means "including without limitation". "In writing" includes email. References to legislation are to that legislation as amended or re-enacted.


2. How this agreement fits together

2.1 This Agreement consists of: (a) these terms (the body of the Agreement); (b) Schedule 1 (data processing); and (c) the Product Page's published pricing, allowances, rate limits and file-size limits as at the date of each purchase, which are incorporated by reference.

2.2 If there is any conflict, the order of precedence is: Schedule 1 first (for data protection matters), then the body of this Agreement, then the incorporated Product Page terms.

2.3 Marketing copy on our website is not part of this Agreement, except the Product Page elements expressly incorporated by clause 2.1. The Documentation describes how the Service works and how to integrate with it; it is guidance, not a promise of specific results, except where this Agreement expressly says otherwise.


3. Formation and acceptance - business customers only

3.1 A binding contract forms when you register an account and tick the box confirming you accept this Agreement (including the data processing terms in Schedule 1), or when you first use the Service, whichever happens first. This Agreement was available to you before you registered, and the version you accepted is recorded against your account.

3.2 The Service is sold to business customers only. By registering or using the Service, you warrant that:

  • you are acting wholly or mainly for the purposes of a business, trade, craft or profession, and not as a consumer; and

  • the person registering the account has authority to bind the business named on it.

3.3 Because this is a business-to-business contract, consumer protection legislation (including the Consumer Rights Act 2015) does not apply to it. If you are unsure whether you qualify as a business customer, contact us before registering.


4. The service

4.1 The Service accepts document Submissions over a REST API, processes them using Content Disarm and Reconstruction (CDR) technology to remove potentially malicious active content, and makes a Sanitised Output available to you via a time-limited download link. The supported file types, file-size limits and rate limits for your Plan are published on the Product Page and in the Documentation.

4.2 The Service is self-service: you integrate against the API using the Documentation, and you manage your Plan, Credit and billing through the account portal.

4.3 Sanitisation is performed using a specialist third-party CDR engine operating as our subprocessor, as set out in Schedule 1. We remain fully responsible to you for the Service.

4.4 Submissions and Sanitised Output are held only transiently: Sanitised Output is retained for 24 hours from completion so you can collect it (and you can delete it sooner via the API), download links are valid for 24 hours from issue, and submitted content is deleted once processing completes or fails. Collect your Sanitised Output promptly - after the retention period it is gone, and we cannot recover it (see clause 13.1).


5. Your account and API credentials

5.1 You must keep your registration details accurate and current, and nominate at least one contact email address that is monitored - it is where we send billing, service and legal notices.

5.2 API access uses per-organisation credentials issued through the account portal. You are responsible for keeping your credentials confidential and secure, and for all use of the Service under them, whether or not you authorised it, until you tell us they are compromised. If you believe a credential is compromised, revoke or rotate it in the account portal immediately and tell us.

5.3 You must not share credentials outside your organisation, use another customer's credentials, or spread usage across multiple accounts or credentials to circumvent rate limits or allowances.


6. Acceptable use - malware submissions are the point

6.1 Submitting files that contain Malicious Content is not misuse of the Service - it is what the Service is for. You may submit files that contain, or that you suspect contain, Malicious Content, for the purpose of having them analysed and sanitised. You do not need to warn us first, and doing so is not a breach of this Agreement.

6.2 That permission has two conditions:

  • You must have the right to submit the file. Only submit files that you own, control or are otherwise authorised to process, and whose submission to us (and processing under Schedule 1) does not breach any law, third-party right or duty of confidence that binds you.

  • Your purpose must be defensive. Submissions must be made to detect, neutralise or mitigate threats in content you handle in the course of your business - not to develop, test or improve Malicious Content.

6.3 You must not:

  • use the Service, or its outputs, to create, refine, test or improve Malicious Content, or to probe how Malicious Content can evade CDR, anti-virus or other security controls;

  • use the Service to distribute Malicious Content to any third party, or hold the Service out as a source of "safe" files while knowingly distributing unsanitised or weaponised content;

  • attack, disrupt, probe or interfere with the Service or its infrastructure, or attempt to access another customer's data, account or Submissions;

  • circumvent or attempt to circumvent authentication, metering, rate limits or allowance enforcement (see also clause 5.3);

  • resell or sublicense bare access to the API as a standalone sanitisation service without our prior written agreement - though you may integrate the Service into your own applications, products and workflows, including ones that serve your own customers; or

  • use the Service in breach of any applicable law, including computer misuse, data protection, export control and sanctions law.

