Skip to main content
Legal

Data Processing Agreement

Last updated 1 September 2026

Baseline Telemetry Advisory is the trading name of the practice.

This Data Processing Agreement ("DPA") supplements the Master Services Agreement (MSA) between the client ("Controller") and Baseline Telemetry Advisory ("Processor"). It sets out the terms on which Baseline Telemetry Advisory processes personal data on behalf of the Controller, under GDPR art. 28 and, where applicable, UK GDPR. Where an engagement is delivered in Mode B (direct in-platform execution inside the Controller's own tools), the Controller's platform remains under the Controller's control and this DPA governs Baseline Telemetry Advisory's scoped, time-bounded access to that platform rather than storage of Controller content in the Baseline Telemetry Advisory workspace.

Definitions

Terms not defined here have the meaning given in the GDPR. "Personal Data", "Processing", "Data Subject", "Sub-processor", "Supervisory Authority" and "Personal Data Breach" carry their GDPR meanings.

Scope and roles

  • The Controller determines the purposes and means of processing.
  • Baseline Telemetry Advisory acts as Processor and processes Personal Data only on the Controller's documented instructions, as set out in the MSA, this DPA, and reasonable configuration options in the workspace.

Subject-matter and duration

Subject-matter: Information Security, Cyber Risk, and GRC advisory services delivered through the Baseline Telemetry Advisory workspace and, where the engagement calls for it, directly inside the Controller's own platforms under scoped, time-bounded access. Duration: the term of the MSA plus the retention period set out in section 9.

Nature and purpose of processing

Storage, structuring, review, editing, exporting, and transmission of engagement content for the purpose of delivering the advisory services.

Categories of data subjects and personal data

Axis
Data subjects
Detail
Controller's employees, contractors, and any individuals identifiable in engagement content.
Axis
Data categories
Detail
Business contact details, job titles, security-role assignments, authentication events, and any Personal Data included in risk, control, incident, vendor, policy, and planning records the Controller uploads.
Axis
Special categories
Detail
Baseline Telemetry Advisory does not require special-category data. If the Controller uploads any, they instruct Baseline Telemetry Advisory to process it under this DPA.

Processor obligations

Obligation
Process Personal Data only on documented instructions.
Reference
Art. 28(3)(a)
Obligation
Ensure that authorised personnel are subject to confidentiality.
Reference
Art. 28(3)(b)
Obligation
Implement the technical and organisational measures set out in Annex II.
Reference
Art. 28(3)(c), 32
Obligation
Assist the Controller with data-subject requests, DPIAs, and prior consultations, taking into account the nature of processing.
Reference
Art. 28(3)(e)-(f)
Obligation
Notify the Controller without undue delay, and in any event within 72 hours of becoming aware, of a Personal Data Breach.
Reference
Art. 28(3)(f), 33(2)
Obligation
At the Controller's choice, delete or return Personal Data at the end of processing, subject to statutory retention (see Retention and deletion).
Reference
Art. 28(3)(g)
Obligation
Inform the Controller if an instruction, including an instruction to delete, conflicts with EU or member-state law that Baseline Telemetry Advisory is subject to.
Reference
Art. 28(3)(h)
Obligation
Make available all information necessary to demonstrate compliance and allow for audits by the Controller or an auditor mandated by the Controller, on reasonable notice.
Reference
Art. 28(3)(h)

Mode B, in-platform execution

Where a Statement of Work selects Mode B, Baseline Telemetry Advisory works inside platforms the Controller owns and administers (for example Jira, Linear, Vanta, Drata, Secureframe, or a document store). The following terms apply in addition to the rest of this DPA.

Axis
Roles
Term
The Controller remains controller of all data in its own platforms. Baseline Telemetry Advisory processes that data as processor, acting only through the named accounts the Controller provisions.
Axis
Sub-processors
Term
The Controller's own platform providers are the Controller's sub-processors, not Baseline Telemetry Advisory's. Baseline Telemetry Advisory does not appoint them, does not contract with them for this processing, and is not responsible for their measures or their transfer mechanisms.
Axis
Storage
Term
Content stays in the Controller's platform. Baseline Telemetry Advisory does not copy Controller content into the Baseline Telemetry Advisory workspace unless the Statement of Work says so, in which case that copy is governed by the retention terms below.
Axis
Access
Term
Named individual accounts, least privilege, multi-factor authentication, scoped to the systems and projects listed in the Statement of Work, and time-bounded to the access window. No shared or generic credentials. No credential storage outside the Controller's own identity provider or Baseline Telemetry Advisory's managed secret store.
Axis
Instructions and change control
Term
Actions taken in the Controller's platform are performed on the Controller's documented instruction and follow the Controller's own change-control and approval process. Where the Statement of Work requires it, Baseline Telemetry Advisory submits proposals for Controller approval rather than editing records directly.
Axis
Logging
Term
The Controller's platform audit log is the record of Baseline Telemetry Advisory activity in that platform. Baseline Telemetry Advisory keeps its own record of the access grant, the access window, and the revocation confirmation.
Axis
Exports and extracts
Term
Any extract Baseline Telemetry Advisory takes for analysis or reporting is minimised to what the engagement needs, held for the engagement only, and deleted at close unless the Controller instructs otherwise.
Axis
Breach notification
Term
Baseline Telemetry Advisory notifies the Controller without undue delay, and in any event within 72 hours of becoming aware, of any incident involving its access credentials or its activity in the Controller's platform. An incident originating in the Controller's platform outside Baseline Telemetry Advisory's access is the Controller's to assess and notify.
Axis
End of processing
Term
Baseline Telemetry Advisory ceases access and confirms revocation in writing within two business days of engagement close. Because the content remains in the Controller's platform, deletion and return obligations are met by ceasing access and deleting Baseline Telemetry Advisory-held extracts.
Axis
Transfers
Term
Baseline Telemetry Advisory personnel access the Controller's platform from the EEA (Ireland) and the United Kingdom. Where the Controller's platform stores data outside the EEA, that transfer is the Controller's arrangement with its provider.

Sub-processors

The Controller grants general authorisation to engage the sub-processors listed at /subprocessors. Baseline Telemetry Advisory will notify the Controller of any intended addition or replacement of a sub-processor at least 30 days in advance and gives the Controller the right to object on reasonable grounds. Baseline Telemetry Advisory imposes data-protection obligations on each sub-processor no less protective than this DPA. In Mode B engagements, the Controller's own platform providers are not Baseline Telemetry Advisory sub-processors and are not listed at that page.

International transfers

Personal Data is stored in the United Kingdom (managed Postgres service, eu-west-2, London). Transfers from Baseline Telemetry Advisory (EEA, Ireland) to the United Kingdom rely on the European Commission's UK adequacy decision (2021). The providers are identified at /subprocessors.

Where the engagement uses AI features that route to model providers in the United States through the managed AI gateway, those transfers rely on the Standard Contractual Clauses set out in Commission Implementing Decision (EU) 2021/914, module 2 (controller-to-processor), which are incorporated by reference into this DPA.

Delivery tooling

Baseline Telemetry Advisory may use managed AI and coding assistants for limited internal research, drafting, coding, and analysis. They are not a routine route for client workspace content, and we do not intentionally submit client secrets, credentials, raw evidence, sensitive personal data, or confidential engagement material. This tooling is not authorised for Controller Personal Data or engagement evidence. Any engagement that requires AI processing of Personal Data must have the Controller's written authorisation and a corresponding sub-processor entry before processing begins.

A separate, disclosed process, Drift Watch, uses Anthropic's Claude to read Baseline Telemetry Advisory's own source code and a dedicated internal reference tenant (a permanent fixture we maintain for exactly this purpose, never a real client engagement) to verify the platform's own behaviour against the live database on a recurring schedule. It is not authorised to query any other tenant, and it never processes a client's engagement data. Every tenant runs on the same underlying structure, so a fix that comes out of this audit applies across the board rather than to one client's workspace. Because this activity never reads a Controller's own tenant, it does not trigger the written-authorisation requirement above; it is disclosed here and at /subprocessors instead.

Baseline Telemetry Advisory uses a managed business productivity suite for email, bookings, documents, and administration. A managed transactional email provider sends authentication messages, invitations, booking confirmations, reminders, and operational notifications.

Where the Controller is established outside the EEA/UK and the transfer to Baseline Telemetry Advisory would require a transfer mechanism, the parties enter into the SCCs (module 2 or 3 as appropriate) or the UK IDTA, incorporated by reference.

UK International Data Transfer Addendum

For Personal Data subject to the UK GDPR that is transferred to a country without UK adequacy, the parties incorporate the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B1.0, in force 21 March 2022, issued by the Information Commissioner under section 119A of the Data Protection Act 2018). The Addendum applies to the SCCs referenced above, with the following tables completed by reference to this DPA:

Addendum table
Table 1, parties
Completed by
The Controller and Baseline Telemetry Advisory as identified in the engagement documents (MSA or SOW).
Addendum table
Table 2, selected SCCs, modules and clauses
Completed by
SCCs 2021/914, module 2 (controller to processor) or module 3 (processor to sub-processor) as applicable. Docking clause: not used. Option 1 for clause 9(a), prior written authorisation, with the sub-processor list at /subprocessors and 30 days' notice of change.
Addendum table
Table 3, appendix information
Completed by
Annex I (description of processing), Annex II (technical and organisational measures), and Annex III (sub-processors) of this DPA.
Addendum table
Table 4, ending the Addendum when the Approved Addendum changes
Completed by
Either party may end the Addendum as set out in section 19 of the Addendum.

