AeternaData
Security Reference

Data Security Policy.

The technical and organisational measures Aeterna Data applies to protect client data throughout every annotation engagement. Documented in compliance with GDPR Article 32 and EU AI Act Article 10.

GDPR Art. 32Legal Basis
72 HoursBreach Notification SLA
Client EnvData Never Leaves Client Env
Per-AnnotatorIndividual Access Controls

Policy Scope

This Data Security Policy describes the technical and organisational security measures (TOMs) that PT Aeterna Data Intentio Logic (Aeterna Data) applies to the protection of client data throughout every annotation engagement. It applies to all processing activities performed by Aeterna Data as a data processor on behalf of clients under a signed Data Processing Agreement.

This policy is provided to clients as part of the DPA review process and constitutes the Annex II Technical and Organisational Measures documentation required under the EU SCCs Module 2. It is reviewed and updated at minimum annually, or following any material change to Aeterna Data's processing infrastructure or annotator management practices.

Entity
PT Aeterna Data Intentio Logic
Role
Data Processor (GDPR Art. 28)
Legal basis for policy
GDPR Article 32
Policy version
1.0 — March 2026

GDPR Article 32 — Security of Processing

GDPR Article 32 requires data controllers and processors to implement technical and organisational measures appropriate to the risk of the processing — taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons.

Article 32 specifies four exemplary measures that may be appropriate: pseudonymisation and encryption of personal data, the ability to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems, the ability to restore availability and access in the event of an incident, and a process for regularly testing, assessing, and evaluating the effectiveness of measures.

Aeterna Data's security measures are designed against the specific risk profile of annotation processing — which differs from general data processing in one critical respect: the annotation task inherently requires human annotators to read and understand the content of the data being labeled. Encryption at rest and pseudonymisation reduce but do not eliminate the data exposure inherent in the annotation workflow. The primary security measure for annotation processing is access control — ensuring that only the minimum number of authorised annotators access only the minimum data required for their assigned task.

Confidentiality

Technical and organisational measures to ensure that personal data is accessible only to authorised persons — implemented through per-annotator access controls, individual NDAs, and the data residency model's inherent security properties.

Integrity

Measures to ensure that personal data is not altered or corrupted during annotation processing. Aeterna Data's annotators work in read-annotate mode — they add annotations but do not modify or delete source data.

Availability

Measures to ensure ongoing availability of processing systems. Aeterna Data's annotation model means client platform availability is the client's responsibility — Aeterna Data's availability obligation is annotator capacity, not platform uptime.

Resilience

The ability to restore access in the event of an incident. Aeterna Data's annotation workflow does not depend on Aeterna Data-hosted infrastructure — resilience is provided by the client's own platform architecture.

Data Residency Security Model

Aeterna Data's primary structural security measure is that annotation work is performed inside the client's own annotation environment. Rather than asking clients to transfer data to an Aeterna Data-managed platform, annotators access the client's existing annotation tool directly. Client data never leaves the client's own infrastructure at any point during the engagement.

The security implications of this approach are substantial. The client's platform inherits all security controls that the client has already implemented — encryption at rest, network access controls, audit logging, multi-factor authentication, and platform-level data governance. Aeterna Data's annotators operate within those controls as authorised users — not as external parties receiving data exports.

Standard Vendor vs Aeterna Data Approach

Standard Vendor Model

  • → Client exports data to vendor platform
  • → Vendor platform stores client data
  • → Vendor annotators access vendor platform
  • → Vendor exports annotations to client
  • → Client data exists in vendor's infrastructure

Client data exists outside client infrastructure throughout the engagement. Vendor platform security is the client's dependency.

Aeterna Data Approach

  • → Client data stays in client platform
  • → Aeterna Data annotators access client platform via provisioned credentials
  • → Annotations written directly to client platform
  • → No data export to Aeterna Data infrastructure
  • → Client data never leaves client environment

Client's own security controls apply at all times. Aeterna Data has no copy of client data.

