Data Processing Agreement
Last updated: August 29, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between AssetSort ("we", "us", the "Processor") and the customer organisation using the AssetSort service (the "Customer"). It governs the personal data we process on the Customer's behalf and reflects the requirements of Article 28 of the EU General Data Protection Regulation ("GDPR") and the UK GDPR.
1. Roles of the Parties
For personal data imported into the service — whether synced from the Customer's Microsoft 365 tenant or entered manually — the Customer is the controller and AssetSort is the processor. Where the Customer is a managed service provider ("MSP") acting on behalf of its own clients, the Customer may itself be a processor for those clients; in that case AssetSort acts as a sub-processor, and the Customer warrants that it is authorised by each client to connect that client's Microsoft 365 tenant and to have its data processed under this DPA.
2. Scope of Processing
Subject matter and purpose: providing the AssetSort IT asset-intelligence platform — inventorying hardware, licences, and certificates, tracking renewals and lifecycle, and surfacing security posture — for the duration of the Customer's subscription.
Categories of personal data: identity and contact data of staff (names, email addresses, job titles), device and login associations, licence and seat assignments, and security posture data from Microsoft 365 (such as multi-factor authentication status and sign-in risk signals).
Data subjects: the Customer's staff and users and, for MSP customers, the staff and users of the MSP's clients.
3. Processing on Instructions
We process Customer personal data only on the Customer's documented instructions — which are the Terms of Service, this DPA, and the Customer's use and configuration of the service — unless processing is required by EU, member state, or UK law, in which case we will inform the Customer before processing unless that law prohibits it.
4. Confidentiality
We ensure that all persons authorised to process Customer personal data are bound by contractual or statutory obligations of confidentiality.
5. Security
Taking into account the state of the art and the nature of the data, we implement appropriate technical and organisational measures under Article 32 GDPR, including encryption of data in transit and at rest, tenant-scoped access controls, authenticated API access with per-organisation authorisation, rate limiting, and audit logging of destructive operations.
6. Sub-processors
The Customer grants a general authorisation for the sub-processors listed at assetsort.com/legal/subprocessors. We will give the Customer at least 30 days' notice before adding or replacing a sub-processor, during which the Customer may object on reasonable data-protection grounds; if the objection cannot be resolved, the Customer may terminate the affected subscription. We impose data-protection obligations on each sub-processor equivalent to those in this DPA and remain liable for their performance.
7. Assistance with Data Subject Rights
Taking into account the nature of the processing, we assist the Customer with appropriate technical and organisational measures in fulfilling data subject requests (access, rectification, erasure, restriction, portability, and objection). Individuals whose data reaches AssetSort through their employer or IT provider should direct requests to that organisation as controller; we will support the Customer in responding.
8. Personal Data Breaches
We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data, and will provide information reasonably required for the Customer to meet its own notification obligations under Articles 33 and 34 GDPR.
9. Deletion and Return of Data
On termination of the subscription, or on deletion of an organisation by the Customer, we delete the organisation's personal data — including database records and stored files — unless EU, member state, or UK law requires retention. A minimal deletion audit record (who requested deletion, when, and what was removed) is retained to evidence compliance. The Customer can export its data via the service's reporting and export features before deletion.
Deletion of an organisation is reversible for 30 days: it is first archived — read-only, still exportable — and permanently deleted at the end of that window, or sooner if the Customer chooses. Separately, an individual account holder may delete their own AssetSort account from within the service; that deletion is subject to a 14-day cancellation window and removes their profile, sign-in, and any organisation they alone own. It never removes an organisation shared with others, which must first be transferred to another administrator.
10. Audits
We make available the information necessary to demonstrate compliance with this DPA and, no more than once per year and on at least 30 days' written notice, allow for and contribute to audits or inspections conducted by the Customer or an auditor mandated by the Customer, at the Customer's expense and subject to reasonable confidentiality and scope constraints.
11. International Transfers
The service is hosted in Google Cloud region europe-west2 (London, United Kingdom), with the primary database in AWS region eu-west-2 (London) operated by Neon. Where a sub-processor processes personal data outside the EEA or the UK, the transfer is protected by an adequacy decision, the EU Standard Contractual Clauses (with the UK Addendum where applicable), or certification under the EU–US Data Privacy Framework, as listed on the sub-processor page.
12. Precedence and Liability
In the event of a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA prevails. The parties' liability under this DPA is subject to the limitations of liability in the Terms of Service to the extent permitted by applicable data protection law.
Contact Us
Questions about this DPA, or requests for a countersigned copy, can be sent to admin@assetsort.com.