Credocent

Last updated ยท 2026-08-19

Data processing agreement

This agreement applies automatically to every customer and covers processing of personal data under Article 28 GDPR.

1. Roles

The customer is the data controller for the documents, employee accounts and questions in its workspace. Credocent is the data processor.

2. Subject matter and duration

The processing consists of storing, indexing and searching the customer's documents in order to answer employee questions. It lasts for as long as the subscription is active.

Categories of data subjects: the customer's employees and anyone named in uploaded documents. Categories of data: contact details, role, questions asked and any personal data contained in the documents.

3. Instructions

We only process personal data on documented instructions from the customer, including the settings the customer chooses in the product, unless required otherwise by EU or member state law.

4. Confidentiality

Everyone with access to customer data is bound by confidentiality, and access is limited to what is needed to operate and support the service.

5. Security measures

Encryption in transit and at rest, per-workspace isolation enforced in the database, role-based access, logging, backups and tested restore procedures.

6. Sub-processors

The customer gives general authorisation for the sub-processors listed on our security page (hosting, AI inference, transactional email). We give notice before adding or replacing one, and the customer may object on reasonable grounds.

7. Assistance

We help the customer answer data subject requests and meet its obligations on security, breach notification and impact assessments, taking into account the nature of the processing.

8. Personal data breach

We notify the customer without undue delay, and in any case within 48 hours of becoming aware of a breach affecting its data, with the information needed for the customer's own reporting.

9. Return and deletion

On request or at the end of the agreement the customer can export its data. All personal data is then deleted within 30 days, unless storage is required by law.

10. Audits and transfers

We make the information needed to demonstrate compliance available and allow audits with reasonable notice, normally through documentation.

Data is processed in the EU/EEA. If a transfer outside the EEA is ever necessary, it is covered by the EU Standard Contractual Clauses and additional safeguards.

Back to home