Aeterna Data does not maintain servers, databases, or cloud storage for client annotation data. All annotation work is performed inside client-owned or client-licensed platforms. Aeterna Data has no copy of client data at any point before, during, or after the engagement.

Access Controls

Access to client platforms and data is controlled at the individual annotator level. Aeterna Data does not use shared credentials, team accounts, or pooled access. Every annotator who works on a client project is provisioned with individual, unique credentials by the client — and those credentials are the sole means of access to the client's environment for that annotator.

This architecture means that access can be revoked immediately for any individual annotator without affecting the rest of the team — and that client audit logs record per-annotator activity, not pooled team activity. The access control model is consistent with the principle of least privilege: each annotator can access only what they need to complete their assigned annotation task.

Individual Credential Provisioning

Client provisions unique credentials for each annotator before the engagement begins. Credentials are not shared between annotators under any circumstances. Aeterna Data communicates credentials to annotators through a documented provisioning process.

Minimum Necessary Access

Annotators are assigned to task queues that contain only the data items required for their annotation assignment. Where the platform supports task-level scoping, annotators do not have access to the full client dataset beyond their assigned queue.

Immediate Access Revocation

When an annotator rotates off a project — for any reason — Aeterna Data notifies the client within 24 hours and requests credential revocation. Where Aeterna Data has the ability to deactivate credentials directly, it does so immediately and notifies the client.

Access Log Review

Where the client platform provides access audit logs, Aeterna Data reviews annotator access patterns on a periodic basis to detect anomalous behaviour — access outside normal working hours, access to data items outside assigned queues, or unusually high data access volumes.

Multi-Factor Authentication

Where the client platform supports MFA, Aeterna Data requires annotators to enroll in MFA before beginning work. Aeterna Data does not request MFA exceptions or bypasses for annotators on any client platform.

Engagement End Revocation

Upon engagement end, Aeterna Data requests immediate revocation of all annotator credentials within the timeline specified in the SOW — typically within 24 hours of the final delivery date. Written revocation confirmation is requested from the client and maintained in the engagement record.

Annotator Confidentiality Obligations

Every annotator assigned to a client project signs an individual Non-Disclosure Agreement before receiving access credentials or any project information. The individual NDA is distinct from the entity-level DPA — it creates direct contractual obligations between the annotator as an individual and Aeterna Data, covering the confidentiality of client data and the restrictions on its use.

Individual annotator NDAs are the primary mechanism through which Aeterna Data operationalises the GDPR Article 29 requirement that persons acting under the authority of a processor process data only on the controller's instructions. The NDA binds each annotator individually — meaning the security obligation is not merely organisational but personal.

Confidentiality of Client Data

Annotators are prohibited from disclosing any client data — including prompts, model outputs, images, text, or any other data item encountered during annotation — to any third party for any purpose, at any time during or after the engagement.

No Personal Copies

Annotators are prohibited from copying, downloading, screenshotting, or otherwise retaining any client data on personal devices or personal cloud storage. All annotation work is performed and saved within the client platform only.

No Unauthorised Processing

Annotators are prohibited from using client data for any purpose other than the annotation task specified in the project brief. This includes using client data to train personal AI models, for research, for any commercial purpose, or for any purpose not explicitly authorised in writing.

Device Security

Annotators are required to work on password-protected devices with current operating system and browser security updates applied. Work on public or shared devices is prohibited. Work on unsecured public Wi-Fi networks is prohibited without VPN.

Incident Reporting

Annotators are required to report any suspected security incident — including unauthorised access to their credentials, loss of a device used for annotation work, or accidental disclosure of client data — to Aeterna Data immediately upon discovery. Aeterna Data then assesses and triggers the breach notification procedure if required.

Data in Transit

The primary data in transit concern is the communication between annotators' devices and the client annotation platform. Personal data is transmitted over this channel every time an annotator loads a task item, views data in the annotation interface, or saves an annotation.

