By using the hosted validation service under an agreement that incorporates this DPA, each party agrees to it. A signed copy is available for procurement processes on request.

1. Definitions and roles

Controller, processor, data subject, personal data, processing, personal data breach, and supervisory authority have the meanings in applicable data-protection law. “Applicable Data Protection Law” includes the GDPR, UK GDPR and Data Protection Act 2018, and applicable US state privacy laws.

The customer is controller or processor, as applicable, for Customer Data. EasyBRL is the customer’s processor or subprocessor. Each party remains an independent controller for its own account, billing, employment, and legal-compliance records.

2. Instructions and purpose limitation

EasyBRL will process Customer Data only on documented instructions to provide, secure, and support the hosted validation service, or as law requires. The agreement, API requests, region selection, support requests, and documented configuration are the customer’s instructions.

If EasyBRL believes an instruction violates Applicable Data Protection Law, it will inform the customer unless prohibited and may suspend the affected processing. If law requires other processing, EasyBRL will notify the customer beforehand unless prohibited. EasyBRL will not sell Customer Data, use it for targeted advertising, combine it for its own purposes, or train models on it.

3. Processing schedule

ItemDetails
Subject matter and purposeTransient validation of customer-submitted XBRL XML and xBRL-CSV packages and return of JSON diagnostics.
NatureReceive, parse, validate, compare against taxonomy rules, generate diagnostics, transmit the response, and securely destroy transient data.
DurationFor each API request until it succeeds, fails, or times out; the DPA otherwise lasts while EasyBRL provides processing services.
Personal-data typesAny personal data the customer includes in a filing, potentially including identity, employment, professional, financial, ownership, counterparty, and contact data.
Data subjectsCustomer users and personnel; directors and officers; customers, clients, investors, owners, counterparties, and other persons represented in a regulatory filing.
Sensitive dataNot intended for routine submission. Customer must obtain written authorization and agree additional safeguards before knowingly submitting special-category, criminal-offence, or similarly restricted data.
FrequencyAs initiated by authenticated customer API calls.
RetentionNo intentional persistence of files or results. Content-free metadata follows the Privacy Policy and is controller data unless an order states otherwise.

4. Confidentiality and personnel

EasyBRL ensures that persons authorized to process Customer Data are bound by confidentiality, receive appropriate privacy and security guidance, and access data only as needed for assigned duties. Routine personnel access to submitted files is not part of the service design.

5. Security measures

EasyBRL will maintain measures appropriate to the risk, including those in the Security page, and will not materially reduce their overall protection during the service term. Measures include encrypted transport, region controls, least privilege, tenant isolation, non-recoverable API-key storage, monitoring, vulnerability and patch management, incident response, backup controls for retained metadata, and secure deletion.

6. Subprocessors

The customer gives general authorization for the subprocessors in the published register. EasyBRL will impose data-protection obligations providing substantially equivalent protection and remains responsible for their performance to the extent required by law.

EasyBRL will give at least 30 days’ notice before a new subprocessor processes Customer Data. The customer may object on reasonable data-protection grounds during that period. The parties will seek a practical alternative; if none is reasonably available, the customer may terminate the affected service and receive a prorated refund for its unused prepaid portion.

7. Data-subject requests

Taking account of the processing, EasyBRL will provide reasonable technical and organizational assistance for requests to exercise data-subject rights. If EasyBRL receives a request concerning Customer Data, it will direct the requester to the customer and will not respond substantively unless instructed or legally required.

8. Compliance assistance

EasyBRL will reasonably assist the customer with security obligations, breach assessments and notices, data-protection impact assessments, prior consultations, and regulator inquiries, considering the nature of processing and information available. Additional work beyond standard documentation may be charged at agreed rates unless caused by EasyBRL’s breach.

9. Personal data breaches

EasyBRL will notify the customer without undue delay after confirming a personal data breach affecting Customer Data. Notice will include available information about the nature and scope, likely consequences, measures taken or proposed, and a contact point, with supplemental information provided as it becomes available.

Notice is not an admission of fault. The customer is responsible for notifications it must make as controller. EasyBRL will preserve relevant evidence while avoiding retention of submitted file content beyond what is strictly required by law.

10. Return and deletion

The API returns results directly and does not provide later retrieval because files and results are not retained. On request completion, failure, or timeout, EasyBRL destroys transient Customer Data. Customer Data is not placed in backups.

At termination, EasyBRL will delete remaining processor data unless law requires retention. Content-free controller records remain subject to the Privacy Policy. If legally retained processor data exists, it will be isolated, protected, and used only for that legal requirement.

11. Information and audits

EasyBRL will provide information reasonably necessary to demonstrate compliance, such as this DPA, security documentation, subprocessor information, and completed reasonable questionnaires. Once per year, or after a substantiated incident, the customer may request an audit by an independent qualified auditor bound by confidentiality.

Audits require at least 30 days’ notice, must occur during business hours without disrupting services or exposing other customers, and should first use existing evidence. The customer pays its audit costs unless the audit identifies a material EasyBRL breach.

12. International transfers

The customer selects an available EU or US content region. Decrypted Customer Data must remain within the selected boundary, including configured Cloudflare processing. EasyBRL will document the applicable region and will not change it without instruction or an agreed migration.

For a restricted EEA transfer to EasyBRL LLC or a US recipient, the parties incorporate the controller-to-processor clauses in European Commission Decision 2021/914 (Module Two), with the customer as exporter, EasyBRL as importer, the law and courts of the Netherlands governing the SCCs, the customer’s competent supervisory authority, and this DPA and Security page completing the annexes. The Terms remain Wyoming-governed for matters outside the SCCs. For UK restricted transfers, the then-current UK International Data Transfer Addendum applies. The transfer terms prevail over conflicting terms.

13. US service-provider terms

Where US state privacy law applies, EasyBRL acts as a service provider or contractor for Customer Data. It will not sell or share Customer Data, retain/use/disclose it outside the business purposes in the agreement, or combine it with personal data received from another source except as law permits. The customer may take reasonable steps to verify compliant use and require remediation.

14. Liability and duration

The agreement’s liability provisions apply to this DPA except where Applicable Data Protection Law requires otherwise. This DPA begins with processing and ends when EasyBRL no longer processes Customer Data, subject to surviving confidentiality, deletion, audit, and transfer obligations.

15. Contact

DPA notices and requests should be sent to [email protected] with “Data Processing” in the subject line.

Contact

Questions about this document can be sent through the contact form or to [email protected].

Complete purchase

Enter your details and continue to secure payment.

Enterprise XBRL package validation

Choose a service term or contact us about procurement.

Contact PenguinXBRL

Tell us who to contact and what you need.

Cookie settings

Choose whether optional advertising and analytics may run in this browser.

Necessary

Preference, security, checkout, and requested session functions.

Always on