CEDX Systemscedxsystems.com
Legal

Data processing agreement

This agreement governs everything CEDX does with personal data inside a customer's tenant. The customer is the controller and decides what the data is for; CEDX is the processor and acts only on the customer's instructions. It is incorporated into the terms of service and applies automatically to every subscription, no separate signature is required, although a countersigned copy is available on request.

Version
5.1
Last updated
14 May 2026
Effective from
1 July 2026
Contents

1.Interpretation

Terms defined in the terms of service have the same meaning here. In addition:

Data Protection Law
the UK GDPR, the Data Protection Act 2018, Regulation (EU) 2016/679, and any other law governing the processing of personal data that applies to a party in respect of the Services.
Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Supervisory Authority
have the meanings given to them in Data Protection Law.
Customer Personal Data
Personal Data contained within Customer Data and processed by CEDX on the Customer's behalf under the Agreement.
Sub-processor
any processor engaged by CEDX to process Customer Personal Data, including an affiliate of CEDX.
Standard Contractual Clauses
the clauses annexed to Commission Implementing Decision (EU) 2021/914, and where the UK GDPR applies, those clauses as modified by the UK Addendum issued by the Information Commissioner.

2.Status of the parties

  1. 2.1For Customer Personal Data the Customer is the Controller and CEDX is the Processor. Where the Customer is itself a processor for a third party, CEDX is a sub-processor and this agreement applies as if references to the Controller were references to that third party.
  2. 2.2The Customer is responsible for establishing a lawful basis for the processing, for providing any notice or obtaining any consent Data Protection Law requires, and for the accuracy and lawfulness of the Customer Personal Data it submits.
  3. 2.3CEDX acts as an independent Controller only in respect of account administration data, billing records and platform security telemetry. That processing is described in the privacy notice and is outside the scope of this agreement.
  4. 2.4Each party will comply with the obligations that apply to it under Data Protection Law. Neither party's compliance relieves the other of its own obligations.

3.Particulars of the processing

The subject matter, duration, nature, purpose, categories of Personal Data and categories of Data Subject are as follows. This clause constitutes the record required by Article 28(3) of the UK GDPR.

Particulars of processing carried out by CEDX Systems Limited as processor.
ParticularDetail
Subject matterProvision of the CEDX applications and platform services identified on the Order Form.
DurationThe Subscription Term, plus the thirty-day export window and the deletion period described in clause 11.
Nature of processingCollection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, restriction, erasure and destruction, by automated means.
PurposeTo provide, secure, support and administer the Services for the Customer, and to carry out the Customer's documented instructions.
Categories of Data SubjectThe Customer's employees, contractors and other authorised users; the Customer's own customers, suppliers, applicants and other counterparties whose records the Customer chooses to hold in the Services.
Categories of Personal DataIdentification and contact data, employment and organisational data, transaction and financial records, communications content, access and authorisation records, and audit and activity logs.
Special category dataOnly where the Customer configures a product that is designed to hold it, such as absence records in CEDX People. The Customer determines whether to submit it and is responsible for the Article 9 condition relied upon.
FrequencyContinuous, for the duration of the Subscription Term.
Particulars of processing carried out by CEDX Systems Limited as processor.

4.Instructions

  1. 4.1CEDX will process Customer Personal Data only on the Customer's documented instructions. The Agreement, the product documentation and the configuration the Customer applies within the Services together constitute those instructions.
  2. 4.2CEDX will not process Customer Personal Data for its own purposes, will not sell it, and will not use it to train any machine learning model made available to another customer.
  3. 4.3Where CEDX is required by law to process Customer Personal Data other than on the Customer's instructions, it will inform the Customer of that requirement before processing, unless the law prohibits it from doing so on important grounds of public interest.
  4. 4.4CEDX will inform the Customer promptly if, in its opinion, an instruction infringes Data Protection Law. CEDX may suspend performance of that instruction until it is withdrawn, amended or confirmed.
  5. 4.5The Customer may issue additional written instructions. Where an instruction requires work beyond what the Services provide, CEDX may charge a reasonable fee, agreed in advance.

5.Confidentiality of personnel

  1. 5.1CEDX will ensure that every person it authorises to process Customer Personal Data is subject to a binding written obligation of confidentiality that survives the end of their engagement.
  2. 5.2Access is limited to those personnel who need it to provide or support the Services, is granted for the shortest period that achieves the purpose, and is revoked automatically on a change of role or on leaving.
  3. 5.3All personnel with access complete data protection and security training on joining and annually thereafter. Completion is recorded and is auditable.
  4. 5.4Personnel with access to production environments are subject to background screening appropriate to the role and to the jurisdiction, carried out before access is granted.

