Processing roles
The applicable customer agreement and product configuration determine whether an organization acts as a controller, business, or similar decision-maker and whether Corsaca processes customer information on its behalf.
Documented instructions
Corsaca processes customer information to provide configured services, support authorized product operations, protect the service, and follow documented customer instructions consistent with the agreement and applicable law.
Confidentiality and access
Customer information should be available only to authorized people and providers with a service-related need. Customers remain responsible for their own user assignments, staff practices, and lawful collection.
Security responsibilities
Corsaca maintains product and infrastructure safeguards represented in the Trust Center. Customers configure roles, permissions, organization settings, and appropriate use within their tenant.
Service providers
Corsaca may rely on providers for hosting, data, authentication, payments, storage, and conversational services. Provider roles depend on the products and capabilities the customer enables.
Individual requests and incidents
Customers can contact support for reasonable assistance routing data-subject requests or investigating a product incident. The organization remains the primary contact for people whose records it manages.
Request an applicable DPA
Email hello@corsaca.com with the organization name, products in scope, and contracting contact. Corsaca will identify the agreement path applicable to the customer relationship.