Aeterna Data requires that client platforms accessed by annotators are served over HTTPS — TLS-encrypted connections — as a condition of engagement. Annotation work on platforms served over unencrypted HTTP connections is not permitted. Where Aeterna Data cannot verify that a client platform is served over HTTPS, this is raised during scoping before any annotator is assigned.

Communication Security

HTTPS-Only Platform Access

All client platform access by Aeterna Data annotators is conducted over HTTPS connections. Annotators are instructed to verify the padlock indicator and report any certificate warnings immediately.

Internal Communication Encryption

All internal Aeterna Data communication about client projects — including task assignments, annotator briefings, and quality reports — is conducted over encrypted communication channels. Client-identifiable project information is not transmitted over unencrypted email.

No Data Transfer via Email

Client data is never transferred to annotators by email or unencrypted file sharing. All data access is through the client platform interface. Where file-based datasets must be shared for file-based validation work, encrypted transfer methods specified in the SOW are used.

VPN for Sensitive Projects

For projects involving particularly sensitive personal data — medical records, legal documents, financial data — Aeterna Data may require annotators to use a VPN for platform access. VPN requirements are specified in the SOW before the engagement begins.

Data at Rest

Client data at rest resides in the client's own platform and storage infrastructure — not in Aeterna Data's infrastructure. Aeterna Data does not maintain servers, databases, or cloud storage that contain client data at rest. This means the security of client data at rest is determined by the client's own platform security — not by Aeterna Data's infrastructure security.

The data at rest security obligations that apply to Aeterna Data concern the annotation output and any project-related documentation that Aeterna Data creates during the engagement — quality reports, IAA scores, annotator calibration records, and SOW documentation. These documents may reference client data characteristics but do not contain copies of client data.

Aeterna Data Internal Documentation

No Client Data in Internal Documents

Quality reports, IAA reports, and annotator calibration documentation reference annotation quality metrics and aggregate statistics — not copies of individual data items. Raw client data is never included in internal Aeterna Data documents.

Project Documentation Retention

Project documentation — SOWs, quality reports, IAA records, and annotator assignment records — is retained for the period specified in the DPA, which is typically the duration of the engagement plus 12 months. Documentation is deleted on schedule unless retention is required by law.

Access to Internal Documentation

Access to internal project documentation is restricted to Aeterna Data personnel with a direct role in the engagement. Documentation is not accessible to annotators beyond what is required for their task briefing.

Device Encryption

Aeterna Data personnel who handle project documentation use devices with full-disk encryption enabled. Device encryption is a condition of handling client-related project documentation.

Breach Notification

In the event of a personal data breach involving client data — whether discovered by an annotator, by Aeterna Data's project management, or through a client notification — Aeterna Data follows a documented breach response procedure. The procedure is aligned with GDPR Article 33 and the breach notification obligations in the EU SCCs Module 2 and the DPA.

72 Hours
Maximum time from breach discovery to client notification

Consistent with GDPR Article 33(2), which requires processors to notify the controller without undue delay after becoming aware of a personal data breach.

Breach Response Procedure

Stage 01

Discovery and Assessment

Upon discovery of a suspected breach — by any annotator or Aeterna Data personnel — the incident is immediately escalated to the engagement lead. Initial assessment determines whether the incident constitutes a personal data breach under GDPR Article 4(12).

Stage 02

Client Notification — Within 72 Hours

If the incident is confirmed or reasonably suspected to constitute a personal data breach, the client is notified within 72 hours of Aeterna Data becoming aware. Notification is provided by email to the client's designated DPA contact, with copy to [email protected]. [email protected].

Stage 03

Notification Content

The breach notification includes: the nature of the breach, the categories and approximate number of data subjects concerned, the categories and approximate number of records involved, the likely consequences of the breach, and the measures taken or proposed to address the breach and mitigate its effects.

Stage 04

Access Revocation

If the breach involves an annotator's credentials — actual or suspected — those credentials are immediately suspended pending investigation. The client is notified of the suspension and the credentials are permanently revoked unless the investigation establishes that no breach occurred.

Stage 05

Incident Documentation

All breach incidents — including incidents that do not meet the notification threshold — are documented in Aeterna Data's internal incident register. The register records the nature of the incident, the response taken, and the outcome. The register is available to clients and supervisory authorities on request.

Data Deletion at Engagement End

Upon engagement end — whether at the natural conclusion of the project, at the client's request, or following early termination — Aeterna Data takes immediate steps to ensure that no client data is retained in any Aeterna Data system or annotator device.

Aeterna Data does not hold copies of client data in its own infrastructure. The primary deletion obligation at engagement end is therefore annotator-side: confirming that no annotator has retained any data item, screenshot, or extract from the client platform on a personal device.

Annotator Credential Revocation

Aeterna Data requests revocation of all annotator credentials from the client platform within the timeline specified in the SOW — typically within 24 hours of the final delivery date. Credential revocation prevents any further access to client data by former annotators.

Annotator Confirmation

Each annotator on the project is required to confirm in writing that they have not retained any copy of client data on personal devices or personal storage, and that they have deleted any local cache or temporary files that may have been created by the annotation platform.

Aeterna Data Written Confirmation

Aeterna Data provides the client with written confirmation that: (1) all annotator credentials have been revoked, (2) all annotator deletion confirmations have been received, and (3) no client data is retained in any Aeterna Data system or annotator device.

Retention of Project Documentation

Project documentation — SOWs, IAA reports, quality reports — that does not contain client data may be retained for the period specified in the DPA (typically engagement duration plus 12 months) for Aeterna Data's own records. This documentation is deleted on schedule unless legally required to be retained.

Written deletion confirmation is provided within 5 business days of engagement end as the default. Where earlier confirmation is required — for regulatory deadlines or client audit schedules — an earlier confirmation deadline can be specified in the SOW.

Sub-Processor Security

Where Aeterna Data engages sub-processors — third-party services that process personal data on Aeterna Data's behalf as part of a client engagement — those sub-processors are required to provide equivalent security guarantees to those in this policy. Sub-processor engagement is governed by Clause 9 of the EU SCCs Module 2 and the sub-processing provisions of the DPA.

Prior to engaging any sub-processor, Aeterna Data conducts a security assessment to verify that the sub-processor's security practices meet the standards required for the personal data being processed. Sub-processors are not engaged without prior written client approval.

Equivalent Security Standard

Sub-processors are required to implement technical and organisational measures that provide a level of data protection at least equivalent to the measures in this policy. This is contractually required in Aeterna Data's sub-processor agreements.

Prior Written Client Approval

No sub-processor is engaged for processing client personal data without prior written approval from the client. Clients are notified at least 14 days before any new sub-processor is engaged and have the right to object.

Sub-Processor Liability

Aeterna Data remains fully liable to the client for the performance of sub-processors' data protection obligations. A sub-processor breach is treated as an Aeterna Data breach for notification and remediation purposes.

Physical Security

Aeterna Data operates as a remote-first organisation. Annotators and project personnel work from their own locations rather than a shared office facility. Physical security measures therefore apply to individual work environments rather than a central premises.

This remote-first model — requires specific personal device and workspace security standards rather than building-level access controls.

Screen Privacy

Annotators working in shared spaces — co-working environments, shared households — are required to use privacy screens when working with sensitive client data. For projects involving sensitive personal data categories under GDPR Article 9 (medical, legal, financial), work in public or shared spaces is prohibited.

Unattended Device Policy

Annotators are required to lock their devices when leaving their workstation. Screen lock must activate automatically after a maximum of 5 minutes of inactivity for devices used to access client platforms.

Device Loss Reporting

Loss or theft of any device used to access a client platform must be reported to Aeterna Data immediately. Aeterna Data assesses whether the loss constitutes a breach risk and triggers the breach notification procedure if required. The client is notified within 72 hours if a breach is confirmed or reasonably suspected.

