data processing agreement.
Version 1.9, 26 August 2026. Questions: contact@noctovisor.com
Noctovisor is Noctovisor – Piotr Bogdanowicz, registered in Poland, ul. Hoża 5/7/61, 00-528 Warszawa. EU VAT ID PL5262736443, REGON 146596070, D-U-N-S® Number 427695885. Contact for everything in this agreement: contact@noctovisor.com.
The Customer is the organisation that sends Noctovisor a list of companies to watch or subscribes to the service.
The watched companies are the companies on that list. They may be the Customer's suppliers, service providers, customers, partners or any other third party, and a company here includes a business run by an individual, such as a sole trader.
This agreement is deliberately short. It states what the service does, what it holds, and what each party can rely on: nothing that is not currently true.
1. Roles, and what this covers
The Customer is the controller. Noctovisor is the processor. This agreement covers the personal data Noctovisor processes on the Customer's behalf: the list the Customer sends, the findings produced about the watched companies, and the email addresses the Customer nominates to receive alerts.
One part of the work sits outside that. Noctovisor decides for itself which public sources are worth reading and collects material from them: no customer instructs it which registers to watch, and the same reading serves every customer. For that step Noctovisor is an independent controller on its own legitimate-interests basis, set out in section 5 of the privacy policy. It becomes the Customer's processor from the point that material is assessed against the Customer's criteria and reported to them. The distinction matters because it decides who answers an objection from an individual named in a source, and whose assessment has to stand behind the collection.
Noctovisor is also a separate controller for its own website visitors, prospects and business records. That is covered by the privacy policy, not by this agreement.
This agreement takes effect when the Customer accepts it or, if earlier, when a list is first sent. It lasts as long as Noctovisor holds the Customer's data.
2. What the processing is
Subject matter. Monitoring public sources for information about the companies the Customer identifies, and reporting by email what meets the criteria the Customer has stated.
Processing operations. Parsing the list. Resolving each name on it to its legal entity and public identifiers, merging duplicates. Checking each public source on an interval matched to how often that source changes, with the fastest-moving checked daily. Assessing findings against the Customer's criteria. Drafting and translating alert text using commercial language models. Checking each alert against its source before sending. Sending alerts, summaries and reports by email. Keeping a dated record of what was checked and what was sent. Deleting or returning the data at the end.
Categories of data. From the Customer: the watched companies' names and domains, the Customer's own business contact details, the addresses nominated for alerts, and what the Customer says about an alert: the mark set on it and any words written about it, whether by reply or through the link the alert carries. That last category has been held since replies were first logged and was not listed here until this version; the omission is corrected rather than quietly filled. From public sources: the names and roles of individuals who appear in company registers, court and insolvency filings, sanctions listings, regulatory notices and press reports about those companies.
Categories of data subject. People at the Customer who send the list, give instructions or receive alerts. Individuals named in public sources about the watched companies: directors, officers, beneficial owners, insolvency administrators.
What Noctovisor does not hold. No contracts or contract terms. No spend or pricing data. No questionnaire responses, because the watched companies are never asked for anything. No credentials, API keys or access into the Customer's systems. There is no portal and no login, so there is no Noctovisor account for anyone at the Customer to hold. The page an alert links to for answering it is not a portal and does not change this: it holds no account and no session, shows only that alert's reference, and can reach nothing else about the Customer.
Duration. For the term of the service, plus the deletion periods in section 8.
3. Instructions
Noctovisor processes the data only on the Customer's documented instructions, including as to transfers, unless Union or Member State law requires otherwise. If that happens (a court order, a lawful demand from an authority), Noctovisor tells the Customer about the legal requirement before processing on it, unless that same law forbids telling them on important public interest grounds. If it is forbidden from telling them, it says as much as it lawfully can, as soon as it lawfully can. This is the clause that makes the rest of this agreement checkable, so it is stated rather than assumed.
