ArtAML™ Privacy Policy

Version 3.0 | Last updated 18th June 2026

Introduction

1.1. This Privacy Policy explains how ArtAML Limited (‘ArtAML’, ‘we’, ‘us’) collects, uses, stores and protects personal data in connection with our anti-money laundering (AML) compliance platform for the art market. It applies to Clients, their customers who provide Customer Due Diligence (CDD) information, Prospective Clients, website visitors and business contacts.

1.2. This policy covers ArtAML’s processing in two distinct capacities: as Processor, when handling personal data on behalf of Clients in connection with CDD, KYC, sanctions screening and related compliance activities; and as Controller, when handling personal data for ArtAML’s own operational purposes. The detailed contractual terms governing ArtAML’s role as Processor are set out in our Data Processing Agreement (‘DPA’), available on our website. This policy should be read alongside the DPA and our Platform Security Policy.

1.3. The third-party providers used by ArtAML are listed in two separate appendices to this policy, reflecting ArtAML’s dual role. Appendix 2 lists providers engaged in ArtAML’s capacity as Processor — those who handle personal data uploaded by or collected on behalf of Clients. Appendix 3 lists providers used by ArtAML in its capacity as Controller for its own business operations. Different notification and objection rights apply to each category, as set out in clause 5.4 of the DPA and section 17 of this policy.

1.4. This policy is written primarily by reference to the United Kingdom General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. ArtAML is a UK-registered company and UK GDPR is the primary framework governing our processing activities. We also recognise that Clients and individuals based in the European Economic Area may have rights under EU GDPR (Regulation (EU) 2016/679), and that Clients in other jurisdictions may be subject to their own applicable data protection legislation. ArtAML will cooperate with Clients to address jurisdiction-specific requirements on request. This policy also reflects our obligations under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (‘MLRs’).

1.5. Defined terms are signalled by an initial capital letter and are set out in Appendix 1.

2. Who We Are

2.1. ArtAML Limited provides anti-money laundering compliance technology to Art Market Participants. We are incorporated in England and Wales (company no. 11806741) with registered address at 27 Old Gloucester Street, London WC1N 3AX. We are registered with the Information Commissioner’s Office (ICO) under reference ZA566966.

2.2. Our website is www.artaml.com. Our compliance platform is available at aml.art.

2.3. ArtAML Limited (company number 11806741) is the data controller for personal data processed under this policy. Our registered address is 27 Old Gloucester Street, London WC1N 3AX.

2.4. For contact details, including how to reach our Data Protection Officer, see section 22.

3. Our Role as Controller and Processor

3.1. ArtAML acts in two distinct capacities:

3.1.1. As a Data Processor: when handling CDD and KYC data uploaded by, or collected on behalf of, Clients and Prospective Clients. In this role, ArtAML processes personal data on the Client’s instructions, as governed by our DPA. The DPA applies from the first day of any trial period.
3.1.2. As a Data Controller: when handling data relating to platform accounts, billing, analytics, security monitoring and communications. In this role, ArtAML determines the purposes and means of processing and is directly responsible to individuals for compliance with applicable Data Protection Legislation.

3.2. This policy covers both roles. The processing table in section 7 identifies ArtAML’s role for each activity. The DPA sets out the detailed terms governing our Processor role.

4. How We Collect Personal Data

4.1. We collect personal data through the following means:

4.1.1. Direct interactions: data provided by Clients, Prospective Clients or their customers, including uploaded CDD documents, account registration information and support correspondence.
4.1.2. Automated technologies: cookies on artaml.com (not on aml.art), security logs and analytics tools.
4.1.3. Third parties: identity verification providers, screening partners, payment processors and publicly available company information sources. Refer to Appendices for sub-processors lists.