6.4 We may monitor usage patterns and service logs to detect abuse, investigate suspected breaches of this clause, and suspend or terminate access under clause 20. Where we reasonably believe the Service is being used to further unlawful activity, we may report it to law enforcement or relevant authorities.

6.5 Rate limits protect the Service for everyone. Requests over your Plan's rate limit are throttled (the API returns a rate-limiting response); being throttled is not a breach of this Agreement, but deliberately engineering around throttling is.


7. Plans, credit and payment

7.1 The Service is sold in the Plans published on the Product Page: monthly subscription sizes, each with an included allowance of documents per billing period, and a pay-as-you-go option using prepaid Credit. Current prices, allowances, per-document rates, rate limits and file-size limits are on the Product Page - we publish the whole price card, deliberately.

7.2 Subscriptions run on a rolling monthly basis with no minimum term, billed monthly in advance. You can cancel, upgrade or downgrade at any time in the account portal; cancellation takes effect at the end of the current billing period, and we do not refund the remainder of a part-used period. Unused allowance does not roll over to the next period.

7.3 When a subscription's included allowance is used up, further Submissions are refused until the next billing period starts (the API tells you why), unless you upgrade or we have agreed an overage option for your Plan. We never silently bill for usage beyond what you have bought.

7.4 Pay-as-you-go uses prepaid Credit, topped up through the account portal (minimum top-up £10). Each Accepted Submission draws down Credit at the pay-as-you-go rate current at the time of that Submission. When your Credit reaches zero, further Submissions are refused until you top up - the Service hard-stops rather than going into debt. You can optionally enable automatic top-ups with your own threshold and daily cap.

7.5 Payment is collected by our payment provider, Stripe, using the payment method you provide in the account portal. All prices exclude VAT, which is charged at the applicable rate. VAT invoices are available in the account portal.

7.6 If a subscription payment fails, Stripe retries it automatically and we email you. If your account remains unpaid, we may suspend the Service under clause 20.4 and, if it is still unpaid 30 days after the first failed payment, terminate this Agreement. We may charge statutory interest and compensation on overdue sums under the Late Payment of Commercial Debts (Interest) Act 1998.


8. The billable unit and failure credits

8.1 The billable unit is one Accepted Submission. One document accepted for processing costs one document's price - there are no credit multipliers, minimum batch sizes or per-megabyte surcharges. Submissions the API rejects (failed validation, failed authentication, an exhausted allowance or Credit balance, or rate limiting) are not billed.

8.2 If we fail, you don't pay. If an Accepted Submission fails to process because of a fault on our side (including an internal error in the Service or our processing chain), it is not chargeable: the document is automatically credited back to your allowance or Credit balance. You do not need to ask.

8.3 A Submission that cannot be processed because of the file itself - for example a corrupt, truncated or password-protected file that passes initial validation but cannot be sanitised - is not a fault on our side, and remains chargeable. The same applies where the Service judges a file too dangerous to reconstruct: the API tells you a threat was detected, no file is released, and the Submission remains chargeable - the analysis is the work you paid for. The API's response taxonomy in the Documentation tells you which outcome occurred.

8.4 The automatic credit in clause 8.2 is your sole and exclusive remedy for the charge relating to a failed Submission. It does not limit your other rights under this Agreement, including under clauses 15 and 20, in respect of matters beyond the charge itself.

8.5 If you believe your usage has been metered incorrectly, tell us within 60 days of the relevant billing period and we will investigate promptly and correct any error. Our metering records are authoritative absent manifest error.


9. Credit expiry and refunds

9.1 Prepaid Credit is valid for 12 months from the date of the purchase that added it. Credit is consumed oldest-first. Any Credit unused 12 months after its purchase automatically expires and is forfeited, and you will not be entitled to a refund or compensation for expired Credit. We state this here, at the point of purchase and in the account portal, because expiry terms should never be a surprise.

9.2 Credit is a prepaid entitlement to use the Service. It is not stored value, a deposit, or a consumer gift voucher; it cannot be transferred to another account, exchanged for cash, or used for anything other than the Service.

9.3 Except as expressly stated in this Agreement or required by law, all fees and charges (including Credit purchases and subscription fees) are non-refundable.

