08 · Data processing

What happens to data we touch.

The summary your vendor review needs, in the order it usually asks. The executable agreement is sent with every proposal, before work starts, so nobody is chasing it three weeks into a security review.

What this page is

A summary of the data processing agreement, not the agreement. The executable version goes out with any proposal and forms part of the contract. We send it unprompted because a vendor review that stalls for three weeks waiting on a document is three weeks nobody gets back.

Who is who

In almost every engagement you are the controller and we are the processor. You decide what personal data is collected and why; we act on your documented instructions and nothing else. Where we process data about our own prospects and correspondents, such as an email you send us, we are the controller and the privacy notice covers it.

Under India's Digital Personal Data Protection Act the equivalent roles are Data Fiduciary and Data Processor, and the same split applies.

What we process, and why

Only what the engagement requires, for only as long as it requires. In most of our work that means we hold no production personal data at all: we work against synthetic or masked data and your engineers keep the real thing. Where the work genuinely needs production access, that is scoped in writing, time-limited, and logged.

Where it sits

In your infrastructure, by default. We build in cloud accounts you own, which means your data never leaves your control and access ends when you revoke it rather than when we get round to it. Where we must hold data ourselves, the region is agreed with you in advance and written into the agreement.

Sub-processors

A short list, disclosed before signature rather than buried in an annex you find later. We give you thirty days notice of any addition and you can object. We do not use sub-processors that would move your data to a region you have not agreed to.

International transfers

We are established in India, which the European Commission has not granted an adequacy decision. Transfers of EU personal data therefore run on Standard Contractual Clauses, which are attached to the agreement, together with a transfer impact assessment. For UK clients the UK Addendum applies. If your review requires data to stay inside the EEA, say so at the start and we will scope the work so that it does.

Our people

Everyone with access is bound by confidentiality that survives the engagement, works on least privilege, and loses access at handover rather than at some later cleanup. The security page covers the controls.

If something goes wrong

We notify you without undue delay and in any case within twenty four hours of becoming aware of a personal data breach, with what we know at that point rather than waiting until we know everything. You are the controller, so the regulatory clock is yours and you need the information early enough to use it. We assist with your notifications and with any data subject request you receive.

Retention and deletion

On termination we return or delete personal data at your choice, within thirty days, and confirm it in writing. Backups are covered by the same commitment on their own expiry cycle, which we state rather than leave vague. We do not keep a copy for our own purposes.

Audit

You can audit, on reasonable notice, once a year or after an incident. For most clients a written questionnaire and a call with the engineer who built the thing answers it faster than a formal audit, and we would rather do that than trade PDFs.

Certifications, honestly

We hold none yet. CALIPER LABS LLP is newly formed and any badge on this page would be a lie. We will say so plainly in your vendor review rather than gesturing at a framework we merely follow the spirit of. What we can give you is the agreement, the sub-processor list, the controls on the security page and a call with the people doing the work.

Questions

Write to hello@caliperlabs.dev. A person reads it.

Last updated 24 September 2026. All legal documents.