AirGap Keeper logoAirGap Keeper
Data Processing Agreement

UK GDPR Article 28 Processor Terms

This Data Processing Agreement (DPA) governs all personal data that AirGap Keeper processes on behalf of a customer. It is written to satisfy Article 28 of the UK GDPR and incorporates our contractual Zero-Retention Guarantee.

This DPA forms part of, and is subject to, the Terms of Service and any signed statement of work between AirGap Keeper ("the Processor") and the customer ("the Controller"). Where the customer requires a countersigned copy on its own paper, we will execute this DPA as a standalone agreement on request. Personal data we hold about website visitors and business contacts, where we act as controller, is covered by our Privacy Policy.

1. Definitions

"UK GDPR", "Data Protection Legislation", "personal data", "special category data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given to them in the UK General Data Protection Regulation and the Data Protection Act 2018. "Client Data" means all documents, media, files and personal data supplied by the Controller for processing. "Deliverables" means the outputs we return to the Controller. "Zero-Retention Guarantee" means the erasure commitment set out in clause 10.

2. Roles of the Parties

The Controller determines the purposes and means of processing Client Data. AirGap Keeper acts solely as Processor in respect of Client Data and does not determine the purposes of processing. Nothing in this DPA makes us a joint controller. If we ever determine the purposes of processing personal data contained in Client Data, we accept that we would be treated as a controller for that processing under Article 28(10) of the UK GDPR.

3. Subject Matter, Duration, Nature and Purpose (Article 28(3))

  • Subject matter: offline extraction, structuring, indexing, chronology building, summarisation and analysis of documents supplied by the Controller.
  • Nature of processing: ingestion from customer media, processing by locally hosted AI models on isolated hardware, human quality assurance, production of Deliverables, then secure erasure.
  • Purpose: to produce the Deliverables described in the applicable statement of work, and for no other purpose.
  • Duration: from secure intake until the Deliverables are accepted and erasure is completed in accordance with clause 10.
  • Types of personal data and categories of data subject: as set out in Annex 1 below.

4. Processing on Documented Instructions (Article 28(3)(a))

We process Client Data only on the Controller's documented instructions, including in relation to transfers of personal data to a third country or an international organisation, unless required to do otherwise by UK law. The statement of work, intake form and any written instruction issued by an authorised contact constitute the Controller's documented instructions. Where UK law requires us to process for another purpose, we will inform the Controller before processing unless that law prohibits it on important grounds of public interest.

We will inform the Controller without delay if, in our opinion, an instruction infringes the UK GDPR or other Data Protection Legislation.

We do not use Client Data to train, fine-tune, evaluate or improve any AI model, and we do not use it for product development, benchmarking, marketing or analytics.

5. Confidentiality (Article 28(3)(b))

Access to Client Data is restricted to personnel who need it to deliver the services. All such personnel are bound by written confidentiality undertakings that survive the end of their engagement, are vetted before being granted access, and receive data protection and information security training appropriate to their role.

6. Security of Processing (Articles 28(3)(c) and 32)

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk to data subjects, we implement the technical and organisational measures set out in Annex 2, which include:

  • Physical air-gap: the processing environment has no internet connection; networking is disabled on the processing hosts.
  • Controlled intake: customer media is mounted read-only through forensic write-blocking so that original files, timestamps and metadata cannot be altered.
  • Content neutralisation: incoming documents are scanned and normalised before they reach the processing enclave.
  • Encryption: Client Data is encrypted at rest on our systems and in transit on any media exchanged with the Controller.
  • Access control: physical access to the facility is restricted and logged; logical access is role-based and individually attributed.
  • Resilience and testing: documented operating procedures, logging of intake and erasure events, and periodic review of the effectiveness of these measures.

Because processing takes place offline, remote attack surface is materially reduced; this does not remove our obligation to keep the measures under review.

7. Sub-Processors (Articles 28(2) and 28(3)(d))

We do not engage sub-processors for the AI processing itself; that work is carried out on hardware under our direct control at our UK facility. The Controller gives general written authorisation for the use of sub-processors for ancillary functions only, listed in Annex 3. We will inform the Controller of any intended addition or replacement of a sub-processor with at least 30 days' notice, giving the Controller the opportunity to object on reasonable data protection grounds. Where we engage a sub-processor, we impose data protection obligations no less protective than those in this DPA and remain fully liable to the Controller for its performance.

8. Data Subject Rights (Article 28(3)(e))

Taking into account the nature of the processing, we assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to requests to exercise data subject rights under Chapter III of the UK GDPR, including access, rectification, erasure, restriction, portability and objection. If a data subject contacts us directly, we will not respond substantively and will refer the request to the Controller without undue delay.

