apokto
Draft — for review before publishing.This is placeholder legal language and has not been reviewed by counsel.

Legal

Data Processing Agreement

Last updated 30 August 2026

This Data Processing Agreement (DPA) template describes how Apokto, Inc. processes personal data on a customer's behalf within the apokto platform. It supplements our Terms of Service. A signed, negotiated version will be made available to customers ahead of general availability.

1. Purpose and scope

This DPA applies where Apokto, Inc. (“processor”) processes personal data contained in customer data on behalf of a customer (“controller”) in connection with the apokto platform. It is incorporated into, and forms part of, the applicable order form and Terms of Service.

2. Definitions

“Personal data,” “processing,” “controller,” “processor” and “data subject” have the meanings given in applicable data protection law, including the UK and EU GDPR where relevant. “Customer data” has the meaning given in the Terms of Service.

3. Roles of the parties

As between the parties, the customer is the controller of personal data within its customer data, and Apokto, Inc. is the processor, processing that data only as described in this DPA and the customer’s documented instructions.

4. Processing instructions

Apokto, Inc. will process personal data only to provide, secure and support the platform as instructed by the customer through its use of the service, or as otherwise agreed in writing, and will not process it for any other purpose, including its own marketing.

5. Confidentiality

Apokto, Inc. limits access to personal data to personnel who need it to provide the service, under scoped seats and capacities, and requires those personnel to be bound by confidentiality obligations.

6. Security measures

Apokto, Inc. maintains technical and organizational measures designed to protect personal data appropriate to its sensitivity, consistent with the custody mode selected for a given transaction. A description of our current controls and certifications is available in the security package on request.

7. Subprocessors

Apokto, Inc. may engage subprocessors to help provide the service. A current list, once finalized, will be published at apokto.co/legal/subprocessors, with advance notice of material changes as required by applicable law and any negotiated order form.

8. Assistance with data subject rights

Apokto, Inc. will provide reasonable assistance to help the customer respond to requests from data subjects to exercise their rights under applicable data protection law, to the extent the customer cannot reasonably do so itself using the platform.

9. Personal data breach notification

Apokto, Inc. will notify the customer without undue delay after becoming aware of a personal data breach affecting that customer’s customer data, and will provide information reasonably available to assist the customer in meeting its own notification obligations.

10. Audit rights

On reasonable request, Apokto, Inc. will make available information reasonably necessary to demonstrate compliance with this DPA, including relevant certifications, and will permit audits as reasonably required by applicable data protection law, subject to reasonable confidentiality and scheduling terms.

11. Return and deletion of data

On termination of the applicable order form, Apokto, Inc. will, at the customer’s choice, return or delete customer data, except to the extent retention is required by applicable law.

12. Liability

Liability under this DPA is subject to the limitations of liability set out in the Terms of Service and the applicable order form, except to the extent such limitations cannot lawfully apply to obligations under data protection law.

13. Precedence and term

This DPA applies for as long as Apokto, Inc. processes personal data on the customer’s behalf. In the event of a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA controls.

14. Contact

Questions about this DPA, or requests for a signed copy, can be sent to hello@apokto.co.

Questions about this document?

These pages are drafts ahead of legal review. If you need something clarified or want a signed copy for diligence, get in touch.

Contact us

Controls and attestations

SOC 2 Type II
ANNUAL · ON REQUEST
ISO 27001
ISMS CERTIFIED
RFC 3161 timestamping
THIRD-PARTY TSA
WORM object-lock
7-YEAR RETENTION
GDPR · DPA
EU/UK · SUBPROCESSORS
Okta · Entra · Ping
SAML · SCIM
© 2026 APOKTO, INC.SOC 2 TYPE II · ISO 27001 · RFC 3161

Book a briefing

Architecture overview, data-flow diagram and custody specification go to your team before we talk. 45 minutes, on a live deal.

Briefings run 45 minutes on a live deal, not a slide.

Request the security package

SOC 2, ISO 27001, RFC 3161, and the full custody architecture — sent immediately.

Architecture overview, data-flow diagram and custody specification — sent immediately, no call required.