Data Access & Sharing Addendum
This Data Access & Sharing Addendum (“Addendum”) forms part of the DLEGATE Terms of Service and governs the technical and operational modalities for data access, export, portability, and sharing in connection with the Customer’s use of the Service, in accordance with Regulation (EU) 2023/2854 (“EU Data Act”).
1. Relationship to the Agreement and Definitions
1.1 Relationship to the Terms and DPA
This Addendum supplements the Terms of Service and the Data Processing Agreement (“DPA”). It applies to all Customer Data processed in connection with the Service.
In case of conflict:
- this Addendum prevails with respect to data access, export, portability, and sharing rights;
- the DPA prevails with respect to personal data processing obligations.
1.2 Definitions
For the purposes of this Addendum:
- "EU Data Act" means Regulation (EU) 2023/2854.
- "Customer Data" has the meaning given in the Data Processing Agreement.
Capitalised terms not defined in this Addendum have the meanings given to them in the Terms of Service or the Data Processing Agreement.
2. Scope of Data Covered
2.1 Included Data
This Addendum applies to all Customer Data processed under the DPA, including session data, collected assets, workflow outputs, audit and activity logs, and derived or compiled data generated during use of the Service.
2.2 Excluded Data
Transient operational data (for example, real-time video streams or ephemeral telemetry) is excluded unless it is explicitly stored or exported at the Customer’s request.
3. Data Access Rights
3.1 Self-Service Access
The Customer’s authorised users may access and retrieve available Customer Data through the Service interface in accordance with the applicable subscription plan, the Plan and Feature Description, and the DPA.
3.2 Access Conditions
Access is provided under fair, reasonable, and non-discriminatory (“FRAND”) conditions and is protected by secure, role-based authentication mechanisms.
3.3 Assisted Access
Upon request, the Provider shall provide reasonable assistance with large-scale or bulk exports.
4. Export and Portability
4.1 Export Formats
Customer Data may be exported in commonly used machine-readable formats, including ZIP, PDF, PNG, JPG, CSV and, when API functionality is activated, JSON.
4.2 Structure and Reusability
Exported data is structured to allow reuse by the Customer’s systems in accordance with the applicable plan and the Data Processing Agreement.
4.3 API-Based Access
Where API functionality is enabled:
- access is subject to authentication, rate-limiting, and security controls defined by the Provider;
- API activation may require separate technical enablement and written agreement.
5. Third-Party and Sub-Processor Access
5.1 Sub-Processors
Sub-processors engaged by the Provider are bound by confidentiality, data protection, and data access obligations consistent with the DPA.
5.2 Third-Party Access on Customer Instructions
Access to Customer Data by third parties (for example, integration partners or downstream recipients) occurs only:
- on the Customer’s explicit instruction, or
- where technically necessary to deliver the Service as configured by the Customer.
Such access is deemed to occur on the Customer’s instructions for purposes of data protection and data transfer law.
6. Retention, Deletion and Availability
6.1 Retention Period
Data is retained for the period defined in the Terms of Service, the applicable subscription plan, and the Customer’s configuration settings.
6.2 Post-Termination Access
Upon termination or expiry of the Agreement, the Customer may access and export its Customer Data for up to ninety (90) days, unless a shorter period is defined in the applicable plan.
6.3 Deletion
After expiry of the applicable retention or post-termination access period, Customer Data is deleted or anonymised in accordance with the DPA, unless retention is required by applicable law or for the establishment, exercise, or defence of legal claims.
Where User accounts are deactivated during an active Customer relationship, limited system-related metadata and associated activity records may continue to exist in pseudonymised form as described in the DPA. Such records are deleted upon termination or expiry of the Customer relationship unless further retention is legally required.
7. Security and Traceability
7.1 Security Measures
Customer Data is protected using appropriate technical and organisational measures, including encryption of data in transit using HTTPS/TLS and encryption of stored data using industry-standard mechanisms.
7.2 Auditability
System access and actions may be logged to support traceability, auditability, security, and integrity of the Service. Where appropriate, system records may rely on pseudonymised identifiers rather than directly identifying user information.
7.3 Reference to DPA
Further details on security controls are set out in the DPA.
8. Requests and Operational Handling
8.1 Request Submission
Requests for data access, export, or portability must be submitted through the Customer’s designated account or support contact.
8.2 Response
The Provider will process such requests without undue delay and will confirm completion where applicable.
9. International Transfer
Where Customer-initiated data access, export, or sharing results in a transfer of data to a third country or third party, such transfer is deemed to occur on the Customer’s instructions. The Customer is responsible for ensuring that appropriate safeguards are in place where required by law.
10. Modification of the Addendum
The Provider may update this Addendum to reflect changes in legal or technical requirements, including the EU Data Act. The current version is available here.