Data Processing Agreement
Constructive News Mirror Version 1.0, 22 September 2026
This Agreement is an addendum to the Service Agreement between the parties and forms an integral part of it. Terms defined in the Service Agreement have the same meaning here.
It is published at constructivenewsmirror.com/legal/dpa and is not signed on its own: the Order Form the parties sign states the version of this Agreement they enter into, and the Customer's elections under it.
1. Roles and scope
1.1 The Customer is the controller and the Supplier is the processor for personal data contained in Customer Content.
1.2 Annex 1 sets out the subject matter and duration of the processing, its nature and purpose, the types of personal data and the categories of data subjects.
1.3 The Customer is responsible for the lawfulness of the personal data it submits and for its own obligations as controller.
2. Instructions
2.1 The Supplier processes the personal data only on the Customer's documented instructions. Those instructions are this Agreement, the Service Agreement and the Customer's use of the Service. Where EU or Member State law to which the Supplier is subject requires it to process otherwise, the Supplier informs the Customer before processing unless that law prohibits it.
2.2 The Supplier does not process the personal data for any purpose of its own.
2.3 The Supplier informs the Customer if it considers an instruction to infringe the GDPR or other applicable data protection law, and may suspend the affected processing until the instruction is confirmed, withdrawn or amended.
3. Personnel
3.1 The Supplier limits access to the personal data to those persons who need it to provide the Service, and ensures that each of them is bound by an obligation of confidentiality that survives the end of their engagement.
3.2 The Supplier reviews the list of persons with access regularly and withdraws access that is no longer necessary. It demonstrates on the Customer's request that a person with access is bound by an obligation of confidentiality.
4. Security
4.1 The Supplier implements the technical and organisational measures set out in Annex 2. The parties agree that those measures are appropriate under Article 32 GDPR, having regard to the nature, scope, context and purposes of the processing and to the risks to data subjects.
4.2 The Supplier may change a measure provided the change does not reduce the overall level of security.
4.3 The Supplier has assessed the risks the processing presents to data subjects, and its security measures address them. It reviews that assessment when the Service changes materially. The Customer provides the information the Supplier needs to identify risks arising from the Customer's own use of the Service.
4.4 The Service is hosted in the EEA. Moving its hosting outside the EEA is a change under clause 5.3.
5. Sub-processors
5.1 The Customer gives general written authorisation for the Supplier to engage sub-processors. Those engaged at the date of this Agreement are listed in Annex 3.
5.2 The Supplier imposes on each sub-processor data protection obligations equivalent to those in this Agreement, except a sub-processor listed as not bound by such obligations. The Supplier remains liable to the Customer for the performance of every sub-processor, whether or not it is so bound.
5.3 The Supplier gives the Customer at least 30 days' written notice before engaging a new sub-processor or materially changing the role of an existing one, and publishes a summary of the current list at constructivenewsmirror.com/legal/subprocessors. The Customer may object on reasonable data protection grounds at any time before that notice period ends.
5.4 Where the Customer objects, the parties shall discuss the objection in good faith. If within 60 days of the objection the Supplier has neither refrained from the change for the Customer's personal data nor offered a reasonable alternative that removes the ground of objection, the Customer may terminate the affected part of the Service, or the whole of it where that part cannot be severed, on written notice and without penalty, with a pro rata refund of fees paid for any period after termination.
5.5 The Supplier provides, on the Customer's written request, a copy of the data protection terms agreed with a sub-processor, or a reference to them where the sub-processor publishes them.
6. Assistance
6.1 Taking into account the nature of the processing, the Supplier assists the Customer by appropriate technical and organisational measures in responding to requests by data subjects to exercise their rights. Export and deletion under clause 11 are provided for that purpose.
6.2 Where the Supplier receives such a request directly, it forwards the request to the Customer without undue delay and does not respond to it itself except to confirm the referral.