The instructions are: this agreement, the list as sent, and a written, dated confirmation that Noctovisor sends at the start recording the companies monitored, the criteria that trigger an alert, who receives alerts, which companies are marked critical, and which email addresses are authorised to give instructions. Every change is confirmed in writing and dated the same way. The Customer can ask for the current confirmation and the full history at any time.
Because there is no login, instructions arrive by email. Noctovisor acts only on instructions from an address recorded as authorised. If an instruction changes where alerts are delivered, Noctovisor confirms the change to the previously nominated recipients as well as to the requester before it takes effect.
A comment left through an alert's link is not an instruction and is never acted on as one. The link identifies the alert rather than the person holding it, so it authenticates nobody; what it records is a note in the Customer's own record, marked as having arrived that way, and Noctovisor changes nothing about the service on the strength of it. Anything that asks something of Noctovisor still has to come by email from an authorised address.
Noctovisor will not use the Customer's data for anything except providing the service. It will not sell it, will not pool it with another customer's data, will not use it to train any model, and will not use it for its own analytics or product development. If Noctovisor considers that an instruction would breach data protection law, it will say so and may pause that instruction until the Customer confirms or changes it.
4. Confidentiality, including before there is a contract
The list and everything derived from it are confidential from the moment they are received. That applies whether or not the sender becomes a customer, and it does not expire.
Access is limited to persons bound by confidentiality obligations. Anyone engaged who would have access is bound in writing before access is granted.
If the sender does not become a paying customer, everything that is theirs is deleted no later than 90 days after the later of the date the list arrived and the last day of any free watch: the list, the record of which companies were matched to the names on it, the watch settings, every alert and report prepared for them, and their contact details and correspondence record. This happens without the sender asking. Earlier deletion on request, at any time, no questions asked.
What that deletion does not cover. The material Noctovisor collected from public sources about the watched companies belongs to the collection step it is controller for under section 1, and remains part of Noctovisor's own records on the retention terms in section 9 of the privacy policy. The deletion destroys every link between that material and the sender: once it has run, nothing in Noctovisor's systems can show who asked about those companies, and the confidentiality of the list is kept by exactly that. Where a watched company is a business run by an individual, such as a sole trader, this exception does not apply: the public-source material about them is deleted with everything else, unless another customer independently watches them.
5. Security
The technical and organisational measures are set out in section 12. Noctovisor holds no ISO 27001 certification and no SOC 2 report, and nothing in this agreement should be read as suggesting otherwise.
6. Public sources only
Noctovisor collects information about the watched companies from publicly available sources only. It does not contact them, send them questionnaires, accept evidence from them, use credentials it is not entitled to, or ask the Customer for contracts or spend data. It will not accept an instruction to do investigative or covert work.
The limitation that follows: if something is not published, Noctovisor will not see it. No alert does not mean nothing happened.
7. Sub-processors, and where the data is
The current list of sub-processors is published separately and is available to the Customer before the Customer sends anything. The Customer authorises those sub-processors by accepting this agreement.
Notice of change. Noctovisor will give at least 30 days' notice by email before adding or replacing a sub-processor, and will publish the change on the sub-processor list at the same time. The Customer may object on reasonable data protection grounds within those 30 days. If the objection cannot be resolved, the Customer may terminate immediately without penalty and be refunded any fees covering the period after termination. If a sub-processor has to be replaced urgently to protect the security or continuity of the service, Noctovisor will make the change and give notice as soon as it can and within 5 business days at the latest, and the right to object and terminate runs from that notice.
Noctovisor contracts each sub-processor on data protection terms that match these in substance, and remains fully liable to the Customer if a sub-processor fails.
Where the data is processed. The data is held and processed on a server in Canada, operated by OVH and contracted through OVH's Polish entity. The database and the monitoring both run on that server. Backups are held in Canada and as a second copy in Warsaw, Poland. The language model providers and Resend (which sends alert emails) are in the United States. The contact mailbox, which holds the Customer's list from the moment it is emailed, is hosted by Google Workspace with the data region set to Europe, so that list is held in the EU; some service metadata sits outside that setting's scope and may be processed in the United States.
