Security & data protection addendum

Summary for procurement. A fuller pack (subprocessors, retention schedules, incident process) is shared with pilot and enterprise customers under NDA.

What we provide today

  • TLS in transit for the app and marketing site
  • Authenticated access to workspaces; session handling via established auth infrastructure
  • Written subprocessor and processing terms for customers who sign an order or pilot agreement
  • EU-facing operational contact for privacy and security questions

DPA & EU clauses

For organizations that need GDPR Article 28 terms or SCCs, we execute a DPA alongside the pilot or subscription contract. Request the current template via Contact with “DPA request” in the message.

Security questionnaires

We complete targeted questionnaires for design partners where proportionate. Full SIG-lite / enterprise reviews are phased in as scale grows—state your deadline on Contact so we can be direct about timelines.

Vendor identity

Adriatic Holdings OÜ, registry code 16571644. Security and privacy escalations: krukovskiadrian@gmail.com.