6.Security measures

CEDX implements and maintains the technical and organisational measures set out below, which constitute the measures required by Article 32. CEDX may replace a measure with one that is at least equivalent, and will not degrade the overall level of security during the Subscription Term.

Technical and organisational measures maintained by CEDX Systems Limited.
AreaMeasure
EncryptionTLS 1.3 in transit; AES-256 at rest. Keys held in FIPS 140-2 Level 3 hardware security modules and rotated annually. Customer-managed keys available on enterprise subscriptions.
Access controlLeast privilege enforced by the platform entitlement service; multi-factor authentication mandatory for all personnel; time-bound, reason-recorded elevation for production access; quarterly access review.
Tenant isolationLogical isolation enforced at the data layer rather than in application code, with cross-tenant reads structurally impossible and continuously tested.
ResidencyCustomer Personal Data stored only in the region selected on the Order Form. Eleven regions available; regional isolation continuously verified.
Logging and monitoringImmutable audit trail of every administrative and data-access action, retained for thirteen months and available to the Customer through the platform.
ResilienceMulti-zone deployment within each region; recovery point objective of five minutes and recovery time objective of two hours; restoration tested quarterly.
Secure developmentPeer review of every change; static analysis and dependency scanning in the pipeline; segregated environments; no production data in test.
AssuranceISO/IEC 27001 certification, annual SOC 2 Type II examination, and independent penetration testing at least annually and after material architectural change.
PersonnelBackground screening, confidentiality obligations, annual training, and documented joiner, mover and leaver processes.
Supplier managementDocumented due diligence before engagement, written processing terms, and annual reassessment of every Sub-processor.
Technical and organisational measures maintained by CEDX Systems Limited.

7.Sub-processing

  1. 7.1The Customer gives CEDX general written authorisation to engage Sub-processors, subject to this clause. The current Sub-processors are listed on the sub-processors page, which forms part of this agreement.
  2. 7.2CEDX will impose on each Sub-processor, by written contract, data protection obligations no less onerous than those in this agreement, and remains fully liable to the Customer for that Sub-processor's performance.
  3. 7.3CEDX will give at least thirty days' notice before adding or replacing a Sub-processor. Notice is given by updating the sub-processors page and by email to the address the Customer has registered for that purpose.
  4. 7.4The Customer may object to a proposed Sub-processor within thirty days of notice, on reasonable grounds relating to data protection. The parties will discuss the objection in good faith and CEDX will use reasonable efforts to make available a change in configuration or a workaround that avoids the Sub-processor.
  5. 7.5Where no reasonable alternative can be made available within thirty days of the objection, the Customer may terminate the affected subscription on written notice and receive a refund of Fees paid for the unused remainder of the Subscription Term. This is the Customer's sole remedy for an objection.
  6. 7.6Sub-processors engaged solely to provide infrastructure capacity, with no ability to access Customer Personal Data in an intelligible form, do not require notice under clause 7.3 but are listed for completeness.

8.Data subject requests

  1. 8.1The Services provide functions allowing the Customer to access, correct, restrict, export and delete Customer Personal Data. In most cases the Customer can answer a data subject request itself without involving CEDX.
  2. 8.2Where CEDX receives a request directly from a Data Subject relating to Customer Personal Data, it will not respond to it substantively. It will confirm receipt, direct the individual to the Customer, and inform the Customer without undue delay and in any event within three Working Days.
  3. 8.3Where the Customer cannot answer a request using the functions in the Services, CEDX will provide reasonable assistance, taking into account the nature of the processing and the information available to it.
  4. 8.4Assistance under clause 8.3 is provided at no charge for the first ten requests in any twelve-month period, and thereafter at CEDX's standard professional services rates.

9.Assistance to the controller

  1. 9.1CEDX will provide the Customer with reasonable assistance in carrying out a data protection impact assessment relating to the Services, and in any prior consultation with a Supervisory Authority that arises from it.
  2. 9.2CEDX maintains and publishes a standard assessment pack covering the architecture, the security measures, the sub-processors and the transfer mechanisms. In most cases this pack is sufficient and no bespoke work is required.
  3. 9.3CEDX will provide reasonable assistance in demonstrating the Customer's compliance with Articles 32 to 36, taking into account the nature of the processing and the information available to CEDX.
  4. 9.4Assistance beyond the provision of the standard pack and reasonable follow-up questions may be charged at CEDX's standard professional services rates, agreed in advance.

