Data Processing Addendum
Effective date: August 13, 2026
Get AI Explanation
Need help understanding this document? Get an AI-powered explanation from your favorite AI models.
1. Introduction
This Data Processing Addendum (the "DPA") governs the processing of personal data by Detcord on behalf of participating institutions in connection with the Detcord intelligence network. The DPA forms part of the agreement between Detcord and each participating institution.
2. Roles of the Parties
For the purposes of applicable data protection law, the participating institution is the controller and Detcord is the processor. Where signal data is shared across the network, each participating institution acts as an independent controller of the data it lawfully receives.
3. Details of Processing
Detcord processes personal data to detect, investigate, and disrupt agentic financial crime. The processing includes:
- Ingesting and analyzing behavioral, transactional, and network signals;
- Maintaining shared signal intelligence across participating institutions;
- Generating alerts, case files, and investigative artifacts.
4. Processor Obligations
Detcord will:
- Process personal data only on documented instructions from the controller, unless required otherwise by law;
- Ensure persons authorized to process the data are subject to confidentiality obligations;
- Implement appropriate technical and organizational measures to protect the data;
- Not engage a sub-processor without prior notice and the opportunity to object;
- Assist the controller in responding to data subject requests and complying with data protection obligations.
5. Sub-Processors
Detcord may engage sub-processors to provide hosting, analytics, and security services. A current list of sub-processors is available on request. Controllers may object to a new sub-processor on reasonable grounds; where the parties cannot resolve the objection, the controller may terminate the affected services.
6. Security of Processing
Detcord maintains a security program that includes encryption in transit and at rest, access controls, continuous monitoring, vulnerability management, and regular independent audits. Where a personal data breach occurs, Detcord will notify the controller without undue delay and provide reasonable assistance.
7. Data Subject Rights
Detcord will reasonably assist the controller in fulfilling its obligations to respond to requests from data subjects exercising their rights. Given the operational security purpose of the service, the parties acknowledge that certain data may be subject to lawful restrictions on access.
8. Data Retention and Deletion
On termination of the agreement, Detcord will delete or return personal data in accordance with the controller's instructions, subject to any legal retention obligations.
9. Governing Law
This DPA is governed by the laws specified in the agreement between the parties. Any conflict between this DPA and the main agreement shall be resolved in favor of the DPA.