Data categories and subjects
The distinct categories of data in Eddy, who controls each, the data subjects covered by the DPA, and sensitive data tiers.
1. Data categories
"Data" across the Eddy policies refers to the following distinct categories, each carrying different rights.
| Category | Description | Controller |
|---|---|---|
| Customer Content | Data typed, uploaded, or decided by users in Map stages | Customer |
| Map Configuration | Process designs — Maps, Stages, Blocks, Transitions, Roles | Customer (author org) |
| Process Execution State | Live state of a run — Session assignments, stage state, routing | Customer |
| Process Metadata | Operational trace — timestamps, durations, handoff timing, path taken | Generated by Eddy Works |
| Usage Telemetry | Product analytics events — page views, feature events, audit logs | Eddy Works |
| Analytical Data | De-identified / aggregated statistics and trends | Eddy Works |
| Template IP | Map blueprints in Private, Partner, or Public tier | Tier-dependent — see clause 11 |
| AI Inputs/Outputs | Prompts submitted to and results returned from AI features | Customer Content in nature |
The Controller column determines who can request, export, or delete each category — and who is legally responsible for it. Categories where the Customer is controller are processed by Eddy Works as Processor under the DPA. Categories where Eddy Works is controller are governed by the Privacy Policy.
2. Data subjects
The Data Processing Addendum covers the following categories of data subject.
| Category | Description |
|---|---|
| Organisation Owners, Admins, and Members | Employees or contractors of the Customer using the Service under the Customer's Organisation |
| Guests / External Participants | Individuals invited to participate in a Session via a link; hold independent Eddy accounts; access is scoped to the Session stages they are assigned to |
| Contacts | Individuals named in Customer Content (form responses, comments) who are not Eddy users; no FK link to user record; Customer is controller |
3. Sensitive data
The following categories of personal data (some of which may constitute sensitive data, or special categories of personal data, as defined in Applicable Data Protection Law) may be processed where the Customer (as controller) and the Customer's Members and Guests input those categories of personal data when using the Services. The Customer is solely responsible for confirming it has an appropriate lawful basis under Applicable Data Protection Law (including Article 9 GDPR where applicable to the relevant personal data) for processing any sensitive data or special categories of personal data using the Service, including making the data available to Eddy Works for processing in accordance with the Terms, and has provided all notifications required under Applicable Data Protection Law to the relevant data subject:
- Health and safety incident data
- Equality and diversity data
- Educational records
- Employment-related performance and disciplinary data
Payment card data, biometric data for identification, HIPAA-regulated health data, and other Tier 1 categories (as defined in the AUP) may not be processed via Eddy without a separate written agreement signed by us.
4. Nature and purpose, and duration, of processing of personal data by Eddy Works and by sub-processors
Eddy Works processes Personal Data to: provide the Service (Map execution, Session routing, Table storage); send transactional notifications; provide support; maintain platform security and integrity; and generate anonymised operational analytics. Processing is carried out for the duration of the Customer's subscription and as described in clause 12 of the DPA on termination.
The subject matter, nature, and duration of the processing of the personal data by sub-processors to whom Eddy Works transfers personal data in accordance with the DPA and other Terms are as set out in the DPA and the other Terms, on an as-needed basis to provide the Service.
5. Frequency of processing of personal data
Continuous, subject to the Customer's requirements and use cases.
6. Period for which personal data will be retained
As set out in clause 12 of the DPA.
