Roles
Each customer is the controller of the data it connects to Xevrion Ops. Xevrion processes that data only to provide the service and only on the customer's documented instructions, which include the connections, permissions and approval rules the customer sets.
Confidentiality and security
Access is limited to people who need it and are bound by confidentiality. Security measures are described on our security page, including tenant isolation, sealed credentials, two-factor sign-in, approvals and audit logging.
Subprocessors
We use the subprocessors listed on our subprocessors page and will give notice of changes in writing.
Assistance
We help customers respond to data subject requests, carry out assessments and meet their security obligations, using the export, deletion and audit features of the platform.
Incidents
We will notify affected customers without undue delay after becoming aware of a personal data breach affecting their data, with the information they need.
End of service
On cancellation, customers can export their data. An owner can then complete deletion; operational data is deleted or anonymised, financial records follow retention rules and a minimal record of the deletion is kept.
Signed agreement
A signed data processing agreement is available on request: write to outreach@ops.xevrion.co.uk.
Contact
Questions about this page: outreach@ops.xevrion.co.uk. We reply in writing.