Data processing addendum
This page summarises the standard data processing addendum (DPA) Cardean B.V. concludes with controllers that engage us for paid services — pilots, support, or hosted operations. The Cardean software itself is self-hosted, so for software-only users no DPA is required: there is no processor relationship.
Last updated · 2026-06-091. Roles
Where Cardean B.V. processes personal data on your behalf in the course of a paid engagement, you act as controller (Art. 4(7) GDPR) and Cardean acts as processor (Art. 4(8) GDPR). The DPA forms part of the underlying order form between us and is governed by Art. 28 GDPR.
2. Subject matter, nature, and purpose
- Subject matter — the services described in the order form (e.g. assisted deployment, custodial operations, policy tuning).
- Nature — installation, configuration, monitoring, incident response, and reporting on the Cardean gateway and adjacent infrastructure.
- Purpose — enabling you to operate the gateway in compliance with your governance and audit requirements.
- Duration — the term of the underlying order, plus a 30-day wind-down for return or deletion.
3. Categories of data subjects & data
Personal data processed in a typical engagement is limited to:
- Operator-account identifiers — usernames, e-mail addresses, and access roles for the admin console (Scout) and the policy-bundle repo.
- Operational metadata — request IDs, route names, key IDs, rate-limit decisions, audit-chain digests. By design, prompts, completions, and bearer tokens are excluded from logs, metrics, and audit events.
- Any additional categories are scoped explicitly in the order form.
4. Sub-processors
Where we engage a sub-processor (e.g. infrastructure providers for our own tooling) we maintain a current list on request and notify you of intended changes with at least 30 days' notice, giving you a right of objection.
5. International transfers
Personal data is processed within the EU/EEA by default. Any transfer outside the EU/EEA relies on the European Commission's adequacy decisions or on Standard Contractual Clauses (Implementing Decision (EU) 2021/914), accompanied by the supplementary measures identified in the transfer impact assessment.
6. Security measures
We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR), including encrypted secrets stores, least-privilege access control, multi-factor authentication for operator accounts, log redaction by default, and the supply-chain controls described in our security & disclosure policy.
7. Assistance & audit
We assist you in fulfilling data-subject requests, in conducting data protection impact assessments, and in responding to enquiries from supervisory authorities. Audit rights are provided in accordance with Art. 28(3)(h) GDPR, executed where practicable through documented evidence (SOC 2 reports where available, audit-chain exports, signed policy bundles).
8. Breach notification
We notify you of a personal data breach affecting your data without undue delay and at the latest within 72 hours of becoming aware of it, with the information you need to meet your own notification obligations under Art. 33 and Art. 34 GDPR.
9. Return & deletion
At the end of the engagement, we return or delete all personal data we hold on your behalf, except where retention is required by EU or Member-State law.
To execute the DPA, contact [email protected].