Data processing agreement
Who is who
When you use Ceodore to hold information about your customers, suppliers and staff, you are the controller of that personal data and we are your processor. This agreement sets out what we do with it on your behalf, and forms part of our terms of service.
What we process, and why
Subject matter: providing the Ceodore service to you.
Duration: for as long as your account is open, plus any retention period required by law.
Categories of data subject: your customers, your suppliers, your staff, and anyone else whose details you enter.
Types of personal data: names, contact details, addresses, transaction records, booking details, review content, and public wallet addresses you associate with a person.
We do not process special category data, and you should not enter any.
Our obligations
We process personal data only on your documented instructions, which includes using the service as intended, unless we are required to do otherwise by law. If we are, we will tell you before processing unless the law prevents us.
Everyone with access is bound by confidentiality. Access within our organisation is limited to those who need it and is logged.
We will help you respond to requests from data subjects, and with data protection impact assessments and consultations with regulators, so far as is reasonable.
At the end of the agreement we will delete or return the personal data, at your choice, except where we are required to keep it.
Security measures
Encryption in transit and at rest. Identifying fields are encrypted at the field level with a key belonging to your organisation alone, held in a managed key service with separately audited access.
Access control by role, with passkey authentication and re-authentication required at the point of sensitive actions. Session revocation available to you at any time.
Logical separation between organisations enforced in the data layer, so one organisation cannot read another's records.
Audit logging of changes. Backups encrypted and held in the United Kingdom. Regular restore testing.
Sub-processors
We use a small number of suppliers to run the service. Each is bound by terms no less protective than these, and each is listed with its role and location. We will give you notice before adding or replacing one, and you may object on reasonable data protection grounds.
Current sub-processors cover hosting and database, object storage, transactional email, payment processing for your subscription, and error monitoring. The current list with named entities is available on request and will be published here alongside the final version.
International transfers
Personal data is stored in the United Kingdom. Where any transfer outside the UK or EEA is necessary, it will be made under an adequacy decision or the appropriate safeguards, and we will tell you which applies.
Blockchain data we read is public and is not a transfer of your personal data.
Breach notification
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need to meet your own obligations, and we will keep you updated as we learn more.
Audit
We will make available the information needed to demonstrate compliance with this agreement, and allow for audits on reasonable notice, including by an auditor you appoint, subject to confidentiality and to not compromising the security of other customers.
Need a signed copy?
If your procurement process needs an executed DPA, or your auditors want the sub-processor list in a particular form, write to us and we will sort it out rather than pointing you at a web page.
Ask us