5. Categories of Personal Data We Process

5.1. Depending on the nature of the relationship, we may process the following categories of personal data:

5.1.1. Identification data: name, date of birth, nationality.
5.1.2. Government-issued photo identification.
5.1.3. Proof of address.
5.1.4. Contact details: email, telephone, postal address.
5.1.5. Financial or billing data: payment records, transaction history, subscription details.
5.1.6. AML screening data: PEP status, sanctions status, UBO details.
5.1.7. Technical data: IP address, device information, authentication logs, access logs, usage data.
5.1.8. Marketing data: business contact details, email preferences, communication history.
5.1.9. Some processing may involve Special Categories of Personal Data, as set out in section 6. ArtAML does not knowingly collect personal data relating to children except where required by applicable AML legislation as part of the CDD process (for example, where a minor appears as a beneficial owner or as a family member of a PEP). Where such data is processed, it is handled with appropriate care and only to the extent required to fulfil the relevant AML obligation.

6. Special Categories of Personal Data

6.1. Certain CDD and identity verification processes may involve Special Categories of Personal Data, including biometric data and information that may reveal or infer political opinions through AML screening activities. Where ArtAML processes Special Categories of Personal Data, it does so on the following basis:

Type of Special Category Data

Context

Lawful Basis (Article 9 UK GDPR / EU GDPR)

Biometric data (e.g. facial recognition in identity documents)

Identity verification

Substantial public interest — preventing or detecting unlawful acts (UK: Schedule 1, paragraph 10, Data Protection Act 2018; EU: Article 9(2)(g) EU GDPR and applicable Member State law)

Data that may reveal or infer political opinions (including information relating to Politically Exposed Persons (PEPs))

PEP and sanctions screening

Substantial public interest — preventing or detecting unlawful acts (UK: Schedule 1, paragraph 10, Data Protection Act 2018; EU: Article 9(2)(g) EU GDPR and applicable Member State law)

6.2. ArtAML processes Special Categories only to the extent required to fulfil AML compliance obligations under the MLRs or equivalent applicable legislation, and only in accordance with the Client’s Documented Instructions.

7. Purposes of Processing, Types of Data and Lawful Basis

7.1. The table below summarises how and why we process personal data, ArtAML’s role in each activity, and the lawful basis relied upon. Where ArtAML acts as Processor, the Client is the Controller and determines the ultimate lawful basis for the underlying CDD or KYC activity. References to legal obligations in the table below reflect the regulatory context in which the processing is typically carried out.

Purpose / Activity

ArtAML Role

Type of Data

Lawful Basis

AML CDD/KYC checks

Processor

IDs, proofs of address, date of birth, PEP status, UBO data

Legal obligation (MLRs or equivalent applicable AML legislation)

Identity verification via partners

Processor

ID images, metadata, verification results

Legal obligation (MLRs or equivalent applicable AML legislation)

Sanctions and PEP screening

Processor

Names, dates of birth, nationality, identification data

Legal obligation (MLRs or equivalent applicable AML legislation). Screening results are presented to the Client for human review and determination. ArtAML does not independently act on screening outputs or communicate results to third parties.

Trial-period CDD data uploaded by Prospective Clients

Processor

All personal data uploaded during a trial, as above

DPA applies from day one of the trial. The Prospective Client determines the lawful basis for any personal data processed during the trial. Processing will typically be carried out to enable the Prospective Client to evaluate the Services and, where applicable, to comply with AML obligations.

Platform account creation and login

Controller

Name, email, login credentials, role, IP address, logs

Performance of contract; legitimate interests in platform security

Billing and payments

Controller

Contact details, subscription and payment records

Performance of contract; legal obligation (tax and accounting compliance)

Support and service communications

Controller

Contact details, support requests, correspondence records

Performance of contract; legitimate interests in service continuity

Security monitoring and fraud prevention

Controller

IP addresses, device information, authentication and access logs, technical telemetry

Legitimate interests in maintaining platform security and preventing fraud

Analytics and service improvement

Controller

Usage data, feature interaction data, diagnostic information, error reports

Legitimate interests in improving platform performance and user experience

Regulatory or law enforcement requests

Controller / Processor

Relevant personal data as required by the requesting authority

Legal obligation. Where ArtAML is required to disclose personal data, it will give reasonable prior notice to the affected Client to the extent permitted by law: see section 16.2.

Marketing to business contacts

Controller

Business contact details, email address

Legitimate interests in promoting services; consent where required by applicable law (including PECR for direct email marketing to individuals in the UK; equivalent national ePrivacy legislation for EU individuals)

Cookies on artaml.com

Controller

Analytics identifiers, marketing trackers

Consent

aml.art compliance platform (no cookies)

Controller / Processor

Strictly necessary session identifiers (e.g. tokens) for secure login and operation only

Legitimate interests; performance of contract

Website enquiries, demo requests and contact form submissions

Controller

Name, email address, organisation, enquiry details

Legitimate interests in responding to enquiries and taking steps prior to entering into a contract

7.2. Where ArtAML relies on legitimate interests as a lawful basis, we have carried out a balancing assessment and concluded that our interests are not overridden by the interests, rights or freedoms of the individuals concerned. Individuals have the right to object to processing based on legitimate interests: see section 18.

8. Automated Decision-Making

8.1. ArtAML does not make automated decisions with legal or similarly significant effects on individuals. All screening outputs produced by the platform — including PEP matches, sanctions alerts and risk scores generated by ComplyAdvantage — are presented to Clients for human review and determination. It is the Client’s responsibility, as Controller, to assess whether a match is confirmed and to make any consequential compliance decisions. ArtAML does not act independently on screening outputs, nor does it communicate results to third parties.

9. Data Protection Impact Assessments

9.1. Where a Client’s use of the Services is likely to result in a high risk to the rights and freedoms of individuals — for example, where the Client processes Special Categories of Personal Data at scale or conducts systematic identity verification — a Data Protection Impact Assessment (DPIA) may be required under Article 35 UK GDPR or the equivalent provision of applicable data protection law.

9.2. ArtAML will cooperate with Clients in carrying out DPIAs where required, including by providing relevant information about the technical and organisational measures in place and the nature of the processing carried out on the Client’s behalf. Clients who require DPIA support should contact [email protected].

10.Accuracy of Personal Data

10.1. It is important that the personal data we hold is accurate and current. Clients and their customers should notify us of any changes to personal data held on the platform. ArtAML relies on information provided by Clients, their customers and integrated verification providers. ArtAML does not determine whether a Client should proceed with, reject or escalate a customer relationship and does not make compliance decisions on behalf of Clients.

11.Cookies and Similar Technologies

11.1. Cookies are used only on artaml.com, our marketing and information website. Cookies on artaml.com support site functionality, analytics and marketing where consent is given. You can manage cookies through your browser or the cookie consent tool on artaml.com.

11.2. No cookies are used within aml.art, our compliance platform. The platform uses only strictly necessary technical session identifiers (such as authentication tokens) to enable secure login and operation. These are essential to the functioning of the service and are not used for marketing, analytics or tracking.

12.Third-Party Links

12.1. Our website may include links to third-party sites, plug-ins or applications. Clicking those links or enabling those connections may allow third parties to collect or share data about you. We do not control those websites and are not responsible for their privacy practices. We encourage you to read the privacy policy of any third-party site you visit.

13.Data Retention

13.1. We retain personal data only for as long as necessary for the purposes described in this policy or as required by applicable law. The following table summarises our principal retention periods.

Category

Retention Period

Notes

CDD/KYC data (Processor role)

Five years from end of occasional transaction or business relationship

Required by the MLRs or equivalent applicable AML legislation. Retained on behalf of the Client. Deleted or exported on subscription termination per the DPA.

Platform account data

Duration of subscription plus 30-day post-termination export window

Securely exported to Client on termination. Deleted from active systems on export confirmation or after 30 days. Backup copies permanently deleted within 90 days.

Trial / Prospective Client data

30 days from end of trial if not converted to paid subscription

Secure export provided. Deleted if not downloaded within 30 days.

Billing and financial records

7 years

Required by applicable accounting and tax legislation.

Support and communications records

3 years

Retained for service continuity and dispute resolution purposes.

Security and access logs

12 months

Retained for fraud prevention and platform security purposes.

Marketing contact data

Until opt-out or withdrawal of consent

Reviewed periodically against legitimate interest assessment.

13.2. On termination or expiry of a subscription, ArtAML will provide the Client with a secure export of its data. The Client will have 30 days to download the exported data and confirm receipt. ArtAML may extend this period on request. Following confirmation of receipt, or after the expiry of the download period, ArtAML will delete the Client’s data from active platform systems, except to the extent that continued retention is required by applicable law or regulatory obligation. Where deleted data remains within backup systems, ArtAML will ensure permanent deletion within 90 days.

13.3. The same process applies where a Prospective Client completes a trial that does not convert to a paid subscription.

13.4. The Client remains solely responsible for complying with any statutory, regulatory or professional record-retention obligations applicable to its business following export of its data.

13.5. Where a Client uses the platform on a seasonal or intermittent basis, personal data uploaded to the platform is retained for the duration of the applicable MLR retention period or until the Client confirms in writing that it is no longer required, whichever is earlier.

14.International Data Transfers

14.1. ArtAML is a UK-registered company and processes personal data under UK GDPR. ArtAML’s platform is hosted on servers located within the European Economic Area (EEA) — specifically on DigitalOcean infrastructure in the Netherlands. Personal data processed through the Services is therefore stored within the EEA.

14.2. Where personal data is transferred from the United Kingdom to the EEA for the purposes of hosting and storage, ArtAML relies on the UK Government’s adequacy regulations in respect of EEA states.

14.3. Where personal data is accessed by or transferred to Sub-processors located in the United States or other jurisdictions not covered by UK adequacy regulations, ArtAML implements appropriate safeguards in accordance with applicable Data Protection Legislation. Details of the transfer mechanisms applicable to each Sub-processor are set out in Appendices 2 and 3. For providers located in the United States, ArtAML generally relies on participation in the UK Extension to the EU–US Data Privacy Framework and/or the UK Addendum to the EU Standard Contractual Clauses, as applicable.

14.4. Where Clients are based in the European Economic Area, personal data transferred from the EU to ArtAML in the United Kingdom is subject to the UK’s adequacy decision under EU GDPR (Commission Implementing Decision (EU) 2021/1772), which recognises the UK as providing an adequate level of protection. ArtAML will cooperate with EEA-based Clients to put in place any additional transfer documentation required by their applicable law on request.

14.5. Where the Client is based in a jurisdiction other than the UK or EEA, the Client is responsible for ensuring that appropriate transfer mechanisms are in place for the transfer of personal data to ArtAML. ArtAML will cooperate with Clients to put in place any required transfer documentation on request.

15.AI-Assisted Tools

15.1. ArtAML uses carefully selected AI-assisted tools where appropriate in connection with software development, technical support, internal administration and the preparation of draft documents, including draft risk assessments and compliance documentation prepared on behalf of Clients. Where AI-assisted tools are used in document preparation, outputs are reviewed and finalised by a qualified member of ArtAML’s team before delivery. No AI-generated output is provided to Clients as a final work product without human review. Such tools are used only in accordance with applicable contractual arrangements, Data Protection Legislation and ArtAML’s internal security controls.

15.2. ArtAML does not use AI-assisted tools in connection with Client Personal Data where adequate contractual controls are not in place to govern that processing, including controls restricting the use of such data for model training purposes.

15.3. ArtAML does not knowingly permit Client Personal Data processed on behalf of Clients to be used for the training of any AI model, whether publicly available or otherwise.

15.4. Where AI-assisted tools are used in connection with Services provided to Clients, ArtAML remains responsible for ensuring that appropriate technical and organisational measures are maintained and that processing is carried out in accordance with applicable contractual obligations.

16.Data Sharing and Sub-Processors

16.1. ArtAML does not sell personal data. We share personal data only with the Sub-processors listed in Appendix 2 (for processing in our capacity as Processor on behalf of Clients) and Appendix 3 (for processing in our capacity as Controller in connection with our own business operations).

16.2. ArtAML may also disclose personal data where required by law, regulation or order of a competent authority. Where we are required to make such a disclosure, we will give reasonable prior notice to the affected Client to the extent permitted by law. We will not disclose more personal data than is required to satisfy the relevant legal obligation.

16.3. ArtAML ensures that each Sub-processor is bound by written contractual obligations that provide a level of protection for personal data equivalent to that required under this policy and, where applicable, the DPA.

