Panel.agencyPanel.agency Home
Last updated: 07.07.2026

Terms of Service

Panel.agency — operated by Panel Ag LTD

Panel.agency

Last updated: 07.07.2026

Effective date: 07.07.2026

1. Who we are

Panel.agency (the "Platform", "Service", "we", "us", "our") is operated by Panel Ag LTD, a company registered in England and Wales, company number SC876534, with registered office at Ridgmount St, London WC1E 7AQ, United Kingdom ("the Company").

Contact:

These Terms of Service (the "Terms") govern access to and use of the Platform. By registering for, accessing, or using the Platform, you agree to be bound by these Terms. If you do not agree, you must not use the Platform.

2. Who may use the Platform

The Platform is a business-to-business tool. It is not intended for, or directed at, consumers or members of the general public, and it is not a dating website.

The Platform has two categories of user:

(a) Agencies — dating agencies that register an account and use the Platform to manage profiles, communications, statistics, payouts and related operations across the dating websites made available to them. Agencies (and the individuals who register on their behalf) represent that they are acting in a professional or business capacity.

(b) Site Owners — owners or operators of dating websites who apply to connect their website to the Platform via our API and, where applicable, enter into a separate agreement with us.

The Platform is not used by, and is not intended to serve, the end users (members, customers, or subscribers) of any connected dating website. We do not knowingly provide any service directly to such end users.

You must be at least 18 years old and legally capable of entering into a binding contract to use the Platform.

3. Accounts and access

3.1 Access to an Agency panel is granted at our discretion. We determine which websites are made available within each Agency's panel.

3.2 You are responsible for maintaining the confidentiality of your login credentials and for all activity that occurs under your account. You must notify us promptly at security@panel.agency of any unauthorised use.

3.3 You are responsible for the acts and omissions of everyone you permit to access your account (including your operators, managers and staff), as if they were your own.

3.4 We may suspend, restrict or terminate access to any account at any time where we reasonably believe these Terms have been breached, where required by law, or where continued access presents a legal, security or reputational risk.

4. The Service

4.1 The Platform provides Agencies with tools to manage profiles, conduct and route communications, run mailings, deliver gifts, view statistics, manage payouts and operate affiliate programmes across connected websites, depending on the features each connected website supports.

4.2 Functionality available for any given website depends on the technical capabilities that website makes available through its integration. We do not guarantee that any particular feature will be available for any particular website.

4.3 We may modify, add, or remove features of the Platform at any time. We will use reasonable efforts to give notice of material changes.

4.4 The Platform is provided on an "as available" basis. We do not guarantee uninterrupted or error-free operation.

5. Profiles and content — your responsibilities

This section is central. By uploading, creating, editing, or transmitting any profile, photograph, video, text, or other material (together, "Content") through the Platform, you represent, warrant and undertake that:

5.1 You have all rights, licences, consents and permissions necessary to upload the Content and to have it displayed on the connected websites, including all rights in any photographs and videos and the consent of every individual depicted.

5.2 Every individual depicted in or associated with the Content is at least 18 years old, and you hold verifiable proof of age which you will provide to us on request.

5.3 The Content does not infringe any third party's intellectual property, privacy, publicity or other rights, and does not breach any applicable law.

5.4 You have obtained all consents required under applicable data protection law from every individual whose personal data is contained in the Content, for the processing and display carried out through the Platform.

5.5 The Content is not unlawful, defamatory, fraudulent, or designed to deceive or harm any person.

5.6 You are solely responsible for the accuracy, legality and appropriateness of all Content you handle through the Platform. We do not pre-screen Content and act only as a technical facilitator in transmitting or hosting it on your instructions.

You agree to indemnify and hold us harmless against any claim, liability, loss, damage, cost or expense (including reasonable legal fees) arising out of or in connection with any breach of this Section 5.

6. Acceptable use

You must not use the Platform to:

  • upload or transmit any Content depicting or involving minors, or any child sexual abuse material of any kind;
  • upload Content without the rights or consents required under Section 5;
  • engage in fraud, deception, human trafficking, coercion, or any unlawful activity;
  • transmit malware, attempt to gain unauthorised access to the Platform or its systems, or interfere with its operation;
  • circumvent access controls, scrape data at scale, or reverse-engineer the Platform except to the extent permitted by law;
  • use the Platform to compete with us by replicating its functionality;
  • violate the terms, policies or technical requirements of any connected website;
  • infringe any applicable law of any jurisdiction that applies to you or to the connected websites.