6.3 Taking into account the nature of the processing and the information available to it, the Supplier assists the Customer in complying with Articles 32 to 36 GDPR.
6.4 The Supplier may charge for assistance that goes beyond the functions the Service provides and is not attributable to the Supplier's own act or omission. The Supplier states the rate before the work begins and does not begin it without the Customer's agreement.
7. Source protection
7.1 The Customer may be subject to source-protection obligations under applicable law and professional press ethics.
7.2 The Supplier shall:
(a) refer to the Customer any law enforcement, prosecutorial, intelligence or other public authority, other than a data protection supervisory authority, that asks it for the Customer's data;
(b) give such an authority access only where the law requires it, and challenge a request where, after careful assessment, there are reasonable grounds to consider it unlawful;
(c) notify the Customer without undue delay of any legal demand for access to the Customer's data, unless prohibited from doing so, and not disclose data in response before the Customer has had a reasonable opportunity to object.
8. Personal data breach
8.1 The Supplier notifies the Customer of any personal data breach affecting the Customer's personal data without undue delay and, where possible, within 24 hours of becoming aware of it.
8.2 The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed, so far as that information is available to the Supplier. Where it is not available at once, the Supplier provides it in phases without undue delay.
8.3 The Supplier assists the Customer in meeting its obligations under Articles 33 and 34 GDPR.
9. International transfers
9.1 Every model call carrying article or draft content is processed within the EEA. Where the Customer uses the email channel, a submitted draft transits the inbound email provider's global network before it reaches the Service.
9.2 Otherwise, personal data is transferred outside the EEA only to listed sub-processors that are established or process data outside the EEA.
9.3 The list of sub-processors states, for each one established or processing outside the EEA, the mechanism relied on under Chapter V GDPR, or that no such mechanism is in place. Where the mechanism is the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914, the Supplier concludes them with the recipient.
9.4 The transfers described in this Agreement are made on the Customer's instruction, given by entering into it and by the elections recorded in the Order Form. The Supplier makes no other transfer outside the EEA without the Customer's documented instruction.
10. Information and audit
10.1 The Supplier makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR and with this Agreement, and allows for and contributes to audits conducted by the Customer or an auditor it mandates. The Supplier may respond to an information request with existing documentation.
10.2 An audit may be conducted once in any twelve-month period, on at least three weeks' written notice, during normal business hours, and in a manner that does not disrupt the Service or give access to another customer's data. The auditor may be the Customer's own staff or an independent third party that is not a competitor of the Supplier and is bound by confidentiality. The Customer bears the cost of the audit and reimburses the Supplier's reasonable costs for staff time.
10.3 Clause 10.2 does not apply where a personal data breach has affected the Customer's personal data, where a supervisory authority requires an audit, or where the Customer has reasonable grounds, stated in writing, to believe the Supplier is not complying with this Agreement.
10.4 The Supplier gives a supervisory authority exercising a right of access under applicable law the access and the information that right requires.
11. Deletion and return
11.1 On termination the Supplier deletes the personal data it processes on the Customer's behalf or, where the Customer has elected return in writing, returns it and then deletes it, unless EU or Member State law requires the Supplier to retain it. The Customer may make or change that election by written notice at any time before termination.
11.2 Return is by export of the Workspace in machine-readable form. Deletion covers the Workspace's Customer Content and Output, its job records, its memberships, the accounts of its Users who belong to no other Workspace, and the Workspace itself. The Supplier completes deletion within 30 days of termination and confirms completion in writing. Until then the Workspace remains readable, so that the Customer can retrieve its data, unless the Customer asks for earlier deletion.
11.3 During the term, the Customer may instruct the Supplier in writing to delete any data it holds for the Customer, or to export the Workspace. The Supplier accepts such an instruction only from an owner of the Workspace, sent to newsmirror@constructiveinstitute.org. The Supplier carries it out within 30 days and confirms in writing what was deleted or exported.
