i2bIntelligence to Base

Data Processing Agreement

Last reviewed 31 August 2026

This agreement is between DIGITAL GLOBAL TECHNOLOGIES LTD, trading as i2b (the Processor), and the customer entering into it (the Controller). It forms part of the Terms and takes precedence over them where personal data is concerned.

1. What this covers

The Controller uses i2b to read a database it controls and carry its contents into another. Where that database contains personal data, the Controller is the controller of it and the Processor processes it only to provide that service.

Subject matter: analysis of a database schema and migration of its contents. Duration: for as long as the Controller holds an account, and for any single migration, its duration. Nature and purpose: reading, structural analysis, transformation and writing, as configured by the Controller. Types of personal data and categories of data subject: determined by the Controller, being whatever its own database contains; the Processor neither selects nor requires any particular category.

2. When no personal data reaches the Processor at all

i2b has two modes and the Controller chooses which. In local mode — the default — no personal data is transmitted to the Processor. The database file is read by code executing in the Controller’s own browser; it is not uploaded, and the Processor has no access to it. For a Controller using only that mode, the Processor is not processing personal data on its behalf and the obligations below apply to account data alone.

In direct mode the Controller supplies credentials and the Processor connects to the database to read it. Personal data is then processed by the Processor for the duration of that operation, and clauses 3 to 11 apply in full.

3. Instructions

The Processor processes personal data only on the Controller’s documented instructions, which are: this agreement, the Terms, and the operations the Controller configures in the product. The Processor will tell the Controller if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.

The Processor will not transfer personal data outside the European Economic Area without the Controller’s prior instruction.

4. Confidentiality

Every person the Processor authorises to process personal data is bound by a duty of confidentiality that survives the end of their engagement. Access is granted only where it is needed to provide or support the service.

5. Security

The Processor implements technical and organisational measures appropriate to the risk under Article 32:

  • Passwords stored using scrypt with high work factor.
  • Session tokens stored only as SHA-256 hashes.
  • IP addresses stored only as peppered one-way hashes.
  • In-memory only credential handling for direct connections.
  • Transactional migration runs (all-or-nothing atomicity).

6. Sub-processors

The Controller gives general authorisation for sub-processors. Current hosting: Contabo GmbH (European Union). The Processor will give at least 30 days’ notice before adding or replacing any sub-processor.

7. Assisting data subjects

The product enables full account export and erasure by the account holder at any time. The Processor will assist the Controller in responding to data subject requests under GDPR Chapter III.

8. Breaches

The Processor will notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Controller’s data.

9. Return and deletion

Within 30 days of termination the Processor deletes the personal data it holds on the Controller’s behalf, except where retention is required by European Union or Member State law (e.g. tax and accounting records).

10. Audit

The Processor will make available to the Controller the information needed to demonstrate compliance with Article 28, and allow for audits on reasonable notice.

11. Governing law

This agreement is governed by Bulgarian law and the courts of Plovdiv, Bulgaria have jurisdiction. The supervisory authority is the Commission for Personal Data Protection (CPDP), Sofia.

Data Processing Agreement · i2b