About this agreement
This Data Processing Agreement is part of the Terms of Service between Cenelira Ltd (“we”) and the person or organisation that holds the Cenelira workspace or agency account (“you”). Cenelira Ltd is a company registered in England and Wales with company number 17124132, whose registered office is 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
It applies whenever we handle personal data on your behalf and data protection law applies to that handling. You do not need to sign anything: you accept it when you accept the Terms of Service. If this agreement and the Terms of Service say different things about personal data, this agreement applies.
In this agreement, “data protection law” means the UK GDPR and the Data Protection Act 2018, and any other data protection law that applies to your use of Cenelira. “Customer personal data” means personal data that you or your team put into a workspace, or that other people give through a link you sent them. Annex 1 describes it.
Who does what
For customer personal data, you are the controller and Cenelira Ltd is your processor. If you are an agency acting for your own clients, you may be a processor for a client. We are then your sub-processor, the same terms apply between you and us, and you are responsible for having your client's authority.
For the personal data in your own account, for the security and support records we keep to run the service, and for the evidence records described under “When the service ends”, Cenelira Ltd is a controller. The Privacy Policy covers that data, and the processor terms in this agreement do not apply to it.
Your instructions
We process customer personal data only on your documented instructions. Your instructions are this agreement, the Terms of Service, and what you and your team do in the product, such as scheduling a post, sending a review link or sharing a report. They include sending the data to the countries listed in Annex 3.
If UK law requires us to process customer personal data in some other way, we will tell you before we do, unless that law prohibits us from telling you on important grounds of public interest. We will tell you immediately if we think an instruction breaks data protection law.
We do not sell customer personal data or use it for advertising.
Your responsibilities
- You have a lawful basis for the personal data you put into Cenelira and for sending links to people outside your workspace.
- You tell those people how their details are used. Our Privacy Policy has a section for people without an account that you can point them to.
- You send a review link or a report link only to people who are entitled to see what it shows.
- Cenelira is not designed for special category data, such as health information, or for data about criminal offences. Do not use it to store either about other people.
Confidentiality
We make sure that anyone we authorise to handle customer personal data is bound by a duty of confidentiality.
Security
We put in place and maintain appropriate technical and organisational measures to protect customer personal data, as Article 32 of the UK GDPR requires, taking account of the risks of the processing. Annex 2 lists the measures in place today. We may change them as the product changes, but we will not lower the overall level of protection.
Other processors we use
You give us general authorisation to use the sub-processors listed in Annex 3.
We will impose on each sub-processor, by written contract, data protection obligations that give at least the same protection as this agreement. If a sub-processor fails to meet those obligations, we remain fully liable to you for its performance of them.
We will tell you at least 14 days before we add or replace a sub-processor, by email to the workspace owner and by updating Annex 3. You may object in that time, on reasonable data protection grounds, by emailing [email protected]. If we cannot resolve your objection, you may stop using the affected part of the service or close your workspace.
The social platforms you connect, such as Instagram, Facebook, Threads, LinkedIn, X, Pinterest, YouTube and TikTok, are not our sub-processors. When you publish to a platform or read its statistics, we send and receive data on your instruction, and the platform handles it under its own terms.
Requests from individuals
If a person asks us to see, correct, erase or otherwise exercise their rights over customer personal data, we will pass the request to you without undue delay. We will not answer it ourselves, other than to tell the person that we have passed it on, unless you ask us to or the law requires it.
Taking into account what the product does, we will help you respond. Where the product lets you correct or remove the data yourself, you can do so there. For anything else, such as removing a reviewer's name and email address from an approval record, email [email protected] and we will act on your written instruction without undue delay.
Personal data breaches and other help
If we become aware of a personal data breach affecting customer personal data, we will tell you without undue delay, and within 48 hours where feasible, by email to the workspace owner. We will tell you what we know about what happened, the people and records affected, the likely consequences and what we are doing about it, and we will add to that as we learn more.
Taking into account the nature of the processing and the information we have, we will also give you reasonable help with your own security duties, with telling the Information Commission and the people affected about a breach, with data protection impact assessments, and with consulting the Information Commission where an assessment calls for it.
Transfers outside the United Kingdom
Cenelira Ltd is based in the United Kingdom. Some of the sub-processors in Annex 3 store or handle customer personal data outside the United Kingdom, and by using Cenelira you instruct us to make those transfers.
We make a transfer outside the United Kingdom only where UK adequacy regulations cover it, or where a safeguard that UK data protection law accepts is in place, such as the UK International Data Transfer Addendum. Annex 3 gives the basis for each sub-processor.
When the service ends
When you close your workspace or your account, or tell us that you have stopped using Cenelira, we will delete customer personal data. If you ask us to, we will first return it to you in a commonly used electronic form. We will finish within 30 days of your instruction, unless UK law requires us to keep the data.
Two kinds of record are kept for longer:
- Copies that remain in backups or in our providers' logs. They are put beyond use: we do not use them for anything else, and they are deleted when they expire in the normal cycle.
- Evidence that a deletion or a publication took place. So that we can show it happened, stop deleted data coming back after a restore, and stop a post being published twice, we keep identifiers of the workspace, user, connected account and post concerned, with times, outcomes and checksums, for 12 months after the deletion or publication is settled. Part of this evidence is held in write-once storage that cannot be erased earlier. It contains none of your content, captions or media. We hold it as a controller and use it only for those purposes.
