Data Processing Agreement
How we handle data on your behalf.
This agreement applies where Pocavi Limited processes personal data as a processor on behalf of a customer acting as controller. It forms part of the Terms of Service.
Last updated: 30 August 2026
1. Definitions
"Controller", "Processor", "Data Subject", "Personal Data" and "Processing" have the meanings given in the UK GDPR and EU GDPR. "Customer" means the entity subscribing to POCAVI. "Services" means the POCAVI platform.
2. Roles and scope
The Customer is the Controller and Pocavi Limited is the Processor. Pocavi processes Personal Data only to provide the Services, only on the Customer's documented instructions, and not for its own purposes. Use of the Services constitutes those instructions.
If Pocavi believes an instruction infringes data protection law, it will inform the Customer without undue delay.
3. Nature of the processing
POCAVI is designed to minimise the Personal Data it holds. Backup and analysis operate on Salesforce metadata — objects, fields, flows, Apex, layouts and permissions — not on the Customer's Salesforce records.
Personal Data processed is limited to:
- Account data: names, email addresses, job roles and authentication credentials of the Customer's users.
- Salesforce user references: usernames and user identifiers appearing in metadata, permissions and deployment records.
- Data subject records surfaced during a privacy request: where the Customer uses the GDPR and SAR features, records identified in the Customer's own org during discovery, export or erasure.
- Data selected for sandbox seeding: processed for anonymisation before being written to a sandbox.
Categories of Data Subject: the Customer's personnel, and any individual whose records exist in the Customer's Salesforce org where privacy features are used. Duration: for the term of the subscription, plus the retention period in clause 9.
4. Confidentiality
Pocavi ensures that personnel authorised to process Personal Data are bound by confidentiality obligations, and limits access to those who need it to deliver or support the Services.
5. Security measures
Pocavi implements appropriate technical and organisational measures under Article 32, including:
- Encryption in transit (TLS) and at rest (AWS-managed keys for database and object storage; a dedicated KMS key for credentials and API secrets).
- Logical separation of Customer data by partition key, with authorisation enforced before a request reaches application code.
- Salesforce connections established through OAuth. Pocavi never requests or stores Salesforce passwords, and the Customer may revoke access at any time from Salesforce.
- Role-based access within the product (Admin, Deployer, Viewer).
- Serverless infrastructure defined in code, removing long-lived hosts from the estate.
- Automated monitoring and alerting on the production estate.
Current assurance status, including what Pocavi does not yet hold, is published in the trust centre.
6. Sub-processors
The Customer gives general authorisation for Pocavi to engage sub-processors. The current list is published at pocavi.ai/legal/sub-processors.
Pocavi will give at least 30 days' notice by email before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds within that period; if the objection cannot be resolved, the Customer may terminate the affected Services without penalty.
Pocavi imposes data protection obligations on each sub-processor no less protective than those in this agreement, and remains liable for their performance.
7. International transfers
Production infrastructure runs in AWS eu-west-2 (London). Additional regions in the EU, US and APAC are available and will be brought up for Customers with a residency requirement.
Where Personal Data is transferred outside the UK or EEA — for example to Anthropic or Stripe as listed in the sub-processor list — Pocavi relies on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses, together with supplementary measures where required.
8. Data subject rights and assistance
Taking into account the nature of the processing, Pocavi will assist the Customer by appropriate technical and organisational measures in responding to Data Subject requests, and in meeting obligations under Articles 32 to 36 (security, breach notification and data protection impact assessments).
If Pocavi receives a request directly from a Data Subject relating to Customer data, it will not respond substantively and will refer the request to the Customer without undue delay.
9. Retention and deletion
On termination, Pocavi will delete Customer Personal Data within 30 days, except where retention is required by law. Backup snapshots are deleted with everything else, not left to rotate out separately. On written request, Pocavi will confirm deletion.
During the subscription, the Customer can export or delete data through the product at any time.
10. Personal data breach
Pocavi will notify the Customer without undue delay, and in any event within 72 hours, of becoming aware of a Personal Data breach affecting Customer data. The notification will describe the nature of the breach, the likely consequences, the measures taken, and a contact point for further information.
11. Audit
Pocavi will make available information reasonably necessary to demonstrate compliance with this agreement, and will contribute to audits conducted by the Customer or an auditor it mandates. Audits take place on reasonable notice, no more than once in any twelve month period unless required by a supervisory authority, during business hours, and without unreasonable disruption to operations.
12. Liability and precedence
Liability under this agreement is subject to the limitations in the Terms of Service. Where this agreement conflicts with those Terms on the subject of data protection, this agreement prevails.
13. Contact
Pocavi Limited, incorporated in Hong Kong (company number 80011011), registered address Unit B, 11/F, 23 Thomson Road, Wan Chai, Hong Kong SAR.
Data protection enquiries: sam@pocavi.ai.
To execute a countersigned copy of this agreement for your records, email the address above.