Data processing agreement
These are our standard Article 28 terms. They apply to every customer using Outweigh and can be signed as a standalone document on request.
Last updated 1 September 2026
1. Parties and roles
The customer organisation is the controller. Probity Net Limited, registered in Ireland and trading as Outweigh, is the processor. Where a consultancy uses the platform on behalf of its own client, the consultancy is the controller in relation to us and is responsible for its arrangement with that client.
2. Subject matter, duration, nature and purpose
We process personal data only to provide the Outweigh platform: assembling evidence, generating Decision Council responses and briefs, producing decision records, and keeping a workspace's decision history available to it. Processing continues for as long as the customer's account or workspace is active, and ends on deletion as set out in clause 10.
3. Categories of data and data subjects
- Data subjects — the customer's own staff and consultants who hold accounts, and any individuals identifiable within material the customer uploads.
- Personal data — names, email addresses, organisation membership, authentication records, activity and access logs, and whatever personal data is contained in uploaded briefs, evidence and notes.
- Special category data — the platform is not designed for special category data (including health data) and we do not ask for it. If a customer intends to upload it, that must be agreed in writing with us first.
4. Controller instructions
We process personal data only on the documented instructions of the controller, which include using the platform's features and any written instruction sent to hello@personalobby.ie. We will tell the controller if, in our opinion, an instruction infringes data protection law. We will not process the data for our own purposes, and we will not use customer decision content to train general-purpose models.
5. Confidentiality
Everyone we authorise to process customer data is bound by a written confidentiality obligation that survives the end of their engagement. Access is limited to the personnel who need it to operate and support the service.
6. Security measures
We maintain the technical and organisational measures described on our security page, which forms part of this agreement. In summary: organisation-level isolation enforced in the database with row-level security and covered by an automated test suite; authorisation derived from the verified signed-in session; private file storage served through short-lived signed links; TLS in transit and provider encryption at rest; hosting in Ireland; and logging of platform-administrator access, visible to the customer's own owner.
We state plainly what these measures do not do: decision content is stored as readable text so that the platform can search it and generate outputs from it, and personnel with infrastructure credentials are technically capable of reading it. The protections against that are least privilege, access logging, confidentiality obligations and this agreement — not encryption that would make the content unreadable to us. We hold no SOC 2, ISO 27001 or HIPAA certification and make no such claim.
7. Sub-processors
The controller gives general authorisation for the sub-processors listed on our sub-processors page. We impose data protection obligations on each of them no less protective than those in this agreement, and we remain liable for their performance. We will publish and notify any addition or replacement before it begins processing, and the controller may object in writing within thirty days as described on that page.
8. Assistance with data subject rights
The platform allows a controller to access, correct, export and delete the personal data in its workspace directly. Where a request cannot be satisfied through the platform, we will assist the controller within five working days of a written request, at no charge for reasonable volumes. If a data subject contacts us directly, we will refer them to the controller rather than respond on the controller's behalf.
9. Personal data breach
We will notify the controller without undue delay and in any case within 48 hours of becoming aware of a personal data breach affecting its data. The notification will describe what we know at the time: the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, the measures taken, and a named contact. We will provide updates as the investigation progresses and reasonable assistance with the controller's own notification obligations under Articles 33 and 34.
10. Deletion and return
On written request, or within thirty days of the end of the service, we will delete the controller's workspace and its contents, or return an export of it first if asked. We retain only what we are legally required to keep, and backups containing deleted data expire on our normal backup cycle, within thirty days. We will confirm deletion in writing.
11. Audit and information
On request, and no more than once in any twelve-month period unless required by a supervisory authority, we will provide the information reasonably necessary to demonstrate compliance with this agreement: our completed security questionnaire, our current sub-processor list, and the dated output of our tenant isolation test suite. Where that is insufficient for the controller's regulator, we will agree an inspection in good faith on reasonable notice, during business hours, without disrupting other customers, and subject to confidentiality.
12. International transfers
Platform data is stored in Ireland. Transfers outside the European Economic Area occur only through the model providers identified on the sub-processors page and rely on the European Commission's Standard Contractual Clauses, which are incorporated into this agreement by reference where they apply.
13. Precedence and signature
This agreement forms part of our terms of service. Where a signed enterprise agreement or a controller's own DPA has been executed with Probity Net Limited, that document takes precedence. To receive this as a signable standalone document, write to hello@personalobby.ie.
These terms are governed by the laws of Ireland. This page is provided in good faith and is not legal advice; a controller should have its own adviser review it before signature.