This page explains how Priveloq Chat fits into a business customer's own data protection obligations. It is information, not a contract.
No data processing agreement is in place merely because you read this page. A DPA is a signed document between your organisation and ours. If you need one, ask us — see section 6.
1. Who is responsible for what
For the business content inside your workspace — your people's messages, files, Work items and Knowledge documents — your organisation decides what goes in, who may see it, how long it is kept and when it is deleted. We handle it on your instructions so that the product works.
For our own dealings with you — your account with us, billing, support correspondence, this website — we decide why and how information is used, and the Privacy Notice describes that.
Where the law that applies to you uses the words controller and processor, the first paragraph is normally you as controller and us as processor, and the second is normally us as controller. The allocation that binds is the one in your signed agreement, not this summary.
2. Your responsibilities as a customer
- Having a lawful basis for the personal information your people put into the workspace, and telling the people concerned what you do with it.
- Deciding who gets an account, what role they hold, and removing access when somebody leaves.
- Configuring the controls the product gives you: multi-factor requirements, session lifetimes, guest room retention windows, retention policies, classification and legal holds.
- Answering the rights requests of your own people about content in your workspace. We will help you do it.
- Not putting content into the product whose confidentiality depends on the server being unable to read it — the product is not end-to-end encrypted.
3. What we do
- Process workspace content only to provide, secure, maintain and support the Service, and where the law requires.
- Apply technical and organisational security measures designed to protect it, described on the security page.
- Keep the people who handle it bound to confidentiality.
- Maintain a security audit trail that lets an organisation account for consequential actions in its workspace.
- Tell you without undue delay if we become aware of a personal data breach affecting your workspace, with what we know and what we are doing.
- Help you with rights requests, impact assessments and regulator enquiries, to the extent the information is ours to provide.
- Delete or return workspace content at the end of the relationship, in line with your agreement, except where we must keep something by law or under a legal hold.
4. Subprocessors
The third parties this installation sends information to are listed on the subprocessor page, read from its live configuration. Where you have agreed a notice period for new subprocessors with us, we will honour it.
5. Evidence you can obtain
Priveloq records what it does, and lets an authorised administrator obtain evidence of it: authentication and multi-factor configuration, who holds privileged access, role and capability assignments, session and sign-in activity, retention configuration and runs, classification levels, legal holds, privacy requests and their outcomes, and the security audit trail.
That evidence describes Priveloq. It is not a governance, risk or compliance programme for your organisation, and Priveloq does not run one: it does not hold your risk register, your vendor assessments, your policy programme or your certification process, and it makes no determination about whether your organisation is compliant with anything. Evidence may help support a requirement; deciding whether the requirement is met belongs to you, your auditors and your assessors.
6. Getting a data processing agreement
If your organisation needs a signed DPA, standard contractual clauses, a security questionnaire completed, or details of the transfer safeguards and retention periods configured for your deployment, contact us and we will work through it with you.
Or write to us through the contact page.