Liskov Data Processing Addendum
Version 1.0 — effective 1 September 2026
This Data Processing Addendum (DPA) forms part of the Contract between MOOSE LABS LTD trading as PROOF (PROOF) and Customer. It applies only where PROOF processes Personal Data on Customer’s behalf in providing the Services.
1. Scope and precedence
1.1 Application
This DPA applies to Customer Personal Data, meaning Personal Data contained in Customer Data that PROOF Processes solely on Customer’s documented instructions to provide hosted, PROOF-controlled Services: application configuration and manifests, sealed secrets, uploaded artifacts, managed application logs, and support content Customer submits.
1.2 Excluded processing
This DPA does not apply to:
(a) Account Data or other Personal Data for which PROOF determines its own purposes and acts as an independent Controller, as described in the Privacy Notice;
(b) Distributed Workload Data, which runs on independently operated Network Infrastructure outside PROOF’s systems and for which Customer is the sole Controller under clause 7 of the Master Business Terms;
(c) Personal Data that Customer sends directly to an independent third-party service outside PROOF’s processing chain; or
(d) public blockchain records controlled by an independent Network.
An Enterprise Order may extend this DPA to additional processing only where the Order identifies the processing parties, countries, safeguards and additional terms.
1.3 Precedence
For a conflict about Processing of Customer Personal Data, this DPA prevails over the other Contract documents. The Order prevails over this DPA only if it expressly identifies the DPA clause varied and the variation complies with Data Protection Laws.
2. Definitions
Capitalised terms not defined here have the meanings in the Master Business Terms. In this DPA:
Applicable Data Protection Law means Data Protection Laws applicable to the relevant Processing.
Approved Addendum means the UK Information Commissioner’s then-current international data transfer addendum to the European Commission’s standard contractual clauses.
Approved IDTA means the UK Information Commissioner’s then-current international data transfer agreement.
Customer Personal Data has the meaning in clause 1.1.
Restricted Transfer means a transfer of Personal Data from the United Kingdom to a country or recipient that is not covered by applicable UK adequacy regulations and requires a transfer safeguard under Applicable Data Protection Law.
Subprocessor means a Processor engaged by PROOF to Process Customer Personal Data on Customer’s behalf. It does not include PROOF personnel or a Network Participant executing a Distributed Workload at Customer’s direction.
3. Roles and Customer instructions
3.1 Roles
For Customer Personal Data:
(a) Customer is Controller or a Processor acting for another Controller;
(b) PROOF is Customer’s Processor or, where Customer is a Processor, PROOF is a subprocessor; and
(c) each party will comply with obligations applicable to its role.
3.2 Instructions
Customer instructs PROOF to Process Customer Personal Data:
(a) to provide, secure, support and maintain the Services;
(b) as configured or initiated by Customer and its Authorised Users;
(c) to prevent fraud, abuse and security threats where compatible with Customer’s use and Applicable Data Protection Law;
(d) as stated in the Contract, including this DPA and Annex 1; and
(e) under additional documented instructions agreed by the parties.
The Contract is Customer’s complete instruction at the Effective Date. A later instruction that materially changes scope, cost or risk requires written agreement and may incur Fees.
3.3 Lawful instructions
Customer is responsible for the lawfulness, fairness and transparency of its Processing, its instructions, its legal bases, notices, data minimisation and rights to provide Customer Personal Data. Customer must not instruct PROOF to violate Applicable Data Protection Law or the Contract.
3.4 Unlawful instruction
If PROOF reasonably believes an instruction infringes Applicable Data Protection Law, it will inform Customer unless prohibited and may suspend the affected Processing until the parties resolve it. PROOF is not required to give legal advice.
3.5 Processing required by law
PROOF may Process Customer Personal Data where required by UK law. It will inform Customer before doing so unless the law prohibits notice for an important public-interest reason.
4. Processing obligations
4.1 Purpose limitation
PROOF will Process Customer Personal Data only on documented instructions and will not sell it or use it for unrelated advertising or to train a general-purpose model, unless Customer separately gives valid express instructions and the parties agree necessary terms.
