Data Processing Agreement

Last updated: 2026-08-26

This Data Processing Agreement (the "DPA") is Annex 1 to and forms part of the Terms of Service between the customer identified in them (the "Customer") and Causa Prima Germany GmbH, registered with the commercial register of the Local Court (Amtsgericht) of Berlin-Charlottenburg under HRB 286382 B, with registered seat in Berlin ("Causa Prima"). It governs the Processing of Personal Data by Causa Prima on behalf of the Customer in connection with the Services and implements Article 28(3) GDPR. A single acceptance of the Terms of Service — by either method described there — also constitutes acceptance of this DPA.

If there is any conflict between this DPA and the Principal Agreement on a matter relating to Personal Data, this DPA prevails.

1. Definitions

Capitalised terms not defined here have the meaning given in the Principal Agreement or in the GDPR.

  • GDPR: Regulation (EU) 2016/679.
  • Personal Data, Processing, Controller, Processor, Sub-processor, Data Subject, Personal Data Breach and Supervisory Authority: the meanings given in the GDPR.
  • Principal Agreement: the Terms of Service between the Customer and Causa Prima, together with any order form incorporating them.
  • Services and Customer Content: the meanings given in the Principal Agreement.
  • Customer Personal Data: Personal Data that Causa Prima Processes on behalf of the Customer under the Principal Agreement.
  • Customer Data: Customer Content, together with any other data Causa Prima Processes on the Customer's behalf under the Principal Agreement, including the Customer Personal Data contained in it.
  • Connected Source Data: Customer Data received through third-party services the Customer connects or authorizes (including via Google Workspace APIs), and any data derived from it.
  • Anonymised Data: data and derived material — including AI or machine-learning models — that (a) does not relate to an identified or identifiable natural person and cannot be attributed to one by any means reasonably likely to be used, by Causa Prima or another person (Article 4(1) and Recital 26 GDPR), and (b) is no longer attributable to the Customer or to any other identifiable customer of Causa Prima. Data that does not meet both limbs is not Anonymised Data.
  • TOMs: the technical and organisational measures described in Annex A.
  • Sub-processor List: the list of authorised Sub-processors maintained at https://trust.causaprima.ai.

2. Roles and scope of Processing

2.1 The Customer is the Controller of the Customer Personal Data. Causa Prima is the Processor.

2.2 This DPA applies to all Processing of Customer Personal Data carried out by Causa Prima in the course of providing the Services. It does not apply to Personal Data that Causa Prima Processes as an independent Controller for its own purposes — in particular security, audit and integrity logs, and billing and account records — which Causa Prima Processes in accordance with its privacy policy and applicable law.

2.3 For the purposes of Article 28(3) GDPR, the parties agree:

(a) Subject-matter: the provision of the Services by Causa Prima to the Customer under the Principal Agreement. (b) Duration: the term of the Principal Agreement, plus the post-termination return and deletion period under clause 13. (c) Nature and purpose of Processing: hosting, processing and analysis of Customer Personal Data within the Services to deliver the agentic finance workflows ordered by the Customer, including the retrieval of Connected Source Data from third-party services the Customer connects, the operation of AI features on the Customer's inputs, and the production of Anonymised Data under clause 6. (d) Categories of Data Subjects: the Customer's personnel (such as employees, contractors and authorised Users), and any other natural persons whose Personal Data is contained in Customer Data (such as the Customer's end-users, customers, suppliers, and persons appearing in connected messages and documents). (e) Categories of Personal Data: identification data (such as name, e-mail address and role), business contact data, transactional or financial metadata, and Personal Data contained in the documents and messages the Customer or its Users submit to the Services or connect to them (such as names and contact details appearing in invoices and correspondence). No special categories of Personal Data under Article 9 GDPR and no criminal-offence data under Article 10 GDPR are intentionally Processed. (f) Obligations and rights of the Customer: as set out in this DPA and applicable data protection law, including the right to give instructions (clause 3), to receive assistance (clause 8) and to audit (clause 12), and the obligation to ensure that its instructions and the Processing have a lawful basis.

2.4 Each party will comply with its obligations under applicable data protection law, including the GDPR and the German Federal Data Protection Act (BDSG).

