DATA PROCESSING
This page summarises how Corenade handles data processed on behalf of customers. A full Data Processing Agreement is available for enterprise customers on request.
01Roles
For data you upload or sync into Corenade — products, orders, customers — you are the data controller and Corenade acts as processor, processing that data only on your documented instructions.
02Scope of processing
Processing covers storing, synchronising and analysing commerce records to deliver the platform features you enable, including integrations, automation and reporting.
03Sub-processors
We use managed cloud infrastructure and communication providers to deliver the service. A current list of sub-processors is available on request, and we give notice of material changes.
04Security measures
Encryption in transit and at rest, role-based access control, least-privilege internal access, audit logging and regular backups.
05International transfers
Where data is transferred outside its region of origin, we rely on recognised safeguards such as standard contractual clauses.
06Breach notification and deletion
We will notify affected customers without undue delay after becoming aware of a personal data breach.
On termination, customer data is deleted or returned on request. Contact hello@corenade.com to request a DPA or deletion.