This Data Processing Addendum ("DPA") forms part of the agreement between Citeroot Labs, Inc. ("Processor") and the customer ("Controller") and applies where Citeroot processes personal data on the customer's behalf.
#1. Scope and roles
Customer is the controller and Citeroot is the processor of personal data contained in Customer Data. Details of processing:
- Subject matter: providing the Service.
- Duration: the term of the agreement plus deletion period.
- Nature and purpose: storing, analysing and presenting data submitted by the customer.
- Categories of data subjects: the customer's personnel and any individuals named in submitted content.
- Types of personal data: names, business contact details and any personal data included in prompts or imported analytics data.
#2. Instructions
Citeroot processes personal data only on documented instructions from the customer, including as set out in the agreement and this DPA.
#3. Confidentiality
Personnel authorised to process personal data are bound by confidentiality obligations.
#4. Security
Citeroot implements technical and organisational measures described on the security page, including encryption in transit, hashed passwords and tokens, access controls scoped to each account, and rate limiting. Our hosting and database providers encrypt stored data at rest.
#5. Subprocessors
The customer authorises the subprocessors listed at /legal/subprocessors. Citeroot will give notice of new subprocessors and the customer may object on reasonable grounds.
#6. Assistance
Citeroot will assist the customer, taking into account the nature of processing, with data subject requests, security, breach notification, impact assessments and consultations.
#7. Personal data breaches
Citeroot will notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Data.
#8. Return and deletion
On termination, Citeroot will make Customer Data available for export and then delete it within a reasonable period, unless law requires retention.
#9. Audits
Citeroot will make available information necessary to demonstrate compliance and allow for audits as described in the agreement.
#10. International transfers
Where personal data is transferred outside the EEA/UK, the parties will rely on an approved transfer mechanism such as Standard Contractual Clauses.