At a glance
- Role
- Privacy Culture acts as your Processor for the personal data you add and as an independent controlly for the account and usage data.
- Data residency
- Microsoft Azure UK South.
- Security
- Encryption at rest and in transit, role-based and least-privilege access, multi-factor authentication for administrative access.
- Assurance
- Cyber Essentials and independent annual penetration testing
This page summarises the key terms of our standard Data Processing Addendum (DPA). The full DPA forms part of your contract with us and is provided when you sign. It is written to meet the processor requirements of Article 28 of the UK GDPR and EU GDPR.
01
Roles
Privacy Culture acts as your processor for the personal data you add to the Platform, and processes it only on your documented instructions. We act as an independent controller only for the account and usage data needed to run your subscription, as described in our Privacy Notice.
02
What we process
The personal data you record in the Platform to run your privacy programme, including RoPA and data maps, assessments and DPIAs, data subject requests, incidents, vendors, risks and tasks. This may include information about your staff, vendor contacts, requesters and other individuals named in your records. Where you use AI-assisted features, the relevant content is processed to generate a response. It is never used to train models.
03
Where your data is held
All customer data is stored in Microsoft Azure UK South. AI-assisted features are processed in Azure's EEA region (Sweden Central) without being stored there, and transactional emails are sent via Twilio SendGrid in the EU. Transfers to the EEA rely on the UK's adequacy regulations. We will give you at least 30 days' notice before any transfer to another country, and put appropriate safeguards in place first.