11.4 Deletion does not reach the copies that Annex 1 describes as remaining for a limited time. They expire on the schedules stated there, and none of them is restored to active use after deletion.
12. Term and general
12.1 This Agreement takes effect with the Service Agreement and continues for as long as the Supplier processes personal data on the Customer's behalf.
12.2 The provisions of the Service Agreement on liability, notices, changes, governing law and venue apply to this Agreement.
12.3 Either party may require this Agreement to be renegotiated where a change in applicable law makes it necessary.
Annex 1: Particulars of the processing
Parties
As stated in the Order Form.
Subject matter and duration
The provision of the Service. The processing continues for the term of the Service Agreement and until deletion or return under clause 11 is complete.
Nature and purpose
Automated assessment of journalistic text, returning assessments and editorial suggestions to a journalist. The supporting purposes are authentication and access control, aggregate reporting over the Customer's own corpus, keyword monitoring, source suggestion and usage accounting.
Categories of data subjects
1. Users of the Service. 2. Individuals named or described in the material submitted, including interviewees, public figures, named sources, the subjects of a case, and the author of the material. 3. Individuals identified as potential sources, where the Customer uses source suggestion.
Types of personal data
| Category | Detail |
|---|---|
| Account data | Name, email address, organisation, password hash, role within the Workspace, and invitations |
| Article and draft content | The text of articles or drafts submitted for analysis, which may contain personal data of any kind about the people it concerns |
| Analysis output | Scores, written assessments, and verbatim passages quoted from the submitted text as evidence for a criterion |
| Batch corpus data | Article metadata, including author names, and extracts of article bodies |
| Source lead data | Names, affiliations, source URLs and verbatim quotations for suggested sources |
| Usage data | Timestamps, word counts, language, allowance consumption |
Special categories of personal data
The Service does not request personal data within Articles 9 or 10 GDPR and no feature depends on it. Material submitted for assessment may nevertheless contain such data concerning the people it discusses. The measures in Annex 2 apply to submitted material without distinction.
Retention and deletion
| Data | Period |
|---|---|
| Analysis records, source lead results and watchlist diagnoses | 90 days from creation |
| Batch job records | 30 days |
| Batch reports and uploaded corpora | Until the Customer deletes them |
| Saved story ideas | Until the User who saved them deletes them |
| Account and Workspace data | The term of the Service Agreement, then deleted under clause 11.2 |
| Submitted draft text | Not retained |
| Inbound email bodies | Not retained |
The Customer may set shorter periods in the Order Form.
Who deletes what. A daily automated deletion enforces the periods above; within them, Users delete what the Service lets them delete, and the Supplier deletes anything else on instruction under clause 11.3.
Copies that remain for a limited time. Deleted data does not remain in the active Service. Copies remain in database backups for up to 90 days, in previous versions of stored files for up to 30 days, and with sub-processors under their own retention schedules, as stated in Annex 3.
Source suggestion (Find sources)
Find sources sends search queries, written by a model from the article, to search services in the United States. A query can contain a name that appears in the article; no article text is sent. Where the Order Form states that Find sources is included, the Customer instructs the Supplier to make those transfers.
Annex 2: Technical and organisational measures
Level of security
The measures reflect that Customer Content is unpublished journalistic work that may identify a confidential source.
Access control
Access requires authentication. Permissions are enforced by role, and each Workspace's data is separated from every other's.
Encryption
Connections use TLS. Stored data is encrypted at rest.
Credentials
Production credentials are kept in a managed secret store.
Backup and recovery
The database is backed up nightly within the EEA. Backups are kept for up to 90 days, and restores are tested. Previous versions of stored files are kept for up to 30 days. No recovery point or recovery time is agreed.
Incident response
A documented incident procedure applies.
Logging and monitoring
Logs and error monitoring are configured not to record submitted text. Product analytics contains no Customer Content.
