CrossTenant

Data Processing Agreement

Last updated: 31 August 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between CrossTenant Ltd (company no. 17349672, registered office Unit 82a James Carter Road, Mildenhall, Bury St. Edmunds, IP28 7DE, United Kingdom) and the Customer. It applies wherever CrossTenant processes personal data on the Customer’s behalf, and satisfies Article 28 of the UK GDPR and, where applicable, of the EU GDPR. Capitalised terms not defined here have the meaning given in the Terms of Service.

Read section 1 first. CrossTenant sits at the end of a three-party chain — a Managed Organisation, the MSP that administers it, and us. Section 1 says exactly who is controller, who is processor, and which data this DPA does not cover. Getting that wrong is the most common mistake in agreements of this shape.

1. Roles of the parties

1.1 Managed Organisation data — the main case

For personal data within a Managed Organisation’s Google Workspace:

The Customer confirms that it has the authority described in section 4 of the Terms of Service, and that its agreement with each Managed Organisation permits our engagement on these terms. CrossTenant has no direct contractual relationship with the Managed Organisation and takes its instructions from the Customer.

1.2 What this DPA does not cover

CrossTenant is an independent controller, not a processor, for two categories of data, and this DPA does not govern them:

We are the controller for those because we determine that they exist, what they contain, and how long they are kept — they are how the service is secured and made accountable, and the Customer cannot instruct us to stop keeping them while using the service. Our handling of them is described in the privacy policy. The audit log is deliberately minimised: a record identifies the operator, the customer scope, the class of operation and the outcome, and — outside two narrow, disclosed exceptions — does not retain the identifier of the account an action targeted; the record is of the action, not of any person’s activity. Sections 5, 9 and 12 of this DPA are applied to that data as a matter of contract even though we hold it as controller.

2. Scope, duration, and instructions

This DPA applies for as long as CrossTenant processes personal data for the Customer, and its surviving obligations continue afterwards. Annex I describes the subject matter, nature, purpose, data types, and data subjects.

CrossTenant will process personal data only on the Customer’s documented instructions, which are: the Terms of Service, this DPA, the configuration and actions the Customer’s Authorised Users perform in the console, and any further written instruction the parties agree. We will not process it for any other purpose, and in particular we do not use it to train machine-learning models, sell it, or use it for advertising.

We will tell the Customer if we consider an instruction infringes data protection law, and may pause the affected processing while it is resolved. If we are required by law to process personal data other than on the Customer’s instructions, we will inform the Customer beforehand unless the law prohibits it on important grounds of public interest.

3. Confidentiality

CrossTenant ensures that every person authorised to process personal data under this DPA is bound by an appropriate duty of confidentiality, has been made aware of the confidential nature of the data, and is granted access only to the extent their role requires.

4. Security

CrossTenant implements and maintains the technical and organisational measures set out in Annex II, which are appropriate to the risk under Article 32. We may update those measures as the service develops, provided the level of protection is not reduced. The most significant measure is architectural: the service does not store Google Workspace content, so the great majority of the Customer’s customers’ personal data is never at rest with us at all. Annex II states precisely what is.

5. Sub-processors

The Customer gives general written authorisation for CrossTenant to engage sub-processors. The current list, with each sub-processor’s purpose, location, and transfer mechanism, is published at crosstenant.com/subprocessors and forms Annex III. A provider already listed as Current when the Customer enters into this DPA is part of the disclosed list the Customer authorises at that point.

Google is a special case and is treated as such in Annex III: the Workspace data CrossTenant reads already resides with Google under the Managed Organisation’s own agreement with Google. CrossTenant does not place that data with Google; it retrieves it from there.

6. Assistance with data subject rights

Because CrossTenant stores no Workspace content, a data subject’s personal data almost always remains in the Managed Organisation’s own Google Workspace, where the controller can act on it directly — which is normally the fastest route for everyone.

Taking that into account, CrossTenant will assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling obligations to respond to requests to exercise data subject rights. If a request reaches us directly, we will not respond to it ourselves except to acknowledge it and direct the individual appropriately, and we will inform the Customer without undue delay. Assistance is provided at no charge for reasonable volumes.

7. Assistance with the Customer’s wider obligations

Taking into account the nature of the processing and the information available to us, CrossTenant will assist the Customer in complying with its obligations under Articles 32 to 36 — security of processing, breach notification, data protection impact assessments, and prior consultation. This includes providing the information in this DPA, the security page, and reasonable responses to security questionnaires.

8. Personal data breach

CrossTenant will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting personal data processed under this DPA. The notification will describe, so far as known at the time and supplemented as we learn more:

We will cooperate with the Customer and take reasonable steps as it directs to assist in investigating, mitigating, and remediating the breach. A notification under this section is not an admission of fault or liability. The Customer is responsible for any notification it or a Managed Organisation owes to a supervisory authority or to data subjects.

