Products
SCRS — the AI data firewall Other Me — the workspace Compare both products
Solutions
All solutions AI Assistants Email + Projects CRM Live Chat Ticketing Flows HR-lite Control Center
By industry
Accountancy Legal Mortgage & IFA Healthcare
Company
Custom Solutions Pricing Blog About Us
Log in
SCRS login Other Me — Business Other Me — Family Get started with SCRS
Legal

Data Processing Addendum

Last updated: 24 June 2026

1. Roles

For client personal data processed within the product, the customer is the controller and Pop Hasta Labs Ltd is the processor. This DPA forms part of the agreement between us.

2. Scope & instructions

We process personal data only to provide the service and on the customer’s documented instructions, including as configured in the Control Center.

3. Nature of processing & SCRS

Personal data is detected and tokenised by the Secure Context Retrieval System (SCRS) before any AI model or search index processes it, and rehydrated only for authorised users at egress. We do not use customer content to train shared models.

4. Confidentiality

Personnel with access to personal data are bound by confidentiality obligations.

5. Security

We implement appropriate technical and organisational measures, including encryption at rest and in transit, HSM-backed key management, the SCRS firewall, field-level access controls, BYOK options and a tamper-evident audit trail. ISO 42001, SOC 2 and ISO 27001 are on our roadmap.

6. Sub-processors

We engage vetted sub-processors (for example infrastructure, payments and governed AI inference). The current list is published at Sub-processors, and we give notice of changes with a right to object.

7. International transfers

We host in the UK/EU and support data residency. Where transfers occur, we use the UK IDTA or EU SCCs as appropriate.

8. Data subject requests & assistance

We assist the customer in responding to data subject requests and in meeting security, breach-notification and impact-assessment obligations, including via the Governance module.

9. Breach notification

We notify the customer without undue delay after becoming aware of a personal data breach affecting their data.

10. Deletion & return

On termination, the customer can export data for a limited period, after which we delete it — including by crypto-shred where keys are customer-managed.

11. Audits

We make available information needed to demonstrate compliance and allow for audits in line with the agreement.

12. Contact

privacy@pophastalabs.com · Pop Hasta Labs Ltd, a company registered in England and Wales (no. 16742039), registered office 128 City Road, London EC1V 2NX, United Kingdom. See also our Privacy Policy.