9.4 There are two exceptions in your favour. If we terminate this Agreement for convenience under clause 20.3, or discontinue the Service, we will refund your unexpired, unused Credit in full. And if you terminate for our material breach under clause 20.5, we will refund your unexpired, unused Credit and the pro-rata unused portion of any prepaid subscription period.

9.5 If you close your account or we terminate for your breach, unused Credit is forfeited on termination.


10. Price changes

10.1 We may change our prices by giving at least 30 days' notice by email. For subscriptions, a change takes effect from your next billing period after the notice period ends - never part-way through a period you have already paid for. For pay-as-you-go, a rate change applies to Submissions made after it takes effect; Credit you already hold keeps its value in pounds and simply buys documents at the new rate.

10.2 We will not increase the price of your Plan more than once in any 12-month period. If you do not wish to accept a price change, you may cancel under clause 7.2 so that your Plan ends before the change takes effect - because you can leave at any time, your right to leave is your protection.


11. Availability, support and maintenance

11.1 We will use commercially reasonable efforts to make the Service available 24 hours a day, 7 days a week, and to restore it promptly when it is not. However, this Agreement does not include a contractual uptime guarantee or service-level agreement: the Service is a self-service product, and a missed availability expectation is not of itself a breach of this Agreement.

11.2 We may introduce service-level commitments for particular Plans in future. If we do, they will be published as separate terms and will apply only to the Plans and customers they expressly name.

11.3 We may temporarily suspend or limit the Service for scheduled maintenance, upgrades or emergency security work. For scheduled maintenance expected to cause material disruption, we will give notice by email where reasonably practicable and schedule it outside UK business hours where we can.

11.4 Support is provided by email through the support contact published on the Product Page, during UK business hours. We publish our support response expectations on the Product Page; like our availability efforts, they are honest targets, not contractual guarantees.


12. Service changes and API versioning

12.1 We may modify and improve the Service over time, including its features, infrastructure, security controls and the third-party engine used for sanitisation (subject to the subprocessor change process in Schedule 1 where personal data is affected).

12.2 The API is versioned. We will not make breaking changes to a published API version. If we retire an API version, we will give at least 6 months' notice by email before it stops working, and the Documentation will describe the migration path.

12.3 If a change we make materially reduces the overall functionality of the Service for your Plan, you may terminate this Agreement and clause 9.4's refund position applies as if we had terminated for convenience.


13. Your obligations

13.1 You agree to:

  • retrieve your Sanitised Output within the retention window in clause 4.4 - the Service is a processing pipeline, not a storage service, and we cannot recover content after it is deleted;

  • only submit files you have the right to submit (clause 6.2), and comply with the laws that apply to your use of the Service, including data protection law in respect of any personal data your files contain;

  • keep your own copies of original files - sanitisation transforms documents, and the original is your only authoritative copy;

  • maintain your own layered security controls (see clause 14.3 - the Service is one defensive layer, not a substitute for endpoint protection, backups or governance);

  • keep your account details, contact email and payment method current; and

  • give us accurate, timely information if we ask for it in connection with suspected abuse, a security incident or a billing query.

13.2 We may rely on instructions and API calls made with your credentials as authorised by you (clause 5.2).


14. Warranties and what we can't promise

14.1 We warrant that the Service will be provided with reasonable skill and care, consistent with good industry practice.

14.2 All other warranties, conditions and terms implied by statute or common law are excluded to the fullest extent permitted by law. This does not affect the statutory rights referred to in clause 15.1.

14.3 Important - no sanitisation guarantee.

Content Disarm and Reconstruction substantially reduces the risk carried by document files, but no CDR process, and no security service, can guarantee that every threat is detected, neutralised or removed. We do not warrant that Sanitised Output is free of Malicious Content, that every Submission can be sanitised, or that sanitisation preserves every feature of every document. The Service is one layer of a defence-in-depth strategy and is not a substitute for your own endpoint protection, security governance, insurance and business continuity arrangements. We flag this prominently because it is important, not because we plan to hide behind it.


15. Limits on liability

15.1 Nothing in this Agreement excludes or limits either party's liability for: death or personal injury caused by negligence; fraud or fraudulent misrepresentation; or any other liability that cannot lawfully be excluded or limited.

15.2 Subject to clause 15.1, neither party is liable to the other for: loss of profits, revenue, business, goodwill or anticipated savings; or any indirect or consequential loss, in each case arising under or in connection with this Agreement, whether in contract, tort (including negligence), breach of statutory duty or otherwise.

