Third Party Index

Snapshot 21220

Document
Data processing addendum
URL
https://tresora.io/legal/data-processing
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
41581 bytes
SHA-256 (raw)
bc5e1cde381beb4fcc4b11a1625fc8d478bd9d7a93413d564d57d2b293fbd3c0
SHA-256 (normalized text)
3036520f63aede7cc6ce80f7577abae0f7dbc5d5d18bf75ec74e929160b29b32

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to content
Legal
Data processing
A customer’s data stays the customer’s. Tresora processes it to run the service they bought, on their instructions, under an agreement signed before any of it arrives. This page says what that agreement is for and what it settles; the agreement itself is the document that binds.
On this page
01Who is the controller, and who is the processor
02What the agreement settles
03What is true of the platform whatever the paperwork says
04Who we engage underneath us
05Getting a copy
The two roles
Who is the controller, and who is the processor
Inside the platform, the customer is the controller.
It is their data. They decide what goes into it and what it is for, and Tresora processes it on their documented instructions and for nothing else. Nobody at Tresora decides that a customer’s ledger would be interesting for another purpose.
On this website the roles are the other way around: there Tresora decides what is collected and why, so there Tresora is the controller. The privacy policy is the page for that, and the two do not overlap.
The agreement
What the agreement settles
It is part of the commercial contract rather than a separate favor, and it is in place before any customer data is processed.
What is being processed, for how long, and for what
The kinds of data, and the kinds of people the data is about
The instructions Tresora acts on, and the limits of them
Confidentiality, and who inside Tresora may reach anything at all
What happens at the end, including what comes back and what goes
Those are commitments to a named customer, with that customer’s own systems and obligations behind them. That is why they live in a signed document rather than on a page a stranger reads — a page cannot promise anybody anything.
There is no version of this that is negotiated after the data arrives. The agreement is signed first.
Architecture
What is true of the platform whatever the paperwork says
Three of the answers a data protection officer asks for are decided by the architecture rather than by a clause, which is why they read the same for every customer.
Customer data is processed in the European Union, and stays there.
Separation between customers is enforced by the database, so a query without a context returns nothing rather than somebody else’s rows.
Who can sign in follows the customer’s own identity provider, so a leaver loses Tresora when they lose everything else.
The security page describes each of those in the detail a reviewer wants, including the one you can ask us to demonstrate on a call.
Security
Sub-processors
Who we engage underneath us
One, named, in France.
A processor owes you the list of everyone it engages beneath it, and a short list is easier to assess than a long one. Ours has a single entry: OVHcloud, a European provider operating its own data centers in France, supplying the compute, storage and backup this platform runs on.
Sub-processor
OVHcloud
Processing carried out
Hosting, storage and backup of the platform
Location
France, European Union
No other party processes your data on our behalf. Google Analytics does not run inside this platform: it is on the public website and nowhere else. There is no other analytics vendor here, no third-party support tool with a view of your records, no offshore operations team and no subcontracted processing of any kind. Where we need something a vendor would normally supply — matching, forecasting, resolution — it was built here, which is the reason the list stays this short.
The public website is a separate question with a separate answer, and it is answered in the privacy and cookie documents rather than here: it can set a Google Analytics cookie if a visitor accepts one. Nothing that happens on the marketing site reaches this platform, and no customer record is ever visible to it.
How a change to this list is notified, and what you are able to do about it, is set out in the data processing agreement itself. Ask for the agreement and read that clause before you sign rather than after — it is short, and it is one of the few in there that decides what happens on a day you have not planned for.
The document
Getting a copy
Current and prospective customers can ask for the agreement and the security documentation that goes with it.
Say who is asking and what they need to review, and it comes back with the material that answers those questions rather than a folder of everything.
If your own security or legal team has a standard questionnaire, send that too. Answering yours is more useful to you than asking you to read ours.
The rest of it, written down
Security
Privacy
Cookies
Legal notice