Where the Information Commissioner issues a revised Approved Addendum, the revised version applies from the date it comes into force. Baseline Telemetry Advisory carries out and maintains transfer impact assessments for every transfer path, covering the destination country's law, the supplementary measures applied, and the fallback if a transfer mechanism is invalidated. Assessments are made available to the Controller on request under the audit provisions of this DPA. Baseline Telemetry Advisory notifies the Controller of any binding request from a public authority for Controller Personal Data, unless legally prohibited from doing so, and challenges requests that appear unlawful or overbroad.

Retention and deletion

Data set
Engagement data
Retention window
engagement duration plus 24 months by default
Ground
Contract; MSA may specify otherwise.
Data set
Audit trail
Retention window
24 months
Ground
GDPR art. 5(2) accountability.
Data set
Handover exports
Retention window
Client-owned; retained on the same schedule as engagement data (above), then deleted, subject to any legal or regulatory hold.
Ground
Contract; same schedule as engagement data.
Data set
Records under statutory retention or legal hold
Retention window
Duration of the obligation or claim, then deleted.
Ground
GDPR art. 17(3)(b) and 17(3)(e); storage only.
Data set
Tax and invoicing records
Retention window
Six years
Ground
Irish Revenue statutory retention.

At the end of processing Baseline Telemetry Advisory deletes or returns Personal Data at the Controller's choice. Where EU or member-state law requires Baseline Telemetry Advisory to keep specific records, or where the records are needed to establish, exercise, or defend a legal claim, Baseline Telemetry Advisory informs the Controller of that requirement before acting on the deletion instruction, keeps only the minimum necessary, restricts it to storage, and deletes it once the requirement lapses.

Liability

Liability under this DPA is subject to the limitation of liability in the MSA.

Annex I, description of processing

Section 3 (subject-matter and duration), section 4 (nature and purpose), section 5 (categories).

Annex II, technical and organisational measures

Control area
Isolation
Measure
Row-level security on all workspace tables; per-tenant isolation enforced in Postgres, with a blocked attempt logged to the audit trail rather than failing silently.
Control area
Authentication
Measure
Multi-factor authentication mandatory for every user account.
Control area
Password hygiene
Measure
Leaked-password screening (Have I Been Pwned) on sign-up and password change.
Control area
Encryption
Measure
In transit (TLS 1.2+) and at rest with provider-managed key management.
Control area
Access lifecycle
Measure
Least-privilege, time-bounded advisor accounts; credentials rotated at engagement close; scheduled secret rotation tracked in the advisor SRE dashboard.
Control area
Audit trail
Measure
Append-only audit trail for user-role and workspace actions, and for actions blocked by role or tenant permissions, retained 24 months. Immutability (no update or delete) is enforced by database trigger.
Control area
Backups
Measure
Retained in-region (eu-west-2, London).
Control area
Business continuity
Measure
RPO 24 hours, RTO 6 hours for a managed platform outage and 72 hours for a rebuild on alternative infrastructure. Quarterly restore drills exercise the database export, tenant handover bundle, secret rotation, and external health probes; failed checks open corrective actions tracked to closure before the next drill.
Control area
Reliability
Measure
Public liveness and readiness endpoints, external uptime monitor with paging on failure, and application error telemetry through a managed EU error-tracking service covering the delivery workspace as well as the public site, with request bodies and auth tokens excluded at the SDK layer. Browser errors additionally capture a masked session replay of the moments leading up to the error (all text and input values masked, all media blocked); healthy sessions are never recorded.
Control area
Edge protections
Measure
Strict security headers (HSTS with preload, locked-down Content Security Policy, X-Frame-Options DENY, Referrer-Policy strict-origin-when-cross-origin); rate limiting on authentication, booking, privacy-request, and health endpoints backed by a Postgres-durable counter.
Control area
Incident response
Measure
72-hour notification to Controller, and to the Data Protection Commission (or the UK Information Commissioner's Office for UK data subjects) where Baseline Telemetry Advisory acts as controller.

Annex III, sub-processors

See /subprocessors for the current list.

Legal / last updated 1 September 2026