How Privacy Automated handles privacy & security.
Privacy Automated uses Privacy Automated to operate its privacy program. This page is generated automatically from the live workspace and reflects the current state of the sub-processor inventory, policies, and platform-level security controls.
Sub-processors
Third parties Privacy Automated authorises to process personal data on their customers' behalf. List is generated live from Privacy Automated's approved-vendor inventory.
| Sub-processor | Purpose | Location† | Role |
|---|---|---|---|
| Anthropic, PBC | Large-language-model inference and verification (Claude) for AI features — Q&A drafting, DPIA / PIA generation, DSAR classification, vendor | US (United States) | processor |
| Backblaze, Inc. | Off-site, encrypted, geographically separated backup storage for the application database. | US (US-East) | processor |
| Clerk, Inc. | Identity, authentication, and organization management (sign-in, SSO, MFA, workspace membership). | US (United States) | processor |
| Greptile | Engage Greptile, a third-party AI service, to automatically review code on pull requests to improve code quality and catch defects/security issues. | US | processor |
| Hetzner Online GmbH | Application and database hosting (compute, storage, networking, physical security) for the Privacy Automated platform. | EU (Falkenstein, Germany) | processor |
| Monkey See Monkey Do, s.r.o. (Healthchecks.io) | Dead-man's-switch monitoring of scheduled jobs (backup pipeline, daily expiry tasks). Alerts on failure. | EU | processor |
| Postmark (ActiveCampaign LLC) | Transactional email delivery (escalation notifications, DSAR routing emails, customer ack messages) and inbound email parsing for the privac | US | processor |
| Sentry (Functional Software, Inc.) | Application error monitoring — captures stack traces and request context when the API or web app encounters an unhandled error. | EU (Frankfurt, Germany — Sentry EU region) | processor |
| Slack Technologies, LLC | Engaged only when a workspace installs the Slack integration. Routes inbound privacy questions and DSAR receipts from the customer’s Slack w | US | processor |
| Stripe, Inc. | Billing, subscription management, payment processing (Managed Payments). | US (United States) | processor |
† Sub-processor locations are self-reported by each sub-processor and are not independently verified by Privacy Automated or Privacy Automated.
Platform security
Controls maintained by Privacy Automated (the underlying platform) that apply to every workspace, including this one.
- TLS 1.2+ for all customer-facing traffic, HSTS enabled.
- AES-256 encryption at rest for the application database.
- Row-level security (PostgreSQL RLS) enforces workspace isolation at the database engine.
- Daily off-site encrypted backups (Backblaze B2), 35-day retention, restore drilled.
- Identity provided by Clerk (SOC 2 Type II). MFA available to all administrators.
- Payment processing by Stripe (PCI DSS Level 1). No card data stored by Privacy Automated.
- Application error monitoring with PII scrubbing (Sentry).
- Audit log of every significant action — visible to the workspace administrator.
Continuously-verified controls
Commitments Privacy Automated re-verifies automatically every day. Each verdict is computed deterministically; its hash is recorded and included in the next daily public transparency root, which is periodically anchored to Bitcoin. Only currently-passing commitments are shown.
Not currently shown: 7 commitments. 7 have no records to check yet, so they have not been reported on either way.
What ‘Verified’ means here: the platform deterministically confirmed that the named record, election, or attestation exists and is current, and recorded its hash for inclusion in the daily transparency root. For attestation-type controls, it confirms a named human attested the practice — it is not a grade of the underlying practice’s adequacy.
