Data processing agreement.
You are the controller. We are your processor.
You are the controller of the records you put into Cobalt ERP. We are your processor. This sets out what that means in practice.
What this is
This data processing agreement applies where Cobalt ERP processes personal data on your behalf as part of providing the Cobalt ERP service. You are the controller of that data; Cobalt ERP is your processor.
It supplements the terms. Where they conflict on data protection, this document takes precedence.
Scope of processing
Subject matter. Providing the Cobalt ERP service to you.
Duration. For as long as your subscription runs, plus the export window set out in the terms.
Nature and purpose. Storing, organising, retrieving and analysing the operational and financial records you put into Cobalt ERP, so the service can present them, reason over them and prepare work for your approval.
Types of personal data. Typically the contact details of your customers, suppliers and staff — names, business addresses, email addresses, phone numbers — and records of transactions with them. You decide what you put in.
Categories of data subject. Your customers, your suppliers and your staff.
Our obligations
We process personal data only on your documented instructions, which include your use of the service’s features, unless we are required otherwise by law — in which case we will tell you first unless the law forbids it.
We make sure anyone we authorise to process the data is bound by confidentiality.
We implement appropriate technical and organisational measures. The measures in force are described on the security page and form part of this agreement.
We assist you, taking account of the nature of the processing, with responding to data subject requests and with your obligations on security, breach notification and impact assessments.
We notify you without undue delay, and in any case within [to be completed], on becoming aware of a personal data breach affecting your data.
On the end of the service we delete or return the personal data at your choice, except where we are legally required to keep a copy.
We make available the information needed to demonstrate compliance and allow for audits, on reasonable notice and subject to confidentiality.
Artificial intelligence processing
Personal data in your records is read by Cobalt ERP’s reasoning engines in order to answer your questions and prepare work you have asked for. That processing happens under your instruction and under the same permission model as a user — an agent cannot read a record the person asking could not read.
We do not use your personal data to train models for anyone else.
Where processing relies on a third-party model provider, that provider is listed on the sub-processors page and is bound by terms consistent with this agreement.
Sub-processors
You give general authorisation for us to engage sub-processors. The current list is published at cobalterp.com/sub-processors.
We will give you at least [to be completed] notice before adding or replacing a sub-processor, and you may object on reasonable data protection grounds. Each sub-processor is bound by obligations no less protective than these.
International transfers
Where personal data is transferred outside the UK or EEA, the transfer is made under an appropriate safeguard — the UK International Data Transfer Addendum, the EU Standard Contractual Clauses, or an adequacy decision. The mechanism in force for each sub-processor is stated on the sub-processors page: [to be completed].
Questions about any of this?
Email us and a person will answer. We would rather explain a clause than have you guess at it.
Talk to us