Trust Center
Privacy Automated
Live
2026-09-05 05:39 UTC

How Privacy Automated handles privacy & security.

Privacy Automated uses Privacy Automated to operate its privacy program. This page is generated automatically from the live workspace and reflects the current state of the sub-processor inventory, policies, and platform-level security controls.

Operates under: Florida

Sub-processors

Third parties Privacy Automated authorises to process personal data on their customers' behalf. List is generated live from Privacy Automated's approved-vendor inventory.

Sub-processorPurposeLocationRole
Anthropic, PBCLarge-language-model inference and verification (Claude) for AI features — Q&A drafting, DPIA / PIA generation, DSAR classification, vendorUS (United States)processor
Backblaze, Inc.Off-site, encrypted, geographically separated backup storage for the application database.US (US-East)processor
Clerk, Inc.Identity, authentication, and organization management (sign-in, SSO, MFA, workspace membership).US (United States)processor
GreptileEngage Greptile, a third-party AI service, to automatically review code on pull requests to improve code quality and catch defects/security issues.USprocessor
Hetzner Online GmbHApplication and database hosting (compute, storage, networking, physical security) for the Privacy Automated platform.EU (Falkenstein, Germany)processor
Monkey See Monkey Do, s.r.o. (Healthchecks.io)Dead-man's-switch monitoring of scheduled jobs (backup pipeline, daily expiry tasks). Alerts on failure.EUprocessor
Postmark (ActiveCampaign LLC)Transactional email delivery (escalation notifications, DSAR routing emails, customer ack messages) and inbound email parsing for the privacUSprocessor
Sentry (Functional Software, Inc.)Application error monitoring — captures stack traces and request context when the API or web app encounters an unhandled error.EU (Frankfurt, Germany — Sentry EU region)processor
Slack Technologies, LLCEngaged only when a workspace installs the Slack integration. Routes inbound privacy questions and DSAR receipts from the customer’s Slack wUSprocessor
Stripe, Inc.Billing, subscription management, payment processing (Managed Payments).US (United States)processor

† Sub-processor locations are self-reported by each sub-processor and are not independently verified by Privacy Automated or Privacy Automated.

Platform security

Controls maintained by Privacy Automated (the underlying platform) that apply to every workspace, including this one.

  • TLS 1.2+ for all customer-facing traffic, HSTS enabled.
  • AES-256 encryption at rest for the application database.
  • Row-level security (PostgreSQL RLS) enforces workspace isolation at the database engine.
  • Daily off-site encrypted backups (Backblaze B2), 35-day retention, restore drilled.
  • Identity provided by Clerk (SOC 2 Type II). MFA available to all administrators.
  • Payment processing by Stripe (PCI DSS Level 1). No card data stored by Privacy Automated.
  • Application error monitoring with PII scrubbing (Sentry).
  • Audit log of every significant action — visible to the workspace administrator.

Continuously-verified controls

Commitments Privacy Automated re-verifies automatically every day. Each verdict is computed deterministically; its hash is recorded and included in the next daily public transparency root, which is periodically anchored to Bitcoin. Only currently-passing commitments are shown.

Not currently shown: 7 commitments. 7 have no records to check yet, so they have not been reported on either way.

What ‘Verified’ means here: the platform deterministically confirmed that the named record, election, or attestation exists and is current, and recorded its hash for inclusion in the daily transparency root. For attestation-type controls, it confirms a named human attested the practice — it is not a grade of the underlying practice’s adequacy.

other (8)

  • Alberta PIPA s. 34 reasonable safeguards attestedVerified Sep 4, 2026
  • BC PIPA s. 34 reasonable safeguards attestedVerified Sep 4, 2026
  • PIPEDA 4.10 challenge-compliance attestedVerified Sep 4, 2026
  • PIPEDA 4.6 accuracy attestedVerified Sep 4, 2026
  • Quebec Law 25 s. 12.1 automated decision attestedVerified Sep 4, 2026
  • Quebec Law 25 s. 3.8 incident register attestedVerified Sep 4, 2026
  • Quebec Law 25 s. 9.1 privacy-by-default attestedVerified Sep 4, 2026
  • Quebec Law 25 ss. 8-8.2 transparency attestedVerified Sep 4, 2026

retention_declared (4)