Content already published to a social platform stays on that platform until you remove it there.
Showing that we comply
We will give you the information you reasonably need to show that this agreement is being met. We will also allow, and contribute to, an audit or inspection by you or by an independent auditor you appoint.
Unless the Information Commission requires otherwise or a personal data breach has affected your data, an audit may take place once in any 12 months, on at least 30 days' written notice, during UK working hours and at your cost. The auditor must keep what they learn confidential, and an audit must not put other customers' data at risk.
Liability, changes and law
The limits of liability in the Terms of Service apply to this agreement, except where the law does not allow liability to be limited.
We may update this agreement when the product, our sub-processors or the law change, and the date at the top shows the current version. We will tell the workspace owner by email before a change that reduces the protection this agreement gives.
This agreement lasts for as long as we hold customer personal data. It is governed by the law of England and Wales, and the courts of England and Wales may hear any dispute about it.
Annex 1: the processing
- Subject matter
- Providing Cenelira, a service for preparing, approving, publishing and reporting on social media posts.
- Duration
- For as long as you use Cenelira, and afterwards until the data is deleted as described under “When the service ends”.
- Nature and purpose
- Storing, displaying, sending to the platforms you connect, and deleting personal data so that you and your team can prepare posts, have them approved, publish them and report on them.
- People the data is about
- Members of your workspace and people you invite to it. People you send a review link or a report link to, such as your clients and their staff. People who appear or are named in your media and captions. The holders of the social accounts you connect.
- Types of personal data
- Workspace and team: the names and email addresses of workspace members and of people invited to join, their roles, their comments and their approval decisions.
- Content: media, captions, titles and any personal data they contain.
- Connected accounts: the names and identifiers of the social accounts, pages and channels you connect, and the post results and statistics the platforms return.
- Review links: the full name and email address a person gives when they record a decision, the decision and its time, how many times the link has been opened and when it was last opened.
- Report links: no name or email address of the viewer. Counts of views and of accepted report terms, with their times, and one cookie in the viewer's browser.
- Technical: the internet address of a person using a review link or a report link, handled to deliver the page and, for report links, used briefly to limit abuse.
- Special category data
- None intended. See “Your responsibilities”.
Annex 2: security measures
These are the measures in place today.
- Connections to Cenelira are encrypted in transit with HTTPS, and browsers are told to use HTTPS only (HSTS).
- Access tokens for the social accounts you connect are encrypted at rest with AES-256-GCM.
- Requests for workspace data are authorised on the server against the signed-in person's membership of that workspace and their role.
- The secret in a review link or a report link is 32 random bytes. Only a salted hash of it is stored, so a link cannot be rebuilt from our database.
- Review links and report links expire. The workspace can turn off a review link that has not been decided, and any report link.
- Report links are rate limited by internet address and by link.
- The name and email address typed on a review link are limited in length and validated on the server.
- Access tokens, passwords and cookies are removed from error reports before they are sent to our monitoring provider, and the reporting tool is set not to collect personal details by default.
Annex 3: sub-processors
These companies handle customer personal data for us, or records derived from it. The last line of each entry says what makes the transfer out of the United Kingdom lawful.
Railway Corporation
- What it does:
- Hosts the application, the main database and the job queues, and keeps server logs.
- Where:
- United States.
- Basis for the transfer:
- UK adequacy regulations for the United States: the provider is certified under the UK Extension to the EU-US Data Privacy Framework.
Cloudflare, Inc.
- What it does:
- Carries traffic to Cenelira through its network and stores uploaded media and exported files.
- Where:
- Cloudflare's global network, including the United Kingdom, the European Union and the United States.
- Basis for the transfer:
- UK adequacy regulations for the United States: the provider is certified under the UK Extension to the EU-US Data Privacy Framework. Cloudflare's data processing terms also include the UK International Data Transfer Addendum.
Plus Five Five, Inc. (Resend)
- What it does:
- Sends email for Cenelira, such as sign-in codes, workspace invitations and review decisions.
- Where:
- United States.
- Basis for the transfer:
- UK adequacy regulations for the United States: the provider is certified under the UK Extension to the EU-US Data Privacy Framework. Resend's data processing terms also include the UK International Data Transfer Addendum.
Functional Software, Inc. (Sentry)
- What it does:
- Receives error reports from the application. Access tokens, passwords and cookies are removed before a report is sent.
- Where:
- Germany.
- Basis for the transfer:
- UK adequacy regulations for the European Economic Area. Sentry is a United States company and is certified under the UK Extension to the EU-US Data Privacy Framework.
Amazon Web Services
- What it does:
- Stores recovery records that let us show a deletion happened and stop deleted data coming back. They hold coded identifiers and checksums, and no names, email addresses or content.
- Where:
- Sweden.
- Basis for the transfer:
- UK adequacy regulations for the European Economic Area.
Google (Google Workspace)
- What it does:
- Hosts the mailbox for messages sent to our support address.
- Where:
- Google's data centres, including in the European Union and the United States.
- Basis for the transfer:
- UK adequacy regulations for the European Economic Area. Google LLC is certified under the UK Extension to the EU-US Data Privacy Framework.
Contact
Questions about this agreement should be sent to [email protected].