This means Noctovisor cannot offer EEA-only processing. The contact mailbox and the second backup copy are in the EU, but the server running the database and the monitoring is in Canada, and the model providers and Resend are in the United States. There is no choice of processing region. If the Customer's policy requires EEA-only or in-country hosting, this service cannot meet it, and it is better to establish that now than after a review.
Transfer bases. For Canada: the European Commission's adequacy decision for Canada (Decision 2002/2/EC), confirmed still in force by the Commission's review published 15 January 2024, supplemented by the standard contractual clauses in Commission Implementing Decision (EU) 2021/914 with the hosting provider, so the transfer stands on either basis independently. The clauses are there because the Canadian capacity sits in Quebec, whose provincial regime does not hold adequacy in its own right, while the adequacy decision covers organisations subject to PIPEDA. For the United States providers: the standard contractual clauses in Commission Implementing Decision (EU) 2021/914, as incorporated in each provider's data processing terms, with EU–US Data Privacy Framework certification as additional cover where a provider holds it.
Language models. Alert text is drafted and translated by commercial language models, so company names and public-source content go into those requests. That is a real flow of data to a third party and it is named rather than buried. Neither provider trains on the content. Both hold the request and response for up to 30 days by default and then delete them. Content flagged under a provider's usage policy may be retained for longer periods under that provider's terms, outside Noctovisor's control.
8. Deletion, return and export
Export at any time. The Customer can ask for an export of its whole record at any time: the resolved list, the criteria and their dated history, every alert and summary sent with its date and source references. It is free, in a structured machine-readable format that is not proprietary, and provided within 10 business days. Taking one quarterly is recommended, so that the Customer's evidence sits in a file it holds.
At the end of the service, Noctovisor deletes or returns the data, at the Customer's choice, and deletes remaining copies. Return within 10 business days. Deletion of the working record within 30 days. Written confirmation of deletion, with the date, is sent once it is done: the Customer does not have to ask for it.
Copies that outlive the deletion, stated because a deletion clause that ignores them is not accurate:
- The backup copies. Backups run daily and are kept for 30 days, so a deleted record is gone from them at most 30 days after it leaves the live system.
- The language model providers, on the periods in section 7.
- The email delivery provider, which holds sent messages and delivery metadata after delivery under its terms.
- The mailbox that received the Customer's email, and the Customer's own mailbox, which holds every alert already delivered and is outside Noctovisor's control.
Noctovisor's own records. Invoices and accounting records are kept for the periods Polish law requires. They may contain the Customer's business contact details. They are not deleted under this section. Two further records survive it, named because a deletion clause that hides them is not accurate. First, the dated deletion records themselves: the proof that this section was honoured outlives the data it is about, and is what the Customer or a supervisory authority is shown when they ask whether deletion happened. Second, the material collected from public sources about the watched companies, which Noctovisor holds as independent controller under section 1 on the retention terms in section 9 of the privacy policy; after deletion it carries no link to the Customer. Where a watched company is a business run by an individual, the public-source material about them is deleted with the rest, unless another customer independently watches them.
Nothing to unwind. There is no software installed at the Customer, no integration and no credential to revoke. Stopping the service stops an email.
9. Data subject requests
Noctovisor has no relationship with the individuals who appear in public sources. Where a request concerns the Customer's watch, Noctovisor does not answer it itself: it forwards it to the Customer without undue delay and within 5 business days of working out which customer it concerns, tells the person it has been passed to the controller, and does not respond substantively unless instructed or required by law. Where the request concerns only Noctovisor's own collection of public-source material, the step it is controller for under section 1, it answers directly.
Noctovisor does not tell an individual which customer a record relates to unless the Customer agrees or the law compels it. Who is assessing whom is the Customer's commercial position, and disclosing it to the subject of the assessment would defeat the confidentiality in section 4. If Noctovisor is compelled, it tells the Customer first where it lawfully can.