  • Alberta PIPA s. 35 retention attestedVerified Sep 4, 2026
  • BC PIPA s. 35 retention attestedVerified Sep 4, 2026
  • Quebec Law 25 s. 23 retention/destruction attestedVerified Sep 4, 2026
  • Retention periods declaredVerified Sep 4, 2026

dpo_governance (8)

  • Alberta PIPA s. 5 accountability attestedVerified Sep 4, 2026
  • Alberta PIPA s. 6 policies (+ foreign SP) attestedVerified Sep 4, 2026
  • BC PIPA s. 4 accountability attestedVerified Sep 4, 2026
  • BC PIPA s. 5 policies & complaint process attestedVerified Sep 4, 2026
  • PIPEDA 4.1.1 accountable individual attestedVerified Sep 4, 2026
  • PIPEDA 4.1.4 privacy program attestedVerified Sep 4, 2026
  • Quebec Law 25 s. 3.1 person in charge attestedVerified Sep 4, 2026
  • Quebec Law 25 s. 3.2 governance policies attestedVerified Sep 4, 2026

lawful_basis (12)

  • Alberta PIPA ss. 11/16/19 reasonable-purposes attestedVerified Sep 4, 2026
  • Alberta PIPA ss. 7-8 consent attestedVerified Sep 4, 2026
  • BC PIPA ss. 11/14/17 reasonable-purposes attestedVerified Sep 4, 2026
  • BC PIPA ss. 6-7 consent attestedVerified Sep 4, 2026
  • Lawful basis declaredVerified Sep 4, 2026
  • Per-purpose basis human-confirmedVerified Sep 4, 2026
  • PIPEDA 4.2 purposes identified attestedVerified Sep 4, 2026
  • PIPEDA 4.3 knowledge & consent attestedVerified Sep 4, 2026
  • PIPEDA 4.4 collection limited attestedVerified Sep 4, 2026
  • PIPEDA 4.5 use/retention limited attestedVerified Sep 4, 2026
  • Quebec Law 25 ss. 12-14 consent conditions attestedVerified Sep 4, 2026
  • UK GDPR legitimate-interests split (DUAA 2025)Verified Sep 4, 2026

dsar_rights (5)

  • Alberta PIPA ss. 24-25 access & correction attestedVerified Sep 4, 2026
  • BC PIPA ss. 23-24 access & correction attestedVerified Sep 4, 2026
  • PIPEDA 4.9 access account-of-use attestedVerified Sep 4, 2026
  • Quebec Law 25 s. 27 access & portability attestedVerified Sep 4, 2026
  • Quebec Law 25 s. 28.1 de-indexation attestedVerified Sep 4, 2026

vendor_dpa (8)

  • Art. 28(3) processor terms completeVerified Sep 4, 2026
  • CCPA § 7051 processor terms completeVerified Sep 4, 2026
  • EU GDPR cross-border transfers on a valid Chapter V gatewayVerified Sep 4, 2026
  • State processor-contract terms completeVerified Sep 4, 2026
  • Sub-processor consumer opt-out flow-down attested (US state)Verified Sep 4, 2026
  • Sub-processor DPA flow-down attested (Art. 28(4))Verified Sep 4, 2026
  • UK GDPR cross-border transfers on a valid Chapter V gatewayVerified Sep 4, 2026
  • Vendor DPAs in placeVerified Sep 4, 2026

customer_security_program (2)

  • Art. 32(1) security measures attestedVerified Sep 4, 2026
  • Information-security program attestedVerified Sep 4, 2026

ccpa_right_to_know (1)