9. Deletion and return

On termination of the Terms of Service, or earlier on the Customer’s written request:

Exception — the write-audit log. The audit log is retained for a maximum of 24 months from the date of each entry, then deleted automatically, including after termination. It is retained as the accountable record of privileged administrative actions taken against Managed Organisations, in the legitimate interests of CrossTenant, the Customer, and those organisations; a documented legitimate interests assessment supports this, and it contains no Workspace message or file content. This is the only category we retain beyond the deletion window.

10. Audits and information

CrossTenant will make available to the Customer the information reasonably necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.

In practice, and to keep this proportionate:

11. International transfers

CrossTenant is established in the United Kingdom and processes personal data in the United Kingdom and the European Economic Area, except for the sub-processors identified in Annex III as processing elsewhere.

Where personal data is transferred out of the UK or the EEA to a country without an adequacy decision, that transfer is made under an appropriate safeguard under Article 46 — the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses as supplemented by the UK Addendum, as identified for each sub-processor in Annex III. Where the UK Addendum applies, it is incorporated into this DPA and, unless the parties agree otherwise: the Customer is the exporter and CrossTenant the importer; the appendix information is taken from Annexes I and II; and neither party may end the Addendum under Section 19 of the Approved Addendum.

Google Workspace data resides in the region the Managed Organisation has configured with Google, under its own agreement with Google. CrossTenant does not relocate it.

12. Liability, precedence, and general


Annex I — Description of the processing

A. Parties

Exporter / controller or processor: the Customer, as identified in the Order.
Importer / processor or sub-processor: CrossTenant Ltd, Unit 82a James Carter Road, Mildenhall, Bury St. Edmunds, IP28 7DE, United Kingdom. Contact: privacy@crosstenant.com.

B. Description of the processing

ItemDetail
Subject matter Administration of Managed Organisations’ Google Workspace tenants through the CrossTenant console.
Nature of the processing Retrieval of data from Google’s APIs on request, transmission to and display for an Authorised User, and execution of administrative changes the Authorised User instructs. Generation of reports and posture assessments from that data. Storage limited to the categories in Annex II.
Purpose Enabling the Customer to deliver Google Workspace administration and security services to the Managed Organisations that have engaged it.
Categories of data subject End users, administrators, and other account holders of Managed Organisations; the Customer’s own Authorised Users; recipients of scheduled reports and alerts whose addresses the Customer enters; and people whose details the Customer deliberately places in a saved joiner role template.
Categories of personal data Directory data (names, email addresses, aliases, org-unit and group membership, admin roles, account status); device identifiers, ownership, and telemetry; mailbox configuration (forwarding addresses, delegates, send-as identities, vacation and filter settings, IMAP/POP state); Drive storage quota, file metadata, sharing and ownership information, and activity records; calendar lists, sharing permissions, and resources; audit and usage events including sign-in records and IP addresses; licence assignments; Vault matter and hold metadata; and operator-authored joiner role templates containing selected onboarding steps, org-unit, group and licence settings, an optional delegate address, and optional signature HTML.
Data not processed The content of email messages, the content of files, and the content of calendar entries and chats. The service reads mailbox and file settings and metadata, never the contents.
Special category data Not processed by design. The service requests no scope for special category data. Such data could in principle appear incidentally in a free-text directory field a Managed Organisation has populated, or in delegate or signature text an operator deliberately enters in a joiner template; it is not sought, categorised, or used.
Children’s data Where a Managed Organisation is an education deployment, its directory may include accounts of children. These are processed only as directory records, on the Managed Organisation’s instructions.
Frequency Continuous while the service is in use; each console page view is a fresh retrieval. Scheduled reports and alerts run on the Customer’s configured schedule.
Duration For the term of the Terms of Service, plus the deletion and audit-log retention periods in section 9.

C. Competent supervisory authority

The Information Commissioner’s Office (ICO), United Kingdom, in relation to UK GDPR. Where the EU GDPR applies to a transfer, the competent authority is that of the exporter’s establishment or, where it has none in the EEA, of the Member State where the data subjects concerned are located.

Annex II — Technical and organisational measures

These are the measures implemented in the CrossTenant service. A private CrossTenant-hosted release is running for founder dogfood on Microsoft Azure in the UK West region (United Kingdom); it is not yet a generally available customer service. The current hosted controls are identified below. Backups remain a separately identified future control and are not claimed as live. CrossTenant also supports an operator-controlled deployment, where disk encryption, network exposure and backups are the Customer’s responsibility to the specification we document. Every application measure applies either way.

1. Data minimisation — the primary control

2. Access control and identity

3. Control over changes

4. Accountability and audit

5. Cryptography and secret handling

6. Network and operational security

7. Assurance

Annex III — Sub-processors

The current list is maintained at crosstenant.com/subprocessors and is incorporated into this DPA by reference. It states each sub-processor’s identity, purpose, the personal data it can reach, its processing location, and the transfer mechanism relied on.

Contact

Data-protection matters: privacy@crosstenant.com. Related documents: Terms of Service · Privacy policy · Sub-processors · Security.