Enterprise-grade protection

Security & Compliance

How we protect client data at every stage — from upload through annotation, review, delivery, and deletion. Every claim below is policy, not marketing.

Security posture

Six things every enterprise client asks about

Encryption everywhere

Data is encrypted in transit with TLS 1.3 and at rest using AES-256. Backups are encrypted with the same standard. No client data moves between systems unencrypted.

Role-based access

Every user has exactly one role: admin, reviewer, annotator, or client. Annotators see only assigned items. Reviewers see their project. Clients see only their own progress and downloads.

Full audit trail

Every action — login, label submitted, review decision, export, gate toggle — is timestamped with user ID and IP address. Logs are immutable and retained for 12 months.

Retention & deletion

Client data is deleted within 30 days of project completion, or on request — whichever comes first. Certified deletion receipts available on request.

Data residency

Data is stored on EU-based infrastructure (Infrasu, Frankfurt). We can provision dedicated storage in other regions for enterprise contracts.

NDA-covered workforce

Every annotator and reviewer signs an individual NDA before accessing production work. Violations trigger immediate termination and legal action.

Infrastructure

STATIK Annotate operates on a hardened hosting environment:

ComponentConfiguration
HostingInfrasu LiteSpeed, Frankfurt, Germany (EU)
Transport encryptionTLS 1.3, HSTS enabled, forced HTTPS
At-rest encryptionAES-256 for database and file storage
BackupsDaily encrypted snapshots, 30-day retention
DDoS protectionEdge-level, provider-managed
Uptime SLA99.5% monthly (target), 99.0% contractual minimum
MonitoringUptime checks every 60 seconds, alerting to on-call

Application-level protections

Access control

Access is governed by a strict role model. No user can access data outside their role's scope.

RoleCan accessCannot access
AdminEverything, all projects—
ReviewerAssigned projects, disputed items, quality metricsClient billing, other clients' data
AnnotatorOnly assigned items in assigned projectsClient identities, other annotators' work
ClientOwn projects, progress, exportsOther clients, annotator identities

Multi-tenant isolation

Each client's data is logically partitioned. Queries are always scoped by client_id. There is no path where a client can retrieve another client's data, even by guessing URLs.

Data Processing Agreement

Every client that uploads personal data must sign a DPA before project kickoff. Our standard template is available below. For enterprise clients with their own DPA, we review and execute theirs at no charge.

What the DPA covers

Standard Data Processing Agreement

Print-ready template. Sign as-is, or send us your own for mutual execution.

Print / Save as PDF

Data Processing Agreement

Effective upon signature by both parties

This Data Processing Agreement ("DPA") forms part of the Master Services Agreement or Terms of Service between STATIK Annotate ("Processor") and the client identified below ("Controller").

1. Definitions

"Personal Data" means any information relating to an identified or identifiable natural person processed under this DPA.

"Processing" means any operation performed on Personal Data, including collection, storage, annotation, review, transmission, and deletion.

"Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.

2. Scope of Processing

The Processor shall process Personal Data solely for the purpose of providing data annotation, review, and delivery services as specified in the applicable Statement of Work. Processing activities include:

  1. Ingesting datasets uploaded by the Controller
  2. Assigning items to trained annotators under NDA
  3. Performing quality assurance and consensus review
  4. Exporting labeled datasets in the format requested by the Controller
  5. Retaining audit logs for compliance purposes

3. Duration

Processing shall continue for the term of the applicable Statement of Work, plus a 30-day deletion window after project completion.

4. Obligations of the Processor

  1. Process Personal Data only on documented instructions from the Controller
  2. Ensure all personnel authorized to process Personal Data are bound by confidentiality agreements
  3. Implement appropriate technical and organizational measures including encryption, access control, and audit logging
  4. Assist the Controller in responding to data subject access, rectification, and erasure requests
  5. Notify the Controller without undue delay (within 72 hours) upon becoming aware of a Personal Data breach
  6. Delete or return all Personal Data at the end of the provision of services
  7. Make available all information necessary to demonstrate compliance and allow for audits

5. Sub-processors

The Controller authorizes the engagement of the following Sub-processors:

The Processor shall notify the Controller of any intended change to Sub-processors, giving the Controller an opportunity to object.

6. International Transfers

Where Personal Data originates from the European Economic Area and is transferred outside the EEA, such transfers shall be governed by the European Commission's Standard Contractual Clauses (Module Two: Controller to Processor).

7. Security Measures

The Processor shall implement at minimum: transport encryption (TLS 1.3), storage encryption (AES-256), role-based access control, session hardening, multi-tenant logical isolation, and immutable audit logging.

8. Data Subject Rights

The Processor shall promptly notify the Controller if it receives a request from a data subject. The Processor shall not respond to such requests directly, except on documented instructions from the Controller.

9. Deletion and Return

Upon termination of services, the Processor shall delete all Personal Data within 30 days, unless applicable law requires storage. A written certification of deletion will be provided on request.

10. Liability

Each party's liability under this DPA is subject to the limitations of liability set out in the Master Services Agreement, except that liability arising from a breach of data protection obligations shall not be limited to the extent prohibited by applicable law.

11. Governing Law

This DPA shall be governed by the laws of [Jurisdiction], without prejudice to any mandatory data protection laws applicable to the Controller.

For the Controller Name: ___________________________
Title: ___________________________
Signature: ___________________________
Date: ___________________________
For the Processor (STATIK Annotate) Name: ___________________________
Title: ___________________________
Signature: ___________________________
Date: ___________________________

Need a custom DPA or security review?

We respond to every security questionnaire within 3 business days. Send yours to hello@zumsphere.com.

Contact security team