4.2 Confidentiality
PROOF will ensure that persons authorised to Process Customer Personal Data are subject to an appropriate statutory or contractual duty of confidentiality and receive relevant privacy/security training.
4.3 Data minimisation
PROOF will design the hosted Services to Process Personal Data reasonably necessary for their stated functions. Customer controls the data it submits and should avoid Personal Data in free-text fields and logs where unnecessary.
4.4 Accuracy
PROOF will provide available functions for Customer to correct or delete Customer Personal Data and will reasonably assist where the function is insufficient. Customer remains responsible for data accuracy.
5. Security
5.1 Measures
Taking account of the state of the art, implementation cost, nature, scope, context and purpose of Processing, and risk to individuals, PROOF will implement and maintain the technical and organisational measures in Annex 2 for the PROOF-controlled Services.
5.2 Scope qualification
A measure applies only to the systems and Processing identified in Annex 2. Annex 2 states the measures PROOF operates at the date of this DPA; it does not represent that a planned measure is implemented.
5.3 Customer security
Customer is responsible for:
(a) secure configuration of its Workspace, users, Applications and integrations;
(b) endpoint, wallet, credential, key and source-code security;
(c) using MFA and least privilege where available;
(d) deciding whether the Services are suitable for its Processing;
(e) independent backups and recovery appropriate to Customer’s risk; and
(f) any Personal Data it chooses to process in a Distributed Workload, of which it is the sole Controller.
5.4 Security testing
PROOF will operate a vulnerability-management process appropriate to the Services. Customer may conduct testing only under the AUP, a published vulnerability disclosure policy or written authorisation. Customer must not conduct destructive, high-volume or tenant-impacting tests.
6. Personal Data Breaches
6.1 Notification
PROOF will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. Where reasonably practicable, PROOF’s operational target is to give an initial notice within 48 hours after awareness, but the statutory “without undue delay” obligation controls and the initial notice may be incomplete.
6.2 Content
As information becomes available, notice will include:
(a) the nature of the breach, including categories and approximate numbers of Data Subjects and records where known;
(b) likely consequences;
(c) measures taken or proposed to contain, investigate and mitigate it;
(d) a contact point; and
(e) information reasonably needed for Customer’s notification assessment.
PROOF may provide information in phases and may redact information that would compromise security, another customer or legal privilege.
6.3 Cooperation
PROOF will take reasonable steps to contain and remediate a breach within its control and will reasonably assist Customer with legally required notifications. Customer is responsible for determining whether and how to notify a regulator or Data Subject unless law places that obligation directly on PROOF.
6.4 No admission
A breach notice is not an admission of fault or liability.
7. Data Subject requests
7.1 Forwarding
If PROOF receives a request from a Data Subject relating to Customer Personal Data, PROOF will, where appropriate, direct the requester to Customer and notify Customer, unless prohibited. PROOF will not respond substantively except on Customer’s instruction or where legally required.
7.2 Assistance
Taking account of the nature of Processing, PROOF will provide reasonable technical and organisational assistance for Customer to respond to requests for access, correction, erasure, restriction, portability, objection and applicable automated-decision safeguards.
7.3 Charges
Standard self-service tools are included. PROOF may charge reasonable Fees for exceptional, repetitive or bespoke assistance caused by Customer’s configuration or instruction, to the extent law permits and agreed in advance.
8. DPIAs and regulator consultation
Taking account of the nature of Processing and information available, PROOF will provide reasonable assistance with a data-protection impact assessment and prior consultation required for Customer’s use of the Services. Customer remains responsible for the assessment and consultation. Bespoke assistance may be chargeable at agreed rates.
9. Subprocessors
9.1 General authorisation
Customer gives general written authorisation for PROOF to use Subprocessors listed in the current Subprocessor and International Transfer Schedule.
9.2 Requirements
Before a Subprocessor Processes Customer Personal Data, PROOF will enter a written contract requiring data-protection obligations that provide materially equivalent protection to the relevant obligations in this DPA, to the extent applicable to that Subprocessor’s services. PROOF remains responsible to Customer for the Subprocessor’s performance of those obligations.
