# Data processing addendum | Chersus

Legal

# Data processing addendum

The data processing addendum covering Chersus processing of customer data on behalf of controllers: roles, subprocessors, and audits.

Last updated 2026-09-03

This data processing addendum (DPA) forms part of the terms of service and applies where Chersus processes personal data on behalf of a customer. Chersus is a product of GoodFolk B.V., a company incorporated in the Netherlands; references to Chersus mean GoodFolk B.V. This DPA implements Article 28 GDPR.

## Definitions

Controller, processor, data subject, personal data, processing, and personal data breach have the meanings given in the GDPR. Customer is the controller that uses the service. Payload is the content submitted to the API, including any personal data it contains. Services are the Chersus API and related functionality.

## Subject matter and duration

Subject matter is the processing of payloads to provide the services. For each request, the processing lasts the duration of that request. This DPA applies for the term of the contract between the parties.

## Nature and purpose of processing

Processing is automated and stateless: payloads are held in memory for the duration of a request and are not persisted, not used to train models, and not disclosed to third parties. The purpose is the operation of the services the customer has ordered, namely redaction, tokenization, classification, extraction, and routing on the payload. Chersus determines the means of processing; the purposes and the lawfulness of the processing are determined by the customer.

## Categories of data and data subjects

The categories of personal data are whatever the customer submits as payload, at its sole choice, typically text containing names, contact details, identifiers, or free text. Special categories of data are processed only if the customer submits them. Data subjects are the persons whose data the customer processes, typically its end users or employees.

## Obligations of the processor

Chersus processes personal data only on documented instructions from the customer, which these terms and the customer’s service configuration constitute, and informs the customer if an instruction appears to infringe data protection law. Chersus ensures that persons authorized to process personal data are bound by confidentiality. It takes the technical and organizational measures described in this DPA. It assists the customer with data subject rights, security, breach notification, and impact assessments as described below. It makes available all information necessary to demonstrate compliance and submits to audits as described below. It deletes data as described below at the end of the contract.

## Sub-processors

The customer grants general written authorization to engage sub-processors. The current list, with each sub-processor’s role, location, and engagement date, is on the subprocessors page. Chersus notifies customers of new sub-processors at least 30 days before they begin processing; a customer may object on reasonable data-protection grounds within that period. If an objection cannot be resolved, the customer may terminate the affected services. Chersus binds every sub-processor to obligations no less protective than this DPA and remains fully liable for their performance.

## International transfers

All processing, including by sub-processors, takes place in the European Union. Should any processing ever take place outside the EEA, Chersus will rely on an adequacy decision or, failing that, on standard contractual clauses approved by the European Commission, and will record the safeguards on the subprocessors page before the transfer begins.

## Technical and organizational measures

Stateless processing: payloads exist in memory for the duration of a request and are never written to storage; audit traces contain SHA-256 hashes of payloads, never their content. Encryption in transit with TLS for all traffic. Access to production systems is restricted to personnel who require it, under individual credentials, and logged. One-time-code authentication, API key secrecy, rate limiting, and abuse detection protect the platform. No payload content is included in any log.

## Assistance with data subject rights

Because Chersus stores no payloads, requests by data subjects concerning payload content are handled by the customer as controller; Chersus assists by providing the audit trace of the affected request, which allows the customer to prove what was processed. Where a request concerns data Chersus holds in its own right, such as account or billing data, Chersus responds within one month.

## Personal data breach notification

Chersus notifies the customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting data processed on the customer’s behalf. The notification states the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken. Because processing is stateless, a breach of payload content is limited to exposure during in-memory processing. Chersus does not notify data subjects or supervisory authorities on the customer’s behalf unless instructed in writing.

## Audits and inspections

Chersus provides the information and documentation needed for the customer to demonstrate compliance, including the subprocessor list and this DPA. Once a year, and additionally after a personal data breach, the customer may audit compliance by questionnaire or review of documentation. On-site inspection is available where those do not suffice, at a mutually agreed time, on at least 30 days’ notice, and without access to data of other customers.

## Deletion or return of data on termination

Payloads are never stored, so there is no payload data to return or delete; processing ends with each request. Account and configuration data are deleted within 30 days of the end of the contract, except for billing records retained under statutory bookkeeping obligations, which Chersus protects and uses only for that purpose.

## Liability

Liability between the parties is governed by the limitation of liability in the terms of service; its cap applies to claims under this DPA. Nothing in this DPA limits liability that cannot be limited under mandatory law.

## Governing law

This DPA is governed by Dutch law, without regard to conflict-of-law rules. Mandatory data protection law, in particular the GDPR, applies unchanged.