Data processing addendum
When Antiqore processes personal data on your behalf, you are the controller and we are the processor. This sets out what that means in practice. A countersigned copy is available on request and is included by default on Growth and above.
Last updated 29 July 2026
1. Scope and roles
This addendum forms part of the terms of service and applies whenever we process personal data on your instructions. You determine the purposes and means; we act only on documented instruction, which the terms and your configuration of the service constitute.
2. What is processed
| Category | Data |
|---|---|
| Data subjects | Visitors to your websites, people who contact you through an embed, and business contacts surfaced by research for your workspace. |
| Personal data | Anonymous visitor identifiers, page and event history, approximate location from IP, hashed IP, user agent, consent state, chat transcripts, booking details, email addresses, names, job titles and professional profile URLs. |
| Special categories | None. The service is not designed to process them. |
| Duration | For the term, plus the 30-day export window. |
3. Our obligations
- Process only on your documented instructions.
- Bind everyone with access to confidentiality, and grant access only where it is needed to operate the service.
- Apply the security measures in section 5 and keep them under review.
- Assist you with data subject requests, impact assessments and consultations with a supervisory authority.
- Notify you without undue delay, and in any event within 48 hours, of a personal data breach affecting your data, with what we know at the time.
- Delete or return the data at the end of the term, at your choice.
4. Your obligations
- Have a lawful basis for the processing you instruct, and give the notices your own subjects are owed.
- Operate a consent mechanism on your sites that meets the law applying to your visitors.
- Do not send us special category data or anything the service is not designed to hold.
5. Security measures
- Encryption in transit (TLS 1.2+) and at rest.
- Session recordings mask input fields at capture — keystrokes in form inputs never reach our servers.
- IP addresses are stored only as salted hashes.
- Embeds are locked to origins you register, with per-instance rate limits.
- Role-based access, least privilege, and audited administrative action.
- Encrypted daily backups with a tested restore path.
- Environment separation between production and everything else.
6. Subprocessors
You give general authorisation for the subprocessors listed at antiqore.com/legal/subprocessors. We give 30 days’ notice before adding one, and you may object on reasonable data protection grounds within that window. We flow down equivalent obligations and remain liable for their performance.
7. International transfers
Data is stored in the European Union by default. Where a transfer outside the EEA is necessary, it relies on an adequacy decision or on Standard Contractual Clauses with supplementary measures, and Module Two applies with us as data exporter’s processor.
8. Audit
On reasonable notice, no more than once a year, we provide the information needed to demonstrate compliance. Where a customer requires an on-site audit we accommodate it under confidentiality and at the customer’s cost, unless the audit finds material non-compliance.
9. Deletion
On termination, data is available for export for 30 days and then deleted, including from backups within the backup rotation cycle, unless law requires retention.
10. Liability
Liability under this addendum is subject to the limits in the terms of service, except where applicable data protection law does not permit it.