Scope
This DPA applies when Customer is the Data Controller and Createrun (Createrun) is the Data Processor — i.e. when Customer Data is processed in our managed cloud.It does not apply to on-prem deployments, where Customer is in sole control and Createrun is not a processor.
1. Roles
- Data Controller:Customer.
- Data Processor:Createrun (operating the Createrun managed cloud).
- Sub-processors:Listed in §6 below; Customer is notified 30 days before any addition.
2. Categories of data & data subjects
Customer determines what data flows into the Service. Typical categories:
- Customer's employees, contractors, suppliers (identifiers, contact info, organisational role).
- Customer's end-users (form submissions, workflow approvals, audit logs).
- Customer's business data (whatever the CRApps process — orders, inventory, files, etc.).
3. Purpose & instructions
We process Customer Data only to provide the Service per Customer's documented instructions (the Order Form + UI configuration). We do not use Customer Data for our own purposes, model training, or analytics not requested by Customer.
4. Security measures (Annex II)
See/securityfor full architecture. Summary:
- TLS 1.2+ in transit; AES-256 / DPAPI at rest.
- OAuth2 / OIDC authentication with per-tenant claim isolation.
- Authorization XML store hardened for concurrent writes.
- Secrets in the encrypted Instance Configuration Store (AES-GCM at rest, ownership-scoped groups).
- Logical isolation between tenants on shared infrastructure.
- Encrypted backups with 90-day retention.
- Penetration testing planned Q3 2026; SOC 2 Type II in progress.
- Incident response plan with 72h notification SLA.
5. Sub-processor changes
We notify Customer of any new sub-processor at least 30 days in advance via email and thechangelog. Customer may object on reasonable grounds; if we can't accommodate the objection, Customer may terminate the affected service component without penalty.
6. Approved sub-processors
| Sub-processor | Purpose | Location |
|---|
| Stripe Inc. | Payment processing (Marketplace) | Ireland (EU) / USA |
| Google Analytics | Marketing site analytics | USA (anonymised IP) |
| Cloud hosting provider | Managed cloud infrastructure | EU (data residency by default) |
| Email delivery provider | Transactional email | EU |
7. International transfers
Where transfers outside the EU/EEA / Turkey are required, we rely on Standard Contractual Clauses (SCCs) and supplementary measures as required by GDPR / KVKK case law. Specific transfer mechanisms per sub-processor are listed in the SCC annex.
8. Data subject requests
If a data subject contacts us directly with an access / rectification / erasure request, we forward to Customer within 5 business days. We assist Customer in responding within statutory deadlines.
9. Audits
Once per 12-month period, Customer (or an independent auditor under NDA) may audit our compliance with this DPA. Reasonable notice (30 days) and scope agreed in advance. SOC 2 Type II report (when available) satisfies most audit requests without on-site visit.
10. Incident notification
We notify Customer within 72 hours of becoming aware of a personal data breach affecting their data. Notification includes scope, impact assessment, mitigation steps, and remediation timeline.
11. Return / deletion at end of service
On termination, Customer has 30 days to export Customer Data. After 30 days, we delete or anonymise it within 90 days (subject to legal retention obligations). Backups purge per their 90-day rotation.
12. Liability
Per the Order Form. Where this DPA conflicts with the Order Form, the Order Form governs.
13. Sign & review
For a counter-signed copy of this DPA tailored to your Order Form, contactlegal@createrun.com. We typically turn around DPA review within 5 business days.
Related:Privacy Policy·Terms of Service·Security & Trust