How we protect client data at every stage — from upload through annotation, review, delivery, and deletion. Every claim below is policy, not marketing.
Data is encrypted in transit with TLS 1.3 and at rest using AES-256. Backups are encrypted with the same standard. No client data moves between systems unencrypted.
Every user has exactly one role: admin, reviewer, annotator, or client. Annotators see only assigned items. Reviewers see their project. Clients see only their own progress and downloads.
Every action — login, label submitted, review decision, export, gate toggle — is timestamped with user ID and IP address. Logs are immutable and retained for 12 months.
Client data is deleted within 30 days of project completion, or on request — whichever comes first. Certified deletion receipts available on request.
Data is stored on EU-based infrastructure (Infrasu, Frankfurt). We can provision dedicated storage in other regions for enterprise contracts.
Every annotator and reviewer signs an individual NDA before accessing production work. Violations trigger immediate termination and legal action.
STATIK Annotate operates on a hardened hosting environment:
| Component | Configuration |
|---|---|
| Hosting | Infrasu LiteSpeed, Frankfurt, Germany (EU) |
| Transport encryption | TLS 1.3, HSTS enabled, forced HTTPS |
| At-rest encryption | AES-256 for database and file storage |
| Backups | Daily encrypted snapshots, 30-day retention |
| DDoS protection | Edge-level, provider-managed |
| Uptime SLA | 99.5% monthly (target), 99.0% contractual minimum |
| Monitoring | Uptime checks every 60 seconds, alerting to on-call |
Access is governed by a strict role model. No user can access data outside their role's scope.
| Role | Can access | Cannot access |
|---|---|---|
| Admin | Everything, all projects | — |
| Reviewer | Assigned projects, disputed items, quality metrics | Client billing, other clients' data |
| Annotator | Only assigned items in assigned projects | Client identities, other annotators' work |
| Client | Own projects, progress, exports | Other clients, annotator identities |
Each client's data is logically partitioned. Queries are always scoped by client_id. There is no path where a client can retrieve another client's data, even by guessing URLs.
Every client that uploads personal data must sign a DPA before project kickoff. Our standard template is available below. For enterprise clients with their own DPA, we review and execute theirs at no charge.
Print-ready template. Sign as-is, or send us your own for mutual execution.
Print / Save as PDFThis Data Processing Agreement ("DPA") forms part of the Master Services Agreement or Terms of Service between STATIK Annotate ("Processor") and the client identified below ("Controller").
"Personal Data" means any information relating to an identified or identifiable natural person processed under this DPA.
"Processing" means any operation performed on Personal Data, including collection, storage, annotation, review, transmission, and deletion.
"Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
The Processor shall process Personal Data solely for the purpose of providing data annotation, review, and delivery services as specified in the applicable Statement of Work. Processing activities include:
Processing shall continue for the term of the applicable Statement of Work, plus a 30-day deletion window after project completion.
The Controller authorizes the engagement of the following Sub-processors:
The Processor shall notify the Controller of any intended change to Sub-processors, giving the Controller an opportunity to object.
Where Personal Data originates from the European Economic Area and is transferred outside the EEA, such transfers shall be governed by the European Commission's Standard Contractual Clauses (Module Two: Controller to Processor).
The Processor shall implement at minimum: transport encryption (TLS 1.3), storage encryption (AES-256), role-based access control, session hardening, multi-tenant logical isolation, and immutable audit logging.
The Processor shall promptly notify the Controller if it receives a request from a data subject. The Processor shall not respond to such requests directly, except on documented instructions from the Controller.
Upon termination of services, the Processor shall delete all Personal Data within 30 days, unless applicable law requires storage. A written certification of deletion will be provided on request.
Each party's liability under this DPA is subject to the limitations of liability set out in the Master Services Agreement, except that liability arising from a breach of data protection obligations shall not be limited to the extent prohibited by applicable law.
This DPA shall be governed by the laws of [Jurisdiction], without prejudice to any mandatory data protection laws applicable to the Controller.
We respond to every security questionnaire within 3 business days. Send yours to hello@zumsphere.com.
Contact security team