Last updated ยท 2026-08-19
Data processing agreement
This agreement applies automatically to every customer and covers processing of personal data under Article 28 GDPR.
1. Roles
The customer is the data controller for the documents, employee accounts and questions in its workspace. Credocent is the data processor.
2. Subject matter and duration
The processing consists of storing, indexing and searching the customer's documents in order to answer employee questions. It lasts for as long as the subscription is active.
Categories of data subjects: the customer's employees and anyone named in uploaded documents. Categories of data: contact details, role, questions asked and any personal data contained in the documents.
3. Instructions
We only process personal data on documented instructions from the customer, including the settings the customer chooses in the product, unless required otherwise by EU or member state law.
4. Confidentiality
Everyone with access to customer data is bound by confidentiality, and access is limited to what is needed to operate and support the service.
5. Security measures
Encryption in transit and at rest, per-workspace isolation enforced in the database, role-based access, logging, backups and tested restore procedures.
6. Sub-processors
The customer gives general authorisation for the sub-processors listed on our security page (hosting, AI inference, transactional email). We give notice before adding or replacing one, and the customer may object on reasonable grounds.
7. Assistance
We help the customer answer data subject requests and meet its obligations on security, breach notification and impact assessments, taking into account the nature of the processing.
8. Personal data breach
We notify the customer without undue delay, and in any case within 48 hours of becoming aware of a breach affecting its data, with the information needed for the customer's own reporting.
9. Return and deletion
On request or at the end of the agreement the customer can export its data. All personal data is then deleted within 30 days, unless storage is required by law.
10. Audits and transfers
We make the information needed to demonstrate compliance available and allow audits with reasonable notice, normally through documentation.
Data is processed in the EU/EEA. If a transfer outside the EEA is ever necessary, it is covered by the EU Standard Contractual Clauses and additional safeguards.
Credocent