This agreement forms part of the Subscription Terms and applies where, in providing CloudVerdict™, we process personal data for which you are the controller. Where we are the controller in our own right, the Privacy Notice applies instead.
In this agreement, "UK GDPR", "controller", "processor", "personal data", "processing", "data subject", and "personal data breach" have the meanings given in the UK General Data Protection Regulation and the Data Protection Act 2018.
1. Roles
You are the controller. Apex Edge Sales Engineering Limited is the processor.
2. What is processed
| Subject matter | Providing CloudVerdict™ to you |
| Duration | For as long as your subscription is open, and then for the retention periods in the Privacy Notice |
| Nature and purpose | Hosting, storing, and displaying the workloads, use cases, and results you create, and supporting you in doing so |
| Types of personal data | Contact details of any individual you enter into the product, and any personal data contained in a workload description or a use case you save |
| Categories of data subject | You, and any individual whose details you choose to enter |
CloudVerdict™ is not designed to hold special category data, criminal offence data, or personal data about children, and you should not put any of those into it.
3. Our obligations
We will:
- process personal data only on your documented instructions, which for these purposes are your use of the product and this agreement, unless we are required to do otherwise by law, in which case we will tell you unless the law forbids it;
- ensure that anybody authorised to process the data is under an appropriate duty of confidentiality;
- take appropriate technical and organisational security measures, including keeping each subscriber's data separate from every other subscriber's, enforced in the database and not only in the interface;
- assist you, so far as we reasonably can, with data subject requests, with data protection impact assessments, and with consultations with a supervisory authority;
- on the end of your subscription, delete the personal data within the period stated in the Privacy Notice, except where we are required to keep it by law or where it sits in the immutable records described in clause 6;
- make available the information you reasonably need to demonstrate our compliance with this agreement.
4. Sub-processors
You give general authorisation for us to engage sub-processors. Every sub-processor currently engaged is listed on Sub-processors, with what it does and where it processes.
We impose on each sub-processor data protection obligations no less protective than those in this agreement, and we remain responsible to you for their performance.
Before we add or replace a sub-processor we will update that page and give you notice. If you have a reasonable objection on data protection grounds, tell us at privacy@apexedgesalesengineering.com and we will work with you in good faith; if it cannot be resolved you may cancel under the Subscription Terms.
5. Our staff can reach your account, and it is recorded
Our staff can enter your account to support you. Every session records who opened it, whose account it entered, why, and when it ended, and every action taken during one names the member of staff as well as the person whose account it was.
This is a security measure and an accountability measure, and it is disclosed here rather than buried because it is access to your data by somebody other than you.
6. Records that cannot be edited or deleted
The activity record and the audit record are immutable by design. A correction is a new entry, never a change to an old one.
A deletion instruction therefore meets records that are deliberately preserved. Where that happens we will tell you what is held, why, and for how long, and we will delete everything not covered by it.
7. International transfers
The product is hosted in Europe (Ireland). Where personal data is transferred outside the UK or the EEA, we do so under an approved safeguard, such as the UK International Data Transfer Addendum to the Standard Contractual Clauses, or an adequacy decision.
8. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting your personal data, with the information you reasonably need to meet your own obligations.
Report a suspected breach or any security concern to security@apexedgesalesengineering.com. That address exists because a breach has a deadline on it, and product support is not where that deadline is watched.
9. Audit
We will make available the information reasonably needed to demonstrate compliance with this agreement and, on reasonable notice and no more than once a year unless a supervisory authority requires otherwise, contribute to an audit conducted by you or an auditor you appoint, subject to confidentiality and to not compromising the security of other subscribers.
10. Your obligations
You warrant that you have a lawful basis for the personal data you put into CloudVerdict™, that you have given any notice and obtained any consent required, and that your instructions will not put us in breach of data protection law.
11. The cloud providers are not involved
Amazon Web Services, Microsoft Azure, Google Cloud, and Oracle Cloud Infrastructure are not sub-processors and receive no personal data from CloudVerdict™. We read the prices they publish; we send them nothing.
12. Precedence and changes
Where this agreement conflicts with the Subscription Terms on the processing of personal data, this agreement prevails. We may update it to reflect a change in law or in how the platform works, and where a change materially affects you we will give notice.
13. Contact
Data protection matters: privacy@apexedgesalesengineering.com.
Security reports and suspected breaches: security@apexedgesalesengineering.com.
Anything with no better home: contact@apexedgesalesengineering.com.