Policies
Data Processing Addendum
Where Cairn processes personal data on your behalf, you are the controller and DesignSwift, LLC is the processor. This sets out what that means in practice.
Last updated 8 October 2026
1. Scope and roles
This Data Processing Addendum ("DPA") supplements and forms part of the agreement under which DesignSwift, LLC ("DesignSwift", "we") provides the Cairn service (the "Services") to a customer ("Customer", "you").
In providing the Services, DesignSwift processes personal data on your behalf. You act as the data controller and DesignSwift acts as the data processor. Where you are yourself a processor acting for another controller, DesignSwift acts as a sub-processor and this DPA applies on the same terms.
Capitalised terms not defined here have the meaning given in the main agreement. Where this DPA conflicts with the main agreement on the processing of personal data, this DPA governs.
2. Our instructions
We process your data only on your documented instructions. This DPA, the main agreement, and the configuration choices you make inside the Services together constitute those instructions.
We will not process your data for any other purpose. In particular, we do not sell it, we do not use it to train models, and we do not use it to improve the Services for other customers.
If we are required by law to process your data otherwise, we will tell you before doing so unless the law forbids us from saying. If we believe an instruction you give us would breach data protection law, we will tell you.
3. Confidentiality
Everyone we authorise to process your data is bound by a duty of confidentiality, whether contractual or statutory.
Our staff hold no standing access to a customer organisation. Access is granted only for a specific purpose, is time-boxed, and is recorded.
4. Security
We maintain appropriate technical and organisational measures to protect your data, taking account of the state of the art, the cost of implementation, and the risk to the people whose data it is. Those measures are described on our security page and include:
- Encryption in transit (TLS 1.2 or better) and at rest
- A second, application-level layer of encryption on integration tokens and API credentials
- Tenant isolation enforced centrally rather than per query
- Access control that applies identically to people and to API and MCP tokens
- Operational telemetry restricted to a typed, allowlisted schema that excludes your content
- Change management requiring review and automated checks before anything reaches production
5. Sub-processors
You give us general authorisation to engage the sub-processors published at our sub-processor list. That page is the canonical list and carries the date it last changed.
We will notify you before a new sub-processor begins processing your data. You may object on reasonable data protection grounds within 30 days of that notice. If we cannot address your objection, either party may terminate the affected part of the Services, and we will refund any prepaid fees covering the period after termination.
We impose data protection obligations on every sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance to the same extent as for our own.
6. People exercising their rights
If we receive a request from an individual to access, correct, delete, or restrict processing of their data, we will tell you rather than answer it ourselves, unless you have authorised us to redirect them to you.
We will help you respond to such requests. In practice much of this is built into the product: every contributor has a page showing what has been recorded about them, which they can correct themselves at any time, and we support export and erasure for an individual or an entire organisation. Erasure anonymises in place so your remaining process history stays coherent.
7. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and will give you the information you reasonably need to meet your own notification obligations.
We will not delay notification in order to complete our investigation first; we will tell you what we know and follow up as we learn more.
8. Assistance and demonstrating compliance
Taking into account the nature of the processing and what we know, we will reasonably assist you with data protection impact assessments and any resulting consultation with a supervisory authority.
On reasonable written request, and no more than once a year, we will provide the documentation needed to demonstrate our compliance with this DPA. Where that is not sufficient to satisfy an obligation under data protection law, we will allow an audit, at your cost, conducted so as to minimise disruption, under an appropriate confidentiality agreement.
9. Return and deletion
When the agreement ends you may ask us to return your data, delete it, or both. We will do so within a reasonable period, except where we are required by law to retain it — in which case we will isolate it and stop processing it for any other purpose.
10. International transfers
DesignSwift, LLC is established in the United States and processes data there.
Where your data is subject to the GDPR, UK GDPR, or Swiss data protection law, we will enter into the European Commission's Standard Contractual Clauses — with the UK Addendum or the Swiss equivalent where relevant — on request, and those clauses will govern the transfer. Ask us and we will send them.
11. United States privacy laws
Where US state privacy laws apply, we act as a "service provider" or "processor" as those terms are used in those laws.
We do not sell or share your data, we receive no consideration for it, we do not retain or use it outside our direct relationship with you, and we do not combine it with data from any other source except where you instruct us to or the law permits it. If we can no longer meet those obligations, we will tell you.
12. Definitions
"Personal data", "processing", "controller", "processor", "data subject", and "personal data breach" carry the meanings given in applicable data protection law.
"Data protection law" means the privacy and data protection laws applicable to our processing of your data in connection with the Services, including the GDPR, the UK GDPR, and applicable US state privacy laws.
"Your data" means personal data we process on your behalf in order to provide the Services.
Schedule 1 — Details of processing
Required by Article 28(3) and by the Standard Contractual Clauses.
- Subject matter and nature: providing the Cairn service — capturing what contributors say about how work is done, structuring it, and making it available to authorised people and agents within your organisation.
- Purpose: performance of the Services under the agreement, and nothing else.
- Duration: the term of the agreement, plus the time needed afterwards to complete return or deletion.
- Categories of data subjects: your personnel who contribute to or are named in Cairn — typically employees, contractors, and administrators.
- Categories of personal data: name, work email address, job title, team and group membership, and the free-text content of answers contributors submit, which is determined by them and by your configuration.
- Special category data: none is sought or required. Contributors answer questions about work processes, and the question bank is written so that no answer calls for special category data.
- Frequency: continuous for the duration of the agreement.
- Sub-processor transfers: as described in section 5 and the published sub-processor list, for the duration of the agreement.
Requesting a signed copy
This page is the current text. To execute a DPA, or to request the Standard Contractual Clauses, contact us and we will send a signable copy. If your organisation has its own DPA, send it over and we will review it.