No Unverified Environments

Annotators are prohibited from conducting annotation work in environments where they cannot control who may view their screen. Work in public environments without adequate screen privacy controls is not permitted for projects involving personal data.

Security Review and Testing

GDPR Article 32(1)(d) requires a process for regularly testing, assessing, and evaluating the effectiveness of technical and organisational measures. Aeterna Data implements this requirement through an annual security review process and through project-level security checks at engagement initiation.

Annual Policy Review

This Data Security Policy is reviewed at minimum annually by Aeterna Data's management. The review assesses whether the measures described in this policy remain appropriate to the processing activities conducted and the risk profile of client data processed. The review date and version number are updated on every revision. Clients engaged at the time of a policy update are notified and provided with the updated policy for their records.

Engagement-Level Security Checks

Pre-Engagement Platform Assessment

Before annotators are assigned, Aeterna Data verifies that the client platform is served over HTTPS, that individual credential provisioning is supported, and that the platform provides a task-level interface that limits annotator access to assigned data items only.

Annotator Onboarding Verification

Before any annotator begins work, Aeterna Data verifies that: the individual NDA is signed, credentials have been individually provisioned, the annotator has confirmed device security compliance, and any MFA requirement has been satisfied.

Mid-Engagement Access Review

On engagements lasting more than 30 days, Aeterna Data conducts a mid-engagement review of annotator access patterns and confirms that access controls remain correctly configured. Any anomalous access patterns identified are investigated and reported to the client.

Post-Engagement Deletion Verification

After engagement end, Aeterna Data verifies that annotator credentials have been revoked, annotator deletion confirmations have been received, and no client data is retained. Written confirmation of all three is provided to the client.

EU AI Act and Data Security

The EU AI Act imposes specific requirements on providers of high-risk AI systems regarding the governance and quality of training data. For EU AI teams outsourcing annotation to Aeterna Data, this policy — together with the DPA, EU SCCs, and IAA quality reports — constitutes the data governance documentation required under EU AI Act Article 10.

Article 10 of the EU AI Act requires that training data for high-risk AI systems be subject to appropriate data governance practices, including examination of training data for possible biases, measures to identify and address gaps and shortcomings, and documentation of the provenance, collection method, and quality of the training data. Aeterna Data's security and quality framework is designed to satisfy these requirements as an integrated output of every engagement — not as a compliance retrofit.

Article 10 Data Governance

Aeterna Data's Data Security Policy and DPA together document the technical and organisational measures applied to training data during annotation processing — satisfying the data governance documentation requirement for high-risk AI system providers under Article 10(2)(f).

Article 17 Quality Management

The IAA measurement, quality reporting, and rework obligations in Aeterna Data's standard engagement model satisfy the quality management system requirements under EU AI Act Article 17 for providers of high-risk AI systems who use Aeterna Data as a training data supplier.

Article 18 Technical Documentation

The SOW, IAA reports, quality reports, and this Data Security Policy together constitute the technical documentation that high-risk AI system providers must maintain under EU AI Act Article 18 — demonstrating that the training data annotation process meets the Act's requirements.

EU AI Act high-risk system requirements take full effect August 2, 2026. Establishing a documented annotation processor relationship — with signed DPA and security policy in place — ensures your annotation pipeline is audit-ready before the deadline.

Client Responsibilities

Data security is a shared responsibility. Aeterna Data is responsible for the measures described in this policy — but the security of the client's own platform, the configuration of access controls within that platform, and the security of the client's data infrastructure are the client's responsibility.

This division of responsibility is consistent with the GDPR controller-processor model: the client (as data controller) is responsible for the security of the processing system; Aeterna Data (as data processor) is responsible for the security of its own personnel and processes within that system.