3. Instructions

3.1 Causa Prima will Process Customer Personal Data only on documented instructions from the Customer, including with regard to transfers to a third country, unless required to do otherwise by EU or Member State law; in that case, Causa Prima will inform the Customer of that legal requirement before Processing, unless the law prohibits this on important grounds of public interest. The Principal Agreement, this DPA and the Customer's configuration and use of the Services constitute the Customer's documented instructions.

3.2 Causa Prima will inform the Customer without undue delay if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.

4. Confidentiality

Causa Prima ensures that all persons authorised to Process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and receive training on their data protection responsibilities.

5. Security

5.1 Causa Prima implements and maintains the TOMs set out in Annex A, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of Processing, and the risk to Data Subjects (Article 32 GDPR).

5.2 Causa Prima may update the TOMs from time to time, provided the overall level of security is not materially reduced, and will notify the Customer of material changes.

6. Training, learning and Service improvement

6.1 No training of foundational or general-purpose models. Causa Prima does not use identifiable Customer Personal Data to train foundational or general-purpose AI or machine-learning models. This commitment admits no exceptions and cannot be varied by any configuration, instruction or addendum.

6.2 Training and Service improvement on Anonymised Data. Causa Prima may use Customer Data to develop, improve and train the Services and Causa Prima's AI and machine-learning models and related technology, during and after the term of the Principal Agreement, provided that no Customer Data leaves the Customer's instance or is combined with data of other customers for these purposes unless it is Anonymised Data: identifiable Customer Personal Data — and any Customer Data still attributable to the Customer — is anonymised before it crosses that boundary. The production of Anonymised Data is carried out under a documented anonymisation method, which Causa Prima makes available to the Customer on request, and is a Processing step the Customer instructs and authorises under clause 3.1; to the extent Causa Prima determines the purposes of that step, Causa Prima is the controller of it and discloses that processing in its privacy policy. Causa Prima assesses derived material against the definition in clause 1 before use; material that does not meet it is not Anonymised Data and remains subject to this DPA, including clause 13. Causa Prima will not attempt to re-identify any Anonymised Data and contractually prohibits its Sub-processors from doing so. Anonymised Data is not Customer Data; Causa Prima may retain and continue to use it after termination or expiry of the Principal Agreement. The use of Connected Source Data under this clause 6.2 is subject to clause 6.4.

6.3 Per-tenant learning. The Services may learn from the Customer's own Customer Data within the Customer's instance — for example to improve extraction accuracy, matching and workflow behaviour for that Customer. This per-tenant learning is part of providing the Services under the Principal Agreement, remains within the Customer's instance, is not shared with other customers, and is deleted with the Customer's data under clause 13.

6.4 Connected Source Data and source-platform terms. Connected Source Data may be used under clause 6.2 only to the extent the terms of the source platform it was obtained through permit that use; where a source platform's terms restrict the use of data obtained through it — including of anonymised, aggregated or derived data — those restrictions prevail over clause 6.2. Data received via Google Workspace APIs is never used to develop, improve or train generalized or non-personalized AI or machine-learning models and never enters any cross-customer training pipeline in any form, in accordance with the Limited Use requirements of the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy — which reach raw, aggregated, anonymised and derived data alike; no addendum can authorise this, under any circumstance. Beyond clauses 6.2 and 6.3, training on or inclusion in cross-customer uses of identifiable Customer Personal Data requires a separate written addendum executed by both parties containing the Customer's explicit opt-in. Clause 6.1 remains unaffected by any addendum.

7. Sub-processors

7.1 The Customer grants Causa Prima a general written authorisation (Article 28(2) GDPR) to engage Sub-processors to Process Customer Personal Data, subject to this clause 7. Affiliates of Causa Prima that Process Customer Personal Data are engaged as Sub-processors under this clause 7 and identified on the Sub-processor List.

7.2 The Sub-processors currently authorised are set out on the Sub-processor List at https://trust.causaprima.ai, which is the canonical location of the list and identifies, for each Sub-processor, the legal entity, the Processing location and the purpose of the engagement. The list as of the date the Customer accepts the Principal Agreement is incorporated by reference.

7.3 Causa Prima will publish notice of any intended addition or replacement of a Sub-processor on the Sub-processor List at least 15 days before the effective date of the change. The Customer can subscribe to update notifications through the list's subscribe/update feed at the same URL, which is the notice channel for this clause.