We reserve the right to investigate and to cooperate with law enforcement in relation to any suspected unlawful use, including suspected child exploitation, which we will report to the competent authorities where required.

7. Connected websites and Site Owners

7.1 The Platform interoperates with third-party dating websites through their APIs. Each connected website is operated by an independent third party.

7.2 We are not responsible for the content, conduct, availability, security, payment processing, or lawfulness of any connected website. Your relationship with any connected website, and the treatment of any data or funds on that website, is governed by that website's own terms.

7.3 Where you are a Site Owner applying to connect a website, the technical, commercial and data-protection terms of that connection are set out in a separate written agreement between you and the Company. These Terms govern your use of any application or informational interface we provide; the separate agreement governs the integration itself.

7.4 Correspondence between end users and profiles, and end-user payment data, remain on the connected websites. We do not store, control, or take responsibility for such data.

8. Fees

8.1 Use of the Platform by Agencies is currently provided free of charge. We reserve the right to introduce fees for Agencies in future, with reasonable prior notice.

8.2 Connection of a third-party website by a Site Owner may be subject to fees agreed separately in writing.

8.3 Any fees, once introduced, are exclusive of applicable taxes unless stated otherwise.

9. Intellectual property

9.1 The Platform, including its software, design, structure, text and branding (excluding your Content), is owned by or licensed to the Company and is protected by intellectual property laws. Nothing in these Terms transfers any ownership in the Platform to you.

9.2 You retain all rights in your Content. You grant us a limited, non-exclusive, worldwide, royalty-free licence to host, store, reproduce, adapt (for technical formatting and distribution), transmit and display the Content solely to the extent necessary to provide the Service and to distribute it to the connected websites you have authorised.

9.3 This licence ends when the Content is deleted from the Platform, except where retention is required by law or for the establishment or defence of legal claims.

10. Data protection

Our processing of personal data is described in our Privacy Policy, which forms part of these Terms. Where we act as a processor of personal data on your behalf (for example, in hosting and synchronising profile Content), the terms of a Data Processing Agreement (available on request) apply.

You are responsible, as controller, for the lawfulness of the personal data you handle through the Platform, including having a lawful basis and all required consents.

11. Disclaimers

11.1 To the maximum extent permitted by law, the Platform is provided "as is" and "as available", without warranties of any kind, whether express or implied, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement.

11.2 We do not warrant that the Platform will be uninterrupted, secure, or error-free, that defects will be corrected, or that data synchronised to or from connected websites will be complete or accurate.

12. Limitation of liability

12.1 Nothing in these Terms excludes or limits liability that cannot lawfully be excluded or limited, including liability for death or personal injury caused by negligence, or for fraud.

12.2 Subject to 12.1, we shall not be liable for any indirect, incidental, special, consequential or punitive damages, or for any loss of profits, revenue, data, goodwill or business, arising out of or in connection with the Platform.

12.3 Subject to 12.1, our total aggregate liability arising out of or in connection with these Terms and your use of the Platform shall not exceed the greater of (a) the total fees paid by you to us in the twelve (12) months preceding the event giving rise to the claim, or (b) EUR 100.

12.4 We are not liable for any loss arising from the acts, omissions, content, or data handling of any connected website or of any Agency or Site Owner.

13. Indemnity

You agree to indemnify, defend and hold harmless the Company, its directors, officers and personnel from and against any claims, liabilities, damages, losses and expenses (including reasonable legal fees) arising out of or connected with: (a) your Content; (b) your use of the Platform; (c) your breach of these Terms; (d) your breach of any applicable law or the rights of any third party, including any individual depicted in your Content.

14. Suspension and termination

14.1 You may stop using the Platform at any time and request deletion of your account.

14.2 We may suspend or terminate your access with immediate effect where you breach these Terms, where required by law, or to protect the Platform, its users, or third parties.

14.3 On termination, your right to use the Platform ceases. Sections that by their nature should survive (including Sections 5, 9, 12, 13, 15 and 16) survive termination.

15. Governing law and jurisdiction

15.1 These Terms are governed by the laws of England and Wales.

15.2 The courts of England and Wales have exclusive jurisdiction, save that we may bring proceedings for breach in any jurisdiction where you are established or where harm occurs.

