Data Processing Agreement
Details about how we process data on behalf of our users and partners.
This Data Processing Agreement (“DPA”) applies where Cubie Technologies processes personal data on behalf of a business customer (“Controller”) in the course of providing the Services. It supplements our Terms of Service.
Where you use our Services as an individual for your own purposes, our Privacy Policy applies instead.
1. Roles
The Controller determines the purposes and means of processing personal data. Cubie Technologies acts as Processor and processes personal data only on documented instructions from the Controller, except where required to do otherwise by law.
2. Subject matter and duration
Processing lasts for the term of the Controller's subscription, plus the deletion period described in section 8.
Categories of data subject
- The Controller's employees, contractors and authorised users
- The Controller's own customers or contacts, where the Controller submits their data
Types of personal data
- Identity and contact data — name, email address, profile details
- Account and authentication data
- Content submitted through the Services
- Usage and technical data — log entries, device and connection information
The Services are not designed for special-category data as defined by GDPR Article 9, and the Controller should not submit such data without a separate written agreement.
3. Our obligations
- Process personal data only on the Controller's documented instructions
- Ensure personnel with access are bound by confidentiality
- Implement appropriate technical and organisational security measures (section 5)
- Assist the Controller in responding to data subject requests
- Assist with data protection impact assessments and prior consultations where required
- Delete or return personal data at the end of the engagement
- Make available the information needed to demonstrate compliance
4. Sub-processors
The Controller gives general authorisation for us to engage sub-processors. We currently use providers for hosting and compute, object storage, transactional email, push notification delivery, and error monitoring.
Each sub-processor is bound by data protection obligations no less protective than this DPA. We will give at least 30 days' notice before adding or replacing a sub-processor, and the Controller may object on reasonable data protection grounds.
5. Security measures
- Encryption of data in transit using TLS
- Password hashing using bcrypt at a high work factor
- Parameterised queries throughout, preventing SQL injection
- Per-user and per-tenant data isolation enforced at the query layer
- Role-based access control and least-privilege access for personnel
- Regular backups with defined retention and restoration testing
- Logging and monitoring of access to production systems
6. Personal data breach
We will notify the Controller without undue delay and in any case within 48 hours of becoming aware of a personal data breach affecting the Controller's data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed.
7. International transfers
Where personal data is transferred outside the EEA, UK or other regions with transfer restrictions, we rely on appropriate safeguards, including the European Commission's standard contractual clauses and, where applicable, the UK International Data Transfer Addendum.
8. Deletion and return
On termination, we will delete or return personal data at the Controller's choice. Deletion from active systems happens within 30 days; backup copies expire on their normal rotation within 90 days. We may retain data where required by law, and it remains subject to this DPA while retained.
9. Audits
We will make available information necessary to demonstrate compliance with this DPA and allow for audits, including inspections, conducted by the Controller or an auditor it mandates. Audits take place no more than once in any twelve-month period unless required by a supervisory authority, on reasonable notice and during business hours.
10. Contact
To enter into this DPA, request our sub-processor list, or raise a data protection question, contact legal@cubietec.com.