7.4 The Customer may object to an intended addition or replacement on reasonable data-protection grounds, in writing, within the notice period. The parties will discuss the objection in good faith; if it is not resolved, the Customer may terminate the affected Services on written notice, as its sole remedy.

7.5 Causa Prima engages only Sub-processors that provide sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the Processing meets the requirements of the GDPR (Article 28(4) GDPR), imposes on each Sub-processor, by written contract, data protection obligations that are no less protective than those in this DPA, and remains fully liable to the Customer for the performance of each Sub-processor's obligations. On the Customer's request, Causa Prima provides a summary of a Sub-processor's data-protection terms. These flow-downs include, for every Sub-processor:

(a) a prohibition on using identifiable Customer Personal Data to train or fine-tune AI or machine-learning models — carried by an express term where the Sub-processor's terms provide one, and otherwise resting on the purpose limitation required by Article 28(3)(a) GDPR, with Causa Prima verifying at onboarding that no own-purpose or service-improvement clause in the Sub-processor's terms reaches identifiable Customer Personal Data. A Sub-processor's use of aggregated or de-identified data for service improvement is accepted only where its terms confine that use to data that identifies no natural person; where the Sub-processor offers an opt-out from the use of customer data for training or service improvement, Causa Prima exercises it. Providers of AI models are engaged only on service tiers or endpoints consistent with this prohibition; (b) no retention of Customer Data for the Sub-processor's own purposes, other than the Sub-processor's own security and billing records, retention required by law, and data that identifies no natural person and no customer; where the Sub-processor offers a zero-data-retention configuration, Causa Prima uses it. At the end of the engagement, Customer Data is deleted or returned on Causa Prima's instruction, with any residual copies retained only where and for as long as law requires or permits and isolated from further Processing, and with the Sub-processor's stated deletion window not exceeding 180 days from when the instruction takes effect. Storage Causa Prima instructs a Sub-processor to perform in order to provide the Services (such as production hosting) is governed by clause 13, not by this clause 7.5(b); and (c) Processing of Customer Personal Data only at the locations stated for that Sub-processor on the Sub-processor List; locations outside the EU/EEA are engaged only in accordance with clause 10.2.

8. Assistance to the Customer

8.1 Taking into account the nature of the Processing, Causa Prima assists the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests from Data Subjects exercising their rights under Chapter III GDPR. If a Data Subject request is made directly to Causa Prima, Causa Prima will forward it to the Customer without undue delay and will not respond on the merits without the Customer's instruction, unless legally required to do so. Causa Prima's contact point for this clause 8 and for Personal Data Breach communications under clause 9 is security@causaprima.ai.

8.2 Causa Prima assists the Customer in ensuring compliance with the Customer's obligations under Articles 32 to 36 GDPR (security of Processing, breach notification, data protection impact assessments and prior consultation), taking into account the nature of the Processing and the information available to Causa Prima.

8.3 Causa Prima may charge the Customer reasonable costs for assistance under this clause 8 that goes beyond the functionality of the Services and Causa Prima's standard support. Assistance in connection with a Personal Data Breach under clause 9 is provided at no additional cost.

9. Personal Data Breach

9.1 Causa Prima will notify the Customer of a Personal Data Breach affecting Customer Personal Data without undue delay, and in any event within 72 hours of becoming aware of it.

9.2 The notification will contain the information required by Article 33(3) GDPR, to the extent then available: the nature of the breach, including where possible the categories and approximate number of Data Subjects and records concerned; the name and contact details of Causa Prima's contact point (security@causaprima.ai); the likely consequences; and the measures taken or proposed to address the breach and mitigate its effects.

9.3 Where and insofar as it is not possible to provide all of this information at the same time, Causa Prima may provide it in phases as the investigation progresses, without undue further delay; the initial notification is not delayed until the information is complete.

9.4 Causa Prima will cooperate with the Customer, take reasonable steps to contain, mitigate and remediate the breach, and document the breach, its effects and the remedial action taken.

