Data Processing Agreement

Effective: February 25, 2026 · Last updated: February 25, 2026

This Data Processing Agreement ("DPA") governs the processing of data by Advanced Consulting Experts, LLC ("ACE", "Processor", "we") on behalf of our customers ("Controller", "you") when using the ACE Platform.

ACE processes governance metadata only. We do not process, store, or have access to your LLM prompts, responses, source code, business documents, or end-user personal data. ACE operates at the governance layer — classifying decisions, enforcing gates, and generating audit evidence.

1. Roles

RoleDescription
Controller (You)The customer who determines the purposes and means of processing. You decide what governance policies to apply, which workflows to govern, and how audit data is used.
Processor (ACE)Operates the ACE platform and processes data solely on the Controller's instructions to provide the governance service.
Sub-processorsStripe (payment processing). No other sub-processors. ACE does not forward data to Anthropic or any AI provider.

2. Data Types Processed

CategoryData Elements
Account DataEmail address, name/organization, API key hash (SHA-256), key prefix, key fingerprint, tier, rate limits
Governance MetadataMAI classification results, governance scores (Integrity, Accuracy, Compliance), risk tier assessments, compliance mapping results
Audit RecordsOperation names, timestamps, MAI classification, hash-chained ledger entries, gate decisions, approval records with approver identity
Session MetadataMCP session ID, tool call counts, session duration, client tier
Operational MetricsTime saved, risk blocked counts, success rates, autonomy levels (aggregate, non-identifying)

Data We Do Not Process

3. Purpose of Processing

We process data solely to:

  1. Authenticate and authorize API requests
  2. Execute governance tool calls (classification, scoring, compliance mapping)
  3. Maintain tamper-evident audit trails (hash-chained forensic ledger)
  4. Enforce MANDATORY gates (human-in-the-loop approval workflows)
  5. Generate governance reports and compliance evidence at your request
  6. Enforce rate limits and detect abuse

4. Security Measures

Encryption

Access Control

Infrastructure Security

Audit & Monitoring

5. Data Retention & Deletion

Deletion Requests

You may request deletion of your data at any time by contacting us. Upon receiving a verified deletion request, we will:

  1. Revoke all active API keys associated with your account
  2. Delete account data and governance metadata within 30 days
  3. Provide written confirmation of deletion
  4. Retain only what is required by applicable law (if any)

6. Sub-processors

Sub-processorPurposeData Shared
Stripe, Inc.Payment processing for Professional and Enterprise subscriptionsEmail, subscription tier, payment method (handled entirely by Stripe)

No additional sub-processors are used. ACE tool calls are processed entirely on our infrastructure. We do not forward governance data to Anthropic, OpenAI, or any third-party AI provider.

7. Data Breach Notification

In the event of a data breach affecting your data, we will:

  1. Notify you within 72 hours of becoming aware of the breach
  2. Provide details of the nature, scope, and likely consequences
  3. Describe the measures taken or proposed to address the breach
  4. Cooperate with your regulatory notification obligations

8. Data Location

ACE infrastructure is hosted in the United States. If you require data residency in a specific jurisdiction, contact us about Enterprise hosting options.

9. Audit Rights

You may audit our compliance with this DPA by:

10. Term & Termination

This DPA is effective for the duration of your use of the ACE platform. Upon termination of your subscription, the data retention and deletion provisions in Section 5 apply. Our obligations regarding data security and confidentiality survive termination.

11. Contact

For DPA inquiries, data deletion requests, or compliance questions: