ArtAML™ Privacy Policy
Version 3.0 | Last updated 18th June 2026
Introduction
1.1. This Privacy Policy explains how ArtAML Limited (‘ArtAML’, ‘we’, ‘us’) collects, uses, stores and protects personal data in connection with our anti-money laundering (AML) compliance platform for the art market. It applies to Clients, their customers who provide Customer Due Diligence (CDD) information, Prospective Clients, website visitors and business contacts.
1.2. This policy covers ArtAML’s processing in two distinct capacities: as Processor, when handling personal data on behalf of Clients in connection with CDD, KYC, sanctions screening and related compliance activities; and as Controller, when handling personal data for ArtAML’s own operational purposes. The detailed contractual terms governing ArtAML’s role as Processor are set out in our Data Processing Agreement (‘DPA’), available on our website. This policy should be read alongside the DPA and our Platform Security Policy.
1.3. The third-party providers used by ArtAML are listed in two separate appendices to this policy, reflecting ArtAML’s dual role. Appendix 2 lists providers engaged in ArtAML’s capacity as Processor — those who handle personal data uploaded by or collected on behalf of Clients. Appendix 3 lists providers used by ArtAML in its capacity as Controller for its own business operations. Different notification and objection rights apply to each category, as set out in clause 5.4 of the DPA and section 17 of this policy.
1.4. This policy is written primarily by reference to the United Kingdom General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. ArtAML is a UK-registered company and UK GDPR is the primary framework governing our processing activities. We also recognise that Clients and individuals based in the European Economic Area may have rights under EU GDPR (Regulation (EU) 2016/679), and that Clients in other jurisdictions may be subject to their own applicable data protection legislation. ArtAML will cooperate with Clients to address jurisdiction-specific requirements on request. This policy also reflects our obligations under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (‘MLRs’).
1.5. Defined terms are signalled by an initial capital letter and are set out in Appendix 1.
2. Who We Are
2.1. ArtAML Limited provides anti-money laundering compliance technology to Art Market Participants. We are incorporated in England and Wales (company no. 11806741) with registered address at 27 Old Gloucester Street, London WC1N 3AX. We are registered with the Information Commissioner’s Office (ICO) under reference ZA566966.
2.2. Our website is www.artaml.com. Our compliance platform is available at aml.art.
2.3. ArtAML Limited (company number 11806741) is the data controller for personal data processed under this policy. Our registered address is 27 Old Gloucester Street, London WC1N 3AX.
2.4. For contact details, including how to reach our Data Protection Officer, see section 22.
3. Our Role as Controller and Processor
3.1. ArtAML acts in two distinct capacities:
3.1.1. As a Data Processor: when handling CDD and KYC data uploaded by, or collected on behalf of, Clients and Prospective Clients. In this role, ArtAML processes personal data on the Client’s instructions, as governed by our DPA. The DPA applies from the first day of any trial period.
3.1.2. As a Data Controller: when handling data relating to platform accounts, billing, analytics, security monitoring and communications. In this role, ArtAML determines the purposes and means of processing and is directly responsible to individuals for compliance with applicable Data Protection Legislation.
3.2. This policy covers both roles. The processing table in section 7 identifies ArtAML’s role for each activity. The DPA sets out the detailed terms governing our Processor role.
4. How We Collect Personal Data
4.1. We collect personal data through the following means:
4.1.1. Direct interactions: data provided by Clients, Prospective Clients or their customers, including uploaded CDD documents, account registration information and support correspondence.
4.1.2. Automated technologies: cookies on artaml.com (not on aml.art), security logs and analytics tools.
4.1.3. Third parties: identity verification providers, screening partners, payment processors and publicly available company information sources. Refer to Appendices for sub-processors lists.
5. Categories of Personal Data We Process
5.1. Depending on the nature of the relationship, we may process the following categories of personal data:
5.1.1. Identification data: name, date of birth, nationality.
5.1.2. Government-issued photo identification.
5.1.3. Proof of address.
5.1.4. Contact details: email, telephone, postal address.
5.1.5. Financial or billing data: payment records, transaction history, subscription details.
5.1.6. AML screening data: PEP status, sanctions status, UBO details.
5.1.7. Technical data: IP address, device information, authentication logs, access logs, usage data.
5.1.8. Marketing data: business contact details, email preferences, communication history.
5.1.9. Some processing may involve Special Categories of Personal Data, as set out in section 6. ArtAML does not knowingly collect personal data relating to children except where required by applicable AML legislation as part of the CDD process (for example, where a minor appears as a beneficial owner or as a family member of a PEP). Where such data is processed, it is handled with appropriate care and only to the extent required to fulfil the relevant AML obligation.
6. Special Categories of Personal Data
6.1. Certain CDD and identity verification processes may involve Special Categories of Personal Data, including biometric data and information that may reveal or infer political opinions through AML screening activities. Where ArtAML processes Special Categories of Personal Data, it does so on the following basis:
|
Type of Special Category Data |
Context |
Lawful Basis (Article 9 UK GDPR / EU GDPR) |
|
Biometric data (e.g. facial recognition in identity documents) |
Identity verification |
Substantial public interest — preventing or detecting unlawful acts (UK: Schedule 1, paragraph 10, Data Protection Act 2018; EU: Article 9(2)(g) EU GDPR and applicable Member State law) |
|
Data that may reveal or infer political opinions (including information relating to Politically Exposed Persons (PEPs)) |
PEP and sanctions screening |
Substantial public interest — preventing or detecting unlawful acts (UK: Schedule 1, paragraph 10, Data Protection Act 2018; EU: Article 9(2)(g) EU GDPR and applicable Member State law) |
6.2. ArtAML processes Special Categories only to the extent required to fulfil AML compliance obligations under the MLRs or equivalent applicable legislation, and only in accordance with the Client’s Documented Instructions.
7. Purposes of Processing, Types of Data and Lawful Basis
7.1. The table below summarises how and why we process personal data, ArtAML’s role in each activity, and the lawful basis relied upon. Where ArtAML acts as Processor, the Client is the Controller and determines the ultimate lawful basis for the underlying CDD or KYC activity. References to legal obligations in the table below reflect the regulatory context in which the processing is typically carried out.
|
Purpose / Activity |
ArtAML Role |
Type of Data |
Lawful Basis |
|
AML CDD/KYC checks |
Processor |
IDs, proofs of address, date of birth, PEP status, UBO data |
Legal obligation (MLRs or equivalent applicable AML legislation) |
|
Identity verification via partners |
Processor |
ID images, metadata, verification results |
Legal obligation (MLRs or equivalent applicable AML legislation) |
|
Sanctions and PEP screening |
Processor |
Names, dates of birth, nationality, identification data |
Legal obligation (MLRs or equivalent applicable AML legislation). Screening results are presented to the Client for human review and determination. ArtAML does not independently act on screening outputs or communicate results to third parties. |
|
Trial-period CDD data uploaded by Prospective Clients |
Processor |
All personal data uploaded during a trial, as above |
DPA applies from day one of the trial. The Prospective Client determines the lawful basis for any personal data processed during the trial. Processing will typically be carried out to enable the Prospective Client to evaluate the Services and, where applicable, to comply with AML obligations. |
|
Platform account creation and login |
Controller |
Name, email, login credentials, role, IP address, logs |
Performance of contract; legitimate interests in platform security |
|
Billing and payments |
Controller |
Contact details, subscription and payment records |
Performance of contract; legal obligation (tax and accounting compliance) |
|
Support and service communications |
Controller |
Contact details, support requests, correspondence records |
Performance of contract; legitimate interests in service continuity |
|
Security monitoring and fraud prevention |
Controller |
IP addresses, device information, authentication and access logs, technical telemetry |
Legitimate interests in maintaining platform security and preventing fraud |
|
Analytics and service improvement |
Controller |
Usage data, feature interaction data, diagnostic information, error reports |
Legitimate interests in improving platform performance and user experience |
|
Regulatory or law enforcement requests |
Controller / Processor |
Relevant personal data as required by the requesting authority |
Legal obligation. Where ArtAML is required to disclose personal data, it will give reasonable prior notice to the affected Client to the extent permitted by law: see section 16.2. |
|
Marketing to business contacts |
Controller |
Business contact details, email address |
Legitimate interests in promoting services; consent where required by applicable law (including PECR for direct email marketing to individuals in the UK; equivalent national ePrivacy legislation for EU individuals) |
|
Cookies on artaml.com |
Controller |
Analytics identifiers, marketing trackers |
Consent |
|
aml.art compliance platform (no cookies) |
Controller / Processor |
Strictly necessary session identifiers (e.g. tokens) for secure login and operation only |
Legitimate interests; performance of contract |
|
Website enquiries, demo requests and contact form submissions |
Controller |
Name, email address, organisation, enquiry details |
Legitimate interests in responding to enquiries and taking steps prior to entering into a contract |
7.2. Where ArtAML relies on legitimate interests as a lawful basis, we have carried out a balancing assessment and concluded that our interests are not overridden by the interests, rights or freedoms of the individuals concerned. Individuals have the right to object to processing based on legitimate interests: see section 18.
8. Automated Decision-Making
8.1. ArtAML does not make automated decisions with legal or similarly significant effects on individuals. All screening outputs produced by the platform — including PEP matches, sanctions alerts and risk scores generated by ComplyAdvantage — are presented to Clients for human review and determination. It is the Client’s responsibility, as Controller, to assess whether a match is confirmed and to make any consequential compliance decisions. ArtAML does not act independently on screening outputs, nor does it communicate results to third parties.
9. Data Protection Impact Assessments
9.1. Where a Client’s use of the Services is likely to result in a high risk to the rights and freedoms of individuals — for example, where the Client processes Special Categories of Personal Data at scale or conducts systematic identity verification — a Data Protection Impact Assessment (DPIA) may be required under Article 35 UK GDPR or the equivalent provision of applicable data protection law.
9.2. ArtAML will cooperate with Clients in carrying out DPIAs where required, including by providing relevant information about the technical and organisational measures in place and the nature of the processing carried out on the Client’s behalf. Clients who require DPIA support should contact [email protected].
10.Accuracy of Personal Data
10.1. It is important that the personal data we hold is accurate and current. Clients and their customers should notify us of any changes to personal data held on the platform. ArtAML relies on information provided by Clients, their customers and integrated verification providers. ArtAML does not determine whether a Client should proceed with, reject or escalate a customer relationship and does not make compliance decisions on behalf of Clients.
11.Cookies and Similar Technologies
11.1. Cookies are used only on artaml.com, our marketing and information website. Cookies on artaml.com support site functionality, analytics and marketing where consent is given. You can manage cookies through your browser or the cookie consent tool on artaml.com.
11.2. No cookies are used within aml.art, our compliance platform. The platform uses only strictly necessary technical session identifiers (such as authentication tokens) to enable secure login and operation. These are essential to the functioning of the service and are not used for marketing, analytics or tracking.
12.Third-Party Links
12.1. Our website may include links to third-party sites, plug-ins or applications. Clicking those links or enabling those connections may allow third parties to collect or share data about you. We do not control those websites and are not responsible for their privacy practices. We encourage you to read the privacy policy of any third-party site you visit.
13.Data Retention
13.1. We retain personal data only for as long as necessary for the purposes described in this policy or as required by applicable law. The following table summarises our principal retention periods.
|
Category |
Retention Period |
Notes |
|
CDD/KYC data (Processor role) |
Five years from end of occasional transaction or business relationship |
Required by the MLRs or equivalent applicable AML legislation. Retained on behalf of the Client. Deleted or exported on subscription termination per the DPA. |
|
Platform account data |
Duration of subscription plus 30-day post-termination export window |
Securely exported to Client on termination. Deleted from active systems on export confirmation or after 30 days. Backup copies permanently deleted within 90 days. |
|
Trial / Prospective Client data |
30 days from end of trial if not converted to paid subscription |
Secure export provided. Deleted if not downloaded within 30 days. |
|
Billing and financial records |
7 years |
Required by applicable accounting and tax legislation. |
|
Support and communications records |
3 years |
Retained for service continuity and dispute resolution purposes. |
|
Security and access logs |
12 months |
Retained for fraud prevention and platform security purposes. |
|
Marketing contact data |
Until opt-out or withdrawal of consent |
Reviewed periodically against legitimate interest assessment. |
13.2. On termination or expiry of a subscription, ArtAML will provide the Client with a secure export of its data. The Client will have 30 days to download the exported data and confirm receipt. ArtAML may extend this period on request. Following confirmation of receipt, or after the expiry of the download period, ArtAML will delete the Client’s data from active platform systems, except to the extent that continued retention is required by applicable law or regulatory obligation. Where deleted data remains within backup systems, ArtAML will ensure permanent deletion within 90 days.
13.3. The same process applies where a Prospective Client completes a trial that does not convert to a paid subscription.
13.4. The Client remains solely responsible for complying with any statutory, regulatory or professional record-retention obligations applicable to its business following export of its data.
13.5. Where a Client uses the platform on a seasonal or intermittent basis, personal data uploaded to the platform is retained for the duration of the applicable MLR retention period or until the Client confirms in writing that it is no longer required, whichever is earlier.
14.International Data Transfers
14.1. ArtAML is a UK-registered company and processes personal data under UK GDPR. ArtAML’s platform is hosted on servers located within the European Economic Area (EEA) — specifically on DigitalOcean infrastructure in the Netherlands. Personal data processed through the Services is therefore stored within the EEA.
14.2. Where personal data is transferred from the United Kingdom to the EEA for the purposes of hosting and storage, ArtAML relies on the UK Government’s adequacy regulations in respect of EEA states.
14.3. Where personal data is accessed by or transferred to Sub-processors located in the United States or other jurisdictions not covered by UK adequacy regulations, ArtAML implements appropriate safeguards in accordance with applicable Data Protection Legislation. Details of the transfer mechanisms applicable to each Sub-processor are set out in Appendices 2 and 3. For providers located in the United States, ArtAML generally relies on participation in the UK Extension to the EU–US Data Privacy Framework and/or the UK Addendum to the EU Standard Contractual Clauses, as applicable.
14.4. Where Clients are based in the European Economic Area, personal data transferred from the EU to ArtAML in the United Kingdom is subject to the UK’s adequacy decision under EU GDPR (Commission Implementing Decision (EU) 2021/1772), which recognises the UK as providing an adequate level of protection. ArtAML will cooperate with EEA-based Clients to put in place any additional transfer documentation required by their applicable law on request.
14.5. Where the Client is based in a jurisdiction other than the UK or EEA, the Client is responsible for ensuring that appropriate transfer mechanisms are in place for the transfer of personal data to ArtAML. ArtAML will cooperate with Clients to put in place any required transfer documentation on request.
15.AI-Assisted Tools
15.1. ArtAML uses carefully selected AI-assisted tools where appropriate in connection with software development, technical support, internal administration and the preparation of draft documents, including draft risk assessments and compliance documentation prepared on behalf of Clients. Where AI-assisted tools are used in document preparation, outputs are reviewed and finalised by a qualified member of ArtAML’s team before delivery. No AI-generated output is provided to Clients as a final work product without human review. Such tools are used only in accordance with applicable contractual arrangements, Data Protection Legislation and ArtAML’s internal security controls.
15.2. ArtAML does not use AI-assisted tools in connection with Client Personal Data where adequate contractual controls are not in place to govern that processing, including controls restricting the use of such data for model training purposes.
15.3. ArtAML does not knowingly permit Client Personal Data processed on behalf of Clients to be used for the training of any AI model, whether publicly available or otherwise.
15.4. Where AI-assisted tools are used in connection with Services provided to Clients, ArtAML remains responsible for ensuring that appropriate technical and organisational measures are maintained and that processing is carried out in accordance with applicable contractual obligations.
16.Data Sharing and Sub-Processors
16.1. ArtAML does not sell personal data. We share personal data only with the Sub-processors listed in Appendix 2 (for processing in our capacity as Processor on behalf of Clients) and Appendix 3 (for processing in our capacity as Controller in connection with our own business operations).
16.2. ArtAML may also disclose personal data where required by law, regulation or order of a competent authority. Where we are required to make such a disclosure, we will give reasonable prior notice to the affected Client to the extent permitted by law. We will not disclose more personal data than is required to satisfy the relevant legal obligation.
16.3. ArtAML ensures that each Sub-processor is bound by written contractual obligations that provide a level of protection for personal data equivalent to that required under this policy and, where applicable, the DPA.
16.4. Changes to ArtAML’s Sub-processor arrangements in the context of our Processor role are governed by clause 5.4 of the DPA.
16.4.1. Where ArtAML appoints a new Sub-processor, that is, a provider performing a function not previously carried out by any listed Sub-processor, Clients will be notified by email no less than 30 days before the appointment takes effect.
16.4.2. Where ArtAML replaces an existing Sub-processor with another provider performing the same or substantially the same function with equivalent data protection protections, Appendix 2 of this policy and the corresponding appendix of the DPA will be updated to reflect the change without direct email notification.
16.4.3. Clients who object to a new Sub-processor appointment on data protection grounds may do so in accordance with clause 5.4 of the DPA.
17.Data Security
17.1. We apply appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction or damage. These include physical access controls, system access controls, data access controls, transmission controls, input controls, data backups and data segregation.
17.2. ArtAML’s platform is hosted on DigitalOcean infrastructure. DigitalOcean maintains SOC 2 Type II and SOC 3 Type II platform-level certifications. ArtAML’s hosting facility (AMS3, Netherlands) holds ISO 27001, SOC 1 Type II, SOC 2 Type II and PCI-DSS data centre certifications.
17.3. Further detail is available in our Platform Security Policy at https://artaml.com/platform-security-and-compliance-policy/.
17.4. In the event of a personal data breach affecting personal data for which ArtAML is a Processor, ArtAML will notify the affected Client without undue delay and in any event within 72 hours of becoming aware of the breach, in accordance with clause 8 of the DPA. Where ArtAML is a Controller in respect of the affected data, ArtAML will notify the ICO and, where required, affected individuals, in accordance with applicable Data Protection Legislation.
18.Individual Rights
18.1. Individuals have the following rights under applicable Data Protection Legislation, which may be exercised by contacting our DPO at [email protected]:
18.1.1. Right of access: to obtain a copy of personal data we hold about you.
18.1.2. Right to rectification: to request correction of inaccurate or incomplete personal data.
18.1.3. Right to erasure: to request deletion of personal data in certain circumstances.
18.1.4. Right to restriction: to request that we limit how we use your personal data.
18.1.5. Right to data portability: to receive personal data in a structured, commonly used format.
18.1.6. Right to object: to object to processing based on legitimate interests or for direct marketing purposes.
18.1.7. Right to withdraw consent: where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of prior processing.
18.2. ArtAML will respond to data subject access requests and other rights requests within one month of receipt. This period may be extended by up to two further months where requests are complex or numerous, in which case we will notify the individual within the first month.
18.3. Where personal data is held by ArtAML in its capacity as Processor on behalf of a Client, individuals should direct rights requests to the Client (as Controller). ArtAML will assist Clients in responding to such requests as required under the DPA.
18.4. If you are based in the United Kingdom, you have the right to lodge a complaint with the ICO at www.ico.org.uk or by calling 0303 123 1113. If you are based in the European Economic Area, you have the right to lodge a complaint with the supervisory authority in your EU member state of habitual residence, place of work or the place of the alleged infringement: see section 22 for further details.
19. Marketing and Opting Out
19.1. We may contact business contacts with information about our services and relevant AML compliance developments where we have a legitimate interest in doing so or where consent has been given. Direct email marketing to individuals in the UK is sent only where consent has been obtained, in accordance with the Privacy and Electronic Communications Regulations 2003 (PECR). For individuals in the EEA, equivalent consent requirements under applicable national ePrivacy legislation apply.
19.2. You can opt out of marketing communications at any time by:
19.2.1. using the unsubscribe link in any marketing email;
19.2.2. contacting us at [email protected]; or
19.2.3. objecting to processing based on legitimate interests by emailing [email protected].
19.3. Opting out of marketing does not affect the processing of personal data for other purposes described in this policy, including service communications and billing.
20.Changes to This Policy
20.1. We may update this policy from time to time to reflect changes in our practices, legal obligations or business operations. We will publish the latest version on our website and update the version number and date at the top of the document.
20.2. Where a change to this policy also constitutes a material change to our DPA (for example, a change to data retention periods, international transfer mechanisms or Client audit rights), we will notify affected Clients by email to the account holder’s email address on record no less than 30 days before the change takes effect, in accordance with clause 11 of the DPA.
20.3. Continued use of the platform after the effective date of any material change constitutes acceptance of the updated policy.
21.Governing Law and Jurisdiction
21.1. This Privacy Policy is governed by the laws of England and Wales and is subject to the exclusive jurisdiction of the English courts, without prejudice to the rights of individuals based in the EEA to bring proceedings before their local supervisory authority or courts in accordance with applicable EU law.
22.Contact Us
22.1. For questions about this policy, to exercise your data protection rights, or to raise a concern, please contact us using the details below:
22.1.1. ArtAML Limited 27 Old Gloucester Street, London WC1N 3AX
22.1.2. Data Protection Officer: Dr. Chris King E: [email protected] T: +44 203 488 2966
22.1.3. General enquiries: [email protected]
22.2. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at www.ico.org.uk or by calling 0303 123 1113, or with the supervisory authority in the EU member state of your establishment where applicable.
Appendix 1: Definitions
1. In this policy, the following terms have the meanings set out below. Where a term is also defined in the ArtAML Terms of Business or Data Processing Agreement, it has the same meaning in this policy unless the context requires otherwise.
|
Term |
Meaning |
|
AML |
Anti-Money Laundering. |
|
AMP |
Art Market Participant, as defined in the MLRs. |
|
Business Relationship |
A business, professional or commercial relationship expected to have an element of duration. |
|
CDD |
Customer Due Diligence, the process of verifying identity and assessing risk under the MLRs or equivalent AML legislation. |
|
Client |
A business or organisation that subscribes to ArtAML’s services. Clients may upload, or request their customers to upload, personal data including CDD information into the ArtAML platform in order to meet their obligations as Art Market Participants. |
|
CFT |
Counter-Terrorist Financing. |
|
Controller |
The entity determining the purposes and means of processing personal data. |
|
Data Protection Legislation |
UK GDPR, the Data Protection Act 2018, and any other applicable legislation relating to the processing of personal data in force from time to time, including EU GDPR where applicable to the Client or its customers. |
|
DPIA |
Data Protection Impact Assessment, as described in Article 35 UK GDPR or the equivalent provision of applicable data protection law. |
|
DPA |
ArtAML’s Data Processing Agreement. |
|
DPO |
Data Protection Officer. |
|
EU GDPR |
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data. |
|
ICO |
Information Commissioner’s Office, the UK supervisory authority for data protection. |
|
KYC |
Know Your Customer, a core part of CDD. |
|
MLRs |
The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (as amended). |
|
Occasional Transaction |
A transaction outside a business relationship, as defined in the MLRs. |
|
PEP |
Politically Exposed Person. |
|
Personal Data |
Information relating to an identified or identifiable natural person, as defined in UK GDPR or EU GDPR as applicable. |
|
Processing |
Any operation performed on personal data such as collection, storage, use, disclosure or deletion. |
|
Processor |
The entity processing personal data on behalf of a Controller. |
|
Prospective Client |
A person or business accessing the ArtAML platform during a trial period who has not yet converted to a paid subscription. |
|
Services |
The products and services provided by ArtAML, including SaaS subscriptions, Bundles, AML Training, AML Risk Assessment and Policy, ArtAML™ Protection, ArtAML™ Secure, add-ons and associated support services, as further described in the ArtAML Terms of Business. |
|
Special Categories of Personal Data |
Information revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic and biometric data, health data and data concerning a person’s sex life or sexual orientation, as defined in Article 9 UK GDPR or the equivalent provision of applicable data protection law. |
|
Sub-processor |
A third party engaged by ArtAML to process personal data in connection with the Services. |
|
UK GDPR |
The United Kingdom General Data Protection Regulation, as retained in UK law by the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019. |
|
UBO |
Ultimate Beneficial Owner. |
Appendix 2: Sub-processors (Processor Role)
1. The following Sub-processors are engaged by ArtAML to process personal data on behalf of Clients in ArtAML’s capacity as Processor. These are providers who handle personal data uploaded by or collected on behalf of Clients, including for identity verification, sanctions screening, secure file transfer, backup storage and platform hosting. This list corresponds to Appendix 2 of the ArtAML Data Processing Agreement.
2. Changes to this list are governed by clause 5.4 of the DPA: new Sub-processor appointments are notified to Clients by direct email no less than 30 days before taking effect; like-for-like replacements are reflected by update to this appendix without direct email notification.
|
Provider |
Purpose |
Transfer Location / Mechanism |
|
Anthropic |
AI-assisted analysis, drafting and software development support. Personal data processed only where appropriate under ArtAML’s contractual arrangements, internal security controls and applicable Data Protection Legislation. ArtAML does not knowingly permit Client Personal Data processed on behalf of Clients to be used for the training of any AI model, whether publicly available or otherwise. |
United States (appropriate transfer mechanism in place) |
|
Auth0 |
Secure login management |
United States (appropriate transfer mechanism in place) |
|
Backblaze |
Backup storage |
United States (appropriate transfer mechanism in place) |
|
ComplyAdvantage |
PEP and sanctions screening |
United Kingdom / EEA |
|
DigitalOcean |
Platform hosting (servers located in the Netherlands, EEA) |
Netherlands (EEA — UK adequacy regulations) |
|
Google Workspace |
Business productivity and email |
United States (appropriate transfer mechanism in place) |
|
SendSafely |
Secure file transfer |
United States (appropriate transfer mechanism in place) |
|
Yoti |
Identity verification |
United Kingdom |
3. Transfer mechanisms: where Sub-processors or third-party providers are located in the United States or other third countries, ArtAML implements appropriate safeguards in accordance with applicable Data Protection Legislation. These safeguards may include participation in the UK Extension to the EU–US Data Privacy Framework, the UK Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses, or other legally recognised transfer mechanisms.
3.1. Details of the specific transfer mechanism applicable to any provider are available on request.
Appendix 3: Third-Party Tools (Controller Role)
1. The following third-party tools are used by ArtAML in its capacity as Controller in connection with its own business operations. These providers do not process personal data uploaded by or collected on behalf of Clients. They handle data relating to ArtAML’s own account management, marketing, billing, communications and internal administration. Changes to this list are not governed by clause 5.4 of the DPA.
|
Provider |
Purpose |
Transfer Location / Mechanism |
|
Acuity Scheduling |
Appointment scheduling |
United States (appropriate transfer mechanism in place) |
|
Apple Business |
Device and app management |
United States (appropriate transfer mechanism in place) |
|
Asana |
Project management |
United States (appropriate transfer mechanism in place) |
|
Chargebee |
Subscription management and billing |
European Union (EEA — UK adequacy regulations) |
|
Cloudflare |
Network security, performance and content delivery |
United States (appropriate transfer mechanism in place) |
|
DeepL Pro |
Translation |
United States (appropriate transfer mechanism in place) |
|
Docupilot |
Document automation |
United States (appropriate transfer mechanism in place) |
|
DocuSign |
Electronic signatures |
United States (appropriate transfer mechanism in place) |
|
GoCardless |
Direct debit payment processing |
United States (appropriate transfer mechanism in place) |
|
Google Analytics |
Website analytics |
United States (appropriate transfer mechanism in place) |
|
Google Search Console |
Website search performance |
United States (appropriate transfer mechanism in place) |
|
Hubspot |
CRM, contact forms, cookie consent and email marketing |
United States (appropriate transfer mechanism in place) |
|
Microsoft 365 |
Document creation, spreadsheets and presentations |
United States (appropriate transfer mechanism in place) |
|
OpenAI |
AI-assisted software development support and document drafting |
United States (appropriate transfer mechanism in place) |
|
OpenCorporates |
Publicly accessible company ownership and officer information |
United States (appropriate transfer mechanism in place) |
|
RingCentral |
Telephony |
United States (appropriate transfer mechanism in place) |
|
Slack |
Internal communications |
United States (appropriate transfer mechanism in place) |
|
Stripe |
Payment processing (card) |
United States (appropriate transfer mechanism in place) |
|
Vimeo |
Training video hosting |
United States (appropriate transfer mechanism in place) |
|
WhatsApp Business |
Client messaging via HubSpot CRM integration |
United States (appropriate transfer mechanism in place) |
|
WP Engine |
Website hosting |
United States (appropriate transfer mechanism in place) |
|
Xero |
Accounting |
United Kingdom |
|
Zoom |
Video meetings |
United States (appropriate transfer mechanism in place) |
2. Where providers are located in the United States or other third countries, ArtAML implements appropriate safeguards in accordance with applicable Data Protection Legislation. Details of the specific mechanism in place for any provider are available on request.