CRA Desk

Draft - pending legal review, not yet legally binding.

Data Processing Agreement

Version 1 (Draft) Effective date: 24-08-2026

This document is a template for the data processing agreement (Art. 28 GDPR) between the Customer (the Controller) and Cloudsoft Marcin Malinowski (the Processor), entered into by using CRA Desk in a way that involves the Controller's own staff data.

1. Subject and scope

The Controller engages the Processor to process the email addresses, names and roles of staff the Controller invites into its CRA Desk account, to the extent necessary to provide the service: account provisioning, access control, and email notifications the Controller's team has opted into (deadline reminders, vulnerability alerts). This does not extend to SBOM content or vulnerability data - those are not personal data, and are covered instead by the Terms of Service' confidentiality clause.

2. Processor's obligations

The Processor undertakes to:

  • process data only on the Controller's documented instructions and only for the purpose in Section 1;
  • apply appropriate technical and organisational measures (encryption at rest and in transit, role-based access control, per-tenant isolation);
  • ensure that personnel with access are bound by confidentiality;
  • assist the Controller in responding to data subject requests, through the export and deletion functions available directly in the panel;
  • delete the data covered by this agreement upon account closure, following the process described in the Privacy Policy, except where the law requires longer retention (invoicing records).

3. Sub-processors

The Controller gives general authorisation for the Processor to engage the sub-processors listed at Sub-processors. The Processor will notify the Controller before adding or replacing a sub-processor, giving the Controller an opportunity to object.

4. Data breach notification

The Processor notifies the Controller of any confirmed personal data breach without undue delay, and no later than 48 hours after becoming aware of it, describing the nature of the breach, the categories and approximate number of data subjects affected, and the measures taken or planned.

5. Duration

This agreement remains in effect for as long as the Controller's account is active, and until the data-deletion process described in the Privacy Policy has completed.