16. General

16.1 Changes. We may update these Terms. Material changes will be notified by posting the updated Terms with a new "Last updated" date and, where appropriate, by direct notice. Continued use after changes take effect constitutes acceptance.

16.2 Entire agreement. These Terms, the Privacy Policy, and any separate written agreement (for Site Owners) constitute the entire agreement between you and us regarding the Platform.

16.3 Severability. If any provision is held unenforceable, the remaining provisions continue in full force.

16.4 No waiver. Our failure to enforce any provision is not a waiver of it.

16.5 Assignment. You may not assign your rights under these Terms without our consent. We may assign ours in connection with a merger, acquisition, or sale of assets.

16.6 Contact. Questions about these Terms: .

Last updated: 07.07.2026

Privacy Policy

Panel.agency — operated by Panel Ag LTD

Panel.agency

Last updated: 07.07.2026

Effective date: 07.07.2026

1. Who we are

This Privacy Policy explains how Panel Ag LTD (company number SC876534, registered office Ridgmount St, London WC1E 7AQ, United Kingdom) ("we", "us", "our"), operating the Panel.agency platform (the "Platform"), handles personal data.

For the purposes of the UK GDPR and the EU GDPR, we are the controller of the personal data described in Section 4, and a processor of the personal data described in Section 5.

Data protection contact:

EU representative: Panel Ag LTD

2. Scope — who this applies to

The Platform is a business tool for two categories of user:

  • Agencies — dating agencies and the individuals who use the panel on their behalf (owners, managers, operators).
  • Site Owners — owners/operators of dating websites who apply to connect via our API.

This Policy covers the personal data of these business users, of individuals depicted in profile content handled through the Platform, and of visitors to our website.

The Platform is not directed at, and does not knowingly process the personal data of, the end users (members/customers) of any connected dating website. Correspondence between end users and profiles, and end-user payment data, remain on the connected websites and are outside the scope of this Policy.

3. Summary of what we do and do not hold

We hold:

  • account and identity data of Agencies and their personnel;
  • data of Site Owners who apply to connect;
  • operational statistics generated within the Platform;
  • where the "canon" feature applies, the content of profiles (photographs, videos, texts) that an Agency creates or edits in the Platform for distribution to authorised websites;
  • limited website/cookie data from visitors to panel.agency.

We do not hold:

  • correspondence between end users and profiles (this stays on the connected websites);
  • payment or financial data of end users (this stays on the connected websites);
  • account data of the end users of connected websites.

4. Personal data we process as controller

4.1 Agency account and personnel data

  • Agency name and business details;
  • names, email addresses and role of the individuals who register and use the panel (owner, manager, operator);
  • login credentials (passwords stored in hashed form);
  • activity and audit logs within the Platform (actions taken, timestamps, access records).

Purposes: to create and administer accounts; to provide the Service; to secure the Platform and prevent abuse; to communicate with users; to comply with legal obligations.

Lawful bases: performance of a contract (Art. 6(1)(b)); our legitimate interests in operating and securing the Platform (Art. 6(1)(f)); compliance with legal obligations (Art. 6(1)(c)).

4.2 Site Owner application data

  • website name and URL; contact person's name; email; messenger contact (optional);
  • description of the website and its audience;
  • the API capabilities the Site Owner indicates they can provide.

Purposes: to assess and process connection applications; to communicate about the potential integration.

Lawful bases: steps taken at your request prior to entering a contract (Art. 6(1)(b)); our legitimate interests in evaluating partnerships (Art. 6(1)(f)).

4.3 Website visitor data

  • limited technical data necessary to operate panel.agency and to keep users signed in (see Section 7, Cookies).

Purposes: to operate the website and provide sign-in functionality; to maintain security.

Lawful bases: our legitimate interests (Art. 6(1)(f)); where required, your consent (Art. 6(1)(a)).

5. Personal data we process as processor (profile content)

Where an Agency uses the "canon" feature, we host and synchronise profile content (photographs, videos, texts, and associated attributes) that the Agency creates or edits in the Platform, and distribute it to the websites the Agency has authorised.

In relation to this content:

  • the Agency is the controller and determines what content is uploaded and where it is shown;
  • we act as processor, hosting, storing, formatting and transmitting the content on the Agency's instructions;
  • we process this content only to provide the Service and do not use it for our own purposes;
  • the terms of this processing are set out in a Data Processing Agreement between us and the Agency (available on request).