15.3 Subject to clause 15.1, we are not liable for loss of Customer Data where the loss results from your failure to retrieve Sanitised Output within the retention window (clause 4.4) or to keep your own copies of original files (clause 13.1).

15.4 Subject to clauses 15.1 and 15.5, each party's total aggregate liability arising under or in connection with this Agreement in any 12-month period is capped at the greater of (a) 125% of the fees you paid or which were payable in the 12 months preceding the first event giving rise to liability, and (b) £10,000. This general cap applies to all liability except our liability for data protection and loss of personal data, which has its own, higher cap in clause 15.5.

15.5 Our total aggregate liability for breaches of Schedule 1 (data processing) and for loss of personal data is limited to the amount we actually recover under our cyber-insurance policy in respect of the claim, subject to an overall maximum of £500,000 and a minimum of the general cap in clause 15.4. This data-protection cap is higher than, and applies in place of, the general cap for such claims. It is aligned with the £500,000 cyber-insurance cover we maintain, alongside professional indemnity insurance of not less than £500,000 (certificates available on request).

15.6 The automatic failure credit in clause 8.2 is your exclusive remedy for the charge relating to a failed Submission, as set out in clause 8.4.


16. Indemnities

16.1 We will indemnify you against third-party claims that the Service itself (excluding your Submissions and anything you supply) infringes their intellectual property rights.

16.2 You will indemnify us against third-party claims and regulatory penalties arising from: Submissions you had no right to submit; your breach of the acceptable use rules in clause 6; or your use of the Service or its outputs in breach of applicable law.

16.3 The party claiming an indemnity must notify the other promptly, allow the other party to control the defence and settlement of the claim, and take reasonable steps to mitigate its losses.


17. Data protection

17.1 Your Submissions may contain personal data. Where they do, you are the controller (or a processor acting for your own customers) and we are your processor, and Schedule 1 (the data processing terms) applies. Schedule 1 contains the terms required by Article 28(3) UK GDPR, including the subprocessors we use and where processing happens.

17.2 We are a controller in our own right for the personal data we process to run our business - your account and billing details, our correspondence with you, and our service and usage records. Our privacy policy describes that processing.

17.3 Each party will comply with applicable data protection law, including UK GDPR and the Data Protection Act 2018, in performing this Agreement.

17.4 We do not use the content of your Submissions or Sanitised Output for any purpose other than providing the Service as described in Schedule 1. We do not use your file content to train models, and we do not share it with anyone other than the subprocessors listed in Schedule 1.


18. Confidentiality

18.1 Each party will keep the other's confidential information confidential, use it only for the purposes of this Agreement, and disclose it only to those of its people who need it and are bound by equivalent confidentiality duties. Your Submissions and Sanitised Output are your confidential information.

18.2 These duties do not apply to information that: is or becomes public through no fault of the receiving party; was lawfully known before disclosure; is lawfully received from a third party without duty of confidence; or must be disclosed by law or a regulator (with notice to the other party where lawful).

18.3 Confidentiality obligations survive for 5 years after this Agreement ends, and for trade secrets, for as long as they remain trade secrets.


19. Intellectual property

19.1 You own your files. You retain all intellectual property rights in your Submissions, and you own the Sanitised Output. We claim no rights in the content of your documents.

19.2 You grant us a limited licence to process your Submissions and produce Sanitised Output solely to provide the Service, keep it secure, prevent abuse and comply with law - including passing Submissions through the subprocessing chain in Schedule 1. The licence ends when the content is deleted under clause 4.4.

19.3 We retain all intellectual property rights in the Service: the API, the account portal, the Documentation, our configurations, methods and know-how. We licence them to you for the term of this Agreement, for the purpose of using the Service. You must not reverse engineer the Service except to the extent the law allows despite this clause.

19.4 We may produce and use aggregated, anonymised statistics about Service usage (volumes, file types, processing outcomes and performance). These never include the content of your files and are not personal data.

19.5 If you give us feedback or suggestions about the Service, we may use them without restriction or payment; this does not transfer any of your other rights.


20. Suspension and termination

20.1 You may cancel a subscription at any time under clause 7.2, and may close your account at any time in the account portal. No notice period, no exit fee. Clause 9.5 explains what happens to unused Credit.

