The agreement covering our processing of personal data on your behalf, under Article 28 GDPR.
Status: this is the standing agreement offered to all customers. A countersigned copy is available on request. get in touch and it will be sent for signature. Customers with their own DPA template are welcome to send it; it will be reviewed rather than refused on principle.
The customer is the controller and itbudgit is the processor of personal data contained in the customer's workspace. Processing is carried out solely to provide the service described at itbudgit.com and for the duration of the subscription.
Categories of data subject: the customer's staff and any individuals named in their budget data. Categories of data: names, work email addresses, job titles, reporting lines, and where the customer uses the staffing features, position costs.
itbudgit processes personal data only on the documented instructions of the customer, which include the use of the service itself. Where a legal obligation requires processing beyond those instructions, the customer is informed before processing unless the law forbids it.
Persons authorised to process the data are bound by confidentiality.
The technical and organisational measures are described in full on the Security page, which forms part of this agreement: tenant isolation by row-level security with a per-deploy audit against the live database, server-side role enforcement, encryption in transit, an origin restricted at the network layer, nightly backups with a rehearsed restore, and the stated six-hour point-in-time recovery window.
The customer gives general authorisation for the sub-processors listed on the Sub-processors page. itbudgit will notify customers before a new sub-processor begins processing, with sufficient notice to object.
The application and database are located in Germany. Two sub-processors are US-headquartered, Stripe and Clerk, and transfers to them rely on the EU Standard Contractual Clauses and, where applicable, their certification under the EU–US Data Privacy Framework.
itbudgit assists the customer in responding to data subject requests, and in meeting obligations for security, breach notification and impact assessments, taking into account the nature of processing and the information available.
itbudgit notifies the customer without undue delay, and within 72 hours of becoming aware, of a personal data breach affecting their data.
The customer may export all data at any time as a workbook, without a request. On termination, data is deleted on request via the erasure process described under GDPR. Stripe invoices are excluded and are retained as financial records under a legal obligation.
itbudgit makes available the information necessary to demonstrate compliance with Article 28 and allows for audits by the customer or an auditor they mandate, on reasonable notice and no more than once a year except following a breach.
To be explicit: there is no SOC 2 or ISO 27001 report to offer in place of an audit. Neither certification is held or in progress.
Security & compliance: Trust · Security · GDPR · Sub-processors · DPA · Privacy · Terms · Cookies
Questions a page here does not answer: get in touch.