Data Processing Agreement — Social Neuron
Last updated: March 2026. This DPA supplements our Terms of Service and Privacy Policy. It complies with Article 28 UK GDPR.
Key Points
- Cosmocodex Ltd acts as data processor; the customer is the data controller.
- Personal data is processed only on documented instructions from the controller.
- All personnel with data access are bound by confidentiality obligations.
- Encryption in transit (TLS 1.2+) and at rest, with row-level security.
- Sub-processor changes notified with 30 days' notice and right to object.
- Data subject rights assistance including export, erasure, and rectification.
- Breach notification within 48 hours of becoming aware.
- Data deleted within 90 days of service termination.
- Audit rights and compliance documentation available.
- International transfers governed by UK IDTA or adequacy decisions.