Courtesy translation. The legally binding text of this Agreement is the Spanish version. In case of any discrepancy between the two, the Spanish version prevails. Read the Spanish version.
This Data Processing Agreement (the “Agreement” or “DPA”) implements the obligations of article 25 of Decree 1377 of 2013 and supplements the Terms and Conditions and the Privacy Policy of Cerostaff SAS.
01 Parties and Subject Matter
This Agreement is entered into between the Customer (the “Controller”) and Cerostaff SAS (the “Processor”). Its purpose is to govern the processing of personal data that Cerostaff carries out on behalf of and under the instructions of the Customer when providing the Services, including the data accessed through the Google account the Customer voluntarily connects.
02 Definitions
- Controller: the Customer, who decides on the purposes and means of the processing.
- Processor: Cerostaff SAS, which processes the data on the Controller’s behalf.
- Personal data: information about natural persons processed in the context of the Services, including End User data and data accessible via the Customer’s Google account.
- Data subject: the natural person the data relates to.
- Sub-processor: the third party Cerostaff engages to support the processing.
03 Scope of the Processing
The processing carried out by Cerostaff as Processor comprises:
- Nature and purpose: running the automation of customer service and processes, and the functions the Customer configures over their messaging channels and their Google account.
- Types of data: contact and identification data, conversation content, and data from Calendar, Gmail (sending), Sheets, Docs and the Drive files chosen by the Customer.
- Categories of data subjects: the Customer’s End Users and persons whose data appears in the resources the Customer connects.
- Duration: for as long as the relationship with the Customer remains in force, save where a legal retention obligation applies.
04 Activities Cerostaff Carries Out on the Customer’s Behalf
- Receiving, storing and organizing the data needed to operate the configured flows.
- Scheduling and managing events in Calendar; sending email through Gmail; reading and writing in Sheets and Docs; and working with the Drive files the Customer selects with the Picker.
- Processing the data through AI providers for the sole purpose of delivering the function the Customer requested.
- Deleting or returning the data as instructed by the Customer or on termination of the relationship.
05 Controller’s Instructions
Cerostaff processes the data solely in accordance with the Customer’s documented instructions and applicable law. If Cerostaff believes an instruction infringes the law, it will inform the Customer. Cerostaff will not use the data for its own purposes other than providing the Service.
06 Confidentiality
Cerostaff will keep the data confidential and will ensure that its staff and contractors with access to it are bound by confidentiality duties. This obligation survives termination of the Agreement.
07 Security Measures
Cerostaff will apply appropriate technical and organizational measures, including encryption in transit (TLS 1.3) and at rest, role-based access control, two-step verification for administrators and isolation between accounts, in line with the Security Measures section of the Privacy Policy.
08 Sub-Processors
The Customer authorizes Cerostaff to rely on sub-processors to provide the Service. Current sub-processors include:
- Amazon Web Services, Inc. — cloud hosting.
- Anthropic, PBC — natural language processing.
- Google LLC — Google API services, when the Customer connects their account.
- Meta Platforms, Inc. — messaging infrastructure.
Cerostaff will impose equivalent protection obligations on each sub-processor and will inform the Customer of material changes, allowing them to object on reasonable grounds.
09 Assistance with Data Subject Rights
Cerostaff will assist the Customer, so far as reasonable, in handling data subject requests (access, rectification, erasure, objection, portability and withdrawal of consent) and in meeting their habeas data obligations. If a data subject contacts Cerostaff directly, they will be referred to the Customer, unless the law requires otherwise.
10 Incident Notification
Cerostaff will notify the Customer without undue delay after becoming aware of a security breach affecting personal data processed on the Customer’s behalf, providing the information available about the incident and the measures taken, so that the Customer can meet its notification duties towards the SIC and the data subjects.
11 Return and Deletion on Termination
On termination of the Service, and as instructed by the Customer, Cerostaff will return or delete the personal data processed on the Customer’s behalf, including copies, except for anything that must be retained under a legal obligation. When the Google account is disconnected, the associated access tokens are deleted.
12 Audit and Accountability
Cerostaff will make available to the Customer the information reasonably necessary to demonstrate compliance with this Agreement and will cooperate with proportionate audits, with prior notice and subject to confidentiality, in accordance with the demonstrated accountability principle of Law 1581 of 2012.
13 Term
This Agreement will remain in force for as long as Cerostaff processes data on the Customer’s behalf and until such data is returned or deleted. It is deemed accepted by the Customer upon accepting the Terms and Conditions and connecting their Google account, and forms an integral part of those Terms.
