CedraStack · Legal policies
Data Processing Agreement
1. Application and parties
This DPA applies when incorporated into a service order or expressly agreed by the client and CedraStack for processing on the client’s behalf. Publication alone does not execute a DPA or establish regulatory compliance. The client acts as controller (or an authorized processor instructing a subprocessor); CedraStack acts as processor for the agreed support. CedraStack’s own account, security and billing administration is addressed separately in Privacy.
2. Processing description and duration
Processing concerns remote IT/cloud administration, troubleshooting, agreed maintenance, backup/recovery assistance and related reporting for the service duration, followed by return/deletion and necessary retention. It may involve client personnel, users, business contacts and people whose information is in supported systems; identity/contact, account, device, infrastructure, support and business-file data are possible. The service order must identify actual systems, data subjects, sensitive categories, access scope and any special restrictions.
3. Documented instructions and client duties
CedraStack processes client-system data only on documented instructions and for the agreed purpose, including instructions about disclosure and transfers, unless legally required otherwise. It informs the client of such requirements where permitted and raises instructions that appear unlawful. The client is responsible for lawful authority, necessary notices/permissions, data accuracy, appropriate access and backups, and for avoiding unnecessary disclosure. Further use for CedraStack marketing or unrelated purposes is not authorized by this DPA.
4. Confidentiality and security
Personnel with access must be authorized and bound by confidentiality. Measures include limited remote access, company/role segregation in the portal, password hashing, encrypted MFA seeds, hashed recovery/session tokens, restricted file access, session revocation and relevant audit records. Measures must be appropriate to the agreed data and risks; no absolute security, certification or recovery guarantee is made. Any additional client requirement must be agreed and supported operationally.
5. Subprocessors
Cloudflare and Brevo are listed on Subprocessors for hosting/storage/verification and transactional email. The parties must agree the necessary authorization and provider terms for the relevant processing. CedraStack remains responsible for its agreed processor obligations and should notify material intended changes in advance, permitting reasonable objections and discussion of alternatives. This notice/objection process is currently handled manually, not through an automated subscription service.
6. Rights requests and cooperation
Taking account of the processing and information available, CedraStack assists the client with data-subject requests, risk assessments and relevant security obligations. It forwards requests concerning client-system data to the client and does not independently disclose it without authority. Identity, scope, timeframes and any reasonable additional service costs must be agreed without overriding mandatory law. Requests may need manual extraction; the platform has no universal automated rights-export tool.
7. Security incidents
CedraStack informs the client without undue delay after becoming aware of a personal-data breach affecting agreed client processing, provides available information about impact and mitigation, and cooperates as further facts become known. The client determines its notifications to authorities or individuals, with assistance where appropriate. Exact contact paths, escalation and any required contractual deadlines must be agreed. This does not promise an automated detection service or uninterrupted monitoring.
8. Return, deletion and retention
At the end of agreed processing, the parties arrange return or deletion of client-system data and copies, except retention required by applicable law. Portal deletion follows Retention, including the 30-day grace period for eligible accounts, administrator cleanup and queued storage deletion. Financial and minimized audit/acceptance records are separate business records and may remain. Backup/provider copies and any persistent remote credentials require explicit review; no immediate universal erasure is promised.
9. International processing and information review
Infrastructure may process data outside the client’s country. Before processing requiring particular transfer safeguards, the parties must assess locations, provider arrangements and applicable mechanisms and document them in the service order or addendum. This page does not itself provide standard contractual clauses or establish adequacy. CedraStack provides information reasonably necessary to demonstrate agreed obligations and cooperates with proportionate reviews/audits under confidentiality and security arrangements.
10. Order details and contact
Before execution, complete the service order with party identities, systems, purposes, data subjects/categories, instructions, term, contacts, subprocessors/transfer arrangements and any special security or return requirements. Qualified legal review is required for the applicable relationship, particularly international data and mandatory privacy rules. Contact hello@cedrastack.com; incident/support contact support@cedrastack.com.
SHA-256: bcb17b57f1483dd58d99469cdd87adc371e5f8a87d0be7a90e4c52c048528f2b