16.4. Changes to ArtAML’s Sub-processor arrangements in the context of our Processor role are governed by clause 5.4 of the DPA.
16.4.1. Where ArtAML appoints a new Sub-processor, that is, a provider performing a function not previously carried out by any listed Sub-processor, Clients will be notified by email no less than 30 days before the appointment takes effect.
16.4.2. Where ArtAML replaces an existing Sub-processor with another provider performing the same or substantially the same function with equivalent data protection protections, Appendix 2 of this policy and the corresponding appendix of the DPA will be updated to reflect the change without direct email notification.
16.4.3. Clients who object to a new Sub-processor appointment on data protection grounds may do so in accordance with clause 5.4 of the DPA.

17.Data Security

17.1. We apply appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction or damage. These include physical access controls, system access controls, data access controls, transmission controls, input controls, data backups and data segregation.

17.2. ArtAML’s platform is hosted on DigitalOcean infrastructure. DigitalOcean maintains SOC 2 Type II and SOC 3 Type II platform-level certifications. ArtAML’s hosting facility (AMS3, Netherlands) holds ISO 27001, SOC 1 Type II, SOC 2 Type II and PCI-DSS data centre certifications.

17.3. Further detail is available in our Platform Security Policy at https://artaml.com/platform-security-and-compliance-policy/.

17.4. In the event of a personal data breach affecting personal data for which ArtAML is a Processor, ArtAML will notify the affected Client without undue delay and in any event within 72 hours of becoming aware of the breach, in accordance with clause 8 of the DPA. Where ArtAML is a Controller in respect of the affected data, ArtAML will notify the ICO and, where required, affected individuals, in accordance with applicable Data Protection Legislation.

18.Individual Rights

18.1. Individuals have the following rights under applicable Data Protection Legislation, which may be exercised by contacting our DPO at [email protected]:
18.1.1. Right of access: to obtain a copy of personal data we hold about you.
18.1.2. Right to rectification: to request correction of inaccurate or incomplete personal data.
18.1.3. Right to erasure: to request deletion of personal data in certain circumstances.
18.1.4. Right to restriction: to request that we limit how we use your personal data.
18.1.5. Right to data portability: to receive personal data in a structured, commonly used format.
18.1.6. Right to object: to object to processing based on legitimate interests or for direct marketing purposes.
18.1.7. Right to withdraw consent: where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of prior processing.

18.2. ArtAML will respond to data subject access requests and other rights requests within one month of receipt. This period may be extended by up to two further months where requests are complex or numerous, in which case we will notify the individual within the first month.

18.3. Where personal data is held by ArtAML in its capacity as Processor on behalf of a Client, individuals should direct rights requests to the Client (as Controller). ArtAML will assist Clients in responding to such requests as required under the DPA.

18.4. If you are based in the United Kingdom, you have the right to lodge a complaint with the ICO at www.ico.org.uk or by calling 0303 123 1113. If you are based in the European Economic Area, you have the right to lodge a complaint with the supervisory authority in your EU member state of habitual residence, place of work or the place of the alleged infringement: see section 22 for further details.

19. Marketing and Opting Out

19.1. We may contact business contacts with information about our services and relevant AML compliance developments where we have a legitimate interest in doing so or where consent has been given. Direct email marketing to individuals in the UK is sent only where consent has been obtained, in accordance with the Privacy and Electronic Communications Regulations 2003 (PECR). For individuals in the EEA, equivalent consent requirements under applicable national ePrivacy legislation apply.

19.2. You can opt out of marketing communications at any time by:
19.2.1. using the unsubscribe link in any marketing email;
19.2.2. contacting us at [email protected]; or
19.2.3. objecting to processing based on legitimate interests by emailing [email protected].

19.3. Opting out of marketing does not affect the processing of personal data for other purposes described in this policy, including service communications and billing.

20.Changes to This Policy

20.1. We may update this policy from time to time to reflect changes in our practices, legal obligations or business operations. We will publish the latest version on our website and update the version number and date at the top of the document.

