CustomerDashboard Data Processing Addendum
Effective date: 2026-07-26
This Data Processing Addendum (DPA) forms part of the CustomerDashboard Terms of Use or another agreement governing the Customer’s use of the Service (the Agreement). It applies when CustomerDashboard processes personal data on the Customer’s behalf.
1. Parties and scope
The Customer is the business that accepted the Agreement.
The Customer is a controller or processor, as applicable. CustomerDashboard is the Customer’s processor or subprocessor. Each party will comply with data-protection law applicable to its role, including the EU General Data Protection Regulation (GDPR) where applicable.
If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA controls.
Customer Personal Data means personal data contained in Customer Data that CustomerDashboard processes on the Customer’s behalf. It does not include account, billing, security, analytics, or business-contact information that CustomerDashboard processes as an independent controller.
2. Instructions and purpose
CustomerDashboard will process Customer Personal Data only:
- to provide, secure, maintain, and support the Service;
- as configured or instructed by the Customer through its use of the Service;
- as otherwise documented in the Agreement or agreed in writing; or
- where required by law, after informing the Customer unless the law prohibits notice.
The Agreement, this DPA, and the Customer’s use and configuration of the Service are the Customer’s documented instructions. CustomerDashboard will inform the Customer if it believes an instruction infringes applicable data-protection law.
Details of processing are in Annex 1.
3. Customer responsibilities
The Customer is responsible for:
- the lawfulness, fairness, and accuracy of Customer Personal Data and its instructions;
- providing required notices and having a valid legal basis;
- ensuring that it is authorised to give CustomerDashboard access to connected databases;
- configuring access, sharing, and retention appropriately;
- responding to individuals and assessing whether requests are valid; and
- determining whether the Service’s safeguards are appropriate for the Customer’s data and risks.
If the Customer is a processor, it confirms that its controller has authorised CustomerDashboard as a subprocessor.
4. Confidentiality and security
CustomerDashboard will ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations. It will maintain reasonable technical and organisational measures appropriate to the nature and risks of the processing. Current measures are described in Annex 2.
The Customer acknowledges that security is a shared responsibility and will use read-only, least-privilege database credentials wherever possible; protect accounts and credentials; and configure dashboard access appropriately.
5. Subprocessors
The Customer gives CustomerDashboard general authorisation to use subprocessors. The current list is in Annex 3.
CustomerDashboard will require subprocessors to protect Customer Personal Data through written terms that provide substantially equivalent protection as applicable to their services. CustomerDashboard remains responsible for a subprocessor’s performance to the extent required by law.
We will provide notice of a new subprocessor by updating the published list or by email where reasonably practicable. The Customer may object on reasonable data-protection grounds within 15 days of notice. The parties will try in good faith to resolve the concern. If no reasonable solution is available, the Customer may stop the affected processing or terminate the affected Service.
6. Individual rights
Taking into account the nature of the processing, CustomerDashboard will provide reasonable assistance to help the Customer respond to requests to exercise data-protection rights. If CustomerDashboard receives a request relating to Customer Personal Data, it will refer the requester to the Customer where reasonably possible and will not respond substantively unless instructed or legally required.
7. Personal-data incidents
CustomerDashboard will notify the Customer without undue delay after becoming aware of a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data.
The notice will include available information reasonably needed by the Customer to meet its legal obligations. CustomerDashboard’s notice is not an admission of fault or liability.
8. Compliance assistance
Taking into account the nature of processing and information available to it, CustomerDashboard will provide reasonable assistance with security obligations, breach notifications, data-protection impact assessments, and regulator consultations required by applicable law. Additional or unusually burdensome assistance may be subject to reasonable fees where permitted by law.
9. Deletion and return
During the subscription, the Customer controls its source database and may retrieve information from it directly. The Service does not currently provide a general export of dashboard configurations or cached query results.
