◦ Data Processing
Data Processing Terms
Last updated July 20, 2026
These Data Processing Terms describe how AccessExit, operated by Eastbase Studio, processes workspace content on your behalf. As explained in our Privacy Policy, you (the customer) are the controller of your workspace content and AccessExit is the processor. These terms supplement, and are governed by, our Terms of Service.
1. Roles and scope
For workspace content — the people, app inventory, account mappings, access maps, offboarding cases, tasks, evidence, and receipts you create — you are the controller and AccessExit is your processor. For account data and the marketing site, AccessExit is the controller, as described in the Privacy Policy. These terms apply for as long as AccessExit processes workspace content on your behalf.
2. Processing on documented instructions
AccessExit processes workspace content only to provide and support the service, and on your documented instructions. Your use of the product, its configuration, and these terms together form those instructions. We do not sell workspace content, and we do not use it to train AI models — the product has no AI features. If we believe an instruction violates applicable law, we’ll tell you.
3. Confidentiality
We keep workspace content confidential and limit access to personnel who need it to operate or support the service, and who are bound by confidentiality obligations. We do not disclose workspace content except as you instruct, as needed to provide the service through the subprocessors below, or where required by law — in which case, unless prohibited, we’ll notify you.
4. Security measures
We maintain technical and organizational measures appropriate to the risk, including:
- Encryption in transit, and encryption of integration/OAuth tokens at rest (AES-256-GCM); passwords are hashed, never stored in plaintext.
- Private evidence storage served only through an authenticated, access-checked download route.
- Workspace-scoped access controls, append-only audit events, and least-privilege, read-only integration scopes where possible.
- Rate-limited public auth endpoints, and receipts reachable only via an unguessable 256-bit token that is never indexed.
You are responsible for your own security decisions — managing admins and roles, and not uploading secrets, credentials, or regulated data as evidence, as described in the Terms and Privacy Policy.
5. Subprocessors
You authorize AccessExit to engage the subprocessors listed in the Privacy Policy to help provide the service. We impose data-protection obligations on each subprocessor consistent with these terms, and remain responsible for their processing of workspace content. We’ll keep that list current and, where required, give you a way to object to a new subprocessor before it starts processing your workspace content.
6. International transfers
AccessExit is operated from Vietnam and uses providers that may process data in the United States and other countries. Where a transfer requires additional protection, we rely on the appropriate safeguards those providers make available (such as standard contractual clauses offered under their data-processing terms). We don’t claim safeguards or regions we haven’t confirmed with a provider.
7. Assistance with data-subject requests
Taking into account the nature of the processing, we’ll help you respond to requests from individuals to access, correct, export, or delete their personal data. The product already lets you export receipts and access reviews to CSV (on paid plans) and delete people, apps, and evidence directly; for anything those tools don’t cover, email support@eastbase.studio.
8. Breach assistance
If we become aware of a personal-data breach affecting your workspace content, we’ll notify you without undue delay and share the information reasonably available to help you meet your own notification obligations.
9. Return and deletion
You can export receipts and access reviews and delete your workspace at any time. On deletion, we aim to delete or anonymize active-system workspace content within 30 days. Backups, security logs, audit logs, delivery logs, and diagnostic records may persist up to about 90 days before deletion or overwrite, and we may retain limited records where required by law — consistent with the retention section of the Privacy Policy.
10. Documentation and audits
To help you assess our processing, we’ll make available the information reasonably necessary to demonstrate compliance with these terms — starting with this document, the Privacy Policy, our published security model, and the subprocessor list. Where you have a genuine audit right under applicable law, we’ll work with you in good faith to satisfy it through that documentation first, and discuss proportionate further steps if it is genuinely required.
11. Contact
Questions about these Data Processing Terms, or to raise a data-protection request, email support@eastbase.studio.