20.2 On closure or termination, in-flight Submissions are completed or abandoned, remaining Sanitised Output stays collectable for the remainder of its retention window (clause 4.4) unless you ask us to delete it sooner, and Schedule 1's end-of-processing obligations apply.

20.3 We may terminate for convenience on at least 60 days' written notice, expiring no earlier than the end of your current billing period. If we do, clause 9.4's refund position applies.

20.4 We may suspend some or all of the Service, with as much notice as reasonably practicable, where: your account is unpaid under clause 7.6; suspension is reasonably necessary to contain a security incident or protect other customers; or we reasonably suspect a material breach of the acceptable use rules in clause 6. We lift suspensions as soon as the cause is resolved.

20.5 Either party may terminate immediately on written notice if the other: commits a material breach and fails to remedy it within 14 days of a written notice describing the breach (or the breach is incapable of remedy); or becomes insolvent, enters administration or liquidation, or suffers any analogous event. Weaponisation of the Service (clause 6.3) is a material breach incapable of remedy.

20.6 Clauses that by their nature should survive termination do so, including clauses 8.5, 9, 15, 16, 18, 19, 26 and 27 and Schedule 1's end-of-processing obligations.


21. Events beyond our control

21.1 Neither party is liable for failure or delay in performing its obligations (other than payment obligations) caused by events beyond its reasonable control, including power or telecommunications failure, natural disaster, epidemic, civil unrest, industrial action, or failure of a cloud platform or subprocessor service beyond that party's reasonable control.

21.2 The affected party must notify the other promptly, use reasonable endeavours to mitigate, and resume performance as soon as it can. If a force majeure event continues for more than 30 days, either party may terminate on written notice; if we terminate under this clause, clause 9.4's refund position applies.


22. Changes to these terms

22.1 We may update this Agreement from time to time. For material changes we will give you at least 30 days' notice by email (not merely a website update) before the change takes effect.

22.2 If you do not accept a material change, you may cancel under clause 7.2 (and, for pay-as-you-go, stop using the Service) so that the change never applies to you. Continuing to use the Service after the effective date is acceptance of the updated terms.

22.3 Changes never reduce what you have already paid for: a change materially reducing the Service during a period you have prepaid entitles you to terminate and receive a pro-rata refund of the unused prepaid period, and clause 9's expiry rules cannot be shortened for Credit you already hold.


23. Export control and sanctions

23.1 You must not use the Service in breach of applicable export control or sanctions law, and you warrant that you are not, and are not acting for, a person or entity subject to UK, EU, UN or US sanctions, or located in a country subject to comprehensive sanctions.

23.2 We may suspend or terminate the Service immediately if continuing to provide it would put us in breach of export control or sanctions law.


24. Assignment and subcontracting

24.1 We may subcontract elements of the Service (the subprocessor chain in Schedule 1 is subcontracting in this sense), but we remain fully responsible to you for our subcontractors' performance.

24.2 Neither party may assign this Agreement without the other's consent (not to be unreasonably withheld), except that either party may assign to a group company or to a purchaser of its business without consent, on notice to the other.


25. Notices

25.1 Notices under this Agreement may be given by email: to you, at the contact email address on your account (keep it current); to us, at the contact address published on our contact page.

25.2 A notice sent by email is deemed received on the next business day after sending, unless the sender receives a delivery failure.


26. General

26.1 Entire agreement. This Agreement (these terms, Schedule 1 and the incorporated Product Page terms) is the entire agreement between us about the Service and supersedes all earlier discussions and representations, except any made fraudulently. Website marketing copy is not part of it (clause 2.3).

26.2 Severance. If any provision is found unenforceable, the rest of the Agreement is unaffected, and the provision applies with the minimum modification needed to make it enforceable.

26.3 Waiver. Not enforcing a right is not a waiver of it.

26.4 No partnership. Nothing in this Agreement creates a partnership, joint venture or agency between us.

26.5 Third-party rights. No one other than you and us has any rights under the Contracts (Rights of Third Parties) Act 1999 to enforce this Agreement.


27. Governing law and disputes

27.1 This Agreement and any dispute arising out of or in connection with it (including non-contractual disputes) are governed by the law of England and Wales.

27.2 Before starting proceedings, the parties will first escalate the dispute to a senior manager or director of each party, who will meet (in person or remotely) within 14 days and attempt to resolve it in good faith. If that fails, the parties will consider mediation on the CEDR model before litigating. Binding arbitration is deliberately not used, because it is cost-disproportionate at these contract sizes.