20.2. Where a change to this policy also constitutes a material change to our DPA (for example, a change to data retention periods, international transfer mechanisms or Client audit rights), we will notify affected Clients by email to the account holder’s email address on record no less than 30 days before the change takes effect, in accordance with clause 11 of the DPA.

20.3. Continued use of the platform after the effective date of any material change constitutes acceptance of the updated policy.

21.Governing Law and Jurisdiction

21.1. This Privacy Policy is governed by the laws of England and Wales and is subject to the exclusive jurisdiction of the English courts, without prejudice to the rights of individuals based in the EEA to bring proceedings before their local supervisory authority or courts in accordance with applicable EU law.

22.Contact Us

22.1. For questions about this policy, to exercise your data protection rights, or to raise a concern, please contact us using the details below:
22.1.1. ArtAML Limited 27 Old Gloucester Street, London WC1N 3AX
22.1.2. Data Protection Officer: Dr. Chris King E: [email protected] T: +44 203 488 2966
22.1.3. General enquiries: [email protected]

22.2. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at www.ico.org.uk or by calling 0303 123 1113, or with the supervisory authority in the EU member state of your establishment where applicable.

Appendix 1: Definitions

1. In this policy, the following terms have the meanings set out below. Where a term is also defined in the ArtAML Terms of Business or Data Processing Agreement, it has the same meaning in this policy unless the context requires otherwise.

Term

Meaning

AML

Anti-Money Laundering.

AMP

Art Market Participant, as defined in the MLRs.

Business Relationship

A business, professional or commercial relationship expected to have an element of duration.

CDD

Customer Due Diligence, the process of verifying identity and assessing risk under the MLRs or equivalent AML legislation.

Client

A business or organisation that subscribes to ArtAML’s services. Clients may upload, or request their customers to upload, personal data including CDD information into the ArtAML platform in order to meet their obligations as Art Market Participants.

CFT

Counter-Terrorist Financing.

Controller

The entity determining the purposes and means of processing personal data.

Data Protection Legislation

UK GDPR, the Data Protection Act 2018, and any other applicable legislation relating to the processing of personal data in force from time to time, including EU GDPR where applicable to the Client or its customers.

DPIA

Data Protection Impact Assessment, as described in Article 35 UK GDPR or the equivalent provision of applicable data protection law.

DPA

ArtAML’s Data Processing Agreement.

DPO

Data Protection Officer.

EU GDPR

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data.

ICO

Information Commissioner’s Office, the UK supervisory authority for data protection.

KYC

Know Your Customer, a core part of CDD.

MLRs

The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (as amended).

Occasional Transaction

A transaction outside a business relationship, as defined in the MLRs.

PEP

Politically Exposed Person.

Personal Data

Information relating to an identified or identifiable natural person, as defined in UK GDPR or EU GDPR as applicable.

Processing

Any operation performed on personal data such as collection, storage, use, disclosure or deletion.

Processor

The entity processing personal data on behalf of a Controller.

Prospective Client

A person or business accessing the ArtAML platform during a trial period who has not yet converted to a paid subscription.

Services

The products and services provided by ArtAML, including SaaS subscriptions, Bundles, AML Training, AML Risk Assessment and Policy, ArtAML™ Protection, ArtAML™ Secure, add-ons and associated support services, as further described in the ArtAML Terms of Business.

Special Categories of Personal Data

Information revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic and biometric data, health data and data concerning a person’s sex life or sexual orientation, as defined in Article 9 UK GDPR or the equivalent provision of applicable data protection law.

Sub-processor

A third party engaged by ArtAML to process personal data in connection with the Services.

UK GDPR

The United Kingdom General Data Protection Regulation, as retained in UK law by the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019.

UBO

Ultimate Beneficial Owner.

Appendix 2: Sub-processors (Processor Role)

1. The following Sub-processors are engaged by ArtAML to process personal data on behalf of Clients in ArtAML’s capacity as Processor. These are providers who handle personal data uploaded by or collected on behalf of Clients, including for identity verification, sanctions screening, secure file transfer, backup storage and platform hosting. This list corresponds to Appendix 2 of the ArtAML Data Processing Agreement.