other (8)
- Alberta PIPA s. 34 reasonable safeguards attestedVerified Sep 4, 2026
- BC PIPA s. 34 reasonable safeguards attestedVerified Sep 4, 2026
- PIPEDA 4.10 challenge-compliance attestedVerified Sep 4, 2026
- PIPEDA 4.6 accuracy attestedVerified Sep 4, 2026
- Quebec Law 25 s. 12.1 automated decision attestedVerified Sep 4, 2026
- Quebec Law 25 s. 3.8 incident register attestedVerified Sep 4, 2026
- Quebec Law 25 s. 9.1 privacy-by-default attestedVerified Sep 4, 2026
- Quebec Law 25 ss. 8-8.2 transparency attestedVerified Sep 4, 2026
retention_declared (4)
- Alberta PIPA s. 35 retention attestedVerified Sep 4, 2026
- BC PIPA s. 35 retention attestedVerified Sep 4, 2026
- Quebec Law 25 s. 23 retention/destruction attestedVerified Sep 4, 2026
- Retention periods declaredVerified Sep 4, 2026
dpo_governance (8)
- Alberta PIPA s. 5 accountability attestedVerified Sep 4, 2026
- Alberta PIPA s. 6 policies (+ foreign SP) attestedVerified Sep 4, 2026
- BC PIPA s. 4 accountability attestedVerified Sep 4, 2026
- BC PIPA s. 5 policies & complaint process attestedVerified Sep 4, 2026
- PIPEDA 4.1.1 accountable individual attestedVerified Sep 4, 2026
- PIPEDA 4.1.4 privacy program attestedVerified Sep 4, 2026
- Quebec Law 25 s. 3.1 person in charge attestedVerified Sep 4, 2026
- Quebec Law 25 s. 3.2 governance policies attestedVerified Sep 4, 2026
lawful_basis (12)
- Alberta PIPA ss. 11/16/19 reasonable-purposes attestedVerified Sep 4, 2026
- Alberta PIPA ss. 7-8 consent attestedVerified Sep 4, 2026
- BC PIPA ss. 11/14/17 reasonable-purposes attestedVerified Sep 4, 2026
- BC PIPA ss. 6-7 consent attestedVerified Sep 4, 2026
- Lawful basis declaredVerified Sep 4, 2026
- Per-purpose basis human-confirmedVerified Sep 4, 2026
- PIPEDA 4.2 purposes identified attestedVerified Sep 4, 2026
- PIPEDA 4.3 knowledge & consent attestedVerified Sep 4, 2026
- PIPEDA 4.4 collection limited attestedVerified Sep 4, 2026
- PIPEDA 4.5 use/retention limited attestedVerified Sep 4, 2026
- Quebec Law 25 ss. 12-14 consent conditions attestedVerified Sep 4, 2026
- UK GDPR legitimate-interests split (DUAA 2025)Verified Sep 4, 2026
dsar_rights (5)
- Alberta PIPA ss. 24-25 access & correction attestedVerified Sep 4, 2026
- BC PIPA ss. 23-24 access & correction attestedVerified Sep 4, 2026
- PIPEDA 4.9 access account-of-use attestedVerified Sep 4, 2026
- Quebec Law 25 s. 27 access & portability attestedVerified Sep 4, 2026
- Quebec Law 25 s. 28.1 de-indexation attestedVerified Sep 4, 2026
vendor_dpa (8)
- Art. 28(3) processor terms completeVerified Sep 4, 2026
- CCPA § 7051 processor terms completeVerified Sep 4, 2026
- EU GDPR cross-border transfers on a valid Chapter V gatewayVerified Sep 4, 2026
- State processor-contract terms completeVerified Sep 4, 2026
- Sub-processor consumer opt-out flow-down attested (US state)Verified Sep 4, 2026
- Sub-processor DPA flow-down attested (Art. 28(4))Verified Sep 4, 2026
- UK GDPR cross-border transfers on a valid Chapter V gatewayVerified Sep 4, 2026
- Vendor DPAs in placeVerified Sep 4, 2026
customer_security_program (2)
- Art. 32(1) security measures attestedVerified Sep 4, 2026
- Information-security program attestedVerified Sep 4, 2026
ccpa_right_to_know (1)
- CCPA § 1798.110(c) categories disclosure assembledVerified Sep 4, 2026
ccpa_data_minimization (1)
- CCPA data minimization attestedVerified Sep 4, 2026
ccpa_verification_methods (1)
- CCPA DSAR verification methods attestedVerified Sep 4, 2026
cppa_cyber_audit (1)
- CPPA cybersecurity audit positionVerified Sep 4, 2026
cppa_risk_assessment (1)
- CPPA risk assessments record § 7152 contentVerified Sep 4, 2026
childrens_code (1)
- DPA 2018 s.123 Age Appropriate Design Code (Children's Code) — Standard 2 DPIAVerified Sep 4, 2026
dsar_sla (1)
- DSAR deadlines metVerified Sep 4, 2026
ai_act_literacy (1)
- EU AI Act Art. 4 AI literacy attestedVerified Sep 4, 2026
ai_act_prohibited (1)
- EU AI Act Art. 5 no prohibited practiceVerified Sep 4, 2026
non_discrimination (1)
- No discrimination for exercising rightsVerified Sep 4, 2026
pecr_cookies (1)
- PECR cookie/tracker Schedule A1 basis election (DUAA 2025)Verified Sep 4, 2026
pecr_marketing (1)
- PECR reg 22 electronic-mail marketing basis election (DUAA 2025)Verified Sep 4, 2026
review_currency (1)
- Periodic reviews on scheduleVerified Sep 4, 2026
data_transfers (1)
- PIPEDA cross-border transparency disclosed in noticeVerified Sep 4, 2026
records_ropa (1)
- PIPEDA s. 10.3 breach records attestedVerified Sep 4, 2026
policy_current (1)
- Policy matches processingVerified Sep 4, 2026
dpia_linkage (1)
- Required DPIAs completedVerified Sep 4, 2026
uk_dpo (1)
- UK GDPR Arts 37-39 data protection officerVerified Sep 4, 2026
by_design (1)
- UK GDPR data protection by design & by default (DUAA 2025 Art 25)Verified Sep 4, 2026
uk_complaints (1)
- UK GDPR data-subject complaints facilitated (DUAA 2025)Verified Sep 4, 2026
usstate_minimization (1)
- US-state data minimization attestedVerified Sep 4, 2026
usstate_dpia_available (1)
- US-state data protection assessment available to the AGVerified Sep 4, 2026
optout_honoring (1)
- US-state opt-out signal (GPC) honoring attestedVerified Sep 4, 2026
usstate_purpose_limitation (1)
- US-state purpose limitation attestedVerified Sep 4, 2026
cert_currency (1)
- Vendor certifications currentVerified Sep 4, 2026
Published policies
Privacy Automated keeps its published policies in sync with what it actually does. Each version below is signed and anchored to Privacy Automated’s public transparency log, so you can confirm the policy was current as of the date shown.
