This DPA forms part of the agreement between you ("Controller") and Rahoto ("Processor") and applies where Rahoto processes personal data on your behalf in providing the Service. A signed counterpart is available on request for enterprise agreements.
1. Roles and scope
You are the Controller of Customer Data; Rahoto is the Processor. We process personal data only on your documented instructions, which include your use of the Service and the connections you configure.
2. Nature and purpose
| Item | Detail |
|---|---|
| Subject matter | Provision of the Rahoto reporting runtime. |
| Duration | For the term of the agreement plus the export window. |
| Categories of data | As determined by the sources you connect and the reports you build. |
| Data subjects | As determined by your Customer Data (e.g. your customers, employees). |
3. Security measures
Rahoto implements appropriate technical and organisational measures including encryption in transit and at rest, customer-managed keys (BYOK) on enterprise plans, role-based access control, row-level security, and an append-only, hash-chained audit log. Further detail is in the Trust Center.
4. Sub-processors
You authorise Rahoto to engage the sub-processors listed on thesub-processor page. We give at least 30 days' notice before adding a sub-processor, during which you may object on reasonable data-protection grounds.
5. International transfers
Primary processing occurs in the EU. Where any transfer outside the EEA occurs, it is covered by an adequacy decision or Standard Contractual Clauses. Enterprise plans can pin residency by region.
6. Assistance and audits
Rahoto assists the Controller with data-subject requests, breach notification, and data-protection impact assessments, and makes available information necessary to demonstrate compliance.
7. Deletion and erasure
On termination, Rahoto deletes or returns Customer Data after the export window, except where retention is required by law. Where an account is closed, the account is deactivated immediately and, following a 30-day grace period in which it can be restored, personal data is erased: identifying fields are anonymised and the encryption keys protecting the data are destroyed (crypto-shred), rendering it unrecoverable. A minimal, append-only record of the erasure is retained to evidence that it occurred, as required by law.
Where an erased user contributed content to shared documents owned by others (reports, comments, or edits within an organisation or team), that content is de-attributed (authorship removed) rather than deleted: the contribution is no longer linked to the individual, but the document content itself survives for the controller and the other data subjects who rely on it.
Statutory records that Rahoto must keep by law, such as invoices and billing records, are retained for the legally required period at the organisation level — the legal-obligation exemption to erasure under Article 17(3) of the UK GDPR. Where a legal hold applies, erasure is paused for the duration of that hold.
8. Contact
DPA execution and questions: [email protected].