eddy.docs
ActiveOwner: DanUpdated: 11 Jun 2026

Data categories and subjects

The distinct categories of data in Eddy, who controls each, the data subjects covered by the DPA, and sensitive data tiers.

COUNTER-DRAFT — Eddy Works, 11 June 2026. Published here for review — not yet approved by counsel and not yet in force.

1. Data categories

"Data" across the Eddy policies refers to the following distinct categories, each carrying different rights.

CategoryDescriptionController
Customer ContentData typed, uploaded, or decided by users in Map stagesCustomer
Map ConfigurationProcess designs — Maps, Stages, Blocks, Transitions, RolesCustomer (author org)
Process Execution StateLive state of a run — Session assignments, stage state, routingCustomer
Process MetadataOperational trace — timestamps, durations, handoff timing, path takenGenerated by Eddy Works
Usage TelemetryProduct analytics events — page views, feature events, audit logsEddy Works
Analytical DataDe-identified / aggregated statistics and trendsEddy Works
Template IPMap blueprints in Private, Partner, or Public tierTier-dependent — see clause 11
AI Inputs/OutputsPrompts submitted to and results returned from AI featuresCustomer Content in nature

The Controller column determines who can request, export, or delete each category — and who is legally responsible for it. Categories where the Customer is controller are processed by Eddy Works as Processor under the DPA. Categories where Eddy Works is controller are governed by the Privacy Policy.

2. Data subjects

The Data Processing Agreement covers the following categories of data subject.

CategoryDescription
Organisation Owners, Admins, and MembersEmployees or contractors of the Customer using the Service under the Customer's Organisation
Guests / External ParticipantsIndividuals invited to participate in a Session via a link; hold independent Eddy accounts; co-own access to Session stages they participated in
ContactsIndividuals named in Customer Content (form responses, comments) who are not Eddy users; no FK link to user record; Customer is controller

Eddy Works processes Personal Data to: provide the Service (Map execution, Session routing, Table storage); send transactional notifications; provide support; maintain platform security and integrity; and generate anonymised operational analytics. Processing is carried out for the duration of the Customer's subscription and as described in clause 12 of the DPA on termination.

3. Sensitive data

3.1

The following categories may be processed where the Customer (as controller) has confirmed an appropriate lawful basis under Article 9 GDPR:

  • Health and safety incident data
  • Equality and diversity data
  • Educational records
  • Employment-related performance and disciplinary data
3.2

Payment card data, biometric data for identification, HIPAA-regulated health data, and other Tier 1 categories (as defined in the AUP) may not be processed via Eddy without a separate written agreement.

On this page