Legal

Data processing agreement

This data processing agreement (“DPA”) forms part of the Cecur Terms of Service between Cecur Limited (Companies Registration Office registration number 815071, registered office The Hive, Carrick-on-Shannon, Co. Leitrim, Ireland) (“Cecur”) and the Customer. It is intended to satisfy Article 28(3) GDPR and, for UK customers, the UK GDPR equivalent, for the processing Cecur performs on the Customer’s behalf through the Cecur portal and suite.

Relationship to product DPAs. Where a Product has its own DPA (CecurSign does), that DPA governs processing inside that Product. This DPA covers the portal itself and any Product without its own DPA. The two are drafted to be consistent and neither varies the other.

Last updated: 26 August 2026

1. Roles

1.1 For most portal processing, Cecur is an independent controller: account registration and authentication, billing, invoicing and tax records, the partner programme, the contact form and platform security. That processing is described in the Cecur privacy notice, not this DPA.

1.2 Cecur acts as the Customer’s processor for personal data the Customer submits about its own personnel and contacts in the course of administering its organisation: the names, email addresses and roles of team members the Customer adds, invites and manages through the Portal, and personal data the Customer submits into Products (which, for a Product with its own DPA, is governed by that DPA).

1.3 The same team member record can fall under both roles at once: Cecur processes it as the Customer’s processor for the Customer’s administration of its team, and as controller for the limited purposes of authenticating that person across the suite, securing the platform and complying with law binding on Cecur.

2. Details of processing (Article 28(3) particulars)

  • Subject matter: provision of the Cecur portal: identity, team management, subscriptions and support across the Cecur product suite.
  • Duration: the term of the Terms of Service, plus the period until deletion or return under clause 9.
  • Nature and purpose: hosting and storage of team member records; creation and administration of login identities; routing of support tickets; dispatch of transactional email.
  • Categories of data subjects: the Customer’s personnel and other individuals the Customer authorises to use its account.
  • Categories of personal data: names, email addresses, roles, authentication events, support ticket contents. The Portal does not require special category data and the Customer should not submit it.

3. Instructions

3.1 Cecur will process personal data under this DPA only on the Customer’s documented instructions, including regarding transfers, unless required to do otherwise by EU, Irish or (where UK GDPR applies) UK law, in which case Cecur will inform the Customer before processing unless the law prohibits it.

3.2 The Terms of Service, this DPA, and the Customer’s use of the Portal’s features (inviting a user, changing a role, removing a user) are the documented instructions.

3.3 Cecur will inform the Customer if, in its opinion, an instruction infringes data protection law.

4. Confidentiality

Cecur ensures that persons authorised to process the personal data are bound by contractual or statutory obligations of confidentiality.

5. Security

Cecur implements the technical and organisational measures described in Annex 2, as required by Article 32 GDPR. Annex 2 is an honest statement of what is in place today. It states where Cecur’s own servers and databases are hosted, and it does not claim encryption at rest, certifications, or residency across every provider in the path, because none of those exists today.

6. Sub-processors

6.1 The Customer gives general written authorisation to the sub-processors listed in Annex 1. The maintained list is published at cecur.io/sub-processors.

6.2 Cecur will give the Customer at least 14 days prior notice of any intended addition or replacement of a sub-processor, by email to the account owner. If the Customer reasonably objects on data protection grounds within 14 days of the notice, the parties will discuss in good faith; if no resolution is found, the Customer may terminate the affected service.

6.3 Cecur imposes on each sub-processor data protection obligations no less protective than this DPA, and remains liable for its sub-processors’ performance.

7. Data subject rights

Taking into account the nature of the processing, Cecur will assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer’s obligation to respond to data subject requests under Chapter III GDPR. If a data subject contacts Cecur directly about processing under this DPA, Cecur will pass the request to the Customer without undue delay.

8. Assistance, breach notification and audits

8.1 Cecur will assist the Customer in ensuring compliance with Articles 32 to 36 GDPR, taking into account the nature of processing and the information available to Cecur.

8.2 Cecur will notify the Customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting the Customer’s personal data, and will provide the information reasonably required for the Customer’s own notification obligations.

8.3 Cecur will make available information reasonably necessary to demonstrate compliance with Article 28 and will allow for and contribute to audits, including inspections, by the Customer or its mandated auditor, subject to reasonable notice, at most once per year unless required by a supervisory authority, and under confidentiality. Cecur may first satisfy an audit request with documentation and written answers.

9. Deletion and return

9.1 On termination, at the Customer’s choice, Cecur will delete or return the personal data processed under this DPA and delete existing copies, unless EU, Irish or applicable UK law requires storage (invoicing and tax records in particular are retained for the statutory period).

9.2 Deletion or return under clause 9.1 will be completed within 90 days of the Customer’s written request.

10. International transfers

Cecur’s own application servers and the databases behind them are hosted in the European Union.

Cecur will not transfer personal data processed under this DPA outside the EEA and the UK except to the sub-processors in Annex 1 or with the Customer’s authorisation, and in each case with a valid transfer mechanism under Chapter V GDPR (for transfers subject to UK GDPR, the UK Addendum to the EU Standard Contractual Clauses or the UK extension to an adequacy framework, as applicable).

11. Liability and order of precedence

Liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where the GDPR does not permit that. If this DPA conflicts with the Terms of Service on data protection matters, this DPA prevails.

Annex 1: Sub-processors

Cecur products and internal Cecur services (CecurSign, the Cecur notification service, DocVault) are operated by Cecur Limited itself and are not sub-processors. The maintained public list is at cecur.io/sub-processors; the table below is the list as at the date of this DPA.

Sub-processorPurposeDataLocation
Auth0 (Okta, Inc.)Identity and authentication for the Customer’s authorised usersNames, email addresses, credentials, MFA enrolment, authentication events.Not yet confirmed.
Resend (Resend, Inc.)Transactional email delivery (invitations, verification, invoices, support replies)Names, email addresses, email content.United States.
OVHcloudManaged PostgreSQL database hostingAll portal data.European Union.
Stripe Payments Europe, Ltd / Stripe, Inc.Payment processingBilling identity and payment data. Cecur acts as controller for billing; listed for transparency.Stripe is a United States company with an Irish entity, Stripe Payments Europe, Ltd.

Cecur’s application servers and the databases behind them are hosted in the European Union. The company that provides that hosting is not yet named in this annex, so the annex is not yet complete on that one point.

Annex 2: Technical and organisational measures

This annex states what is actually implemented as at the date of this agreement. It also serves as the security schedule referred to in the Terms of Service.

  • Hosting location: Cecur’s application servers and the databases behind them are hosted in the European Union.
  • Transport encryption: TLS for all web and API traffic; the database connection to the managed cluster uses TLS with certificate verification.
  • Access control: authentication through Auth0, with optional multi-factor authentication; staff administrative actions require staff accounts and are recorded in an audit log.
  • Customer separation: portal data is scoped to the customer organisation.
  • Payment data: card details are collected by Stripe on Stripe’s own pages and are not stored by Cecur; Cecur stores a Stripe customer reference.
  • Backups: database backups are taken daily.

Not currently in place, stated for honesty: encryption at rest; ISO 27001, SOC 2 or comparable certification; a contractual uptime commitment; UK or EU residency guaranteed end to end across every provider in the path (Cecur’s own servers and databases are in the European Union, but email is delivered from the United States and the region of the production Auth0 tenant is unconfirmed); automated retention or deletion schedules; automated breach detection and alerting.