NeateWorks processes personal data for its clients as a processor, on their instructions, under the data-protection terms of the NeateWorks Master Services Agreement. This page is the description of processing (Annex I of the Standard Contractual Clauses) and the technical and organizational security measures (Annex II) those terms refer to. The subprocessors are on a separate list, and NeateWorks' transfer impact assessment is published for clients transferring data from Europe, the UK or Switzerland.
The client named in the Master Services Agreement, contactable through the notice details it gives there. Its activities relevant to the transfer are receiving the Services described in the Agreement and each Statement of Work.
NeateWorks LLC, a Colorado limited liability company, Denver, Colorado, United States. Contact: Tristan Neate, Member, tristan@neateworks.com. Its activities relevant to the transfer are building, hosting, operating, administering and supporting the client's systems.
End users and customers of the apps and websites NeateWorks builds, hosts or administers for the client. The client's personnel and contractors who use the client portal, the app's admin tools, or correspond with NeateWorks. Anyone else whose personal data the client puts into, or routes through, those systems.
None. Special categories of personal data (GDPR Article 9) and criminal-offence data (Article 10) are excluded by the Master Services Agreement unless a Statement of Work expressly agrees otherwise and sets the extra safeguards.
Continuous, for the term of the Agreement.
Hosting, storage, backup, transmission, logging, email delivery, support and troubleshooting access, development and testing, and AI processing where a deliverable includes it.
To build, deploy, host, operate, administer, support, maintain, test and troubleshoot the systems and deliverables in each Statement of Work, as the Master Services Agreement instructs.
To the subprocessors on the subprocessor list, for the purposes and data stated there, for the duration of the Agreement.
The authority competent under Clause 13 of the Standard Contractual Clauses: the one where the data exporter is established or, where it is not established in the EU, where its representative is or where the data subjects are.
For the term of the Agreement plus the 30-day post-termination retrieval window, then deleted or returned at the client's direction.
Nightly snapshots plus continuous transaction-log archiving, kept for 30 days. Superseded backup objects are purged after 35 days. Data deleted from a live database stays in backups until they age out.
30 days.
Purged daily.
Expired access tokens and authorization codes are deleted nightly once they expire. Revoked tokens and revoked assistant approvals are deleted 90 days after revocation. Tokens stop working at expiry or revocation either way. Assistant registrations never approved are deleted after one day.
Deleted 90 days after being read, and in any case 1 year after creation.
Deleted after 2 years.
Kept for the life of the agreement, plus 7 years after it is voided or deleted.
Kept for the life of the agreement, as contract evidence. No copies of the signature, IP address or browser details are kept in the audit trail.
Kept while the client organization, project or item they are on exists and the author's account remains. Deleted with the author's account, and within a day of the item they are on being deleted. Their copies in the audit trail are deleted after 2 years.
NeateWorks maintains the measures below for every system it hosts. It may improve them over time, but will not change them in a way that materially reduces the overall protection they provide.