Legal
Data Processing Agreement
Ioannou & Sharpe LLC · Summary — the version in force is the one published on the service
This page is a plain-language summary. The
definitive Data Processing Agreement — the version you accept at signup and that binds the parties — is published and accepted on the service at
screening.firm.cy/legal/dpa. That text prevails over this summary. Contact
[email protected] for the executed version or any question.
What this is
When your organisation (“Controller”) uses FIRMCY Screening to screen natural or legal persons, Ioannou & Sharpe LLC (“Processor”) processes personal data on your behalf under a Data Processing Agreement (GDPR Art 28). This summary describes its core points; the full terms are on the service.
Core points
- Subject matter & purpose — processing of subject identifiers and related data solely to provide sanctions, PEP and adverse-media screening and produce the associated records, on the Controller's documented instructions.
- Roles & instructions — the Customer is Controller and warrants the lawful basis and transparency toward data subjects; IOS acts as Processor and is not independently AML-obliged. Tier 2 (adverse-media / assess) binds when you actually run it, with a per-run lawful-basis attestation.
- Sub-processors — AWS (EU hosting), xAI (EU endpoint, zero-data-retention, Tier 2 only), GDELT (public news pull, Tier 2 only), Stripe/Revolut (payment — account data only), an SMTP provider and Cloudflare (edge). Screening subject data is not sent to the payment, email or edge sub-processors.
- Security — encryption in transit, per-tenant API keys, row-level database isolation, tamper-evident (hash-chained, append-only) audit logging, EU hosting; Tier 2 adds a grounding allow-list and WORM evidence.
- Retention & erasure — for the term of the agreement plus your applicable record-keeping obligations, then deletion or return on request; erasure may be refused while a retention obligation subsists.
- International transfers — personal data is hosted in the European Union (AWS eu-central-1; xAI EU endpoint with zero-data-retention; EU payment and email sub-processors). No Chapter V transfer mechanism is required for the data covered.
- Breaches — notified without undue delay; special-category breaches trigger Art 33/34 obligations.
- Liability & audit — aggregate liability capped at fees paid in the prior 12 months (GDPR Art 82 unaffected); information made available to demonstrate compliance and support audits.
Read the full DPA
The current, binding Data Processing Agreement is at screening.firm.cy/legal/dpa. It is the version accepted at signup and recorded immutably in the service's acceptance register.