Following termination, CustomerDashboard will disable or delete database credentials promptly and normally delete active Customer Personal Data and dashboard configurations within 30 days, unless retention is legally required. Residual copies may remain in backups for up to 90 days and will remain protected and isolated from ordinary use until deletion.
Where legally required and technically reasonably available, CustomerDashboard will, on a request made before termination, assist the Customer in obtaining a copy of Customer Personal Data then held in active systems. The Customer instructs CustomerDashboard to delete remaining Customer Personal Data according to the schedule above.
10. Information and audits
CustomerDashboard will make information reasonably necessary to demonstrate compliance with this DPA available to the Customer. If that information is insufficient, the Customer may request an audit no more than once per year, unless a personal-data incident or regulator requires otherwise.
Audits must be reasonable, proportionate, conducted during normal business hours, protect other customers’ information, and avoid unnecessary disruption. The Customer will bear its audit costs and reimburse CustomerDashboard’s reasonable costs unless the audit identifies a material breach by CustomerDashboard.
11. International transfers
CustomerDashboard may process Customer Personal Data in the European Economic Area and in countries where authorised subprocessors operate. For a transfer subject to GDPR restrictions, CustomerDashboard will use a lawful transfer mechanism, such as an adequacy decision, the EU–US Data Privacy Framework where available, or European Commission Standard Contractual Clauses, together with supplementary measures where required.
12. Liability and duration
This DPA remains in effect while CustomerDashboard processes Customer Personal Data. Liability under this DPA is subject to the exclusions and limitations in the Agreement to the fullest extent permitted by law.
Annex 1 — Processing details
| Item | Description |
|---|---|
| Subject | Providing database-connected dashboards and client portals |
| Duration | The subscription term plus the deletion period described in this DPA |
| Nature | Accessing connected databases, running queries, temporarily caching results, configuring and displaying dashboards, authenticating users, securing and supporting the Service |
| Purpose | Providing the Service according to the Customer’s configuration and instructions |
| Data subjects | Customer personnel, users, clients, sub-clients, and any other individuals whose information the Customer chooses to connect or display |
| Personal-data types | Identity, contact, account, business, usage, transaction, analytical, and other database information selected by the Customer |
| Sensitive data | Not intended for the Service. If the Customer chooses to process sensitive or regulated data, the Customer is responsible for determining that the processing is lawful and safeguards are appropriate |
| Frequency | As initiated by users, scheduled queries, dashboard operation, and related support or security activity |
Annex 2 — Technical and organisational measures
CustomerDashboard’s baseline measures include:
- hosting primary application infrastructure in AWS Europe (Frankfurt);
- authentication through Auth0;
- logical access controls and limiting administrative access to persons who need it;
- protection of data in transit using current transport encryption;
- protected storage of database connection credentials;
- recommending read-only, least-privilege database credentials;
- monitoring, logging, and reasonable investigation of security events;
- maintaining and updating production software and dependencies; and
- deletion and retention practices described in this DPA.
These measures may evolve as the Service develops, provided the overall level of protection is not materially reduced.
Annex 3 — Subprocessors
| Subprocessor | Purpose | Main processing location |
|---|---|---|
| Amazon Web Services | Cloud hosting and infrastructure | Germany / European Economic Area, with possible ancillary global support processing |
| Auth0 / Okta | Authentication and identity management | United States |
| Microsoft Clarity | Behavioural and session analytics, if enabled for the relevant interface | European Union and United States or other Microsoft locations |
| Mixpanel | Product analytics, if enabled for the relevant interface | United States or European Union depending on configuration |
| Google Analytics | Website and product analytics, if enabled for the relevant interface | Global, including the United States |
Analytics providers are subprocessors under this DPA only to the extent they receive Customer Personal Data processed on the Customer’s behalf. CustomerDashboard should configure analytics to avoid collecting database contents, credentials, and dashboard values.
Contact
Privacy and DPA notices: sales@customerdashboard.io