9.3 Changes
PROOF will provide at least 15 days’ prior notice of a new Subprocessor that will materially Process Customer Personal Data, normally by email or subscription notice. Less notice may be given where an urgent replacement is reasonably necessary for security, law or service continuity; PROOF will notify Customer as soon as practicable.
9.4 Objection
Customer may object within the notice period on reasonable, documented data-protection grounds. The parties will discuss a commercially reasonable solution. PROOF may avoid use for Customer, offer a configuration or substitute, or allow Customer to terminate the affected Service and receive a pro-rata refund of prepaid Subscription Fees for the unused period. PROOF is not required to provide a Service without a necessary Subprocessor where no reasonable alternative exists.
9.5 Network Participants
The general authorisation in this clause does not make a Network Participant a Subprocessor. A Distributed Workload is transmitted to the Network at Customer’s direction and Customer is the Controller of any Personal Data in it; PROOF sends no Customer Personal Data to a Network Participant.
10. International transfers
10.1 Compliance
PROOF will not make a Restricted Transfer of Customer Personal Data unless it uses a transfer mechanism permitted by Applicable Data Protection Law and takes supplementary measures reasonably required by the relevant risk assessment.
10.2 Transfer instruments
Where a Restricted Transfer is made by PROOF to a Subprocessor and no adequacy regulation or other valid mechanism applies, PROOF will ordinarily enter the Approved IDTA or the relevant EU standard contractual clauses together with the Approved Addendum, completed consistently with this DPA.
10.3 Customer-to-PROOF transfer
If Customer’s disclosure to PROOF itself is a Restricted Transfer requiring a transfer instrument, the parties are deemed to enter the Approved IDTA or Approved Addendum identified in Annex 3, to the extent legally effective and completed by the Contract details. If the instrument cannot be incorporated effectively without additional information, the parties will execute it promptly.
10.4 Assessments and information
PROOF will conduct and document transfer risk assessments where required for its Restricted Transfers and provide Customer with reasonable information about safeguards, subject to confidentiality, privilege and security. Customer is responsible for assessing its own transfer to PROOF and its use of the Services.
10.5 Conflict and updates
A mandatory transfer instrument prevails over this DPA to the extent of conflict. References to an approved instrument include a successor approved by the UK Information Commissioner. The parties will cooperate to replace an invalid mechanism.
11. Audit and information
11.1 Compliance information
PROOF will make available information reasonably necessary to demonstrate compliance with the processor obligations in Applicable Data Protection Law. PROOF may satisfy this initially through current independent reports, certifications, security summaries, questionnaires and policy extracts where available.
11.2 Audit
Customer may audit PROOF’s relevant compliance no more than once in any 12-month period, unless a Personal Data Breach, regulator direction or reasonable evidence of material non-compliance justifies an additional audit.
An audit must:
(a) be on at least 30 days’ notice, unless urgent;
(b) occur during normal business hours;
(c) be scoped to Customer Personal Data and relevant controls;
(d) avoid access to another customer’s data, security-sensitive information and privileged material;
(e) be conducted by Customer or an independent auditor that is not a PROOF competitor and is bound by confidentiality;
(f) minimise disruption; and
(g) comply with PROOF’s reasonable security rules.
11.3 Costs
Each party bears its own audit costs. Customer will reimburse PROOF’s reasonable internal/external costs for an onsite or bespoke audit unless it identifies a material breach by PROOF. PROOF may require use of remote evidence where it reasonably demonstrates compliance.
11.4 Regulator
This clause does not restrict a competent regulator’s lawful powers.
12. Return and deletion
12.1 During the Term
Customer may access and export Customer Personal Data using available Service functions. Customer should maintain its own backups and should not wait until termination to test export.
12.2 After termination
Unless law requires retention or Customer instructs earlier lawful deletion:
(a) Customer may request an export during the 30-day period after termination;
(b) PROOF will delete Customer Personal Data from active PROOF-controlled systems no later than 60 days after termination; and
(c) residual backup copies will be overwritten in the ordinary cycle within 90 days after termination.
