Skip to content
A concrete wall with diagonal light and shadow

Data processing agreement

Availability
On request, before a pilot begins
Parties
Customer as controller, Antitropy, LLC as processor
Request it from
privacy@riopex.com
Updated
9 September 2026
Status
Draft for counsel review

How to get it

Write to privacy@riopex.com and we will send the current draft. We would rather you read it early than discover a clause you cannot accept in week six of a security review, so ask for it during the first conversation if it matters to your organisation.

It is a draft pending review by counsel and will be finalised before the first pilot. We will tell you which parts are still moving rather than presenting a draft as settled.

The roles

In a pilot, your organisation is the controller of the personal data inside the platform and Antitropy, LLC is the processor. We process it on your documented instructions and for no purpose of our own.

Enquiries made through this website are different: there we are the controller, and the privacy notice governs.

What it covers

The agreement sets out, at minimum, the following.

  • Subject matter, duration, nature and purpose of the processing, and the categories of data subject
  • The instruction to process only on the controller's documented instructions, and to tell you if we think an instruction breaches the law
  • Confidentiality obligations on everyone who has access
  • Technical and organisational security measures, including isolation at the operating company level and credentials held outside the database
  • The subprocessor list, the flow-down obligation on each, and notice before a new one is engaged
  • Assistance with data subject requests, with data protection impact assessments, and with regulator engagement
  • Personal data breach notification, without undue delay, with what we know at the time
  • International transfer mechanisms for the regions in scope
  • Deletion or return of data at the end of the engagement, and the retention exceptions that apply
  • Audit and information rights, including how they can be exercised without compromising other customers

What personal data the platform actually holds

Less than you might expect, and we would rather scope it precisely than sign a broad agreement. The platform holds account details for the people who use it, and telecom records that are mostly not personal data at all: circuits, contracts, invoices, utilisation.

The exception is mobile telephony. Where mobile usage detail is processed, subscriber numbers are stored hashed with only the last digits in the clear, and per-employee allocation runs on an employee reference rather than a name. That is a design decision, and it narrows what the agreement has to cover.

Security review

We expect your security review to be the real gate rather than the agreement itself, and the security page is written for that conversation. SOC 2 is planned with the first pilot, and we will name a control once an audit backs it.

If your review needs a questionnaire completed, send it. We will answer it honestly, including the answers that are a date rather than a control.