Skip to main content

Legal

Data processing agreement

CertReports holds itself to the same evidence states it shows for others: this DPA is public, dated and indexed.

Last updated 17 Sep 2026

This data processing agreement applies where a customer of a paid CertReports plan is a controller and CertReports processes personal data on its behalf. It is incorporated into the terms of service.

Scope of processing

ItemDetail
Subject matterProvision of the CertReports Service: accounts, watchlists, shortlists, alerts, exports and API access.
DurationThe term of the customer’s subscription plus 30 days.
Nature and purposeStoring account and workspace data and sending alerts the customer configures.
Types of personal dataNames, business email addresses, workspace membership, activity logs.
Data subjectsCustomer employees and contractors who use the Service.

Obligations

  • CertReports processes personal data only on documented instructions from the customer.
  • Personnel with access are bound by confidentiality.
  • Technical and organisational measures include encryption in transit and at rest, row level security on every application table, private-network databases, least-privilege service keys and nightly backups with an off-host copy.
  • Subprocessors are listed publicly; the customer is notified of changes and may object within 30 days.
  • CertReports assists with data subject requests and, where required, data protection impact assessments.
  • On termination, personal data is deleted within 30 days unless law requires retention.
  • CertReports notifies the customer of a personal data breach without undue delay and within 72 hours of becoming aware.

International transfers

Data is hosted in the EU. Where a subprocessor is outside the EU or UK, transfers rely on standard contractual clauses, the UK addendum, or a Data Privacy Framework listing, as recorded on the subprocessors page.