RocSite
Data processing addendum

Data Processing Addendum

Effective 2026-09-18 · incorporated into the Terms of Service

This addendum applies where RocSite processes personal data on behalf of a Customer in connection with the service. It forms part of the Terms of Service. Where this addendum and the Terms differ on the processing of personal data, this addendum controls.

1. Roles

The Customer is the controller of personal data in its workspace and determines the purposes and means of its processing. RocSite is the processor, and processes that data only on the Customer's documented instructions, which include the Customer's configuration and use of the service's features. RocSite will tell the Customer if an instruction appears to breach applicable data protection law.

2. Subject matter, duration, nature and purpose

ItemDetail
Subject matterProvision of the RocSite workspace service.
DurationThe term of the subscription, plus the export and deletion periods in the Terms.
Nature and purposeHosting, storage, indexing, search, retrieval, transcription, AI-assisted answering, transmission, backup and deletion, to operate the service for the Customer.
Categories of data subjectThe Customer's personnel and invited members, and any individuals referenced in content the Customer places in its workspace (for example CRM contacts, meeting participants, email correspondents).
Categories of personal dataIdentification and contact data (name, work email), authentication data (password hashes, tokens), usage and audit records, and any personal data contained in Customer content, documents, notes, wiki and board entries, CRM and calendar records, messages, recordings and transcripts, and, where a mailbox is connected, email.
Special categoriesNot requested or required by the service. The Customer decides what it places in its workspace and is responsible for any special category data it chooses to include.

3. Confidentiality

RocSite ensures that people authorized to process personal data are bound by confidentiality obligations and are granted access only as needed to operate and support the service.

4. Security measures

RocSite implements appropriate technical and organizational measures, including:

5. Subprocessors

The Customer authorizes RocSite to engage the subprocessors listed at /subprocessors. RocSite imposes data protection obligations on each subprocessor no less protective than those in this addendum, and remains liable for their performance. RocSite will give at least 30 days' notice before adding or replacing a subprocessor, and the Customer may object on reasonable data protection grounds; if the objection cannot be resolved, the Customer may terminate the affected part of the service without penalty for the remainder of the term.

6. Location of processing

Customer content is hosted on infrastructure operated for RocSite. AI features, assistant, search, transcription, embeddings, are served by models running on that same infrastructure, not by a third-party model provider, unless a specific feature states otherwise. Network delivery, access control and file storage use Cloudflare; payments use Stripe; transactional email uses Resend. Those subprocessors operate globally and may process the limited data described in the subprocessors list outside the Customer's country.

⚠ CONFIRM BEFORE PUBLISHING. The hosting country and the transfer mechanism relied on for EU/UK customers (Standard Contractual Clauses, UK Addendum) must be stated explicitly here. Both depend on the legal entity and jurisdiction that are still to be set in the Terms of Service, and neither has been guessed.

7. Assistance to the Customer

8. Personal data breach

RocSite will notify the Customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting the Customer's personal data. The notification will describe the nature of the breach, the categories and approximate volume of data affected so far as known, the likely consequences, and the measures taken or proposed. RocSite will provide further information as the investigation progresses.

9. Deletion and return

Customer administrators can export a workspace at any time and can permanently purge it from inside the app. On termination or expiry the Customer may export for 30 days, after which RocSite deletes the personal data from active systems. Residual copies in encrypted backups expire on the ordinary backup cycle. RocSite may retain data where required by law.

10. Audit

RocSite will make available information reasonably necessary to demonstrate compliance with this addendum, and will allow for and contribute to audits by the Customer or an independent auditor appointed by it, no more than once per year unless required by a supervisory authority or following a personal data breach, on reasonable notice, during business hours, subject to confidentiality, and in a manner that does not compromise the security or data of other customers.

11. Liability

Each party's liability under this addendum is subject to the limitations and exclusions in the Terms of Service.

Contact

Data protection enquiries: RocSite · support@rocsite.com