Legal
Data Processing Agreement
Last updated: May 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Allotly ("we", "us", the "Processor") and the customer entity that has subscribed to Allotly's services (the "Customer", "you", the "Controller") for the use of Allotly's AI access governance platform (the "Service").
This DPA applies whenever Allotly processes Personal Data on behalf of the Customer in the course of providing the Service, and is intended to satisfy the requirements of Article 28 of the UK GDPR and the EU GDPR (together, "GDPR").
By subscribing to a Team or Enterprise plan, the Customer is deemed to have entered into this DPA. A countersigned copy is available on request at security@allotly.ai.
1. Definitions
- Personal Data: any information relating to an identified or identifiable natural person processed by Allotly on behalf of the Customer through the Service.
- Data Subject: an identified or identifiable natural person to whom Personal Data relates (typically, the Customer's end-users — employees, students, contractors, or other individuals issued access by the Customer).
- Sub-processor: a third party engaged by Allotly to process Personal Data on behalf of the Customer.
- Restricted Transfer: a transfer of Personal Data from the UK or EEA to a country not benefiting from an adequacy decision.
2. Roles and scope
The Customer is the Controller of the Personal Data. Allotly is the Processor, acting only on the Customer's documented instructions, which are deemed to be the instructions set out in this DPA, the Allotly Terms of Service, and the configuration choices the Customer makes within the Service.
This DPA does not apply to the content of prompts or completions exchanged with third-party AI providers, which Allotly does not store.
3. Subject matter, duration, nature, and purpose of processing
Allotly processes Personal Data to provide the AI access governance platform: authenticating users, enforcing spend budgets, and delivering transactional notifications. The duration of processing corresponds to the term of the Customer's subscription.
4. Allotly's obligations as Processor
Allotly will: process Personal Data only on the Customer's documented instructions; ensure that all authorised persons are bound by confidentiality obligations; implement appropriate technical and organisational measures; assist the Customer with data subject rights; delete or return Personal Data upon termination; and provide all information necessary to demonstrate compliance.
5. Technical and organisational measures
- Encryption at rest: All Personal Data is stored in PostgreSQL with encryption at rest. AI provider API keys are encrypted using AES-256-GCM.
- Encryption in transit: All connections use HTTPS/TLS.
- Access controls: Role-based access controls limit staff access to Personal Data to those who need it for their role.
- Audit logging: Administrative actions are recorded in a comprehensive audit log.
- No prompt storage: Prompts and completions are never written to disk or stored in any database.
6. Sub-processors
Allotly engages the following categories of Sub-processors: application hosting, managed database, payment processing, and transactional email. The current list is maintained at /subprocessors. Allotly will notify Customers of any intended additions or replacements at least 30 days in advance.
7. International transfers
Some Sub-processors are based in the United States. Where Personal Data is transferred outside the UK or EEA, Allotly ensures appropriate safeguards are in place, including Standard Contractual Clauses where required.
8. Data subject rights
Allotly will assist the Customer in fulfilling data subject requests (access, rectification, erasure, portability, restriction, and objection) within 30 days of a written request, taking into account the nature of the processing.
9. Data breach notification
Allotly will notify the Customer of any Personal Data breach without undue delay after becoming aware of the breach, and in any event within 72 hours where feasible, providing sufficient information to allow the Customer to meet its own regulatory obligations.
10. Audit rights
Allotly will provide all information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits and inspections conducted by the Customer or an auditor mandated by the Customer, subject to reasonable notice and confidentiality obligations.
11. Governing law
This DPA shall be governed by and construed in accordance with the laws of England and Wales.
12. Contact
For DPA-related enquiries, contact us at security@allotly.ai.