10. Processing location and international transfers

10.1 Causa Prima Processes Customer Personal Data on its own infrastructure only at the locations disclosed to the Customer — on the Sub-processor List for the cloud infrastructure Causa Prima uses, and in this clause. As at the date of this DPA, all Processing on Causa Prima's own infrastructure takes place within the European Union or the European Economic Area (EEA). Processing on Causa Prima's own infrastructure outside the EEA is permitted under Causa Prima's data protection standards but takes place, if at all, only under clause 10.2 and only after the disclosed locations have been updated. The locations at which each Sub-processor Processes Customer Personal Data are stated on the Sub-processor List; Sub-processor Processing locations are governed by clause 7.5(c).

10.2 Where, by way of exception, Customer Personal Data is to be Processed outside the EEA, (a) the non-EEA Processing location is disclosed before the Processing begins — on the Sub-processor List for Sub-processors (or, for Sub-processors engaged before the Principal Agreement, as at the date the Customer accepts the Principal Agreement), and by an update to the disclosed locations under clause 10.1 for Causa Prima's own infrastructure — and (b) the transfer is covered by a transfer mechanism under Chapter V GDPR: an adequacy decision of the European Commission, where applicable; otherwise the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), in the module appropriate to the parties' roles, supplemented by a transfer impact assessment and supplementary measures where required; or the EU–US Data Privacy Framework, where the recipient is certified. For transfers Causa Prima itself makes to its own infrastructure outside the EEA, the EU Standard Contractual Clauses are the primary mechanism, with adequacy decisions relied on as additional comfort.

10.3 The transfer mechanism applicable to a Sub-processor is documented in that Sub-processor's data processing terms, linked from the Sub-processor List.

11. Government access requests

If Causa Prima receives a legally binding request from a public authority for access to Customer Personal Data, Causa Prima will (a) notify the Customer of the request without undue delay, unless legally prohibited from doing so; (b) where notification is prohibited, use reasonable efforts to direct the requesting authority to the Customer; (c) not voluntarily disclose Customer Personal Data to any public authority; and (d) where lawful and reasonable, challenge a request that is manifestly disproportionate or unlawful. Causa Prima recognises a judgment or decision of a court or authority of a third country requiring disclosure of Customer Personal Data only where it is based on an international agreement in force between that third country and the EU or a Member State (Article 48 GDPR). This clause does not apply to disclosures that Causa Prima itself lawfully initiates under EU or Member State law (such as a report Causa Prima is required by EU or Member State law to make to a competent authority).

12. Audits and demonstration of compliance

12.1 Causa Prima makes available to the Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, in accordance with this clause 12.

12.2 Reports first. Causa Prima makes its security documentation — including any third-party audit reports and certifications Causa Prima holds from time to time (such as SOC 2 reports and ISO/IEC 27001 certificates) — available through its trust center at https://trust.causaprima.ai or on request under confidentiality obligations. The Customer will first review this information and will accept it in satisfaction of an audit request to the extent it reasonably demonstrates compliance.

12.3 Where the information under 12.2 is not sufficient, the Customer may conduct an audit or inspection on reasonable prior written notice, at the Customer's cost, no more than once in any 12-month period — unless a Personal Data Breach affecting Customer Personal Data has occurred or a Supervisory Authority requires it. Audits are conducted during normal business hours, in a manner that does not unreasonably disrupt Causa Prima's operations or compromise the security or confidentiality of other customers' data, and the auditor is bound by appropriate confidentiality obligations.

12.4 Causa Prima maintains records of Processing activities carried out on behalf of the Customer as required by Article 30(2) GDPR and makes them available to the Supervisory Authority on request.

13. Return and deletion

13.1 On termination or expiry of the Principal Agreement — or, if earlier, the end of the provision of the Services to which particular Customer Personal Data relates — Causa Prima will, at the Customer's choice, delete or return the Customer Data (including all Customer Content) within 30 days of that date, rendering it inaccessible for any further Processing, and, subject to clause 13.3, not before the end of that period, unless EU or Member State law requires storage. If the Customer makes no choice within that period, Causa Prima deletes the Customer Data. Copies in backup and archival systems are deleted in accordance with clause 13.4. Anonymised Data produced under clause 6 is not Customer Data and is not subject to this clause 13; its retention and use are governed by clause 6.2.

