CustomerDashboard Data Processing Addendum

Effective date: 2026-07-26

This Data Processing Addendum (DPA) forms part of the CustomerDashboard Terms of Use or another agreement governing the Customer’s use of the Service (the Agreement). It applies when CustomerDashboard processes personal data on the Customer’s behalf.

1. Parties and scope

The Customer is the business that accepted the Agreement.

The Customer is a controller or processor, as applicable. CustomerDashboard is the Customer’s processor or subprocessor. Each party will comply with data-protection law applicable to its role, including the EU General Data Protection Regulation (GDPR) where applicable.

If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA controls.

Customer Personal Data means personal data contained in Customer Data that CustomerDashboard processes on the Customer’s behalf. It does not include account, billing, security, analytics, or business-contact information that CustomerDashboard processes as an independent controller.

2. Instructions and purpose

CustomerDashboard will process Customer Personal Data only:

The Agreement, this DPA, and the Customer’s use and configuration of the Service are the Customer’s documented instructions. CustomerDashboard will inform the Customer if it believes an instruction infringes applicable data-protection law.

Details of processing are in Annex 1.

3. Customer responsibilities

The Customer is responsible for:

If the Customer is a processor, it confirms that its controller has authorised CustomerDashboard as a subprocessor.

4. Confidentiality and security

CustomerDashboard will ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations. It will maintain reasonable technical and organisational measures appropriate to the nature and risks of the processing. Current measures are described in Annex 2.

The Customer acknowledges that security is a shared responsibility and will use read-only, least-privilege database credentials wherever possible; protect accounts and credentials; and configure dashboard access appropriately.

5. Subprocessors

The Customer gives CustomerDashboard general authorisation to use subprocessors. The current list is in Annex 3.

CustomerDashboard will require subprocessors to protect Customer Personal Data through written terms that provide substantially equivalent protection as applicable to their services. CustomerDashboard remains responsible for a subprocessor’s performance to the extent required by law.

We will provide notice of a new subprocessor by updating the published list or by email where reasonably practicable. The Customer may object on reasonable data-protection grounds within 15 days of notice. The parties will try in good faith to resolve the concern. If no reasonable solution is available, the Customer may stop the affected processing or terminate the affected Service.

6. Individual rights

Taking into account the nature of the processing, CustomerDashboard will provide reasonable assistance to help the Customer respond to requests to exercise data-protection rights. If CustomerDashboard receives a request relating to Customer Personal Data, it will refer the requester to the Customer where reasonably possible and will not respond substantively unless instructed or legally required.

7. Personal-data incidents

CustomerDashboard will notify the Customer without undue delay after becoming aware of a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data.

The notice will include available information reasonably needed by the Customer to meet its legal obligations. CustomerDashboard’s notice is not an admission of fault or liability.

8. Compliance assistance

Taking into account the nature of processing and information available to it, CustomerDashboard will provide reasonable assistance with security obligations, breach notifications, data-protection impact assessments, and regulator consultations required by applicable law. Additional or unusually burdensome assistance may be subject to reasonable fees where permitted by law.

9. Deletion and return

During the subscription, the Customer controls its source database and may retrieve information from it directly. The Service does not currently provide a general export of dashboard configurations or cached query results.

Following termination, CustomerDashboard will disable or delete database credentials promptly and normally delete active Customer Personal Data and dashboard configurations within 30 days, unless retention is legally required. Residual copies may remain in backups for up to 90 days and will remain protected and isolated from ordinary use until deletion.

Where legally required and technically reasonably available, CustomerDashboard will, on a request made before termination, assist the Customer in obtaining a copy of Customer Personal Data then held in active systems. The Customer instructs CustomerDashboard to delete remaining Customer Personal Data according to the schedule above.

10. Information and audits

CustomerDashboard will make information reasonably necessary to demonstrate compliance with this DPA available to the Customer. If that information is insufficient, the Customer may request an audit no more than once per year, unless a personal-data incident or regulator requires otherwise.

Audits must be reasonable, proportionate, conducted during normal business hours, protect other customers’ information, and avoid unnecessary disruption. The Customer will bear its audit costs and reimburse CustomerDashboard’s reasonable costs unless the audit identifies a material breach by CustomerDashboard.

11. International transfers

CustomerDashboard may process Customer Personal Data in the European Economic Area and in countries where authorised subprocessors operate. For a transfer subject to GDPR restrictions, CustomerDashboard will use a lawful transfer mechanism, such as an adequacy decision, the EU–US Data Privacy Framework where available, or European Commission Standard Contractual Clauses, together with supplementary measures where required.

12. Liability and duration

This DPA remains in effect while CustomerDashboard processes Customer Personal Data. Liability under this DPA is subject to the exclusions and limitations in the Agreement to the fullest extent permitted by law.

Annex 1 — Processing details

Item Description
Subject Providing database-connected dashboards and client portals
Duration The subscription term plus the deletion period described in this DPA
Nature Accessing connected databases, running queries, temporarily caching results, configuring and displaying dashboards, authenticating users, securing and supporting the Service
Purpose Providing the Service according to the Customer’s configuration and instructions
Data subjects Customer personnel, users, clients, sub-clients, and any other individuals whose information the Customer chooses to connect or display
Personal-data types Identity, contact, account, business, usage, transaction, analytical, and other database information selected by the Customer
Sensitive data Not intended for the Service. If the Customer chooses to process sensitive or regulated data, the Customer is responsible for determining that the processing is lawful and safeguards are appropriate
Frequency As initiated by users, scheduled queries, dashboard operation, and related support or security activity

Annex 2 — Technical and organisational measures

CustomerDashboard’s baseline measures include:

These measures may evolve as the Service develops, provided the overall level of protection is not materially reduced.

Annex 3 — Subprocessors

Subprocessor Purpose Main processing location
Amazon Web Services Cloud hosting and infrastructure Germany / European Economic Area, with possible ancillary global support processing
Auth0 / Okta Authentication and identity management United States
Microsoft Clarity Behavioural and session analytics, if enabled for the relevant interface European Union and United States or other Microsoft locations
Mixpanel Product analytics, if enabled for the relevant interface United States or European Union depending on configuration
Google Analytics Website and product analytics, if enabled for the relevant interface Global, including the United States

Analytics providers are subprocessors under this DPA only to the extent they receive Customer Personal Data processed on the Customer’s behalf. CustomerDashboard should configure analytics to avoid collecting database contents, credentials, and dashboard values.

Contact

Privacy and DPA notices: sales@customerdashboard.io