Data Processing Agreement
The Article 28 terms under which we process personal data on your behalf, accepted with the Terms of Service.
Version 2026-09-03 · effective
1What this is, and when it applies
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (“Controller”) and Alifanov Consulting (“Processor”, “we”). It applies whenever we process personal data on your behalf, and it is accepted with the Terms — you do not need to sign or negotiate anything to have one in place.
It applies where you use Photon Now for a business or another organisation and are therefore a controller under the GDPR. If you use Photon Now purely for personal or household purposes, how we handle the data from your devices is described in the Privacy Policy, and we keep to the same commitments.
It follows Article 28 of the GDPR. If you need it as a countersigned document, write to hello@photonnow.com and we will provide one; the terms will be these. Where this DPA and the Terms conflict on the processing of personal data, this DPA wins.
2Roles
You are the controller of the personal data your devices, flows and users put into Photon Now. You decide which devices you enrol, what your scripts and flows output, and who in your organisation can see it; an enrolled device always reports the baseline facts in Annex I (identifiers, name, network address and system state) while it is connected. We process it only to provide the service to you.
As controller you are responsible for having a lawful basis for the personal data your devices, flows and users send us, for giving us lawful instructions, and for what you choose to output into the service. You have the right to instruct us (section 3), to object to a new sub-processor (section 5), to audit us (section 8) and to have your data returned or deleted (section 7).
We are the controller of your account data — the identities of your users, our billing records, and the security and activity records we keep about the use of the service. Those are ours, kept on the retention set out in the Privacy Policy, and are not covered here.
3Our obligations
We will:
- Process only on your documented instructions, including as to transfers. Your use of the service — the flows you author, the commands you run, the settings you choose — is your instruction. If we believe an instruction breaks data protection law we will tell you. If we are required by EU or Norwegian law to process for another reason, we will tell you beforehand unless that law forbids it.
- Keep it confidential. Everyone we authorise to process your data is bound by confidentiality obligations.
- Apply appropriate security measures under Article 32 — Annex II lists what we do.
- Use sub-processors only under section 5.
- Help you answer data subjects. If you receive a request from someone exercising their rights over data we hold for you, we will help you find, provide, correct or delete that data insofar as the service does not let you do it yourself, in time for your one-month deadline. If someone contacts us directly, we will tell them to contact you and let you know.
- Help you meet Articles 32 to 36 — security, breach notification, impact assessments and prior consultation — taking into account what we know and what is available to us.
- Delete or return your data when we are done (section 7).
- Show you that we comply (section 8).
4If there is a breach
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and in any event quickly enough for you to meet your own 72-hour obligation to your supervisory authority. The notice will describe what happened, the categories and approximate volume of data and people affected, the likely consequences, and what we are doing about it — and we will send what we know rather than waiting for a complete picture.
We notify your organisation administrators at the email addresses on their accounts. Keep those current.
5Sub-processors
You give general authorisation for us to engage sub-processors. Each one is bound by written terms no less protective than these, and we remain liable to you for their performance of these obligations as if it were our own. The liability terms of the Terms of Service apply to that liability.
The current list is published at photonnow.com/legal/subprocessors and is part of this DPA. We will announce a new or replacement sub-processor at least 30 days before it starts processing, by email to your organisation administrators. If we have to replace a sub-processor urgently to keep the service secure or available, we will tell you as soon as reasonably practicable instead, and you keep the same right to object. Our providers’ own sub-processor changes are passed on to you as soon as we receive notice of them.
If you have a reasonable data-protection objection, tell us within those 30 days; if we cannot resolve it, you may terminate the affected part of the service and we will refund the unused part of what you have prepaid — for a subscription, the days after termination; for a data top-up, the data you have not drawn.
6International transfers
Our servers and our database are in the EEA. Where a sub-processor is established outside the EEA or may process data outside it, the transfer relies on the European Commission’s Standard Contractual Clauses, incorporated in that provider’s data processing terms, as recorded on the sub-processor page. We do not currently rely on the EU–US Data Privacy Framework.
You instruct us to make those transfers by using the service. We will not move your data outside the EEA other than through the providers listed there.
7Deletion and return
You can delete devices, files, flows and other records yourself at any time through the service. When our agreement ends, we keep your data for 30 days; if you ask within that window we will return it to you in a machine-readable form. We then delete it, including from backups as they age out, which is at most 14 days beyond that point. Ask us and we will delete it sooner.
We keep only what the law requires us to keep, such as invoices and the accounting records behind them.
8Audits, and how to reach us
We will make available the information you reasonably need to verify that we meet this DPA — Annex II, our sub-processor list, and answers to a security questionnaire.
We do not hold a SOC 2 or ISO 27001 report. Beyond documentary evidence, you may audit us — including through an independent auditor bound by confidentiality — at most once a year and on 30 days’ notice, except after a personal data breach affecting your data or where your supervisory authority requires it; at your cost, without disrupting the service or exposing another customer’s data. We will cooperate promptly with a supervisory authority at any time.
Questions about any of this, or about a supervisory authority request: privacy@photonnow.com.
9Annex I — what is processed
| Subject matter and duration | Providing the Photon Now device fleet management service, for as long as the agreement lasts plus the deletion window in section 7. |
| Nature and purpose | Hosting, transmitting, storing, displaying and executing operations on data your devices and users produce: running commands and flows, distributing files, relaying remote sessions, monitoring health and raising alerts, and delivering the notifications you configure. |
| Categories of data subject | Your personnel and other users of your organisation; people who use or are identifiable from the devices you enrol; anyone identifiable in the output your devices or applications produce; the people you configure as notification recipients; and people who connect to a service you publish through a tunnel. |
| Types of personal data | Identifiers and contact details of your users; device identifiers, names, network addresses and system state; command output, logs and files your devices produce or you publish; the contact addresses you configure for notifications; the access credentials and network allow-lists you configure for tunnels. |
| Special category data | None is required by the service and none should be sent to it. If your flows output it, you are instructing us to process it and you remain responsible for having a lawful basis. |
| Frequency | Continuous, for as long as your devices are connected. |
10Annex II — security measures
These are the measures we operate today. We list nothing aspirational, and we will update this annex as they change.
- Access control. Two-factor authentication is available on every user account. Passwords are stored only as hashes; recovery codes are stored hashed and are single-use. Destructive operations require re-authentication when they are requested, and a flow that runs on a schedule is authorised when the schedule is created or edited.
- Authorisation. Role-based permissions, and each user can see and act on only the devices their organisation has granted them. Every operation on a device is checked against both.
- Customer separation. Each customer’s devices and data are isolated from every other customer’s, and every read and write is scoped to your organisation.
- Encryption in transit. Every connection to our servers uses TLS: HTTPS with HSTS for the dashboard and the API, and WSS for agents. The tunnel gateway accepts agent connections over TLS and terminates TLS for HTTP tunnels; traffic through a TCP tunnel you publish is carried as your application sends it, so use an encrypted protocol or restrict the allow-list.
- File delivery. File bytes move directly between your device and private object storage over short-lived signed URLs, each naming one object.
- Abuse resistance. Rate limiting on every authentication surface and on connection attempts.
- Logging and audit. Security-relevant events are recorded with actor, resource, time, outcome and source address, and are available to your administrators. Records are deleted automatically at their retention horizon.
- Availability. The database is a managed, multi-node replica set with automated backups retained for 14 days, operated in the EU.
- Segregation. The tunnel gateway that carries customer traffic runs on separate infrastructure from our management servers, and every session is authorised before it is carried.
- Development practice. Every change is tested automatically before it can be deployed. Production secrets are held outside the source code.