Data Processing Agreement
Last updated 29 June 2026
This page summarises the data-protection terms on which NDGM processes personal data on behalf of customers inside the platform. It forms part of, and is incorporated into, the signed subscription agreement; the executed DPA is the operative document and is available on request at [email protected].
1. Roles
For personal data processed in the platform, the customer is the controller and NDGM (Agile Tech Global Solutions Limited) is the processor. NDGM processes that data only on the customer’s documented instructions.
2. Subject matter, nature and purpose
NDGM processes personal data to provide identity governance: discovering and classifying identities, running access reviews, enforcing decisions (such as credential rotation and vaulting), and producing audit evidence — for the duration of the subscription.
3. Categories of personal data
- Employee and contractor identifiers (e.g. usernames, directory IDs)
- Work contact details (e.g. work email, department)
- Role and entitlement data (group memberships, access scopes, ownership)
- Authentication events and access logs
- Metadata about non-human identities and their owners
The platform is not intended for special-category data; customers should not load it.
4. Categories of data subjects
The customer’s workforce and contractors, and the human owners of service accounts, keys and AI agents within the customer’s estate.
5. Our obligations as processor
- Process personal data only on documented instructions from the controller
- Ensure persons authorised to process are bound by confidentiality
- Implement appropriate technical and organisational security measures — including database row-level tenant isolation, encryption in transit, secret vaulting, role-based access control and MFA (described in our Trust Centre)
- Engage subprocessors only under written terms and with notice (see below)
- Assist the controller with data-subject requests and with security, breach-notification and impact-assessment obligations
- Notify the controller without undue delay on becoming aware of a personal-data breach
- Delete or return personal data at the end of the agreement, as instructed
- Make available information needed to demonstrate compliance and allow for audits
6. Subprocessors
NDGM uses the subprocessors listed on our Subprocessors page. We give at least 30 days’ notice before adding or replacing a subprocessor, during which the customer may object on reasonable data-protection grounds.
7. International transfers
Where processing involves a transfer outside the UK, an appropriate safeguard applies — the UK Extension to the EU–US Data Privacy Framework where the recipient is certified, or the UK IDTA / Addendum with a transfer risk assessment. Safeguards are recorded per subprocessor on the Subprocessors page.
8. AI processing
The platform’s AI features (including the Reeve agent) run on a locally-hosted model (Mistral 7B) on our own infrastructure. There are no third-party AI providers (no OpenAI, Anthropic or Google) in the processing chain; model interactions are token-attributed and reasoning is retained for explainability, and destructive actions require human approval. In a Sovereign deployment, all processing — including AI inference — remains entirely within the customer’s estate.
9. Contact
To request or sign the full DPA, email [email protected].