1. Parties
- Controller: the organisation that has a written agreement with Custodian (the "Customer").
- Processor: Mirko Casu, who operates Custodian as a private individual ("Custodian"). Custodian is a project developed in Lausanne, Switzerland, and is not yet a registered company. When the company is registered, it takes over this agreement as Section 1 of the Terms describes.
If this agreement and the Terms of Service do not agree on data protection, this agreement applies.
2. Subject, Duration and Purpose
Custodian processes personal data of the Customer's participants to show each participant how AI assistants affect them, and to show the Customer figures combined over at least five participants. The processing lasts as long as the written agreement, plus the deletion period in Section 9.
3. Data and Data Subjects
- Data subjects: the Customer's employees and contractors who create an account with the Customer's invite code and switch capture on ("participants").
- Account data: username, password hash, anonymous ID, session token hashes.
- Conversation records: what the participant and the AI assistant wrote, with the time, the assistant, the conversation and message identifiers, and the site and path of the page. Names and other identifiers are removed before storage.
- Results: estimates of mental states and ratings of the assistant's replies. These estimates can be data about health, a special category of personal data (GDPR Art. 9, nFADP Art. 5(c)).
4. Instructions of the Customer
Custodian processes the data only on the documented instructions of the Customer. The written agreement, the Terms of Service and this agreement are these instructions. Custodian tells the Customer at once if it thinks an instruction breaks data protection law. Custodian does not use the data for its own purposes and does not sell it.
The Customer is responsible for the legal basis of the processing. Participation must be voluntary: each participant gives explicit consent when they create the account and when they switch capture on, and can withdraw it at any time.
5. Confidentiality
Every person who processes the data for Custodian is bound to confidentiality. Only the Custodian administrator has access to the service, and the administrator sees participation counts under anonymous IDs, not conversation text or individual results, in the normal operation of the service.
6. Security Measures
- Encrypted connections (TLS) from the extension, the connector and the website to the service.
- De-identification with Presidio before anything is stored; records kept under an anonymous ID, never under the username.
- Analysis on the service's own computer; no conversation text goes to an AI provider.
- Passwords stored as Argon2 hashes; session tokens stored only as hashes; limits on sign-in attempts and on requests.
- The service answers only through the website proxy; no port of the service's computer is open to the internet.
- An encrypted disk; files of the service readable only by the service's user.
- The organisation view shows figures only where at least five participants contribute, and cannot be filtered down to a person.
The Security page describes these measures in more detail. Custodian keeps them up to date and does not reduce the level of protection.
7. Sub-processors
The Customer authorises these sub-processors:
- Cloudflare, Inc. (United States): carries the traffic between the participants' computers and the service, and serves the website.
- Google LLC (United States): Gmail sends the service's emails to the Custodian team, which contain usernames of new accounts.
Custodian binds each sub-processor to data protection obligations that are at least as strict as this agreement. Custodian tells the Customer at least 30 days before it adds or replaces a sub-processor. The Customer can object in that time; if the parties do not agree, the Customer can end the agreement.
8. Location and Transfers
The service that stores and analyses the conversation records runs on one computer in Italy, inside the EU. Transfers to the sub-processors in the United States rely on the EU-U.S. Data Privacy Framework and its Swiss extension, and on the Standard Contractual Clauses of the European Commission.
9. Deletion at the End
Custodian deletes the participants' accounts, conversation records and results 30 days after the end of the written agreement, unless the agreement sets a shorter period. Before that, the Customer can ask for its combined results. A participant can delete their own account and all its data at any time from their dashboard.
10. Assistance to the Customer
- Rights of participants. Each participant can export and delete their data from their own dashboard. Custodian helps the Customer answer any other request, and sends to the Customer each request that it receives about the Customer's data.
- Data breaches. Custodian tells the Customer without undue delay, and at the latest within 48 hours, after it becomes aware of a breach of the Customer's data, with the information that the Customer needs for its own notification.
- Impact assessments. Custodian gives the Customer the information it needs for a data protection impact assessment and for consultations with the authority or with employee representatives.
11. Audits
Custodian gives the Customer the information needed to show that it keeps this agreement. The Customer, or an auditor bound to confidentiality, can make an audit once a year, or after a breach, with 30 days' notice. Each party pays its own costs.
12. Liability and Law
Liability, governing law and courts are as the Terms of Service set out, except where data protection law does not allow a limit.
13. Contact
Custodian, a project developed in Lausanne, Switzerland
Operated by Mirko Casu (postal address on request)
Contact: info@custodian.health