PROOF may retain a restricted copy for longer only where required by law, sanctions, security evidence or a legal claim. It will remain protected and not be used for another purpose.
12.3 Certification
On reasonable written request after the deletion period, PROOF will confirm completion of its standard deletion process. A bespoke forensic certificate is chargeable and subject to technical feasibility.
12.4 External systems and blockchains
PROOF cannot delete Personal Data from Customer-controlled systems, independent public blockchains, Network Participants or third-party services outside PROOF’s control.
13. Assistance with accountability
PROOF will provide reasonable information needed for Customer’s Article 30 records, security assessment, breach response and compliance, taking account of the nature of Processing. Customer must not publish confidential security information or use it to test another tenant.
14. Liability
Liability arising under this DPA is subject to the liability clause in the Master Business Terms and is aggregated with liability under the rest of the Contract. Nothing limits Data Subject or regulator rights under applicable law.
15. Duration and termination
This DPA starts when PROOF first Processes Customer Personal Data and ends when that Processing has ceased and deletion/return obligations are complete. Clauses that by nature survive continue to apply.
16. Changes in law
If a change in Applicable Data Protection Law or regulator decision requires amendment, the parties will cooperate in good faith to implement a compliant replacement. PROOF may update a mandatory transfer instrument or non-material operational detail on notice. A material adverse change follows the change process in the Master Business Terms.
Annex 1 — Processing details
This Annex must be completed with the applicable Order where the defaults are not accurate.
| Item | Standard hosted-Service position |
|---|---|
| Subject matter | Provision, administration, security, support and maintenance of the PROOF-controlled Liskov Services specified in the Order |
| Duration | Term plus the export/deletion periods in clause 12 |
| Nature of Processing | Collection, recording, organisation, hosting, retrieval, consultation, transmission within approved hosted providers, support, security monitoring, backup, deletion and other operations initiated by Customer |
| Purpose | To provide the Services on Customer’s documented instructions |
| Data Subjects | Customer personnel, contractors, administrators, authorised users, support contacts, and other business individuals whose Personal Data Customer lawfully submits to hosted features |
| Personal Data | Business identifiers and contact details; account/user IDs and roles; support content; technical identifiers; application configuration, sealed secrets, uploaded artifacts and managed logs to the extent they contain Personal Data; other categories expressly stated in the Order |
| Special Category Data | Not permitted unless expressly identified and approved in an Enterprise Order with additional safeguards |
| Criminal-offence data | Not permitted unless expressly identified and approved in an Enterprise Order with an applicable condition and policy safeguards |
| Children’s data | Not permitted |
| Frequency | As initiated by Customer and continuously as required for active hosted Services |
| Customer instructions | The Contract, Customer’s authorised configuration/API actions and additional written instructions accepted by PROOF |
| Return/deletion | Export for 30 days after termination; active deletion by 60 days; backup overwrite by 90 days, subject to law/security |
| Distributed Workloads | Executed on Network Infrastructure at Customer’s direction; Customer is the Controller; not included in this Annex |
Annex 2 — Technical and organisational measures
These are the measures PROOF operates for the PROOF-controlled Services at the date of this DPA.
1. Governance and risk
- the directors of MOOSE LABS LTD own information security and are the escalation point for incidents;
- risk is assessed when a system, provider or data flow changes;
- authorised personnel are bound by confidentiality obligations;
- providers are reviewed for security and privacy before they process Customer Personal Data, and are listed in the Subprocessor Schedule.
2. Access control
- unique identities for each person with administrative access;
- role-based, least-privilege access to production, reviewed periodically;
- hardware-backed multi-factor authentication for PROOF personnel on the source-control and hosting-provider accounts that reach production;
- a documented joiner, mover and leaver process for privileged access;
- no routine access to Customer content except for support, security, legal or operational need.
3. Authentication and secrets
- Customer sign-in is delegated to GitHub or to a single-use email link; PROOF stores no passwords, and session tokens are stored only as hashes;
- Customer application secrets are encrypted by the secrets service so that only the runtime that receives a secret can decrypt it;
- production credentials are held in the hosting provider’s secret store and rotated on compromise or personnel change;
- PROOF never collects Customer private keys or seed phrases.