  • CCPA § 1798.110(c) categories disclosure assembledVerified Sep 4, 2026

ccpa_data_minimization (1)

  • CCPA data minimization attestedVerified Sep 4, 2026

ccpa_verification_methods (1)

  • CCPA DSAR verification methods attestedVerified Sep 4, 2026

cppa_cyber_audit (1)

  • CPPA cybersecurity audit positionVerified Sep 4, 2026

cppa_risk_assessment (1)

  • CPPA risk assessments record § 7152 contentVerified Sep 4, 2026

childrens_code (1)

  • DPA 2018 s.123 Age Appropriate Design Code (Children's Code) — Standard 2 DPIAVerified Sep 4, 2026

dsar_sla (1)

  • DSAR deadlines metVerified Sep 4, 2026

ai_act_literacy (1)

  • EU AI Act Art. 4 AI literacy attestedVerified Sep 4, 2026

ai_act_prohibited (1)

  • EU AI Act Art. 5 no prohibited practiceVerified Sep 4, 2026

non_discrimination (1)

  • No discrimination for exercising rightsVerified Sep 4, 2026

pecr_cookies (1)

  • PECR cookie/tracker Schedule A1 basis election (DUAA 2025)Verified Sep 4, 2026

pecr_marketing (1)

  • PECR reg 22 electronic-mail marketing basis election (DUAA 2025)Verified Sep 4, 2026

review_currency (1)

  • Periodic reviews on scheduleVerified Sep 4, 2026

data_transfers (1)

  • PIPEDA cross-border transparency disclosed in noticeVerified Sep 4, 2026

records_ropa (1)

  • PIPEDA s. 10.3 breach records attestedVerified Sep 4, 2026

policy_current (1)

  • Policy matches processingVerified Sep 4, 2026

dpia_linkage (1)

  • Required DPIAs completedVerified Sep 4, 2026

uk_dpo (1)

  • UK GDPR Arts 37-39 data protection officerVerified Sep 4, 2026

by_design (1)

  • UK GDPR data protection by design & by default (DUAA 2025 Art 25)Verified Sep 4, 2026

uk_complaints (1)

  • UK GDPR data-subject complaints facilitated (DUAA 2025)Verified Sep 4, 2026

usstate_minimization (1)

  • US-state data minimization attestedVerified Sep 4, 2026

usstate_dpia_available (1)

  • US-state data protection assessment available to the AGVerified Sep 4, 2026

optout_honoring (1)

  • US-state opt-out signal (GPC) honoring attestedVerified Sep 4, 2026

usstate_purpose_limitation (1)

  • US-state purpose limitation attestedVerified Sep 4, 2026

cert_currency (1)

  • Vendor certifications currentVerified Sep 4, 2026

Published policies

Privacy Automated keeps its published policies in sync with what it actually does. Each version below is signed and anchored to Privacy Automated’s public transparency log, so you can confirm the policy was current as of the date shown.

Customer Privacy NoticePrivacy policyv12signed

Current as of Aug 31, 2026.

manifest 506fbfa94091247d

Verify independently: fetch the Ed25519 key at /api/keys/signing and confirm the publication event in the daily transparency roots.

Policies we maintain

Privacy Automated maintains the following policies as part of its privacy and security program. The full text isn’t published here — it’s available to customers and reviewers on request.