Noctovisor assists the Customer in answering requests: finding the data held about a named person, correcting or deleting a record on instruction, restricting processing, providing the record in a machine-readable format, and providing the dated log of what was sent and to whom. This is free, unless a request needs work well beyond what the service contemplates, in which case Noctovisor will say so first and agree a fee before starting.
If someone asks Noctovisor to stop processing information about them, the Customer is told promptly, because that is the Customer's decision to make and it may change what the service reports.
10. Data breaches
If there is a personal data breach affecting the Customer's data, Noctovisor tells the Customer without undue delay and in any event within 24 hours of becoming aware. Article 33 of the GDPR gives the Customer 72 hours for its own notification and that clock runs from the same event, so a processor that used all 72 would be handing over a deadline instead of a warning.
The first notification goes out with whatever is known at the time rather than waiting to be complete. It says what happened, what data and roughly how many records are involved, the likely consequences, what is being done and who to contact. More follows as the investigation goes on, and a written follow-up once the cause is understood, in a form the Customer can put in its own incident file.
Noctovisor does not notify regulators or data subjects about the Customer's data on its own initiative (that is the Customer's decision), but will give the Customer what it needs for its own notifications and reporting deadlines.
Noctovisor keeps a record of breaches, including ones it decides are not notifiable, and will show the Customer the entries that concern it.
Impact assessments and prior consultation. If the Customer has to carry out a data protection impact assessment under Article 35, or consult its supervisory authority under Article 36, Noctovisor helps with what it actually knows: how the processing works, what data it touches, where that data goes and on what transfer basis, which sub-processors are involved, the measures in section 12, and written answers to the assessor's questions. Free, within 10 business days. Noctovisor does not write the Customer's assessment (that is the controller's to make), but a controller should not have to guess about its own processor.
11. Information and audit
Information, any time and as often as the Customer likes, provided within 10 business days: the security summary; the sub-processor list; the Customer's dated criteria confirmations, current and historic; the record of alerts sent with dates, recipients and sources; a redacted sample export, including before committing to anything; written answers to specific questions; and evidence that data has been deleted.
Questionnaires. One standard due-diligence or security questionnaire per year, free, plus reasonable follow-ups. Further ones by agreement.
Audit. Once per year, on 30 days' notice, remotely by video and document review, up to one business day of Noctovisor's time, free. It covers the Customer's own data and the measures in section 12.
On-site inspection is available at Noctovisor's registered address, on 30 days' notice, where a regulator requires or directs it, where mandatory law requires it, where there has been a breach affecting the Customer's data, or where a remote audit found something that cannot be resolved remotely. It is not offered routinely, and that is stated rather than granted and then defaulted on.
Regulators. Noctovisor cooperates fully and free of charge with any supervisory, competent or resolution authority with jurisdiction over the Customer or over Noctovisor, including on-site inspections and taking copies, and will not use any term of this agreement to limit that. The limits on frequency and form above do not apply to regulators.
Noctovisor answers audit findings in writing, saying what it will do and by when, and fixes non-compliance with this agreement at its own cost.
12. Security measures
Data minimisation as the primary control. Noctovisor holds company names and domains, public identifiers, findings already published elsewhere, and some business email addresses. If every system were compromised, that is the exposure. It is a confidentiality incident and treated as one. It is not a route into the Customer's environment, because no such route was ever built.
- Encryption. Public endpoints are HTTPS only, with TLS, verifiable from outside. Requests to the language model providers go over TLS. Email is encrypted in transit between well-configured providers but is not end-to-end encrypted, and Noctovisor cannot secure a mailbox it does not run. If the Customer's policy requires encrypted delivery, this should be raised before starting: email is the delivery channel of the product.
- Encryption at rest. The server volume holding the database is encrypted at rest, as is the hardware holding the Warsaw backup copy. This is worth stating because the database is self-hosted rather than a managed service, so encryption at rest is Noctovisor's own responsibility and not something a platform switched on by default: a reviewer who assumed a managed database would assume managed encryption with it.
- Access. Administrative access is restricted to authorised persons bound by confidentiality. No shared accounts. Credentials unique per service and held in a password manager, with multi-factor authentication where the provider supports it.