4. Encryption and communications
- encryption in transit using modern TLS for all public web and API traffic;
- encryption at rest for the managed PostgreSQL databases and object storage that hold Customer Personal Data;
- no representation that encryption prevents access by a system while data is being processed.
5. Tenant and system security
- logical tenant separation by organisation in every hosted data store, enforced in the data model;
- managed hosting infrastructure patched by the hosting provider, with PROOF’s services rebuilt and redeployed from source through a controlled pipeline;
- production and non-production environments are separate, and production Personal Data is not used in development or testing;
- every material change is peer-reviewed and deployed through the pipeline.
6. Secure development and vulnerability management
- all source is version-controlled with change history;
- the build pipeline runs dependency, vulnerability, secret, licence, malware and provenance checks and produces a software bill of materials for each release;
- findings are remediated in priority of severity and exploitability;
- vulnerability reports are received at security@proof.computer and triaged by the directors.
7. Logging and monitoring
- authentication, invitation, role, deployment, billing and security events are logged;
- error monitoring is configured to exclude request content, headers and personal identifiers;
- logs minimise payloads and secrets, and have defined retention periods by category (Privacy Notice, section 10).
8. Availability, backup and recovery
- the control plane runs on managed infrastructure with automatic failover for its databases;
- the hosting provider takes automatic, encrypted backups of the managed PostgreSQL databases;
- PROOF does not back up or recover Network Infrastructure or Customer-controlled systems.
9. Incident management
- the directors triage, contain, investigate and remediate incidents, and preserve evidence;
- a suspected Personal Data Breach is escalated for the customer notification in clause 6;
- material incidents are reviewed afterwards and the lessons applied.
10. Data lifecycle
- data is classified and minimised by design in the hosted Services;
- retention is defined by data category and enforced by automatic pruning where the system supports it;
- deletion follows clause 12, with the hosting provider’s backup cycle overwriting residual copies;
- providers are bound to delete or return data on termination.
11. Physical security
Physical security for the data centres is provided by the hosting Subprocessors under their own certifications. PROOF applies device and remote-work controls to its own personnel and equipment, including hardware-backed authentication.
12. Network-specific safeguards
- Distributed Workloads execute on independently operated Network Infrastructure at Customer’s direction; PROOF sends no Customer Personal Data to a Network Participant;
- PROOF uses only the metadata necessary for orchestration, billing and security;
- Documentation states that a Network Participant’s identity and location can vary and instructs Customers not to embed credentials or secrets in a workload.
Annex 3 — UK restricted-transfer mechanism
Complete this Annex only where needed.
A. UK Addendum approach
Where the Approved Addendum is used:
- Exporter: the party located in/exporting from the UK, as identified in the Order and this DPA;
- Importer: the recipient identified in the Subprocessor Schedule or Order;
- Selected EU SCC module: Module 2 (Controller to Processor) or Module 3 (Processor to Processor), according to roles;
- Docking clause: included where appropriate;
- Annex I details: the parties and Processing details in the Order, Annex 1 and Subprocessor Schedule;
- Annex II: Annex 2 plus recipient-specific measures;
- Annex III: authorised Subprocessors in the Schedule;
- ICO Addendum tables: completed by the information above and any recipient-specific entry;
- Permitted changes: none except as allowed by the Approved Addendum.
B. IDTA approach
Where the Approved IDTA is used, the parties incorporate it with:
- party details from the Order/DPA;
- transfer details from Annex 1 and the relevant Subprocessor entry;
- security requirements from Annex 2 and recipient-specific measures;
- commercial clauses from the Contract, so far as consistent;
- review dates and extra protection identified in the transfer risk assessment.
C. Priority
The executed or incorporated transfer instrument and mandatory law prevail over inconsistent terms. The parties must complete any missing mandatory field before relying on the instrument.
MOOSE LABS LTD trading as PROOF · Version 1.0 · effective 1 September 2026 · previous versions are archived by PROOF and available on request from legal@proof.computer.