10.Personal data breach

  1. 10.1CEDX will notify the Customer without undue delay, and in any event within twenty-four hours of becoming aware, of any Personal Data Breach affecting Customer Personal Data.
  2. 10.2The initial notification will describe the nature of the breach, the categories and approximate number of Data Subjects and records affected so far as known, the likely consequences, the measures taken or proposed, and a named contact. Where the full picture is not yet available, CEDX will provide information in phases rather than delay the first notification.
  3. 10.3CEDX will not notify a Supervisory Authority or any Data Subject on the Customer's behalf unless the Customer instructs it to in writing, or unless CEDX is itself required to do so by law.
  4. 10.4CEDX will take reasonable steps to contain the breach, to mitigate its effects and to preserve evidence, and will cooperate with the Customer's own investigation.
  5. 10.5CEDX will provide a written root cause analysis within ten Working Days of the breach being contained, including the remedial actions taken and the date each was completed.
  6. 10.6A notification under this clause is not, of itself, an admission of fault or of liability by CEDX.

11.Deletion and return

  1. 11.1On expiry or termination CEDX will retain Customer Personal Data in the Customer's tenant for thirty days so that the Customer can export it using the functions in the Services.
  2. 11.2At any point during that window the Customer may instruct CEDX in writing to return the data in a documented machine-readable format, or to delete it immediately.
  3. 11.3Unless the Customer instructs otherwise, CEDX will delete all Customer Personal Data from production systems within thirty days of the end of the export window, and from backups within a further ninety days as those backups reach the end of their normal rotation.
  4. 11.4CEDX may retain Customer Personal Data where required to do so by law, in which case it will retain only what the law requires, will continue to protect it under this agreement, and will process it only for the purpose that requires its retention.
  5. 11.5CEDX will certify deletion in writing on request, at no charge.

12.Audit and inspection

  1. 12.1CEDX will make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28, including its current ISO/IEC 27001 certificate, its most recent SOC 2 Type II report, and a summary of its most recent penetration test.
  2. 12.2The Customer may audit CEDX's compliance once in any twelve-month period, and additionally following a Personal Data Breach affecting its own data or a specific instruction from a Supervisory Authority.
  3. 12.3An audit requires thirty days' written notice, must be conducted during business hours, must not unreasonably disrupt CEDX's operations, and is subject to confidentiality. The Customer bears its own costs, and CEDX's reasonable costs where the audit exceeds two working days.
  4. 12.4An audit may be conducted by the Customer's own staff or by an independent auditor who is not a competitor of CEDX and who accepts the same confidentiality obligations.
  5. 12.5CEDX will not permit an audit to access another customer's data, and may substitute evidence or an attested response where physical access would compromise the security of the platform or the confidentiality of another customer.

13.International transfers

  1. 13.1CEDX will store and process Customer Personal Data only in the region selected by the Customer on the Order Form.
  2. 13.2Where a transfer outside that region is necessary to provide the Services (for example, follow-the-sun support access under an enhanced service level) the transfer is made only with the Customer's configured consent, is limited to the data necessary for the specific purpose, and is recorded in the audit trail.
  3. 13.3Where a transfer is made to a country without an adequacy decision, the Standard Contractual Clauses apply and are incorporated into this agreement by reference. Module Two applies where the Customer is a controller and Module Three where the Customer is itself a processor.
  4. 13.4For transfers subject to the UK GDPR, the UK Addendum applies, with CEDX as the data importer or exporter as the case requires, and with the information required by Table 1 to Table 4 of the Addendum taken from the Order Form and from clause 3 of this agreement.
  5. 13.5CEDX maintains a transfer risk assessment for each transfer, reviewed annually, and will provide a copy on request with commercial terms redacted.
  6. 13.6Where CEDX receives a legally binding request from a public authority for Customer Personal Data, it will challenge the request where there is a reasonable basis to do so, will disclose only the minimum required, and will notify the Customer unless legally prohibited. Where prohibited, it will use reasonable efforts to obtain a waiver and will publish the volume of such requests in aggregate.

14.Liability and precedence

  1. 14.1Liability under this agreement is subject to the limitations in clause 13 of the terms of service, with the enhanced cap in clause 13.4 applying to a breach of this agreement by CEDX.
  2. 14.2Where the parties are jointly liable to a Data Subject, each party bears the share of liability corresponding to its own responsibility for the damage.
  3. 14.3In the event of conflict, this agreement prevails over the terms of service in respect of the processing of Personal Data, and the Standard Contractual Clauses prevail over this agreement.
  4. 14.4This agreement takes effect automatically for every Customer with an active subscription and requires no separate signature. A countersigned copy is available on request to privacy@cedxsystems.com.
  5. 14.5This agreement terminates automatically when the Agreement terminates and the deletion obligations in clause 11 have been discharged.
Related documents

Questions about any of these documents go to our legal and privacy contacts. Enterprise customers may request countersigned copies through their account team.