Legal

Data processing addendum

Incorporated into the terms of service where the customer processes EU/UK personal data through the Service.

1. Scope & roles

Under the GDPR / UK GDPR, the customer is the data controller and cidbee is the data processor, processing personal data solely to provide the Service under the customer's documented instructions. Where the Service provides a sandbox for customer code, the customer determines the purposes; cidbee does not process customer personal data for its own purposes.

2. Instructions

The customer instructs cidbee to process personal data (i) as set out in the terms, (ii) as documented through the Service's controls (settings, automations, function grants), and (iii) to comply with the law. cidbee will inform the customer if an instruction conflicts with applicable law.

3. Subprocessors

cidbee may engage subprocessors to host, back up and deliver the Service, bound by terms at least as protective as this DPA. A current list is available on request to dpo@cidbee.example. cidbee will notify the customer of subprocessor changes at least 30 days before deployment; the customer may object in writing.

4. Assistance

cidbee will, using appropriate technical and organisational measures and to the extent feasible, assist the customer in responding to data-subject requests arising under the GDPR, and in conducting data protection impact assessments, using documentation already available in the Service (audit logs, role and permission models, security documentation).

5. Security measures

Technical and organisational measures include: TLS 1.2+ in transit, encrypted storage, scoped credentials with zero ambient authority, tenant isolation via RLS or BYODB, per-execution V8 isolation, append-only audit logs, and penetration testing at least annually. The DPA acknowledgement in the workspace confirms these are in effect.

6. Breach notification

cidbee will notify the customer without undue delay after becoming aware of a personal data breach affecting customer data, providing the information a controller needs to notify its supervisory authority, and will cooperate on mitigation. Notifications are sent to the workspace owner's email and mirrored in the status page.

7. Deletion

On termination, cidbee deletes or returns customer personal data within 90 days, except where law requires retention (audit logs retained 24 months, then deleted). Customers may exercise deletion earlier via the admin screen.

8. International transfers

Personal data may be transferred outside the EEA/UK under Standard Contractual Clauses EU 2021/914 Module Two (or successor instruments). BYODB tenants maintain their own transfer arrangements.