Acceptable Use & Code of ConductSecurity policyAvailable on requestUpdated Jul 31, 2026
Access Control PolicySecurity policyAvailable on requestUpdated Jul 31, 2026
Annual Security Risk AssessmentSecurity policyAvailable on requestUpdated Jul 31, 2026
Change Management PolicySecurity policyAvailable on requestUpdated Jul 31, 2026
Data Retention & Disposal PolicySecurity policyAvailable on requestUpdated Jul 31, 2026
Incident Response RunbookSecurity policyAvailable on requestUpdated Jul 31, 2026
Information Security PolicySecurity policyAvailable on requestUpdated Jul 31, 2026
Vendor Management PolicySecurity policyAvailable on requestUpdated Aug 3, 2026
Public verifier · no account required

Verify a sealed packet from Privacy Automated

If Privacy Automated has shared a signed evidence packet with you — a sealed DSAR, an approved DPIA — paste its JSON below. The verifier re-checks the Ed25519 signature against the transparency key published at /api/audit/transparency-key — no account, no API key, no contact with Privacy Automated or PrivacyAutomated required.

Don’t have a sample to verify? Ask Privacy Automated for one — sealed packets are a one-click download from any closed DSAR or approved DPIA in their workspace, and the bytes are byte-stable so the same record produces the same packet every time.

Three ways to convince yourself, in order of setup cost

1Read the verdict
Zero setup

The verifier above re-canonicalizes the packet you pasted (sorted keys, compact separators), prepends the domain prefix PA-EVIDENCE-PACKET-V1\n, and Ed25519-verifies the embedded signature against the public key at /api/audit/transparency-key. If the result above says authentic, the packet’s bytes haven’t changed since the customer sealed it.

2Check our side offline
One terminal, no network round-trip

Download the public Ed25519 verification key once, then verify any packet bytes locally — without ever talking to our servers afterwards:

# Once: fetch the public key
curl -o pa-transparency.pem \
  /api/audit/transparency-key

# Per packet: pull the sig, zero that field, prepend domain, canonicalize, verify
python3 -c "import json, base64; \
  d = json.load(open('packet.json')); \
  sig = base64.b64decode(d['verification']['signature_base64']); \
  d['verification']['signature_base64'] = ''; \
  body = b'PA-EVIDENCE-PACKET-V1\n' + \
    json.dumps(d, sort_keys=True, separators=(',',':')).encode(); \
  open('/tmp/sig', 'wb').write(sig); \
  open('/tmp/body', 'wb').write(body)"
openssl pkeyutl -verify -pubin -inkey pa-transparency.pem \
  -rawin -in /tmp/body -sigfile /tmp/sig

Signature Verified Successfully = same answer as the verdict above, no trust in our server required after the initial key fetch.

3Verify against Bitcoin without trusting us
Requires a Bitcoin node (yours or a public RPC)

The packet’s seal references the daily audit-event Merkle root, which is itself anchored to Bitcoin via OpenTimestamps. The full verification chain — packet → audit chain → daily Merkle root → Bitcoin block height → block in YOUR Bitcoin — is documented step-by-step at privacyautomated.ai/trust-architecture.html (Invariant 3). Most regulators don’t need to go this deep, but the option exists, and it’s the answer to “but how do I know you didn’t just sign a fake timestamp?”

What the seal proves

  • The packet bytes are unaltered since sealing.
  • The sealing happened on the embedded date.
  • The named human signed off.
  • Any AI inference that touched the record was running the named system prompt at the named SHA-256 hash.
  • The audit-event chain is intact from the start of the record to the seal.

What the seal does not prove

  • Legal correctness. The seal proves the DSAR closed in 21 days; it does not prove 21 days satisfied the regulatory obligation. That’s a separate claim involving deadline math + legal judgment.
  • Truth of the inputs. The seal proves nothing was altered after sealing. It does not prove the privacy team did the underlying work correctly. Garbage in, signed garbage out.
  • What a court would conclude about the underlying records. That’s for your counsel.

The full engineering substrate behind these claims is documented at privacyautomated.ai/trust-architecture.html.

Have a question?

Skip the questionnaire. Ask Privacy Automated’s privacy team directly — about sub-processors, data residency, certifications, DPAs, anything. They’ll reply to you by email, and may point you at one of the proof packs above.

Goes straight to Privacy Automated’s privacy team. We only use your email to reply.