Skip to main content
CedraStack
ServicesPlansAboutContactEmergencyKnowledge BaseFAQRequest Support
/

CedraStack · Legal policies

Data Processing Agreement

Version 2026-10-07.1 · Effective 2026-10-07 · Updated 2026-10-07

1. Application and parties2. Processing description and duration3. Documented instructions and client duties4. Confidentiality and security5. Subprocessors6. Rights requests and cooperation7. Security incidents8. Return, deletion and retention9. International processing and information review10. Order details and contact

1. Application and parties

This DPA applies when incorporated into a service order or expressly agreed by the client and CedraStack for processing on the client’s behalf. Publication alone does not execute a DPA or establish regulatory compliance. The client acts as controller (or an authorized processor instructing a subprocessor); CedraStack acts as processor for the agreed support. CedraStack’s own account, security and billing administration is addressed separately in Privacy.

2. Processing description and duration

Processing concerns remote IT/cloud administration, troubleshooting, agreed maintenance, backup/recovery assistance and related reporting for the service duration, followed by return/deletion and necessary retention. It may involve client personnel, users, business contacts and people whose information is in supported systems; identity/contact, account, device, infrastructure, support and business-file data are possible. The service order must identify actual systems, data subjects, sensitive categories, access scope and any special restrictions.

3. Documented instructions and client duties

CedraStack processes client-system data only on documented instructions and for the agreed purpose, including instructions about disclosure and transfers, unless legally required otherwise. It informs the client of such requirements where permitted and raises instructions that appear unlawful. The client is responsible for lawful authority, necessary notices/permissions, data accuracy, appropriate access and backups, and for avoiding unnecessary disclosure. Further use for CedraStack marketing or unrelated purposes is not authorized by this DPA.

4. Confidentiality and security

Personnel with access must be authorized and bound by confidentiality. Measures include limited remote access, company/role segregation in the portal, password hashing, encrypted MFA seeds, hashed recovery/session tokens, restricted file access, session revocation and relevant audit records. Measures must be appropriate to the agreed data and risks; no absolute security, certification or recovery guarantee is made. Any additional client requirement must be agreed and supported operationally.

5. Subprocessors

Cloudflare and Brevo are listed on Subprocessors for hosting/storage/verification and transactional email. The parties must agree the necessary authorization and provider terms for the relevant processing. CedraStack remains responsible for its agreed processor obligations and should notify material intended changes in advance, permitting reasonable objections and discussion of alternatives. This notice/objection process is currently handled manually, not through an automated subscription service.

6. Rights requests and cooperation

Taking account of the processing and information available, CedraStack assists the client with data-subject requests, risk assessments and relevant security obligations. It forwards requests concerning client-system data to the client and does not independently disclose it without authority. Identity, scope, timeframes and any reasonable additional service costs must be agreed without overriding mandatory law. Requests may need manual extraction; the platform has no universal automated rights-export tool.

7. Security incidents

CedraStack informs the client without undue delay after becoming aware of a personal-data breach affecting agreed client processing, provides available information about impact and mitigation, and cooperates as further facts become known. The client determines its notifications to authorities or individuals, with assistance where appropriate. Exact contact paths, escalation and any required contractual deadlines must be agreed. This does not promise an automated detection service or uninterrupted monitoring.

8. Return, deletion and retention

At the end of agreed processing, the parties arrange return or deletion of client-system data and copies, except retention required by applicable law. Portal deletion follows Retention, including the 30-day grace period for eligible accounts, administrator cleanup and queued storage deletion. Financial and minimized audit/acceptance records are separate business records and may remain. Backup/provider copies and any persistent remote credentials require explicit review; no immediate universal erasure is promised.

9. International processing and information review

Infrastructure may process data outside the client’s country. Before processing requiring particular transfer safeguards, the parties must assess locations, provider arrangements and applicable mechanisms and document them in the service order or addendum. This page does not itself provide standard contractual clauses or establish adequacy. CedraStack provides information reasonably necessary to demonstrate agreed obligations and cooperates with proportionate reviews/audits under confidentiality and security arrangements.

10. Order details and contact

Before execution, complete the service order with party identities, systems, purposes, data subjects/categories, instructions, term, contacts, subprocessors/transfer arrangements and any special security or return requirements. Qualified legal review is required for the applicable relationship, particularly international data and mandatory privacy rules. Contact hello@cedrastack.com; incident/support contact support@cedrastack.com.

SHA-256: bcb17b57f1483dd58d99469cdd87adc371e5f8a87d0be7a90e4c52c048528f2b

Client Terms of ServicePrivacy PolicySupport Policy and Response TargetsData Processing AgreementProviders and SubprocessorsData Retention Policy
CedraStack
CedraStack

Remote IT & Cloud Support for Modern Businesses.

Beirut, Lebanon

Services

Microsoft 365Servers & VirtualizationNetworking & SecurityCloud & Infrastructure

Support

Support PlansEmergency SupportClient Portal

Contact

FAQRequest IT Supporthello@cedrastack.comsupport@cedrastack.com

Monday–Friday
08:00–18:00 Beirut

Legal

Client Terms of ServicePrivacy PolicySupport Policy and Response TargetsData Processing AgreementProviders and SubprocessorsData Retention Policy
© 2026 CedraStack. All rights reserved.