GDPR: who is responsible for what
The question every business customer's auditor asks, answered in plain language.
The short version
For the personal data you process on your own machine you are the controller. We deliver the hardware and the connectivity, we have no account on your server and we cannot read your disk, so in any ordinary sense we are not your processor for that data.
For the data you give us as a customer — your contact details, your company details, your invoices, your tickets — we are the controller, and our privacy statement says exactly what we do with it.
What that means for you
- A data subject request about data on your server comes to you; we cannot answer it because we cannot see the data.
- A breach inside your application is yours to detect and to report. We will tell you without delay about anything affecting the infrastructure under your service.
- Encryption, access control and retention on the machine are your decisions.
If your compliance needs it on paper
Our data processing agreement sets all of this out formally: roles, security measures, sub-processors, international transfers, breach notification, deletion and audits. It applies to every customer as published, so there is nothing to sign and nothing to wait for — and if your procurement wants a signed copy, ask and you get one.
Where the data physically is
In Amsterdam. We do not move personal data outside the European Economic Area and we do not use infrastructure outside it to deliver these services. That one sentence answers most of a vendor questionnaire.
Still stuck? Mail support@novogara.com — an engineer answers, at any hour. Back to the knowledge base