René Studio
Legal · DPA

What we do with data you are responsible for.

The processor terms that apply whenever your team loads personal data into a René workspace.

Last updated
1 September 2026
Version
v2.1
Sections
8 clauses
In short
  • You are the controller. We are the processor and act only on your instruction.
  • Sub-processors are published, and you are notified 30 days before any addition.
  • We notify you of a personal data breach without undue delay and within 72 hours of becoming aware.
  • On exit, data is returned in a machine-readable export and then deleted.

This DPA forms part of the agreement. Where your organisation has signed its own DPA with Renascence, that document governs instead.

01

Roles and subject matter

For personal data contained in workspace content, your organisation is the controller and Renascence is the processor. The subject matter is the provision of the René platform; the duration is the term of the agreement; the categories of data subject are your customers, citizens, patients or employees as your use determines.

02

Instructions and limits

We process personal data only to provide the service, to comply with your documented instructions, and where required by law. If we believe an instruction breaches applicable data protection law we will tell you and may pause that processing. We do not process for our own purposes, and we do not use the data to train models. [counsel]

03

Sub-processors

Current sub-processors are published on the sub-processor page with purpose and region. We give at least 30 days' notice before adding one, and you may object on reasonable data protection grounds; if the objection cannot be resolved you may terminate the affected service without penalty.

04

Security measures

Tenant isolation, encryption in transit and at rest, role-based access, least-privilege administrative access with logging, secure development practice, annual penetration testing and an ISO 27001-aligned control set. The current technical and organisational measures are listed on the Security page and form part of this DPA.

05

International transfers

Data stays in the region set at provisioning. Where a transfer is necessary and you have instructed it, we rely on an approved transfer mechanism and apply supplementary measures where the assessment requires them. [counsel]

06

Data subject requests

We do not respond to data subject requests about your content directly. We refer the request to you within five working days and provide the tooling and assistance needed for you to answer it, including export, correction and deletion at record level.

07

Breach notification

On becoming aware of a personal data breach affecting your content we notify your named security contact without undue delay and within 72 hours, with the facts known at that point, the likely consequences and the measures taken. Updates follow as the investigation proceeds.

08

Audit, return and deletion

We make our certifications, control descriptions and latest test summary available on request, and will support one audit a year where a regulator requires it. On termination we provide a full export and then delete the data on the schedule in the Privacy Policy, confirming deletion in writing on request.

Make one journey measurable this week.

Start with the journey that costs you the most. Free plan, one journey, all four views — no card, no call.

Or talk to the Renascence team about an enterprise evaluation.