Current as of Aug 31, 2026.
manifest 506fbfa94091247d…
Verify independently: fetch the Ed25519 key at /api/keys/signing and confirm the publication event in the daily transparency roots.
Policies we maintain
Privacy Automated maintains the following policies as part of its privacy and security program. The full text isn’t published here — it’s available to customers and reviewers on request.
Verify a sealed packet from Privacy Automated
If Privacy Automated has shared a signed evidence packet with you — a sealed DSAR, an approved DPIA — paste its JSON below. The verifier re-checks the Ed25519 signature against the transparency key published at /api/audit/transparency-key — no account, no API key, no contact with Privacy Automated or PrivacyAutomated required.
Don’t have a sample to verify? Ask Privacy Automated for one — sealed packets are a one-click download from any closed DSAR or approved DPIA in their workspace, and the bytes are byte-stable so the same record produces the same packet every time.
Three ways to convince yourself, in order of setup cost
1Read the verdictZero setup
The verifier above re-canonicalizes the packet you pasted (sorted keys, compact separators), prepends the domain prefix PA-EVIDENCE-PACKET-V1\n, and Ed25519-verifies the embedded signature against the public key at /api/audit/transparency-key. If the result above says authentic, the packet’s bytes haven’t changed since the customer sealed it.
2Check our side offlineOne terminal, no network round-trip
Download the public Ed25519 verification key once, then verify any packet bytes locally — without ever talking to our servers afterwards:
# Once: fetch the public key
curl -o pa-transparency.pem \
/api/audit/transparency-key
# Per packet: pull the sig, zero that field, prepend domain, canonicalize, verify
python3 -c "import json, base64; \
d = json.load(open('packet.json')); \
sig = base64.b64decode(d['verification']['signature_base64']); \
d['verification']['signature_base64'] = ''; \
body = b'PA-EVIDENCE-PACKET-V1\n' + \
json.dumps(d, sort_keys=True, separators=(',',':')).encode(); \
open('/tmp/sig', 'wb').write(sig); \
open('/tmp/body', 'wb').write(body)"
openssl pkeyutl -verify -pubin -inkey pa-transparency.pem \
-rawin -in /tmp/body -sigfile /tmp/sigSignature Verified Successfully = same answer as the verdict above, no trust in our server required after the initial key fetch.
3Verify against Bitcoin without trusting usRequires a Bitcoin node (yours or a public RPC)
The packet’s seal references the daily audit-event Merkle root, which is itself anchored to Bitcoin via OpenTimestamps. The full verification chain — packet → audit chain → daily Merkle root → Bitcoin block height → block in YOUR Bitcoin — is documented step-by-step at privacyautomated.ai/trust-architecture.html (Invariant 3). Most regulators don’t need to go this deep, but the option exists, and it’s the answer to “but how do I know you didn’t just sign a fake timestamp?”
What the seal proves
- The packet bytes are unaltered since sealing.
- The sealing happened on the embedded date.
- The named human signed off.
- Any AI inference that touched the record was running the named system prompt at the named SHA-256 hash.
- The audit-event chain is intact from the start of the record to the seal.
What the seal does not prove
- Legal correctness. The seal proves the DSAR closed in 21 days; it does not prove 21 days satisfied the regulatory obligation. That’s a separate claim involving deadline math + legal judgment.
- Truth of the inputs. The seal proves nothing was altered after sealing. It does not prove the privacy team did the underlying work correctly. Garbage in, signed garbage out.
- What a court would conclude about the underlying records. That’s for your counsel.
The full engineering substrate behind these claims is documented at privacyautomated.ai/trust-architecture.html.
Have a question?
Skip the questionnaire. Ask Privacy Automated’s privacy team directly — about sub-processors, data residency, certifications, DPAs, anything. They’ll reply to you by email, and may point you at one of the proof packs above.