Data processing
During a migration we act on your instructions and on your data. This explains what that means in practice and how to get the agreement itself.
Last updated September 2026
Our role
You are the controller of the data being migrated. We are a processor, acting on your documented instructions, for the duration of the engagement and no longer.
We access your source and destination systems using credentials you issue and can revoke. We do not use anything we see for any purpose other than delivering your migration.
What we actually hold
On most engagements the recordings and files never enter our systems at all. What we keep is the bookkeeping — which record went where, what state it reached, and the checksums proving it arrived intact — plus the mapping tables needed to resolve people and accounts.
The three custody modes, and which one applies when, are set out on our security page.
Subprocessors
Listed in full, with what each handles and where it runs, on our subprocessors page. We give notice before adding one that would touch an active engagement.
Getting the agreement
Our data processing agreement is provided during scoping, alongside the statement of work, so your legal review runs in parallel with the technical one rather than after it. Ask sooner if your process needs it earlier.