Last updated: 24 June 2026
For client personal data processed within the product, the customer is the controller and Pop Hasta Labs Ltd is the processor. This DPA forms part of the agreement between us.
We process personal data only to provide the service and on the customer’s documented instructions, including as configured in the Control Center.
Personal data is detected and tokenised by the Secure Context Retrieval System (SCRS) before any AI model or search index processes it, and rehydrated only for authorised users at egress. We do not use customer content to train shared models.
Personnel with access to personal data are bound by confidentiality obligations.
We implement appropriate technical and organisational measures, including encryption at rest and in transit, HSM-backed key management, the SCRS firewall, field-level access controls, BYOK options and a tamper-evident audit trail. ISO 42001, SOC 2 and ISO 27001 are on our roadmap.
We engage vetted sub-processors (for example infrastructure, payments and governed AI inference). The current list is published at Sub-processors, and we give notice of changes with a right to object.
We host in the UK/EU and support data residency. Where transfers occur, we use the UK IDTA or EU SCCs as appropriate.
We assist the customer in responding to data subject requests and in meeting security, breach-notification and impact-assessment obligations, including via the Governance module.
We notify the customer without undue delay after becoming aware of a personal data breach affecting their data.
On termination, the customer can export data for a limited period, after which we delete it — including by crypto-shred where keys are customer-managed.
We make available information needed to demonstrate compliance and allow for audits in line with the agreement.
privacy@pophastalabs.com · Pop Hasta Labs Ltd, a company registered in England and Wales (no. 16742039), registered office 128 City Road, London EC1V 2NX, United Kingdom. See also our Privacy Policy.