Annex 3: Sub-processors
The sub-processors the Customer authorises at the date of signature are those in the sub-processor list attached below, which forms part of this Annex. For each, the list states its legal entity and address, the processing it carries out and the data it receives, its processing location, and the transfer mechanism relied on or that none is in place.
The Supplier publishes a summary of the current list at constructivenewsmirror.com/legal/subprocessors. Changes to the list are made under clause 5.3.
Attached list dated: 28 September 2026.
This list sets out the sub-processors the Supplier engages, the processing each carries out and the data it receives, where that data is processed, and the transfer mechanism relied on or that none is in place. A sub-processor established outside the EEA receives personal data under the mechanism stated, whether or not it stores that data inside the EEA. Changes to this list are made under clause 5 of the Data Processing Agreement.
Sub-processors receiving article or draft content
| Sub-processor | Processing and data received | Location | Transfer mechanism |
|---|---|---|---|
| Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland. Company number 256796 | Azure OpenAI. Language models for analysis, source suggestion and archive search. Receives the full text of an article or draft and the outlet profile. Content that Microsoft's abuse monitoring flags may be stored for up to 30 days and reviewed by Microsoft staff located in the EEA | EU data zone, from a resource in Sweden | None required. Established and processing in the EEA |
| Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, D02 R296, Ireland. Company number 660412 | Runs the application, the batch worker and the database backup; stores uploaded corpora, reports and database backups; holds the batch job queue; and translates article bodies before batch scoring. Receives all data the Service processes | Netherlands. Translation in the EU | None required. Established and processing in the EEA |
| Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513 | Database and authentication. Receives account data, analysis records including passages quoted from submitted text, and article extracts | Germany. The sub-processor is established in Singapore | Standard contractual clauses (Commission Implementing Decision (EU) 2021/914), Module Three |
| Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, United States | Frontend hosting. Receives account data, and analysis results when a stored analysis or report is displayed. Its routing layer receives the session cookie and the User's identifier and email address, and no article content | Germany. The routing layer runs in every region. The sub-processor is established in the United States | EU-US Data Privacy Framework, and standard contractual clauses (Commission Implementing Decision (EU) 2021/914), Module Three |
| Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, United States | Inbound email for the email channel. Receives a submitted draft as the email body, in transit, and does not store it | The sub-processor's global network | EU-US Data Privacy Framework, and standard contractual clauses (Commission Implementing Decision (EU) 2021/914), Module Three |
| Functional Software, Inc. (Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, United States | Error monitoring. Receives error reports, configured not to include submitted text | Germany. The sub-processor is established in the United States | EU-US Data Privacy Framework, and standard contractual clauses (Commission Implementing Decision (EU) 2021/914), Module Three |
Sub-processors receiving content derived from articles
These receive no article or draft text, but receive material generated from it.
| Sub-processor | Processing and data received | Location | Transfer mechanism |
|---|---|---|---|
| Serper (serper.dev). The sub-processor does not publish its legal entity or address | Web search for source suggestion. Receives search queries written by a model from the article, which can contain a name that appears in it | United States | No data processing agreement or transfer mechanism is in place |
| Jina AI GmbH, part of Elastic N.V., Prinzessinnenstraße 19-20, 10969 Berlin, Germany. Register number HRB 218021 | Reads the pages that search returns, for source suggestion. Receives the addresses of up to ten search results | United States | Elastic Customer Data Processing Addendum, which provides standard contractual clauses |
| OurResearch (OpenAlex), a non-profit organisation established in the United States | Academic search for source suggestion. Receives up to two search queries written by a model from the article | United States | No data processing agreement or transfer mechanism is in place |
| Plus Five Five, Inc. (Resend), 2261 Market Street #5039, San Francisco, CA 94114, United States | Sends account emails and the reply in the email channel. Receives the recipient's email address and the message. The reply carries the assessment and quotes no passage from the draft | Sent from Ireland. Messages and delivery records are stored in the United States for 30 days | EU-US Data Privacy Framework, and standard contractual clauses |