This data processing agreement applies where a customer of a paid CertReports plan is a controller and CertReports processes personal data on its behalf. It is incorporated into the terms of service.
Scope of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the CertReports Service: accounts, watchlists, shortlists, alerts, exports and API access. |
| Duration | The term of the customer’s subscription plus 30 days. |
| Nature and purpose | Storing account and workspace data and sending alerts the customer configures. |
| Types of personal data | Names, business email addresses, workspace membership, activity logs. |
| Data subjects | Customer employees and contractors who use the Service. |
Obligations
- CertReports processes personal data only on documented instructions from the customer.
- Personnel with access are bound by confidentiality.
- Technical and organisational measures include encryption in transit and at rest, row level security on every application table, private-network databases, least-privilege service keys and nightly backups with an off-host copy.
- Subprocessors are listed publicly; the customer is notified of changes and may object within 30 days.
- CertReports assists with data subject requests and, where required, data protection impact assessments.
- On termination, personal data is deleted within 30 days unless law requires retention.
- CertReports notifies the customer of a personal data breach without undue delay and within 72 hours of becoming aware.
International transfers
Data is hosted in the EU. Where a subprocessor is outside the EU or UK, transfers rely on standard contractual clauses, the UK addendum, or a Data Privacy Framework listing, as recorded on the subprocessors page.