Platform Security Configuration

The client is responsible for ensuring that the annotation platform is securely configured — including HTTPS enforcement, access logging, session timeout settings, and any platform-level encryption at rest. Aeterna Data operates within the security posture of the client's platform.

Credential Provisioning

The client is responsible for provisioning individual, unique credentials for each annotator before the engagement begins — and for revoking those credentials promptly when requested by Aeterna Data at annotator rotation or engagement end.

MFA Enforcement

Where the client platform supports MFA, the client is responsible for enforcing MFA for annotator accounts. Aeterna Data will comply with any MFA requirement — but cannot enforce it on the client platform independently.

Data Scope Limitation

The client is responsible for limiting the data accessible to annotators to only what is required for the annotation task. Where the platform supports task-level scoping, the client should configure annotator access accordingly — Aeterna Data will confirm the correct scope during onboarding.

Breach Notification to Supervisory Authority

Where a breach involving Aeterna Data-processed data meets the threshold for supervisory authority notification under GDPR Article 33, the client (as data controller) is responsible for notifying their lead supervisory authority within 72 hours. Aeterna Data will provide all necessary information to support that notification.

Common Security Questions

The following questions are frequently raised by client security and compliance teams during vendor assessment.

Does Aeterna Data store any client data on its own servers?

No. Aeterna Data does not maintain servers, databases, or cloud storage for client annotation data. All annotation work is performed inside client-owned or client-licensed platforms. Aeterna Data has no copy of client data at any point during the engagement.

What happens to client data on annotator devices?

Annotators work inside the client's web-based annotation platform — they do not download or store client data locally. Browsers may cache temporary data during a session, but annotators are required to clear browser cache at session end for sensitive projects and are prohibited from downloading any data item from the client platform.

Can Aeterna Data provide an Information Security Policy or ISO 27001 certificate?

Aeterna Data does not hold ISO 27001 certification at this time. This Data Security Policy constitutes Aeterna Data's documented security framework under GDPR Article 32 and EU SCCs Annex II. Where a client requires ISO 27001 or equivalent certification as a vendor prerequisite, this should be raised during scoping so we can assess whether the engagement can proceed.

How does Aeterna Data verify annotator device security?

Aeterna Data requires annotators to confirm device security compliance as part of the onboarding process — including password protection, current OS updates, and disk encryption. Aeterna Data does not deploy MDM (Mobile Device Management) software on annotator devices. Device security compliance is contractually required through the individual NDA.

What security measures apply to sensitive personal data under GDPR Article 9?

For projects involving special category personal data — medical, biometric, racial or ethnic origin, political opinions, religious beliefs, trade union membership, or criminal convictions — Aeterna Data applies enhanced measures: prohibition on work in shared or public spaces, mandatory VPN for platform access, enhanced annotator briefing on data sensitivity, and higher-frequency access log review. Article 9 data processing is specified in the DPA with explicit processing basis.

Does Aeterna Data conduct background checks on annotators?

Aeterna Data does not conduct formal criminal background checks on annotators as a standard practice. For projects involving particularly sensitive data — financial records, legal documents, medical records — enhanced vetting procedures can be specified in the SOW. Clients with mandatory background check requirements should raise this during scoping.

How is the security of sub-processors assessed?

Before engaging any sub-processor, Aeterna Data reviews the sub-processor's security documentation — including their data protection policy, security certifications where available, and any relevant audit reports. Sub-processors processing client personal data are required to sign a sub-processor agreement that incorporates security obligations equivalent to this policy.

How do I report a security concern about my Aeterna Data engagement?

Security concerns, suspected incidents, and questions about this policy should be directed to [email protected]. For urgent security incidents, include 'SECURITY INCIDENT' in the subject line. Aeterna Data's engagement lead is also a direct contact for project-specific security concerns. You can also email us directly at [email protected].

Questions About Data Security?

Security questions are reviewed personally by Aeterna Data's engagement team. This policy and the full DPA are available for legal review before any commitment. Email [email protected] or use the contact form.