1. Why self-hosting changes the answer
Most software vendors need a data processing agreement with you because your customers' data flows through their servers. Recurnix does not work that way.
Your installation runs on infrastructure you control, against a database you control. Your customers' personal data never reaches us. For that data you are the controller and we are not a processor, because we do not process it at all.
This is not a technicality we are hiding behind. It is the main reason to run self-hosted billing, and it means the compliance surface between us is unusually small.
2. Where we are a controller
We are an independent controller of the limited personal data we hold about you as our customer: your account details, billing records, support correspondence and licence heartbeat data. How we handle it is set out in the Privacy Policy.
3. Where we could become a processor
There are narrow situations where we might touch data you control, and each requires you to act first:
- If you send us a database export, a log file or a screenshot while requesting support.
- If you ask us to look at your installation and provide access for that purpose.
In those cases we act on your instructions, use the data only to help with the request, and delete it when the request is closed. Do not send us production personal data unless it is genuinely necessary, and redact what you can.
4. Instructions and confidentiality
Where we do process data on your behalf we will act only on your documented instructions, ensure the people involved are bound by confidentiality, and apply appropriate technical and organisational measures.
5. Assistance
We will give you reasonable help with data subject requests, impact assessments and breach notifications that concern data we hold. In practice, requests about your own customers are ones only you can answer, because only you have the data.
6. Deletion
On request we will delete or return personal data you have sent us in a support context. Data we hold as a controller is kept for the periods set out in the Privacy Policy.
7. Your obligations to your customers
You are responsible for having a lawful basis for the data you hold in your installation, for giving your customers the notices they are due, and for answering their requests. Recurnix includes tools that help, including consent capture, data export and erasure, but the obligation is yours.
8. A signed agreement
If your compliance team needs a countersigned data processing agreement, email legal@recurnix.com and tell us what you need. We would rather sign something accurate than have you assume terms that do not describe the actual arrangement.
Questions about this document? Write to legal@recurnix.com or use the contact form. If you already have a licence you can open a ticket from the client area.