This GDPR Policy explains, in more detail than our Privacy Policy, how Cerenos meets its obligations under the EU General Data Protection Regulation (GDPR) and equivalent UK and Swiss data protection law. This is version 1 of this policy - see the version history link above for every previous version.
If you are located in the United States, see our US Data Privacy Policy instead - most of the concepts on this page (our EU/UK/Swiss legal bases and the Data Protection Commission's role, in particular) do not directly apply there.
(Applies to our users in the European Economic Area, the United Kingdom, and Switzerland.)
Cerenos Limited, a private company limited by shares registered in Ireland under company number 824270, with its registered office at Venture Hub, 136 Capel Street, Dublin, Dublin, D01 T2C9, Ireland, is the data controller directly responsible for the personal data described in our Privacy Policy. Where we process data purely on behalf of a customer organisation using our products (for example, a customer's own client records inside our support/ticketing tools), we act as a data processor on that customer's behalf, and we will enter into a data processing agreement with that customer on request.
We keep transaction data (invoices, payment records) for a minimum of 6 years, as required by Irish tax law, and analytics data for Google Analytics' own default retention window (currently 14 months) unless you withdraw consent sooner. Our Privacy Policy's "How long we keep your data" section sets out the full retention schedule for every category of data we hold.
You have the right to:
We do not currently make any decision about you based solely on automated processing (including profiling) that produces a legal or similarly significant effect. To exercise any of these rights, contact [email protected] - this address does not send automated replies, but a member of our team will personally follow up with you once your message is received. We may need to verify your identity before responding, and we will respond within one month as required by the GDPR (extendable by a further two months for complex requests, with notice to you).
You have the right to lodge a complaint with your local data protection supervisory authority. As a company registered in Ireland whose servers are hosted in Ireland, our lead supervisory authority is the Data Protection Commission (DPC) of Ireland: https://www.dataprotection.ie/.
If you are a resident of the United Kingdom, your data is processed in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Because we host in Ireland, transfers of your data from the UK to Ireland are covered seamlessly by the UK's standard adequacy decision for the European Economic Area - no additional transfer mechanism is needed.
If you are a resident of Switzerland, your data is processed in compliance with the revised Swiss Federal Act on Data Protection (FADP). We treat Switzerland alongside the EEA for the purposes of every data subject right described above, and you may exercise those rights in exactly the same way, through the same contact address.
Some of our service providers (see our Privacy Policy) are located outside the European Economic Area, including in the United States. Where we transfer personal data outside the EEA, we put in place appropriate safeguards recognised under the GDPR, such as the European Commission's Standard Contractual Clauses, or rely on an applicable adequacy decision.
We build access controls, encryption for particularly sensitive data stores, and audit logging into our products as standard. New features that introduce a new category of personal data collection are reviewed for their data protection impact before launch.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission within 72 hours of becoming aware of it, and will notify affected individuals directly where the breach is likely to result in a high risk to them, in line with our obligations under the GDPR.
A current list of the main sub-processors we use is set out in our Privacy Policy's "Who we share data with" section. We will update that list as our vendors change.
Questions about this policy, or to exercise your rights, contact [email protected]. This address does not send automated replies - a member of our team will personally follow up with you once your message is received. Our registered office is Venture Hub, 136 Capel Street, Dublin, Dublin, D01 T2C9, Ireland.