LEGAL · GDPR
Our GDPR posture
A plain summary of how Cyphertree meets GDPR — the binding detail lives in our DPA and Privacy policy.
Draft, pending legal review. This document is published for transparency and is being finalised with counsel. For a binding agreement, contact support@cyphertree.com.
Controller and processor roles
Cyphertree's GDPR role depends on whose data is being processed and why.
| Scenario | Cyphertree's role |
|---|---|
| Delivering EOR services on a client's behalf — payroll, tax, onboarding, performance, recruitment for employees hired in India | Processor (Data Processor under DPDP). The European client is the Controller and determines the purposes and means. |
| Data we collect for our own purposes — account creation, our own marketing, platform security | Controller (Data Fiduciary under DPDP). |
The full mapping of processing activities, data categories, and durations is set out in our Data Processing Agreement. Details on the data we collect as controller are in our Privacy policy.
Lawful bases for processing
Every processing activity rests on a defined GDPR lawful basis:
| Processing activity | GDPR basis |
|---|---|
| Account creation & authentication | Art. 6(1)(b) — Contract |
| Google OAuth sign-in | Art. 6(1)(a) — Consent |
| Google Calendar integration | Art. 6(1)(a) — Consent |
| Payroll & tax processing | Art. 6(1)(c) — Legal obligation |
| Employee lifecycle management | Art. 6(1)(b) — Contract |
| Electronic signatures | Art. 6(1)(b) — Contract |
| Performance management | Art. 6(1)(f) — Legitimate interest |
| Recruitment / ATS | Art. 6(1)(b) — Pre-contractual steps |
| AI candidate ranking | Art. 6(1)(a) — Consent |
| Transactional emails | Art. 6(1)(b) — Contract |
| Marketing emails | Art. 6(1)(a) — Consent |
| Platform security | Art. 6(1)(f) — Legitimate interest |
The DPDP equivalents for each activity are listed in the Privacy policy.
Your rights and how to exercise them
Under GDPR you can exercise the following rights over your personal data:
| Right | GDPR article | What it means |
|---|---|---|
| Access | Art. 15 | Request a copy of all data we hold about you |
| Rectification | Art. 16 | Correct inaccurate data |
| Erasure | Art. 17 | Request account and data deletion |
| Portability | Art. 20 | Export your data in JSON or CSV |
| Restriction | Art. 18 | Pause processing of specified data |
| Objection | Art. 21 | Object to processing based on legitimate interest |
| Withdraw consent | Art. 7(3) | Withdraw consent at any time |
How to exercise them: email privacy@cyphertree.com with the subject "Data Subject Request — [Your Name]". We respond within 30 days. For account deletion, email support@cyphertree.com — processed within 30 days, subject to legal retention. You can revoke Google access at any time via Google Account Permissions.
Where Cyphertree acts as processor for a client, we assist the Controller in responding to these requests within the timeframes committed in the DPA, and forward any request we receive directly to the Controller.
International transfers (EU → India)
Cyphertree operates from Pune, India, so personal data processed for EOR services is transferred from the EEA to India. That transfer is protected by:
- Standard Contractual Clauses (SCCs) — European Commission Implementing Decision (EU) 2021/914, Module Two (Controller to Processor), incorporated by reference into our DPA
- A documented Transfer Impact Assessment (TIA) evaluating Indian data protection laws and supplementary measures
- Supplementary measures — encryption at rest and in transit, access controls, audit logging, and contractual commitments
Our primary database runs on Neon in the EU (Frankfurt) region, so operational data storage stays within the EU. Where sub-processors process data outside the EU, SCCs apply — see below.
Sub-processors
The Controller provides general written authorisation for Cyphertree to engage the sub-processors below. Cyphertree gives the Controller at least 14 days' notice before adding or replacing a sub-processor, with the opportunity to object.
| Sub-processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Neon (Neon Inc.) | Database hosting (PostgreSQL) | EU — Frankfurt | DPA + EU hosting |
| Cloudflare (Cloudflare Inc.) | CDN, DNS, DDoS protection, WAF | Global (EU processing) | DPA + SCCs |
| Resend (Resend Inc.) | Transactional & marketing email delivery | US | DPA + SCCs |
| Google (Google LLC) | OAuth authentication, Calendar API | Global | DPA + SCCs |
| AI model provider | Résumé screening & candidate ranking (ATS) | API only — no data retention | DPA + data minimisation |
The current sub-processor list is maintained in the DPA and updated on any change.
Breach notification
Cyphertree runs a documented incident and breach process.
- When Cyphertree acts as processor, we notify the Controller without undue delay and no later than 24 hours after becoming aware of a personal data breach, with the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and remedial measures
- We assist the Controller in notifying the supervisory authority within 72 hours per GDPR Art. 33, and affected data subjects per GDPR Art. 34 where required
- We cooperate fully with the Controller's investigation and any supervisory authority inquiry, and document the breach and remedial actions
- Under Section 8(6) of the DPDP Act, we also notify the Data Protection Board of India without delay of any breach affecting Data Principals in India
Internally, incidents are classified SEV-1 to SEV-4 with defined response and resolution targets, and SEV-1/SEV-2 incidents receive a post-mortem within 72 hours. Full breach terms are in the DPA.
Complaints and contacts
If you have a concern, contact us first so we can resolve it:
- Privacy: privacy@cyphertree.com
- Grievance Officer (DPDP): grievance@cyphertree.com
You also have the right to lodge a complaint with a supervisory authority:
- EEA residents: Autoriteit Persoonsgegevens (Netherlands), or your local data protection authority
- Indian residents: the Data Protection Board of India, after exhausting our internal grievance mechanism
For the full binding terms, see our Data Processing Agreement and Privacy policy.