9. Assistance with Articles 32 to 36 (Article 28(3)(f))

We assist the Controller in ensuring compliance with its obligations relating to security of processing, personal data breach notification, communication of breaches to data subjects, data protection impact assessments and prior consultation with the Information Commissioner's Office, taking into account the nature of processing and the information available to us.

Breach notification: we notify the Controller without undue delay, and in any event within 24 hours, of becoming aware of a personal data breach affecting Client Data. Our notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. We will not notify a supervisory authority or data subjects on the Controller's behalf unless instructed to do so.

10. Deletion or Return of Data and the Zero-Retention Guarantee (Article 28(3)(g))

At the Controller's choice, we delete or return all Client Data at the end of the provision of services and delete existing copies, unless UK law requires storage of the personal data. This obligation is implemented through our Zero-Retention Guarantee:

  • Deliverables are returned by the agreed secure method.
  • All Client Data, derived working files, indexes, temporary artefacts and model context are erased from the processing environment within 72 hours of acceptance of the Deliverables, or sooner on instruction. Erasure is performed by cryptographic erase in line with NIST SP 800-88 Rev. 1 (Guidelines for Media Sanitization): the encryption keys protecting the data are destroyed, rendering the data unrecoverable.
  • Customer-supplied media is returned, or destroyed if the Controller instructs destruction in writing.
  • A certificate of erasure recording the project reference, scope of data erased, method and date is issued to the Controller on request.
  • No copy, backup, archive or excerpt of Client Data is retained for our own purposes after erasure.

Where statutory retention applies to a narrow class of records, we will tell the Controller which records are retained, on what legal basis, and for how long, and we will continue to protect them under this DPA until erasure.

11. Audits and Information (Article 28(3)(h))

We make available to the Controller all information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates. In practice this includes our Security Assurance and Architecture Summary, completed security questionnaires, erasure certificates and, by prior arrangement, a supervised on-site inspection of the processing facility. Audits take place during business hours, on at least 14 days' notice, no more than once in any 12-month period unless a breach or regulator request makes a further audit necessary, and are subject to confidentiality undertakings and the protection of other customers' data.

12. International Transfers

All processing takes place in the United Kingdom. We do not transfer Client Data outside the UK. If a transfer ever becomes necessary, we will obtain the Controller's prior written instruction and put in place an appropriate Article 46 transfer mechanism, such as the ICO International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.

13. Controller Obligations and Warranties

The Controller warrants that it has a lawful basis for the processing it instructs, that it has provided any required privacy information to data subjects, that it has an appropriate condition for processing special category or criminal offence data where applicable, and that the Client Data supplied is limited to what is adequate, relevant and necessary for the agreed purpose. The Controller is responsible for the accuracy of the Client Data and for reviewing Deliverables before relying on them.

14. Liability, Term and Governing Law

This DPA takes effect on the effective date below and continues for as long as we process Client Data. Clauses 5, 6, 10, 11 and 14 survive termination. Liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except that nothing limits liability that cannot lawfully be limited, including liability to data subjects under Article 82 of the UK GDPR. This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

Annex 1 — Details of Processing

  • Categories of data subject: the Controller's clients, employees, patients, claimants, counterparties, witnesses and any other individuals named in the documents supplied.
  • Types of personal data: names, contact details, dates of birth, identifiers and reference numbers, employment and financial information, correspondence, and other content of the supplied documents.
  • Special category and criminal offence data: may include health and medical records, and information relating to alleged offences or proceedings, where these appear in the documents supplied for a matter.
  • Frequency: one-off or recurring per project, as agreed.
  • Retention: duration of the project plus a maximum of 72 hours, per clause 10.

Annex 2 — Technical and Organisational Measures

  • Offline, air-gapped processing environment at a UK facility.
  • Locally hosted AI models; no third-party AI APIs and no cloud inference.
  • Forensic write-blocked intake preserving original files and metadata.
  • Malware scanning and document normalisation before processing.
  • Encryption of Client Data at rest and of media in transit.
  • Role-based, individually attributed access with least privilege.
  • Access-controlled premises with visitor logging.
  • Vetted personnel under written confidentiality undertakings.
  • Documented intake, processing, hand-back and erasure procedures.
  • Cryptographic erasure of working data in line with NIST SP 800-88 Rev. 1 (cryptographic erase), logged, with certificates issued on request.
  • Periodic review of controls and of this Annex.

Annex 3 — Authorised Sub-Processors

No sub-processor receives Client Data. Ancillary suppliers used for our own business operations — website hosting, business email, and accounting — may process the Controller's business contact details only, under written data protection terms and within the UK or EEA. A current list is available on request from compliance@airgapkeeper.com.

Contact

Questions about this DPA, requests for a countersigned copy, audit requests and erasure certificates: compliance@airgapkeeper.com.

Effective date: 1 September 2026. This document is provided for information and does not constitute legal advice.