The Agency is responsible, as controller, for having a lawful basis and all necessary consents and rights for this content, including the consent and verified age (18+) of every individual depicted, as set out in our Terms of Service.

We do not apply the "canon" feature to third-party websites unless separately agreed; for non-canon connections, profile content remains on the connected website and is not stored by us.

6. How we share personal data

We share personal data only as necessary:

  • Connected websites — profile content and operational instructions are transmitted to the websites an Agency has authorised, so that profiles can be displayed and operated there. This is the core function of the Platform.
  • Service providers (processors) — hosting, infrastructure, email delivery, and similar providers who process data on our behalf under written contracts. Our hosting is provided by Hetzner Online GmbH and located in Germany (EU).
  • Legal and safety — competent authorities, regulators, or advisers where required by law, to comply with legal process, or to investigate or prevent unlawful activity (including suspected child exploitation).
  • Corporate transactions — a successor entity in the event of a merger, acquisition or sale of assets, subject to this Policy.

We do not sell personal data.

7. Cookies

We use cookies and similar technologies that are strictly necessary to operate the Platform, including a cookie that keeps an Agency user signed in to their panel (authentication). These are essential for the Service to function.

If we introduce analytics or marketing cookies in future, we will update this Policy and, where required by law, request your consent through a cookie banner before setting them.

You can control cookies through your browser settings, but disabling strictly necessary cookies may prevent the Platform from working.

We do not currently use analytics or marketing cookies.

8. International transfers

Our infrastructure is intended to be located in the EU/EEA. Because we operate as a UK company serving users who may be in the EU/EEA, personal data may be transferred between the UK and the EU/EEA and, where service providers are involved, potentially to other countries.

Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards such as UK/EU adequacy decisions or Standard Contractual Clauses / the UK International Data Transfer Agreement, as applicable. Details are available on request at .

9. Retention

We retain personal data only for as long as necessary for the purposes described:

  • Agency and personnel account data — for the life of the account and for 24 months after closure, then deleted or anonymised, unless a longer period is required by law.
  • Site Owner application data — for the duration of the assessment and, if no connection proceeds, for 12 months.
  • Profile content (canon) — for as long as the Agency maintains it in the Platform; deleted on the Agency's instruction or on account closure, subject to legal retention.
  • Audit and security logs — for 12 months for security and legal-defence purposes.

10. Your rights

Depending on your location and the applicable law (UK GDPR / EU GDPR), you may have the right to: access your personal data; correct inaccurate data; request erasure; restrict or object to processing; data portability; and, where processing is based on consent, to withdraw consent at any time.

To exercise these rights, contact . We will respond within the timeframe required by law (generally one month).

Where we act as processor of profile content, requests from individuals depicted in that content should be directed to the relevant Agency as controller; we will assist the Agency in responding as required.

You also have the right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner's Office (ICO); in the EU/EEA, your local data protection authority; in Spain, the Agencia Española de Protección de Datos (AEPD).

11. Security

We implement appropriate technical and organisational measures to protect personal data, including access controls, logical isolation of each Agency's data, encryption in transit, and hashed storage of credentials. No system is completely secure, and we cannot guarantee absolute security. Users are responsible for safeguarding their own credentials.

12. Children

The Platform is a business tool and is not directed at children. We do not knowingly process the personal data of anyone under 18 as a user. Any individual depicted in profile content must be at least 18; responsibility for verifying this rests with the Agency as controller, as set out in our Terms.

13. Changes to this Policy

We may update this Policy from time to time. Material changes will be indicated by an updated "Last updated" date and, where appropriate, by direct notice. Continued use of the Platform after changes take effect constitutes acceptance.

14. Contact

Questions or requests regarding this Policy or your personal data:

Panel Ag LTD

Data protection contact:

Registered office: Ridgmount St, London WC1E 7AQ, United Kingdom

EU representative: Panel Ag LTD

Last updated: 07.07.2026

Data Processing Agreement

Panel.agency — operated by Panel Ag LTD

Panel.agency

Last updated: 07.07.2026

1. Parties and background

This Data Processing Agreement ("DPA") forms part of, and is subject to, the Terms of Service between:

(1) The Agency — the party that has registered for and uses the Panel.agency platform ("Controller", "you"); and

(2) Panel Ag LTD, company number SC876534, registered office Ridgmount St, London WC1E 7AQ, United Kingdom, operating the Panel.agency platform ("Processor", "we", "us").

