Legal

Data Processing Agreement

The data processing terms that apply when Collabre handles personal data for you, covering roles, security, sub-processors, transfers and deletion.

1. What this agreement covers

This data processing agreement is part of the agreement between you and {{LEGAL_ENTITY}}, registered at {{REGISTERED_ADDRESS}}. It applies whenever we process personal data on your behalf so that we can provide the Service described in the Terms of Service. The words controller, processor, sub-processor, personal data and processing carry the meaning that data protection law gives them.

It lasts as long as your subscription, and for as long after it as we still hold personal data for you. Section 11 says what happens to that data at the end.

2. Roles

You are the controller of the personal data in your workspace, and Collabre is the processor. Where you handle personal data for a client of your own, you are the processor and Collabre is a sub-processor, and every commitment below applies to us in the same way.

You decide which personal data enters the workspace, which platforms and tools it reaches, and who in your organization can open it. You are responsible for having a legal basis for that data and for the notices you give the people it describes.

3. Subject matter, nature, purpose and duration

We process personal data to run the product: to hold Campaigns, briefs, content, approvals, media and reports, to publish to the channels you connect, to answer the AI requests your workspace makes, to send the email the product sends on your behalf, and to support you when you ask.

The categories of personal data are the ones in section 2 of the Privacy Policy. The people they describe are your workspace members, your clients and the people your content is about or addressed to.

4. Your instructions

We process personal data only on your documented instructions. Those instructions are this agreement, the Terms of Service, and the choices you make in the product. We follow an instruction that goes beyond them only when we have agreed to it in writing, or when the law requires it, in which case we tell you first unless the law forbids that. We tell you if an instruction looks to us like a breach of data protection law.

5. Confidentiality

Everyone we let near personal data is bound to keep it confidential, by contract or by a professional duty, and reaches it only as far as their work requires.

6. Security measures

We keep the following measures in place. The security page lists each one with the module that implements it.

7. Sub-processors

You give a general authorization for the sub-processors listed on the subprocessors page, which names each vendor, what it is used for, the data it receives and the region it processes in. We put written terms in place with each of them that are no less protective than this agreement, and we stay responsible to you for what they do.

Before a new sub-processor starts to process personal data for you, we add it to that page and tell the workspace owner by email. If you object on reasonable data protection grounds, write to [email protected] before the change takes effect and we will look for an alternative. If we cannot find one, you may stop using the part of the Service that needs that sub-processor and end the affected subscription, and we refund the part of your prepaid fees you have not used.

8. People who exercise their rights

The product answers most requests on its own: workspace data exports to CSV and PDF, roles show who can reach what, and the audit log shows what was done. Where a request needs more than that, write to [email protected] and we help you answer it, taking account of what we process and what we know. We pass a request that reaches us directly back to you rather than answering it ourselves, unless the law says otherwise.

9. Personal data breaches

We tell you without undue delay after we become aware of a breach of security that leads to the destruction, loss, alteration or unauthorized disclosure of the personal data we process for you. We tell you what we know about it, what we think the effect is, and what we are doing, and we keep you posted as we learn more.

10. International transfers

Personal data is processed in the countries where we and our sub-processors operate, which the subprocessors page names. Where data leaves the European Economic Area, the United Kingdom or Switzerland and the destination has no adequacy decision, we rely on the Standard Contractual Clauses approved by the European Commission and on the equivalent United Kingdom transfer mechanism, together with the measures in section 6.

11. Return and deletion

While your subscription runs, you can export your workspace data from the product at any time. When it ends, and after any export window we have agreed with you, we delete the personal data we hold for you from production systems, and the copies held in encrypted backups age out after that. We keep what the law requires us to keep, and nothing else. We confirm a deletion in writing when you ask for it.

12. Audits and information

We give you the information you reasonably need to show that we meet this agreement, including the security detail on the security page and the subprocessor list. Where that is not enough for an audit your regulator requires, write to [email protected] and we agree the scope, the timing and the cost with you in advance, so that the audit does not disturb other customers.

13. Precedence and changes

Where this agreement and the Terms of Service disagree about the processing of personal data, this agreement wins. We update it when the product or the law changes, and the version and the date at the foot of this page describe the copy you are reading. When a change matters to you, we tell you before it takes effect.

14. Contact

Last updated . Version 2.0.