- Data minimisation. Company records are keyed to public entity identifiers, not to individuals. Individuals appear only where the source names them and are not separately indexed, scored or profiled. There is no searchable register of individuals. Records can be searched for a name in order to answer a data subject request or meet a legal obligation, and for nothing else. Noctovisor will not introduce a risk score or rating for the watched companies, or any feature that indexes or scores individuals, without giving notice under section 17 and reassessing this agreement first.
- Instruction integrity. Because there is no login, email is the authentication surface and is treated as a control: instructions only from authorised addresses, routing changes confirmed to previous recipients too, and a nominated address verified with its owner before the first alert goes to it. The comment link is deliberately outside this surface: it authenticates nobody, so it can record a note and can instruct nothing. The process serving it holds no privilege to read a Customer's list, an alert or anything another person wrote.
- Logging. Every alert and summary is recorded with what was sent, when, to whom and from which source. Criteria changes are dated. Platform administrative access is logged by the platforms themselves.
- Change management. Private repository with full history. Changes on a branch, tested, deployed by a scripted and reversible deployment, with rollback to a known-good version.
- Patching. The self-hosted stack is Noctovisor's responsibility: critical and high-severity updates promptly; everything else reviewed and applied at least monthly.
- Backups. In Canada with the hosting provider and a second, independent copy on Noctovisor's own encrypted hardware in Warsaw. They run daily and are kept for 30 days. No recovery time or recovery point objective is published without operating history to support one. Alerts already delivered are in the Customer's mailbox, and a Customer that exports quarterly holds its evidence independently of Noctovisor.
- Physical. Processing is in the providers' facilities under their controls. Noctovisor operates no data centre and no public office, and holds no customer data on paper. The one piece of hardware it controls directly is the encrypted drive holding the Warsaw backup copy, which is stated here rather than left to be discovered.
- Certifications. No ISO 27001 and no SOC 2 today; ISO 27001 is being worked toward, with SOC 2 to follow. The underlying providers are independently audited, and their attestations are linked from the sub-processor list.
13. Criminal offence data
Noctovisor does not seek special category data and does not profile individuals.
Sanctions screening, court records, regulatory notices and adverse media can contain personal data about criminal convictions or offences, or alleged offences. This is handled narrowly by design: Noctovisor runs no standalone search or screening query about a named individual, does not aggregate adverse media about a person, and does not cross-reference a name across unrelated companies. Any personal detail that reaches an alert already appeared in a source about the monitored company, carried through as found. Noctovisor keeps no register of convictions and applies the measures in section 12 to this data. This limit is also stated publicly at noctovisor.com/sources.html.
The Customer warrants that it holds its own lawful basis and authorisation to receive and act on this category of data, arising from its own regulatory obligations (anti-money-laundering, know-your-customer, sanctions screening or third-party risk) and will tell Noctovisor promptly if that stops being true. Noctovisor processes it strictly as processor, on the Customer's documented instructions, for no other purpose.
Noctovisor may decline to monitor a criterion or report a category of finding if it considers that doing so would be unlawful or out of proportion to the purpose of the service.
14. Continuity and material changes
Noctovisor will tell the Customer without undue delay about anything material affecting its ability to provide the service, including infrastructure, security, legal or financial changes. Planned interruptions to monitoring are notified in advance. If Noctovisor intends to stop providing the service it will say so as early as it can, and where the circumstances are within its control at least 30 days ahead, with a final export first.
If Noctovisor cannot act at all. A standing arrangement is in place naming a person with the access and written instructions needed to return the Customer's data and delete what is left, and to tell every customer that monitoring has stopped, in the event that Noctovisor's operator is unavailable for an extended period or permanently. The Customer is not left with data held by someone who cannot be reached and no route to recover it. The named person is not published here, because their details are not ours to publish, and the arrangement is confirmed in writing to any customer that asks.
