Skip to content
Data processing

Data processing terms & sub-processors

How Recellion processes customer data as a processor, the providers we rely on, and the safeguards that apply.

Last updated

1. What this page is

This page sets out the processing terms that apply when Delta Metrics Ltd (“Recellion”) processes personal data on behalf of a customer, and the current list of sub-processors we use to do it. It is the public reference version. A signed data processing agreement incorporating these terms is available on request from ms@recellion.com. Most customers attach it to their order form.

For the personal data where Recellion is the controller, meaning user accounts, billing and support, see the privacy notice.

2. Roles

The customer is the controller of the operating data, documents and records it supplies or connects to the platform. Recellion is the processor of that data, and processes it only on the customer’s documented instructions, which include the instruction to produce, sign, anchor and share attestation records in the way the platform is configured to do.

Recellion will tell the customer if an instruction appears to infringe UK GDPR or other applicable data protection law, and may pause that processing until the point is resolved.

3. Subject matter, duration and scope

Subject matter: provision of the Recellion attestation platform. Duration: for the term of the customer agreement, plus the return-and-deletion window in section 8. Nature and purpose: hosting, ingestion, evaluation against contract envelopes, record generation, signing, anchoring, evidence packaging and controlled sharing.

Categories of data subject
CategoryWho this covers
Customer personnelNamed users of the platform: asset owners, operators, analysts and administrators.
Counterparty personnelPeople invited to co-sign an attestation or to approve a reliance grant.
Third parties named in customer dataSignatories on uploaded contracts, engineers named in maintenance logs, and similar incidental references.
Categories of personal data
CategoryWhat it includes
Identity and contactName, work email, job title, phone, organisation and role.
AuthenticationPassword hashes, session tokens, invitation and reset tokens, sign-in events.
Customer contentMeter and telemetry data, contract envelopes, uploaded documents, maintenance and lifecycle records, and any personal data the customer chooses to include in them.
TechnicalIP addresses, request metadata and application logs.

No special category data is required by the platform, and customers should not upload it.

4. Sub-processors

We use the providers below to deliver the service. Each is bound by written terms imposing data protection obligations no less protective than these, and each is engaged only for the stated purpose.

Current sub-processors
ProviderPurposeProcessing location
Microsoft AzureApplication and API hosting (Azure Container Apps), secret storage.EU (West Europe)
MongoDB AtlasPrimary application database and encrypted backups.EU / UK region
StripePayment processing, subscription and invoice records. Card data is captured by Stripe and never reaches our servers.EU / US (SCCs + UK Addendum)
OpenAIPowers the in-platform assistant and the document paths behind dispatch-warranty intake. What is sent differs by path and the difference matters, so each is named here rather than covered by "the assistant": the composed answer sends the question and the fleet context needed to answer it; the two routers that place a question or a chart send the question text alone; dispatch-warranty intake sends an uploaded contract itself, the document bytes where a scan has to be transcribed and the recovered text where it does not, so a counterparty agreement leaves the platform on that path; record narration sends facts the signed record has already decided; partner onboarding sends unmapped field names and sample values. Optional throughout: with no key configured every one of these degrades to a deterministic fallback and nothing is sent.US (SCCs + UK Addendum)
SentryError and exception monitoring. Optional, enabled only when a DSN is configured.EU / US (SCCs + UK Addendum)
Transactional email provider (SMTP)Verification, invitation, password-reset and alert emails. The specific provider is named in the signed DPA for your account.EU / UK
Polygon (public network)Publishes content hashes of attestation records for tamper-evidence. Hashes only, never personal data, documents or operating data.Public, distributed
Public Polygon RPC providersRead-only chain lookups the signed-in console makes directly from the browser to confirm an anchor exists: polygon-rpc.com, polygon.llamarpc.com, polygon-bor-rpc.publicnode.com, 1rpc.io and rpc.ankr.com. Each sees the visitor IP address and which registry entry is being read; no account data, documents or operating data are sent. A deployment may point the console at a single keyed endpoint of its own instead, in which case only that provider is used.Global edge
OpenStreetMap FoundationTwo uses, and they reach the provider differently. Map tiles behind the deployment map and the coordinate picker are fetched by the browser, so the tile server sees the visitor IP address and the area of the map requested. Address lookup on the Set Coordinates page (Nominatim) is called by our server, not the browser: the provider receives the address text or coordinate an operator is looking up and our server address, never the operator IP address. Neither use sends account data. Our public pages load no third-party assets at all; fonts and styling are served from our own origin. A deployment may point address lookup at its own Nominatim instance, or switch it off entirely, in which case coordinates are entered on the map or by hand.Global edge
Weather archive provider (site conditions)Ambient conditions for a site over an attested period, recorded on a dispatch-warranty record as context. Called by our server and never by the browser: the provider receives the coordinates of the asset, the dates of the period, and our server address. It never receives the operator IP address, account data, documents or contract text. It is a read of a public archive, and what comes back is modelled weather for a grid cell, already published to anyone who asks. This is off unless a deployment enables it, in which case no such call is made at all. The default provider is the public Open-Meteo archive, and a deployment may point it at its own instance so the coordinates stay inside its own infrastructure.Global edge
GLEIF (Global Legal Entity Identifier Foundation)Company-register lookup on the Account page, called by our server and never by the browser: the register receives the company name or LEI an operator is looking up and our server address, never the operator IP address. It is a read of a public register. No account data, documents or operating data are sent, and the entity records returned are already published by GLEIF to anyone who asks. A deployment may point the lookup at its own mirror, or switch it off entirely, in which case an LEI is entered by hand and checked locally against its own check digits.Global edge

