Skip to content
Legal · DPA summary

Data processing

Last updated 25 September 2026

Summary of the data processing terms that form part of every agreement. The full data processing agreement is provided with your order form; ask our team for a copy to review.

Roles
Client is controller; Sieve is processor for client customer data.
Purpose
Fraud prevention, transaction monitoring, sanctions and PEP screening, case management and related reporting support.
Instructions
Processing only on documented instructions: the API calls and configuration the client makes.
Security
Encryption at rest, keyed-hash identifiers, role-based access with two-factor authentication, tamper-evident audit logging. See the security overview.
Sub-processors
Available on request; used only when the related feature is enabled; changes notified in advance. On-premise deployments with a local AI model need none.
Location
Region chosen by the client, including Kenya; private deployment available.
Breach notification
Without undue delay, with the information the client needs to meet its own obligations.
Assistance
Support for data subject requests, impact assessments and regulator enquiries.
Return & deletion
Full export on request; deletion at the end of the agreement subject to agreed retention.

Questions about this document? Email [email protected] or talk to our team.