Data processing

Data processing terms

You are the controller of the personal data in your workspace. Declara is the processor, and processes it only to provide the service and only on your instructions.

The processor will be [entity to be named]. The company is not registered yet, so this document states the position that will apply rather than one that binds anybody today, and it takes effect with the terms when the entity does. You will find that said here rather than find a name invented for it.

Scope

The personal data processed is the names and email addresses of the people you invite, and the addresses you nominate for reminders. Product data is not personal data, though it is commercially sensitive and treated accordingly.

Sub-processors

The current list, with what each one does and where it runs, is maintained at legal/subprocessors, with the date it last changed. It is a separate page on purpose: your procurement can watch it without having to diff a contract that changes for unrelated reasons. We will tell you before adding a sub-processor that touches personal data, and you may object.

Security

Encryption in transit for everything, and at rest by the database provider. Two secrets get a second layer on top of that: single sign-on client secrets are encrypted by the application, and API keys are stored as hashes and cannot be read back at all. One exception, stated rather than averaged out — the two-factor seed has no second layer. The security page sets out which is which. Isolation between workspaces is enforced in a single database client, with automated tests attempting cross-tenant access on every build. The audit log is append-only and the database itself refuses to alter it. Two-factor authentication is available to every account and enforceable per workspace.

Breach

We will tell you without undue delay, with what we know and what we do not, and we will not wait until the picture is complete to make the first contact. Given what this product is about, it would be difficult to argue otherwise.

On the end of the agreement

You can export everything before you go. Working data is purged within thirty days. Case records and the audit chain are retained for seven years, because they are the evidence you may need to produce, and destroying them on request would not be doing you a favour.

In effect from . Earlier versions are available on request.