Data Processing Terms
Last updated 25 August 2026.
These terms apply where EngSec LLC processes personal data on your behalf in connection with Concentration Chart. They supplement our Terms of Service and Privacy Policy. We will sign a copy on request — write to privacy@engsecsolutions.com.
The short version
For the data most procurement teams are worried about — board layouts, placement files, failure records, serial numbers, technician notes — we are not a processor, because we never receive it. It is read and processed by your own browser on your own machine. There is no copy on our systems to secure, to transfer internationally, to return at the end of a contract, or to lose.
1. Roles
| Data | Our role | Why |
|---|---|---|
| Files you use with the application | None | Processed in your browser; never transmitted to us. Enforced by the application's content security policy. |
| Subscriber and billing details | Controller | We decide how to run subscriptions and meet accounting obligations. |
| Correspondence you send us | Controller | We decide how to handle support and sales enquiries. |
| Personal data inside a sample file you choose to send us | Processor | We handle it only on your instructions, to add support for your format. Sections 2 to 8 apply. |
We ask you not to send personal data in sample files. Where you do, the following applies.
2. Scope and instructions
Subject matter: building and testing support for your export formats. Duration: until the sample is deleted under section 6. Nature and purpose: storage and analysis of file structure. Types of data: whatever remains in a sample you send — typically operator names or identifiers in a repair log. Categories of data subject: your personnel.
We process such data only on your documented instructions, including for transfers, unless required otherwise by law — in which case we will tell you first unless the law forbids it. We will tell you if we believe an instruction breaches data protection law.
3. Confidentiality
Anyone we allow to access the data is bound by confidentiality obligations and is told only what they need to do the work.
4. Security
We implement appropriate technical and organisational measures, taking into account the state of the art and the risk. The principal measure is architectural — the production data does not reach us at all. For what we do hold we use reputable providers, encryption in transit, access limited to those who need it, and multi-factor authentication.
5. Sub-processors
You give general authorisation for the sub-processors listed on our sub-processors page. We will update that page before adding a sub-processor with access to customer personal data, and we will notify you in advance if you ask to be on the notification list. If you reasonably object to a new sub-processor on data protection grounds, you may terminate the affected subscription and we will refund the unused portion of the current period. We remain responsible for our sub-processors' performance.
6. Deletion and return
We will delete a sample on request, and in any case when it is no longer needed for the purpose in section 2. Because there is no ongoing store of your production data, there is nothing to return at the end of a contract.
7. Assistance
Taking into account the nature of the processing, we will assist you with: responding to data subject requests; notifying personal data breaches without undue delay after becoming aware of one; data protection impact assessments; and prior consultation with a regulator.
8. Audit and information
We will make available the information reasonably necessary to demonstrate compliance with these terms, and will allow and contribute to audits by you or an auditor you appoint, on reasonable notice, no more than once a year unless a regulator or a breach requires otherwise, subject to confidentiality. Given the architecture, most questions can be answered by inspecting the application's behaviour directly — see the security model.
9. International transfers
Where personal data we process on your behalf is transferred outside the UK or EEA, we rely on an adequacy decision or the applicable standard contractual clauses, which are incorporated by reference. On request we will confirm which mechanism applies to a given transfer.
10. General
These terms take effect on the date you accept our Terms of Service or the date you first send us data covered by section 1, whichever is earlier. Where they conflict with the Terms of Service on data protection, these terms prevail. Liability is subject to the limits in the Terms of Service.
To request a signed copy, or a copy on your own paper: privacy@engsecsolutions.com.