13.2 Customer Personal Data that Causa Prima is required by law to retain (in particular accounting records and invoices under § 257 HGB and § 147 AO) is retained in accordance with Causa Prima's data retention schedule, remains protected under this DPA for as long as it is held, and is deleted when the applicable statutory retention period ends.

13.3 During the 30-day period under clause 13.1, Causa Prima will, on the Customer's request, return Customer Personal Data by making the Customer Content containing it available for export in a commonly used format, before deletion.

13.4 Customer Personal Data contained in backups is deleted through Causa Prima's standard rolling backup cycle, at the end of which it is no longer accessible; it is not restored to active systems except as needed for recovery, in which case this clause 13 continues to apply to it. The same applies to residual copies in Sub-processors' backup and archival systems, which are purged through those systems' documented cycles and in any event within 180 days.

13.5 On the Customer's written request, Causa Prima confirms deletion in writing.

14. Liability

The liability of each party under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement. Statutory liability under the GDPR — including each party's liability under Article 82 GDPR and administrative fines imposed on a party in its own right — is not excluded or limited where such exclusion or limitation is not permitted by law.

15. Term, governing law and miscellaneous

15.1 This DPA takes effect on the effective date of the Principal Agreement and remains in force for as long as Causa Prima Processes Customer Personal Data on behalf of the Customer, including during the return and deletion period under clause 13.

15.2 This DPA is governed by the laws of the Federal Republic of Germany, excluding the United Nations Convention on Contracts for the International Sale of Goods (CISG) and conflict-of-laws rules. The jurisdiction provisions of the Principal Agreement apply; where the Customer is a merchant (Kaufmann), the exclusive place of jurisdiction for all disputes arising out of or in connection with this DPA is Berlin, Germany.

15.3 If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in full force, and the invalid provision is replaced by a valid one that comes as close as possible to the original intent.

15.4 This DPA is concluded in English.

Annex A — Technical and Organisational Measures (TOMs)

These technical and organisational measures are implemented and maintained by Causa Prima under Article 32 GDPR. They are embedded in, and form an integral part of, this DPA; the version in force when the Customer accepts the Principal Agreement applies, and updates are governed by clause 5.2. They describe the capabilities Causa Prima operates; they do not create service levels, recovery-time commitments or other performance figures beyond those stated in the Principal Agreement.

1. Pseudonymisation and encryption (Art. 32(1)(a) GDPR)

  • Customer Personal Data in transit — between the Customer and the Services, and between Causa Prima and its Sub-processors — is encrypted using TLS.
  • Customer Personal Data at rest in production databases and object storage is encrypted.
  • Backups are encrypted.
  • Access to encryption key material is restricted to privileged accounts.
  • Personal data and authentication secrets are not written to application logs in full: log call sites are designed to accept only opaque identifiers, a rule enforced through code review.

2. Confidentiality and access control (Art. 32(1)(b) GDPR)

  • Physical. Causa Prima operates no data centres of its own; production systems run on Google Cloud Platform, whose data centres are certified against ISO/IEC 27001 and audited under SOC 2. Office locations used by group personnel hold no production systems and no Customer Personal Data.
  • Authentication. Access is passwordless-first: Single Sign-On, passkeys, magic links and federated identity providers. Multi-factor authentication or an equivalently strong passwordless method is required for all access to Causa Prima systems, including by administrators and third parties; disabling or bypassing it is prohibited. Residual passwords (service accounts, break-glass) are generated and stored only in the company password manager.
  • Identity. Each user has a unique identity, verified once during onboarding and provisioned through the identity provider; default and built-in administrative accounts are removed, disabled or restricted to named administrators.
  • Least privilege. Access follows role-based access control on the principle of least privilege: each user and service receives only the access its role requires. Nothing is granted without documented approval, no one approves their own access, and privileged utility programs are restricted to authorised engineering personnel.
  • No standing production access. Production access is disabled by default; nobody holds permanent administrative access to production systems. Access is granted just-in-time on CTO approval, for a specific purpose and a limited period, and is logged.
  • Access reviews. All accounts and permissions — including third-party and vendor accounts and just-in-time production grants — are reviewed quarterly against the holder's current role, with removals recorded and the completed review approved by Executive Leadership.
  • Inactivity. Accounts unused for 90 days are disabled; sessions end after a defined period of inactivity and require re-authentication.
  • Revocation. Access is revoked within 48 hours of the effective termination date for anyone leaving Causa Prima, and immediately where the departure is involuntary or for cause, or where misuse or credential compromise is suspected.
  • Tenant separation. Each customer's data is logically separated by a unique tenant identifier, and the separation is enforced at the database layer: tenant-scoped tables carry row-level-security policies that are forced for all database roles, so queries return only the current tenant's rows.