What limits the consequence of any interruption: the Customer's alerts are already in the Customer's mailbox, exports are available at any time, billing is monthly with no lock-in, and there is nothing installed at the Customer to remove.
15. Exit
If the Customer asks before the end of the service, Noctovisor will keep providing it for up to three further monthly terms at the same monthly fee, with no uplift, so there is time to move to another provider or an internal process. Also free: a full final export in a non-proprietary format; the list as resolved to legal entity identifiers, so the Customer keeps the entity matching work instead of repeating it; answers to a successor provider's reasonable questions about the export format; and written confirmation of deletion, dated, once the transition is done.
16. Liability
Each party's total liability for direct loss under this agreement is limited to the fees paid by the Customer in the 12 months before the event giving rise to the claim.
That cap does not apply to, and nothing here limits:
- liability for breach of the confidentiality obligations in section 4;
- either party's liability to a data subject, including under Article 82 of the GDPR, which is a statutory matter between that party and the data subject, cannot be limited by contract, and is unaffected by the cap;
- liability for death or personal injury caused by negligence, for fraud, or for anything else that cannot be limited under applicable law;
- the liability provisions of the standard contractual clauses referred to in section 7, where those clauses apply.
Fees are monthly, so a 12-month cap is a modest number. A Customer needing a higher cap should raise it before contracting.
17. Other terms
Costs. Everything in sections 9, 10, 11 (first audit and first questionnaire each year), 15 and the export in section 8 is free. Where a charge is allowed, Noctovisor says so in advance and does not start chargeable work without agreement. Help with an incident affecting the service is free.
Data protection officer. None is appointed. Article 37(1) of the GDPR requires one where the core activity is regular and systematic monitoring of data subjects on a large scale. The core activity here is monitoring companies; data about directors and officers is incidental information on documents about those companies, not profiling of individuals in its own right, and the volume is not large scale. This is reassessed in writing as the service grows and on the addition of any feature that indexes or scores individuals rather than companies. Data protection questions go to contact@noctovisor.com.
Supervisory authority. The President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), Warsaw. Noctovisor is subject to the GDPR and the Polish Act of 10 May 2018 on the protection of personal data. It is established in the EU, so it needs no Article 27 representative.
Changes. Noctovisor may update this agreement where law, the service or its sub-processors require. Changes that reduce protection need the Customer's agreement. Others take effect 30 days after notice, and the Customer may terminate without penalty in that period.
Assignment and change of control. Noctovisor may transfer this agreement, and the data held under it, to a company it forms or to a successor that takes over the service, provided that company assumes these obligations in full and unchanged. The Customer is told at least 30 days before it happens and may terminate without penalty in that period, with a full export first. Noctovisor will not assign this agreement to anyone else without the Customer's agreement, and will not sell or otherwise transfer customer data as an asset separately from the service.
In writing. This agreement is in writing, including electronic form, as Article 28(9) of the GDPR requires. It prevails over any conflicting term about personal data. Where the standard contractual clauses in section 7 apply, they prevail over this agreement to the extent of a conflict.
Survival. Sections 4, 8, 13 and 16 survive termination. If any provision is unenforceable, the rest stands.
Law. Polish law, courts of Warsaw, without affecting a data subject's rights under Article 79 of the GDPR or any jurisdiction provision in the standard contractual clauses.
Notices. To Noctovisor: contact@noctovisor.com. To the Customer: the address it has given for notices.
Scope of this version
This agreement reflects the current scope of the service. It does not include the machinery that matters once a customer is a regulated financial entity operating at scale: the clause-by-clause mapping to Article 30 of DORA, the register-of-information field set under Implementing Regulation (EU) 2024/2956, the sub-outsourcing assessment under Delegated Regulation (EU) 2025/532, pooled audits and alternative assurance levels, and the UK international data transfer addendum. Noctovisor does not represent this service as suitable to support a function a customer has classified as critical or important under DORA; a customer considering that should get in touch before contracting rather than proceeding on this agreement.
Version 1.9, 26 August 2026. Questions and corrections to contact@noctovisor.com