Docs

Legal

Data Processing Addendum

This addendum governs personal data that Sedgemark processes on your behalf: the contents of your workspace, and the people whose details end up there. It applies automatically and needs no signature.

Effective 23 August 2026 · Last updated 23 August 2026

1. When this applies

This Data Processing Addendum (“DPA”) forms part of the Sedgemark Terms of Service between you and CodeCube Ventures LLC d/b/a Sedgemark. It applies automatically, without further action by either of us, whenever we process personal data on your behalf and you are subject to a data protection law that requires terms of this kind, including the EU GDPR, the UK GDPR, the Swiss FADP, the CCPA as amended, and the Florida Digital Bill of Rights.

No signature is needed. Accepting the Terms accepts this DPA. If your procurement process requires a countersigned copy, email support@getsedgemark.com and we will provide one on these terms.

2. Definitions

“Data Protection Laws” means all laws about the processing of personal data that apply to a party. “Customer Personal Data” means personal data contained in your workspace that we process on your behalf. “Controller”, “processor”, “data subject”, “processing”, “personal data breach” and “sub-processor” have the meanings given in the GDPR, and equivalent terms in other Data Protection Laws are read accordingly, so “business” and “service provider” under the CCPA map to controller and processor.

Terms not defined here have the meaning given in the Terms of Service.

3. Roles of the parties

You are the controller of Customer Personal Data and we are your processor. Where you are yourself acting as a processor for someone else, we are your sub-processor, and your instructions to us must be consistent with your own controller’s instructions.

You are responsible for:

  • having a lawful basis for the personal data you put into or collect through Sedgemark;
  • giving the required privacy notices to the people it concerns, including on any page carrying one of your forms;
  • the accuracy and lawfulness of what you instruct us to process;
  • your own configuration choices, including who you invite, what permissions you grant, which forms you publish and where you send webhooks.

We are the controller of the account, billing and log data described in our Privacy Policy. That data is not Customer Personal Data and is not governed by this DPA.

4. Our processing obligations

We will:

  • process Customer Personal Data only on your documented instructions (which comprise the Terms, this DPA, the configuration choices you make in the product, and any further written instruction you give us), unless a law we are subject to requires otherwise, in which case we will tell you before processing unless that law forbids it;
  • not process it for our own purposes, and specifically not to train or improve artificial intelligence or machine learning models, to build profiles, or for advertising;
  • tell you promptly if, in our opinion, an instruction infringes Data Protection Laws, though we are not obliged to give you legal advice;
  • ensure the security measures in section 6 and Annex B are in place.

AI features are your instruction, not ours. If you enable AI-populated fields, you are instructing us to transmit the content your prompt names to the provider you selected, using the API key you supplied. That provider acts under your relationship with them, not ours.

5. Confidentiality

We will keep Customer Personal Data confidential, and will ensure that anyone we authorise to process it is under a duty of confidentiality and processes it only on our instructions. Access is limited to those who need it to operate the service or to support you.

6. Security

We will implement appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing. The measures in place are described in Annex B.

We may update those measures over time, provided we do not materially reduce the level of protection. No system is perfectly secure, and we do not warrant that our measures will prevent every incident.

7. Sub-processors

You give us general authorisation to engage sub-processors. The current list is the provider table in section 6 of our Privacy Policy, which we maintain as the single source of truth rather than duplicating it here, so the two can never disagree.

Before adding or replacing a sub-processor that handles Customer Personal Data, we will update that table and notify workspace owners by email at least 30 days in advance. If you reasonably object on data protection grounds within that period, tell us and we will work with you to find an alternative. If we cannot, you may terminate the affected part of the service and we will refund any fees you have prepaid for the period after termination.

We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.

8. Helping you meet your obligations

Data subject requests. The dashboard lets you find, correct, export and delete data in your workspace yourself, which will usually be the fastest route. Where you need more, we will provide reasonable assistance. If a data subject contacts us directly about data we hold for you, we will not respond substantively: we will tell them to contact you and forward the request where we can identify you.

Assessments and consultations. Taking into account the nature of the processing and the information available to us, we will give reasonable assistance with data protection impact assessments and with any prior consultation with a supervisory authority. Our Privacy Policy and Annex B are designed to answer most of what such an assessment needs.

9. Personal data breaches

We will notify you without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records involved so far as known, the likely consequences, the measures taken or proposed, and a contact point for more information.

Where we cannot provide all of that at once we will provide it in phases as it becomes available. Notifying you is not an admission of fault or liability. Notifying supervisory authorities and data subjects is your responsibility as controller; we will give you the information you reasonably need to do it.

10. Return and deletion

You can export your content at any time through the delivery API, the generated client or the MCP server, and we recommend doing so before you leave.

On termination, or on your written instruction, we will delete Customer Personal Data. Deletion in Sedgemark is immediate and irreversible: it cancels the subscription, erases uploaded files from object storage and drops the workspace database. Residual copies persist only in routine backups, which age out within 30 days and are used solely for disaster recovery. We will confirm deletion in writing on request.

We may retain personal data where a law requires it, for as long as that law requires, and will keep it protected by this DPA for that period.

11. Audits and information

We will make available the information reasonably necessary to demonstrate compliance with this DPA, and will respond to a reasonable security questionnaire once in any twelve month period. Our Privacy Policy, this DPA and Annex B are intended to answer the large majority of such questions without a bespoke exchange.

Where Data Protection Laws give you a right to audit that the above does not satisfy, an audit may be carried out on at least 30 days’ written notice, no more than once in any twelve month period (unless a supervisory authority requires otherwise), during business hours, subject to confidentiality, in a manner that does not unreasonably disrupt our operations, and at your cost.