3. Integrity (Art. 32(1)(b) GDPR)

  • Change management. Every change to production systems is documented, assessed for security and availability impact, tested before deployment, approved by someone other than the person who made it (four-eyes), and has a documented way to be reverted to a known good state. Unapproved changes found in production are reviewed and either reverted or approved retrospectively, with the outcome recorded.
  • Code review. Changes to code are reviewed and approved before merging, enforced by branch protection rules on protected branches; changes that materially affect security are additionally reviewed by the CTO.
  • Environment separation. Changes are verified in test environments separate from production before deployment.
  • Logging and monitoring. All access to production systems is logged and production systems have security monitoring enabled; availability, security events and vulnerabilities are monitored, with alerts routed to Engineering, and logs are reviewed in response to incidents and on a regular basis.
  • Data leakage prevention. E-mail and messaging platforms are configured to restrict the movement of Restricted and Confidential data outside Causa Prima, and the resulting alerts are monitored.

4. Availability and resilience (Art. 32(1)(b) and (c) GDPR)

  • Backups. Full backups of production databases run daily and are encrypted, with continuous point-in-time recovery enabled on production databases.
  • Backup access. Access to backups is restricted to authorised personnel; ad-hoc access is revoked as soon as it is no longer needed, and contractors have no access to production backups without executive approval.
  • Restore testing. Backup restoration and disaster recovery are tested at least annually; results are reviewed internally and recovery procedures adjusted based on what the tests show.
  • Continuity. Causa Prima maintains a documented business continuity plan and disaster recovery plan. Production runs on cloud infrastructure; recovery from a regional failure takes place within the cloud platform, in a region other than the affected one. The loss of an office is a personnel and logistics event only, as no office hosts production systems.

5. Regular testing, assessment and evaluation (Art. 32(1)(d) GDPR)

  • Incident response. Every user reports information security events, incidents and vulnerabilities to the Security Officer immediately, through a single channel, without waiting to confirm anything first. The Security Officer assesses each report within 12 hours, decides whether it is an incident and assigns a severity. Evidence — logs, files, configuration state — is preserved before affected systems are rebuilt or wiped, wherever containment allows. Every resolved incident receives a post-incident review that establishes the root cause and feeds back into controls, the plan and training; the plan itself is tested at least annually. Personal Data Breaches are notified to the Customer under clause 9 of this DPA.
  • Vendor management. Vendors pass due diligence before onboarding and are risk-tiered; the highest tier must evidence a current ISO 27001 certification, an unqualified SOC 2 Type 2 report or equivalent, or complete a security due-diligence questionnaire. Relationships involving Restricted or Confidential data require executed agreements (NDA and/or DPA) with security and breach-notification obligations. The vendor list is reviewed at least annually, and material changes to a vendor's service trigger reassessment.
  • Data classification. Data is classified into defined sensitivity tiers, and the handling controls that apply — including encryption — follow the data's classification.
  • Personnel. All personnel and third parties with access to Customer Personal Data are bound by enforceable confidentiality or non-disclosure obligations before access is granted, and are trained on recognising and reporting security incidents on joining and at least annually thereafter.
  • Policy review. The information security policy set is reviewed at least annually, or when there is a significant change to the business.

6. Instruction and deletion control (Art. 28, 29 and 32(4) GDPR)

  • Instruction control. Customer Personal Data is Processed only on the Customer's documented instructions (clause 3); personnel with access are instructed on the permitted scope of Processing, and onward instructions to Sub-processors mirror the Customer's instructions to Causa Prima.
  • Deletion control. Data that is no longer required is deleted in accordance with the Causa Prima Data Retention Policy and deletions are recorded; in cloud systems deletion runs through the provider's deletion APIs, deleted data ages out of backups within the standard rolling backup cycle, and company devices are wiped before reassignment or disposal.
  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Cookie Policy
  • Imprint