LEGAL

Data Processing

How CREANODE processes personal data on behalf of client organizations acting as data controllers. This document applies when CREANODE acts as a data processor.

01

Controller & Processor Roles

When CREANODE develops and operates systems that process personal data belonging to a client organization's customers or users, the client organization is the data controller and CREANODE acts as a data processor. CREANODE processes such data only on documented instructions from the controller and for the purposes specified in the project agreement.

02

Processing Activities

Processing activities performed by CREANODE as a data processor are limited to: hosting and operating client systems, performing maintenance and updates, providing technical support, and performing security monitoring. CREANODE does not process client organization data for any purpose beyond what is necessary to deliver contracted services.

03

Sub-Processors

CREANODE uses infrastructure providers (hosting, email delivery) as sub-processors. Sub-processors are located in the EU/EEA or in jurisdictions with adequate data protection. Client organizations are informed of sub-processor changes in advance of implementation. A full list of sub-processors is available on request.

04

Security Measures

CREANODE implements technical and organizational security measures appropriate to the risk level of the data being processed: access controls, encryption in transit and at rest, audit logging, regular security updates, and incident response procedures. Specific security measures for a given client system are documented in the project architecture documentation.

05

Data Processing Agreement

Organizations requiring a formal Data Processing Agreement (DPA) in accordance with GDPR or other applicable regulation can request one through the contact form. The DPA specifies the nature, purpose, and duration of processing, the categories of data involved, and the technical and organizational measures in place.

Request a DPA →