Legal
Data processing agreement
Last updated: 12 July 2026
This data processing agreement (“DPA”) forms part of the product terms of service between StructQ Ltd, trading as StructLine (the “Processor”), and the customer organization (the “Controller”). It implements Article 28(3) of the UK GDPR and, where it applies, the EU GDPR, for the personal data the Processor handles on the Controller’s behalf in providing the StructLine service.
1. Roles and scope
The Controller determines the purposes and means of processing the workforce AI-usage data the service produces; the Processor processes it only to provide the service. For account and billing data the Processor is an independent controller, as described in the product privacy notice; that data is outside this DPA. The details of the processing are in Annex 1.
2. Instructions
The Processor processes personal data only on the Controller’s documented instructions, given through this DPA, the agreement, and the service’s configuration controls (privacy mode, detection categories, retention settings, erasure and export actions), unless processing is required by law, in which case the Processor informs the Controller before processing where legally permitted. The Processor will inform the Controller if, in its opinion, an instruction infringes data protection law.
3. Confidentiality
Persons authorized to process the personal data are bound by contractual or statutory confidentiality obligations, and access is limited to what their role requires.
4. Security
The Processor implements and maintains the technical and organizational measures in Annex 2, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as required by Article 32. Measures may be updated, but not in a way that reduces the overall level of protection during the term.
5. Sub-processors
- The Controller gives general written authorization to the sub-processors listed at structline.ai/trust/sub-processors (Annex 3).
- The Processor gives customer administrators at least 30 days’ notice before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds; if the parties cannot resolve the objection, the Controller may terminate the affected service and receive a pro-rata refund of prepaid fees.
- The Processor imposes data protection obligations on each sub-processor equivalent to those in this DPA and remains fully liable to the Controller for the sub-processor’s performance.
- No third-party AI sub-processors: the optional AI detection stage runs on infrastructure the Processor controls; the Processor will not engage an external AI service as a sub-processor for Controller personal data without the notice-and-objection process above.
6. Assistance with data subject rights
Taking into account the nature of the processing, the Processor assists the Controller in responding to data subject requests (primarily through the service’s built-in per-person data export, deletion and retention controls) and forwards to the Controller without undue delay any request it receives directly relating to the Controller’s data.
7. Personal data breaches
The Processor notifies the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the Controller’s personal data, and provides the information reasonably needed for the Controller’s obligations under Articles 33 and 34: the nature of the breach, categories and approximate numbers affected, likely consequences, and the measures taken. The Processor supplements the notification as more becomes known.
8. DPIAs and prior consultation
The Processor provides reasonable assistance with data protection impact assessments and prior consultation of supervisory authorities, insofar as they relate to the service. The service’s own DPIA recommendations and privacy-mode documentation may be used as input; they do not replace the Controller’s own assessment.
9. Deletion and return
Upon termination of the service, the Processor deletes the personal data processed on the Controller’s behalf within 30 days, unless the Controller has exported it or requests return first, or law requires longer storage, in which case the data remains protected and is deleted when the requirement ends. In-service, the Controller can erase organization data and configure retention; tightening the privacy mode permanently purges data the stricter mode would not hold. Erasing an individual workforce member anonymizes their attribution in the tamper-evident enforcement log instead of deleting mid-chain entries, so the log’s evidential integrity is preserved while the entries cease to relate to an identifiable person.
10. Audits
The Processor makes available the information reasonably necessary to demonstrate compliance with Article 28 (documentation, the audit trail, and responses to reasonable security questionnaires) and allows for and contributes to audits by the Controller or its mandated auditor: at most once per year absent a breach or supervisory requirement, on at least 30 days’ notice, during business hours, under confidentiality, and without access to other customers’ data.
11. International transfers
The Processor processes Controller personal data on infrastructure it controls, and does not transfer it outside the UK or EEA except to sub-processors listed in Annex 3. Where such a transfer occurs, it is protected by an adequacy decision or by the EU Standard Contractual Clauses (module 3, processor-to-processor, or module 2 as applicable) together with the UK International Data Transfer Addendum, which are incorporated by reference where required.
12. Liability and order of precedence
Liability under this DPA is subject to the limitations in the product terms of service, except where data protection law does not permit such limitation. If this DPA conflicts with the product terms on data protection matters, this DPA prevails.
Annex 1: Details of processing
| Subject matter | Discovery of workforce AI-tool usage and of the categories of data flowing into those tools; production of compliance records. |
|---|---|
| Duration | The term of the agreement, plus the deletion period in section 9. |
| Nature and purpose | Receiving detection events from enrolled browsers; queued, automated analysis (pattern-based detection; optional self-hosted AI detection; the Controller’s custom policies); storage, aggregation and reporting; generation of the AI register, exposure reports and audit trail. For Controllers on the Enforce plan: storage, versioning and device synchronization of the Controller’s enforcement policies, and ingestion of enforcement decisions as metadata into a tamper-evident, hash-chained log. |
| Categories of data subjects | The Controller’s workforce members (employees, contractors) using enrolled browsers; individuals whose personal data appears in monitored content, where the Controller enables content collection. |
| Categories of personal data | Workforce directory data (name, work email, team, device); AI-usage metadata (tool, inferred account type, detected data-category labels, counts, timestamps, risk level); for Controllers on the Enforce plan, enforcement decision metadata (policy, action, outcome, detected data-category labels, counts, latency, tool host, timestamp) attributed to the acting workforce member. Where the Controller opts in: redacted content excerpts or, with a second opt-in, full flagged content, which may include any category of personal data present in that content, including special-category data. |
| Special categories | Not collected in the default zero-retention mode. May be present in content the Controller elects to collect; the Controller is responsible for the lawfulness of that collection. |
Annex 2: Technical and organizational measures
- Data minimization by architecture: pattern detection runs on the device; the default mode transmits and stores metadata only, never typed content; redaction is applied on-device before transmission where excerpts are enabled.
- Encryption: personal data is encrypted in transit (TLS).
- Tenant isolation: all service data is org-scoped with strict tenant isolation.
- Access control: role-based access (administrator / read-only compliance viewer / self-scoped user); authentication via a dedicated identity provider; single-use device enrollment tokens.
- Auditability: privileged actions and privacy-mode/consent changes are recorded in an audit trail, as metadata only, never content or secret values.
- Retention and deletion controls: configurable retention, org-wide erasure, per-person export; tightening the privacy mode purges data the stricter mode would not hold.
- On-device enforcement: where the Controller uses the Enforce plan, policies are evaluated and applied on the device; decisions are recorded as metadata only, in an append-only, hash-chained log whose integrity can be verified from the dashboard.
- Customer-held tokenization keys: where the Controller enables tokenization, the encryption key is generated and held in the workforce member’s browser; the Processor holds neither the keys nor the original values.
- No third-party AI: the optional AI analysis stage runs exclusively on infrastructure the Processor controls.
- Organizational measures: confidentiality obligations for personnel, least-privilege access, documented incident response supporting the section 7 notification duty.
Annex 3: Authorized sub-processors
The current list, with purposes, data categories and locations, is maintained at structline.ai/trust/sub-processors. It forms part of this DPA; changes follow the section 5 notice-and-objection process.