Summary of the data processing terms that form part of every agreement. The full data processing agreement is provided with your order form; ask our team for a copy to review.
- Roles
- Client is controller; Sieve is processor for client customer data.
- Purpose
- Fraud prevention, transaction monitoring, sanctions and PEP screening, case management and related reporting support.
- Instructions
- Processing only on documented instructions: the API calls and configuration the client makes.
- Security
- Encryption at rest, keyed-hash identifiers, role-based access with two-factor authentication, tamper-evident audit logging. See the security overview.
- Sub-processors
- Available on request; used only when the related feature is enabled; changes notified in advance. On-premise deployments with a local AI model need none.
- Location
- Region chosen by the client, including Kenya; private deployment available.
- Breach notification
- Without undue delay, with the information the client needs to meet its own obligations.
- Assistance
- Support for data subject requests, impact assessments and regulator enquiries.
- Return & deletion
- Full export on request; deletion at the end of the agreement subject to agreed retention.
Questions about this document? Email [email protected] or talk to our team.