Data Processing Addendum
This addendum forms part of the Terms of Service and applies where Maatvia LLC processes personal data contained in customer content on the customer's behalf. Where it conflicts with the Terms of Service on data protection, this addendum prevails.
1. Roles
The customer is the controller (or processor for its own customers) of personal data in customer content. Maatvia is the processor (or subprocessor) and processes that data only on the customer's documented instructions, which comprise the Terms of Service, this addendum and the customer's use of the console.
Maatvia remains an independent controller for account administration, billing, security and service improvement, as described in the Privacy Statement.
2. Subject matter, duration, nature and purpose
- Subject matter
- Provision of the Maatvia trade-risk console.
- Duration
- The subscription term plus the deletion window in section 8.
- Nature and purpose
- Hosting, storage, parsing, aggregation, scoring, translation and summarisation of trade and compliance data; export of reports at the customer's request.
- Categories of data subject
- The customer's personnel and authorised users; contacts at counterparties, suppliers and customers; individuals named in screening or regulatory records.
- Categories of personal data
- Business contact details, job roles, user account and log data, and any personal data the customer chooses to include in uploaded or connected files.
- Special categories
- Not requested and not required. Customers should not upload special-category data; if they do, they remain solely responsible for the lawfulness of doing so.
3. Maatvia's obligations
- Process personal data only on the customer's instructions and not for our own purposes, and inform the customer if an instruction appears to breach data-protection law.
- Impose confidentiality obligations on all personnel with access.
- Implement and maintain the technical and organisational measures in section 5.
- Assist the customer, at the customer's cost where the effort is material, with data-subject requests, impact assessments and regulator enquiries.
- Make available the information reasonably necessary to demonstrate compliance.
4. Customer obligations
The customer warrants that it has a lawful basis and any required notices or consents for the personal data it provides, that its instructions comply with applicable law, and that it manages its own users, seats and access rights — including revoking access for departing personnel.
5. Security measures
- Encryption of data in transit (TLS) and at rest.
- Row-level authorisation so each account can access only its own records.
- Role-based restrictions on privileged functions, including regulatory-tracker uploads and source configuration, which are restricted to Maatvia administrators.
- Encrypted storage of third-party integration tokens using authenticated encryption.
- Least-privilege staff access, unique credentials and multi-factor authentication on administrative systems.
- Audit logging of privileged actions, including every tracker fetch run.
- Managed backups with restore testing, and change control with peer review before deployment.
6. Subprocessors
The customer authorises the subprocessors listed on the Subprocessors page. We impose data-protection terms on each of them that are no less protective than this addendum and remain responsible for their performance. New subprocessors are published in advance and may be objected to as described on that page.
7. International transfers
Where processing involves a transfer from the EEA, UK or Switzerland to a country without an adequacy decision, the parties incorporate the European Commission's Standard Contractual Clauses (module two or three as applicable), together with the UK International Data Transfer Addendum where relevant. This addendum, its annexes and the Subprocessors page populate the required annex information.
8. Return and deletion
The customer can export its records at any time during the subscription. On termination we delete or irreversibly anonymise customer content within 30 days, except where retention is required by law, and purge it from rolling backups within 35 days. Written confirmation of deletion is available on request.
9. Personal data breach
We notify the customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting customer content, with the information available at that time, and provide reasonable assistance with the customer's own notification obligations.
10. Audits
On reasonable written notice, and no more than once per twelve months except after a breach or where a regulator requires it, we provide documentation and answer a security questionnaire. On-site audits are by agreement, at the customer's cost, subject to confidentiality and without disrupting other customers.
11. Liability and signature
Liability under this addendum is subject to the limitations in section 10 of the Terms of Service.
Accepting the Terms of Service accepts this addendum; no signature is required. If your procurement process needs a counter-signed copy, request one at privacy@maatvia.com.