Changes: we will give customers at least 30 days’ notice before adding or replacing a sub-processor. A customer may object on reasonable data protection grounds within that period; if we cannot resolve the objection, the customer may terminate the affected part of the service without penalty. Email ms@recellion.com to be added to the sub-processor change notification list.

5. Technical and organisational measures

Security measures
AreaMeasure
Access controlRole- and capability-scoped authorisation on every request; production data access limited to personnel who require it.
Authenticationbcrypt password hashing, signed session tokens, secure cookie flags in production, enforced email verification.
Transport and headersTLS in transit, hardened response headers, origin-restricted CORS by environment, request rate limiting on the API and auth endpoints.
IntegrityContent-hashed attestation envelopes, tamper-evident audit logging, and independent on-chain verification of anchors; anchors that cannot be verified are refused in production rather than recorded.
ResilienceScheduled encrypted database backups with a documented restore procedure; versioned, reversible schema migrations.
ObservabilityStructured logging with request correlation IDs, service metrics and error tracking, so incidents can be reconstructed.

We maintain these measures for the term of the agreement and will not materially weaken them. Detail beyond this summary is available under NDA for security review.

6. International transfers

We prefer UK and EEA processing regions. Where a sub-processor processes data outside the UK, transfers are made under UK adequacy regulations, or under the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, with additional safeguards where the transfer risk assessment requires them.

7. Assistance, incidents and audit

Data subject requests: we will pass any request we receive directly to the customer without undue delay, and assist the customer in responding, taking account of the nature of the processing.

Personal data breach: we will notify the customer without undue delay, and in any event within 48 hours of becoming aware, with the information the customer needs to meet its own notification duties.

Assistance: we will provide reasonable assistance with data protection impact assessments and prior consultations relating to the platform.

Audit: we will make available the information needed to demonstrate compliance with these terms, and will allow an audit by the customer or an independent auditor it mandates, no more than once in any 12-month period unless a regulator or a breach requires otherwise, on reasonable notice and subject to confidentiality.

Confidentiality: personnel authorised to process customer data are bound by confidentiality obligations.

8. Return and deletion

On termination the customer may export its records and evidence packs. We delete or return customer personal data within 90 days of the end of the agreement, except where we are required to retain it by law, or where it forms part of an attestation record that a lender, insurer or counterparty is relying on under a contract. We will identify any such records on request.

Content hashes already published to the Polygon public network cannot be deleted by anyone, including us. As set out in the privacy notice, those entries contain hashes only, never personal data, documents or operating data.

9. Contact

Delta Metrics Ltd, 71–75 Shelton Street, London WC2H 9JQ, United Kingdom. ms@recellion.com. Ask us for the signed DPA, the sub-processor change notification list, or a security review pack.