CRATARA legal

Data Processing Terms

These terms apply when CRATARA processes personal data in Customer Content on behalf of a customer organization. A separately signed data processing agreement controls if it conflicts with this page.

Effective August 26, 2026

1. Roles and instructions

Customer is the business, controller or responsible organization for Customer Content; Provider is its service provider or processor. Provider will process personal data only to provide, secure, maintain and support CRATARA, follow documented lawful instructions, comply with law, and as otherwise permitted by the agreement. Customer is responsible for the lawfulness, accuracy and scope of its instructions.

2. Processing details

The subject matter is operation of a multi-tenant warehouse SaaS. Processing lasts for the authorized service period plus retention needed for return, deletion, backups, security, disputes and law. Activities can include collection, storage, organization, retrieval, display, transmission, logging, support and deletion. Data subjects can include Customer's users, employees, contractors, clients, suppliers, recipients and contacts. Categories are described in the Privacy Policy and can include identity, contact, role, operational activity, scans, notes and evidence photos.

3. Confidentiality and security

Provider will limit access to personnel and providers who need it for their duties and are subject to confidentiality obligations. Provider will maintain reasonable technical and organizational safeguards appropriate to the service and risk, including authenticated access, organization-scoped authorization, secure transport, role controls, restricted evidence storage and security logging. Customer remains responsible for role assignment, endpoint security and lawful operational procedures.

4. Subprocessors

Customer authorizes the subprocessors listed on the Subprocessors page. Provider remains responsible for requiring appropriate data-protection obligations from subprocessors used to process Customer Content. A signed order may provide additional notice or objection procedures.

5. Requests and assessments

Taking into account the nature of processing, Provider will reasonably assist Customer with verified data-subject requests, security assessments and information needed for Customer's compliance, where the information is available to Provider. Customer should first use available account tools. Work beyond standard support may require a written scope and reasonable fees.

6. Security incidents

Provider will notify Customer without undue delay after confirming unauthorized access to Customer Personal Data that requires notice under applicable law, and will provide reasonably available information needed for Customer's response. Notice is not an admission of fault. Customer must maintain current security contacts and notify Provider promptly of incidents involving its users, credentials or devices.

7. Sale, advertising and AI training restrictions

Provider will not sell Customer Personal Data, share it for cross-context behavioral advertising, retain or use it outside the direct business relationship except as permitted by law, or use Customer Content to train a general-purpose AI model. Provider may create aggregated or de-identified operational statistics only when they cannot reasonably identify Customer or an individual and are protected against re-identification.

8. Return and deletion

On termination and verified written instruction, Provider will reasonably return or delete Customer Personal Data unless retention is required by law, needed for security or disputes, contained in protected audit history, or remains in backups until the ordinary deletion cycle. The parties may define specific export formats and retention periods in an order form.

9. International transfers

Customer acknowledges that data may be processed where Provider and its subprocessors operate. If a legally required transfer mechanism or jurisdiction-specific addendum is needed, the parties will execute an appropriate written addendum before the regulated transfer.

Contact

Data-processing questions or security notices may be sent to asielhernandezmartinez@gmail.com.