2. Changes to this list are governed by clause 5.4 of the DPA: new Sub-processor appointments are notified to Clients by direct email no less than 30 days before taking effect; like-for-like replacements are reflected by update to this appendix without direct email notification.

Provider

Purpose

Transfer Location / Mechanism

Anthropic

AI-assisted analysis, drafting and software development support. Personal data processed only where appropriate under ArtAML’s contractual arrangements, internal security controls and applicable Data Protection Legislation. ArtAML does not knowingly permit Client Personal Data processed on behalf of Clients to be used for the training of any AI model, whether publicly available or otherwise.

United States (appropriate transfer mechanism in place)

Auth0

Secure login management

United States (appropriate transfer mechanism in place)

Backblaze

Backup storage

United States (appropriate transfer mechanism in place)

ComplyAdvantage

PEP and sanctions screening

United Kingdom / EEA

DigitalOcean

Platform hosting (servers located in the Netherlands, EEA)

Netherlands (EEA — UK adequacy regulations)

Google Workspace

Business productivity and email

United States (appropriate transfer mechanism in place)

SendSafely

Secure file transfer

United States (appropriate transfer mechanism in place)

Yoti

Identity verification

United Kingdom

3. Transfer mechanisms: where Sub-processors or third-party providers are located in the United States or other third countries, ArtAML implements appropriate safeguards in accordance with applicable Data Protection Legislation. These safeguards may include participation in the UK Extension to the EU–US Data Privacy Framework, the UK Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses, or other legally recognised transfer mechanisms.
3.1. Details of the specific transfer mechanism applicable to any provider are available on request.

Appendix 3: Third-Party Tools (Controller Role)

1. The following third-party tools are used by ArtAML in its capacity as Controller in connection with its own business operations. These providers do not process personal data uploaded by or collected on behalf of Clients. They handle data relating to ArtAML’s own account management, marketing, billing, communications and internal administration. Changes to this list are not governed by clause 5.4 of the DPA.

Provider

Purpose

Transfer Location / Mechanism

Acuity Scheduling

Appointment scheduling

United States (appropriate transfer mechanism in place)

Apple Business

Device and app management

United States (appropriate transfer mechanism in place)

Asana

Project management

United States (appropriate transfer mechanism in place)

Chargebee

Subscription management and billing

European Union (EEA — UK adequacy regulations)

Cloudflare

Network security, performance and content delivery

United States (appropriate transfer mechanism in place)

DeepL Pro

Translation

United States (appropriate transfer mechanism in place)

Docupilot

Document automation

United States (appropriate transfer mechanism in place)

DocuSign

Electronic signatures

United States (appropriate transfer mechanism in place)

GoCardless

Direct debit payment processing

United States (appropriate transfer mechanism in place)

Google Analytics

Website analytics

United States (appropriate transfer mechanism in place)

Google Search Console

Website search performance

United States (appropriate transfer mechanism in place)

Hubspot

CRM, contact forms, cookie consent and email marketing

United States (appropriate transfer mechanism in place)

Microsoft 365

Document creation, spreadsheets and presentations

United States (appropriate transfer mechanism in place)

OpenAI

AI-assisted software development support and document drafting

United States (appropriate transfer mechanism in place)

OpenCorporates

Publicly accessible company ownership and officer information

United States (appropriate transfer mechanism in place)

RingCentral

Telephony

United States (appropriate transfer mechanism in place)

Slack

Internal communications

United States (appropriate transfer mechanism in place)

Stripe

Payment processing (card)

United States (appropriate transfer mechanism in place)

Vimeo

Training video hosting

United States (appropriate transfer mechanism in place)

WhatsApp Business

Client messaging via HubSpot CRM integration

United States (appropriate transfer mechanism in place)

WP Engine

Website hosting

United States (appropriate transfer mechanism in place)

Xero

Accounting

United Kingdom

Zoom

Video meetings

United States (appropriate transfer mechanism in place)

2. Where providers are located in the United States or other third countries, ArtAML implements appropriate safeguards in accordance with applicable Data Protection Legislation. Details of the specific mechanism in place for any provider are available on request.