We do not currently hold a SOC 2, ISO 27001 or comparable third-party certification, and we say so plainly rather than leaving it to be discovered.

12. International transfers

Customer Personal Data is processed in the United States, as described in section 7 of our Privacy Policy.

Where you transfer personal data subject to the EU GDPR, UK GDPR or Swiss FADP to us, and the transfer requires an appropriate safeguard, the European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), are incorporated into this DPA by reference and completed as follows:

  • the data exporter is you; the data importer is CodeCube Ventures LLC d/b/a Sedgemark;
  • the optional docking clause in Clause 7 does not apply;
  • in Clause 9, Option 2 (general written authorisation) applies, with the notice period in section 7 of this DPA;
  • in Clause 11, the optional independent dispute resolution body does not apply;
  • in Clause 17, the Clauses are governed by the law of Ireland; in Clause 18(b), disputes are resolved before the courts of Ireland;
  • Annex I is completed by Annex A of this DPA, and Annex II by Annex B;
  • for UK transfers, the UK International Data Transfer Addendum applies to the Clauses, with the tables completed from this DPA; for Swiss transfers, references to the GDPR are read as references to the FADP and supervision includes the Swiss FDPIC.

If a mechanism the Clauses rely on is invalidated, we will work with you in good faith to put an alternative lawful safeguard in place.

13. California: service provider terms

For personal information subject to the CCPA, we act as a service provider. We will not:

  • sell or share it, as those terms are defined in the CCPA;
  • retain, use or disclose it for any purpose other than performing the services, or as otherwise permitted by the CCPA;
  • retain, use or disclose it outside the direct business relationship between us;
  • combine it with personal information from another source, except as the CCPA permits a service provider to do.

We certify that we understand these restrictions and will comply with them. We will tell you if we determine we can no longer meet them, and you may take reasonable steps to stop and remediate any unauthorised use.

14. Liability and precedence

Where this DPA conflicts with the Terms of Service or the Privacy Policy on the subject matter of processing Customer Personal Data, this DPA prevails. In all other respects the Terms continue unchanged.

The limitations and exclusions of liability in section 15 of the Terms apply to this DPA. Each party’s total liability arising under both documents together is subject to that single aggregate cap, and claims under this DPA do not create a separate one. Nothing here limits any data subject’s rights under the Standard Contractual Clauses or any liability that cannot be limited by law.

Annex A: Details of the processing

Subject matter. Provision of the Sedgemark hosted content management service.

Duration. For as long as your workspace exists, plus the backup window in section 10.

Nature and purpose. Hosting, storage, structuring, retrieval, transmission, backup and deletion of the content you place in your workspace, together with delivery of that content to systems you direct us to, and, where you use site hosting, storage and serving via Cloudflare of the static site files you deploy, so that we can provide the service.

Categories of data subjects.

  • your personnel and anyone you invite to your workspace;
  • visitors to your websites who submit one of your forms;
  • any individual described in the content you store;
  • any individual described in a site you deploy.

Categories of personal data.

  • workspace users: email addresses, password hashes, roles and permission grants;
  • form submissions: whatever fields you define, plus the submitter’s IP address, browser user-agent and originating page, and any files attached;
  • content and media: any personal data you choose to store in entries or uploaded files;
  • integration credentials: API key hashes, webhook signing secrets and AI provider keys;
  • hosted sites: any personal data you choose to include in a site you deploy.

Special categories. None are required, requested or expected. The Terms prohibit using forms to collect payment card numbers, government identifiers, health records and similar sensitive categories. If you store special category data anyway, you do so as controller and on your own assessment.

Frequency. Continuous, for as long as you use the service.

Retention. As set out in section 8 of the Privacy Policy, and otherwise until you delete it.

Annex B: Technical and organisational measures

Encryption and pseudonymisation

  • HTTPS/TLS for all traffic, with automatically renewed certificates.
  • Database credentials, webhook signing secrets and AI provider keys encrypted at rest with AES-256.
  • User passwords stored as salted scrypt hashes, compared in constant time; never recoverable.
  • API keys stored as SHA-256 hashes and displayed once at creation.
  • Password reset tokens stored only as hashes, single use, short lived.
  • Full-disk encryption on application and database servers.

Confidentiality and access control

  • Each workspace has its own PostgreSQL database with its own credentials: tenants do not share tables, and isolation is structural rather than filter-based.
  • Granular per-user and per-API-key permissions, enforced server-side on every route and every agent tool.
  • Administrative access to the platform requires a hardware-backed passkey; there is no password login for it.
  • Production access is limited to authorised personnel only.
  • Backup storage uses a separate credential with no access to the media bucket, and the media credential has no access to backups.
  • Credentials are redacted from server access logs, and provider error messages are redacted before storage.

Integrity and availability

  • Nightly automated database dumps to object storage, retained 30 days with the 7 most recent runs always kept, each run recording its outcome in a manifest.
  • Automated monitoring of service availability, backup completion and disk usage, with alerting on failure and on a job silently not running.
  • Rate limiting and anti-abuse controls on public endpoints, including the public form endpoint.
  • Outbound webhook destinations restricted, and redirects refused.

Testing and governance

  • Automated type checking, test suite and build verification on every change before it can be merged.
  • Source-level assertions enforcing security-relevant conventions, so a new code path cannot silently skip an authorisation or tenant-isolation check.
  • Documented incident and recovery procedures maintained alongside the code.