Background. In using the Platform's profile-management ("canon") feature, the Controller uploads and edits profile content which the Processor hosts and synchronises to websites the Controller has authorised. In doing so, the Processor processes personal data on behalf of the Controller. This DPA sets out the terms of that processing as required by Article 28 of the UK GDPR and the EU GDPR (together, "GDPR").

Where this DPA conflicts with the Terms of Service in respect of the processing of personal data, this DPA prevails.

2. Definitions

Terms such as "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the GDPR. "Data Protection Law" means the UK GDPR, the UK Data Protection Act 2018, the EU GDPR (Regulation (EU) 2016/679), and any other applicable data protection legislation, as amended.

3. Roles of the parties

3.1 The parties acknowledge that, in respect of the profile content processed through the canon feature, the Controller is the controller and the Processor is the processor.

3.2 The Controller is responsible for ensuring that it has a lawful basis and all necessary rights and consents for the personal data it processes through the Platform, including the consent and verified age (18+) of every individual depicted in profile content, as set out in the Terms of Service.

3.3 This DPA does not apply to personal data for which the Processor is itself a controller (for example, Agency account and personnel data), which is governed by the Privacy Policy.

3.4 This DPA does not apply to correspondence between end users and profiles, or to end-user payment data, which remain on the connected websites and are not processed by the Processor.

4. Processing details (Article 28(3))

The details of processing are set out in Annex 1. In summary:

  • Subject matter: hosting, storage, formatting, and synchronisation of profile content to authorised connected websites.
  • Duration: for the term of the Controller's use of the Platform, and until deletion or return of the data under Section 11.
  • Nature and purpose: provision of the profile-management ("canon") functionality of the Platform.
  • Types of personal data: as set out in Annex 1.
  • Categories of data subjects: individuals depicted in or associated with profile content.

5. Processor obligations

The Processor shall:

5.1 Process only on documented instructions from the Controller, including with regard to international transfers, unless required to do otherwise by law (in which case it will inform the Controller, unless legally prohibited). The Controller's instructions are set out in this DPA, the Terms of Service, and the Controller's use of the Platform's features.

5.2 Notify the Controller if, in its opinion, an instruction infringes Data Protection Law.

5.3 Ensure that persons authorised to process the personal data are bound by an appropriate duty of confidentiality.

5.4 Implement the technical and organisational security measures described in Annex 2 and as required by Article 32 GDPR.

5.5 Respect the conditions for engaging sub-processors set out in Section 6.

5.6 Assist the Controller, taking into account the nature of the processing, by appropriate technical and organisational measures, in fulfilling the Controller's obligation to respond to data subject requests (access, rectification, erasure, restriction, portability, objection).

5.7 Assist the Controller in ensuring compliance with its obligations under Articles 32–36 GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of processing and the information available to the Processor.

5.8 At the Controller's choice, delete or return all personal data on termination, as set out in Section 11.

5.9 Make available to the Controller information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits as set out in Section 9.

6. Sub-processors

6.1 The Controller provides general authorisation for the Processor to engage sub-processors to support the provision of the Platform (for example, hosting and infrastructure providers). Current sub-processors are listed in Annex 3.

6.2 The Processor shall impose on each sub-processor, by written contract, data protection obligations equivalent to those in this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures.

6.3 The Processor remains fully liable to the Controller for the performance of each sub-processor's obligations.

6.4 The Processor shall inform the Controller of any intended addition or replacement of a sub-processor, giving the Controller a reasonable opportunity to object on reasonable data-protection grounds. If the parties cannot resolve an objection, the Controller may terminate the affected functionality.

7. International transfers

7.1 The Processor's infrastructure is intended to be located in the EU/EEA. The Processor shall not transfer personal data outside the UK or EEA except in compliance with Data Protection Law.

7.2 Where a transfer to a country without an adequacy decision is necessary, the parties shall put in place an appropriate transfer mechanism, such as the Standard Contractual Clauses and/or the UK International Data Transfer Agreement / Addendum, which shall be incorporated by reference.

8. Personal data breach

8.1 The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data, and in any event within 48 hours of becoming aware.

8.2 The notification shall include, to the extent available: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Where information is not all available at once, it may be provided in phases without undue further delay.

