The customer is the controller and [Operator name] is the processor of personal data contained in the customer's cases, evidence, contacts and logs (Art. 28 GDPR).
Processing to provide CRA IncidentOps for the term of the subscription and until the data is deleted.
The processor acts only on the customer's documented instructions; staff access is restricted and bound by confidentiality. The operator console shows subscription details and usage counts only, never case content.
See the security measures.
The current list is on the subprocessors page. Customers are notified of new subprocessors in advance and may object.
The processor assists with data subject requests, impact assessments and breach notifications, and notifies the customer of a personal data breach without undue delay.
Customer administrators can export all data; deletion takes place 30 days after the request, and backups are removed within [period].
[Procedure for information requests and audits.]