27.3 Subject to clause 27.2, the courts of England and Wales have exclusive jurisdiction.




Schedule 1 - data processing (data processing terms)

Part A - roles and scope

S1.1 For personal data contained in your Submissions and Sanitised Output ("Submission Personal Data"), you are the controller (or a processor acting on behalf of your own customers) and we are the processor. This Schedule contains the terms required by Article 28(3) UK GDPR.

S1.2 The Service is content-agnostic: we do not inspect your files to identify what personal data they contain, and we process whatever personal data your files happen to include, solely to sanitise them.

Part B - processor obligations

S1.3 We will:

  • process Submission Personal Data only on your documented instructions (this Agreement, and each API call you make, are your instruction set), including for international transfers, unless required by law - in which case we tell you first unless the law prevents it;

  • ensure everyone we authorise to process Submission Personal Data is bound by confidentiality;

  • implement appropriate technical and organisational security measures (Article 32 UK GDPR);

  • engage subprocessors only under Part C, and flow down obligations equivalent to this Schedule in a written contract, remaining liable for their performance;

  • taking into account the nature of the processing, assist you (by appropriate technical and organisational measures, insofar as possible) in responding to data-subject rights requests - noting that because content is deleted on the short cycle in Part E, in most cases the data will already be gone;

  • assist you with your security, breach-notification, and data protection impact assessment obligations, taking into account the information available to us;

  • notify you without undue delay after becoming aware of a personal data breach affecting Submission Personal Data;

  • at the end of the Services, at your choice, delete or return all Submission Personal Data and delete existing copies unless law requires storage - in practice the retention cycle in Part E means deletion happens automatically within days; and

  • make available the information necessary to demonstrate compliance with this Schedule, and allow for and contribute to audits (on reasonable notice, no more than once per year unless a regulator requires otherwise or there has been a breach).

Part C - subprocessors

S1.4 You give general written authorisation for the subprocessors in the table below. The table describes each subprocessor's role and processing location; the named identity of each subprocessor is set out in our Sub-processor Register, which we provide to customers and prospective customers on request (see our legal hub). We will give you at least 30 days' advance written notice of any addition or replacement, and you may object on reasonable data-protection grounds within that period; if we cannot resolve a reasonable objection, you may terminate this Agreement without penalty and clause 9.4's refund position applies.

Authorised subprocessors of Submission Personal Data, by role. Named identities are set out in the Sub-processor Register, available on request.
Subprocessor Role in the Service Processing location
A specialist Content Disarm and Reconstruction engine provider (named in the Sub-processor Register)Performs the sanitisation processing on Submissions. The provider's APIs are stateless: payload data is not stored or retained after the transaction completes, and its written data processing terms with us flow down the obligations in this Schedule (S1.3)United Kingdom
Microsoft (Azure)Cloud hosting for the Service: compute, storage of Submissions and Sanitised Output for the retention periods in Part E, and message queuingUnited Kingdom (UK South)

S1.5 Providers that process only your account, billing and correspondence data (for example Stripe for payments) act in relation to data for which we are a controller; they are covered by our privacy policy rather than this Schedule, because they never receive the content of your files.

Part D - international transfers

S1.6 We are based in the United Kingdom, the Service is hosted in Microsoft Azure's UK South region, and sanitisation processing runs in our CDR engine provider's United Kingdom region. In normal operation, Submission Personal Data therefore does not leave the United Kingdom.

S1.7 If that changes - for example if a subprocessor change under Part C would move processing outside the UK - we will ensure an appropriate safeguard recognised by UK data protection law is in place before any restricted transfer happens (in practice the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum), and the Part C notice-and-objection mechanism gives you the chance to object first.

Part E - processing details (Article 28(3) particulars)

Subject matterContent Disarm and Reconstruction processing of files submitted to the Service.
DurationTransient, per Submission: submitted content is deleted once processing completes or fails; Sanitised Output is retained for 24 hours; download links are valid for 24 hours from issue. Usage and billing records (which do not contain file content) are retained per our privacy policy.
Nature and purposeReceiving, analysing and reconstructing document files to remove potentially malicious content, and returning the sanitised copies to you.
Types of personal dataAny personal data contained in the documents you choose to submit. The Service does not require personal data and does not inspect files to identify it (S1.2).
Categories of data subjectIndividuals whose personal data appears in your documents - for example your employees, customers, suppliers and correspondents.

Find us