8.3 The Processor shall take reasonable steps to mitigate and remediate the breach and shall cooperate with the Controller. The Controller is responsible for any notification to supervisory authorities or data subjects required of it as controller.

9. Audit

9.1 The Processor shall make available to the Controller information reasonably necessary to demonstrate compliance with this DPA.

9.2 The Controller may, on reasonable prior written notice (at least 30 days, save in the case of a suspected breach or a supervisory-authority requirement), and no more than once per year unless otherwise required by a supervisory authority, audit the Processor's compliance. Audits shall be conducted during business hours, with minimal disruption, subject to confidentiality, and at the Controller's cost.

9.3 The Processor may satisfy audit requests by providing existing certifications, reports, or third-party audit summaries where these reasonably address the Controller's request.

10. Data subject rights and cooperation

10.1 If the Processor receives a request directly from a data subject relating to the Controller's personal data, it shall not respond directly (except to confirm receipt where appropriate) but shall forward the request to the Controller without undue delay.

10.2 The Processor shall provide reasonable assistance to enable the Controller to respond to data subject requests and to communications from supervisory authorities.

11. Deletion and return

11.1 On termination of the Controller's use of the Platform, or on the Controller's earlier written instruction, the Processor shall, at the Controller's choice, delete or return the personal data processed under this DPA, and delete existing copies, unless retention is required by law.

11.2 Deletion from connected websites is subject to the technical capabilities and cooperation of those websites; the Processor shall delete data within its own systems and shall pass on deletion instructions to connected websites it controls or operates, but does not guarantee deletion on independent third-party websites beyond what their APIs permit.

11.3 Where the Processor retains personal data because required by law, it shall protect it and process it only to the extent and for the period required by that law.

12. Liability

12.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, except to the extent Data Protection Law requires otherwise.

12.2 Nothing in this DPA limits either party's liability to a data subject or supervisory authority under Data Protection Law.

13. Term, governing law

13.1 This DPA takes effect when the Controller accepts the Terms of Service and continues for as long as the Processor processes personal data on the Controller's behalf.

13.2 This DPA is governed by the law and subject to the jurisdiction stated in the Terms of Service, save where Data Protection Law requires otherwise.

Annex 1 — Details of processing

Subject matter of processing: Hosting, storage, technical formatting/adaptation, and synchronisation of profile content created or edited by the Controller in the Platform, and its distribution to connected websites authorised by the Controller.

Duration of processing: For the term of the Controller's use of the Platform and until deletion or return under Section 11.

Nature and purpose of processing: To provide the profile-management ("canon") functionality — maintaining a canonical profile in the Platform and replicating it as instances on authorised websites.

Types of personal data:

  • profile photographs and videos of individuals;
  • profile text (names or aliases, age, descriptions, attributes, location/region as displayed);
  • profile identifiers and metadata generated within the Platform.

Special category data: The Controller must not upload special category data (Article 9) except where it has established a valid Article 9 condition and has instructed the Processor accordingly.

Categories of data subjects: Individuals depicted in or associated with the profiles managed by the Controller (e.g. models/profile subjects).

Annex 2 — Technical and organisational measures

The Processor implements measures appropriate to the risk, including:

  • Access control: role-based access; unique credentials; passwords stored hashed; least-privilege access for personnel.
  • Tenant isolation: logical separation of each Agency's data so that one Agency cannot access another's data.
  • Encryption: encryption of personal data in transit (TLS); encryption at rest.
  • Network and infrastructure security: firewalling, restricted administrative access, hosting with Hetzner Online GmbH in Germany (EU).
  • Logging and monitoring: audit logs of access and key actions; monitoring for anomalous activity.
  • Resilience and backup: regular backups; measures to restore availability after an incident.
  • Sub-processor controls: contractual data-protection obligations imposed on sub-processors.
  • Personnel: confidentiality obligations; security awareness.
  • Breach management: procedures to detect, report and respond to personal data breaches.

*(This Annex should be reviewed and kept current; it is a representation of the Processor's security posture and should reflect actual measures implemented.)*

Annex 3 — Approved sub-processors

Sub-processorService providedLocation
Hetzner Online GmbHServer hosting / infrastructureGermany (EU)
Email delivery providerTransactional emailGermany (EU)
Storage / CDN providerMedia storage / deliveryGermany (EU)

*The Processor will update this Annex and notify the Controller of changes in accordance with Section 6.*