# 1. Scope & Definitions
These processing terms apply where Certifada processes recipient and workspace data for the customer. The customer determines the purpose, recipients, fields, and publication settings. Processing covers storage, issuance, delivery, verification, support, and deletion for the service duration and applicable retention period. Data may include names, contact details, credential content, and activity records relating to recipients and authorized users. A signed DPA and its completed schedules take precedence for their subject matter.
# 2. Processor Obligations
We process customer data on documented instructions, subject to law, and require confidentiality and appropriate security. We assist with rights requests, breaches, and legally required assessments. We notify customers of a personal-data breach without undue delay after awareness. At the end of processing, we return or delete data as instructed unless law requires retention. Instructions that appear unlawful will be raised with the customer.
# 3. Standard Contractual Clauses (SCCs)
Where required, the parties must document the applicable transfer mechanism, parties, processing details, and safeguards before a restricted transfer. A reference to EU Standard Contractual Clauses alone does not complete their annexes or resolve UAE or other local transfer requirements. Contact hello@cuspforge.com to arrange the appropriate documentation.
# 4. Authorized Subprocessors
The provider list identifies services used for customer processing and optional integrations. For subprocessors we engage on the customer’s behalf, we require appropriate data protection terms and remain responsible for their obligations under the applicable DPA. We provide at least 14 days’ advance notice of intended additions or replacements and an opportunity to raise reasonable data-protection objections. Customer-selected integrations are governed by the customer’s provider arrangements.
# 5. Security Audits & Compliance Documentation
We provide information reasonably needed to demonstrate applicable processor obligations and cooperate with proportionate audits under the DPA, with safeguards for confidentiality, security, and other customers. An audit report or certification is represented as available only when specifically confirmed. Contact hello@cuspforge.com for due-diligence requests.