Data Processing Agreement
This Data Processing Agreement applies where Odenaro processes personal data on behalf of a customer in connection with the hosted service.
Controller and processor
The customer determines the purposes and essential means of processing customer workspace data and acts as controller. Odenaro acts as processor for that data and processes it only to provide, secure, support and maintain the service, subject to documented customer instructions and applicable law.
Processing details
Processing may include hosting, storage, retrieval, organisation, transmission for requested communications, backups, support access, security monitoring and deletion. Data subjects may include customers, suppliers, staff, parents, guardians, children, students and other persons recorded by the customer. Data categories depend on the selected Odenaro product and may include special-category data if the customer chooses to record it.
Confidentiality and security
Odenaro restricts access to authorised personnel and applies reasonable technical and organisational security measures appropriate to the service and risk.
Subprocessors
Odenaro may appoint subprocessors needed to provide infrastructure, email, payments or support services. Current principal subprocessors are listed on the Subprocessors page.
Incidents
Odenaro will notify the customer without undue delay after becoming aware of a confirmed personal-data breach affecting customer workspace data and will provide information reasonably available to support the customer's legal assessment and notifications.
Return and deletion
On termination, customer data is returned or deleted according to the applicable service and retention policy, except where law or a legitimate security/compliance purpose requires limited continued retention.
Questions: info@odenaro.com