Your data, processed on your instructions.
Your index contains personal data — Creatio's own list of users, their roles, and who changed what. For that data you are the controller and ctx10 is your processor. This is the agreement that says so, and what it obliges us to do.
Last updated 4 August 2026
1. What this is, and how it applies
We publish it rather than offering it "on request" because a DPA that has to be asked for is a DPA most customers never have, and Article 28 of the GDPR requires the contract to exist before the processing does — not after a procurement review notices it is missing.
If your process needs a countersigned copy, email hello@ctx10.com and we will sign and return one. The same address takes bespoke versions: if your legal team has its own paper, send it and we will read it properly rather than refusing on principle.
2. Who is who
This agreement is between you — the organisation subscribing to ctx10, the controller — and EXPERCEO BİLİŞİM TEKNOLOJİLERİ LİMİTED ŞİRKETİ, trading as ctx10, the processor. "We", "us" and "our" mean that company throughout.
The split is worth stating plainly, because we are not the processor for everything. For your account, the enquiries you send us, billing and this website, we are the controller and the Data & privacy page names our lawful bases. For the index of your Creatio and everything inside it, you are the controller: you decide that it exists, which instance it covers and who in your organisation may read it. This agreement covers that second part only.
3. What we process, and why
- Subject matter
- Indexing how your Creatio is built, and answering questions about it.
- Nature and purpose
- Reading your Creatio's configuration tables, storing the result as an index, and serving that index back to you and to the agents and people you authorise — through the Explorer, the MCP server, checks and reports. Nothing else.
- Duration
- The life of your subscription, plus the deletion windows in section 11.
- Data subjects
- Your people — the users, administrators and developers who exist in your Creatio, and anyone named in its configuration history.
We do not use your index for our own purposes. Not to improve the product against your data, not to build features, not to benchmark you against another customer, and never to train an AI model. That last one is not a clause we have left room to change quietly: there is no AI provider in our vendor list because there is no call to one.
4. What the index actually contains
Mostly configuration: entities, fields, lookups, pages, business processes, business rules, roles and dashboards. That is not personal data. But Creatio's own user list is one of the configuration tables we read, and so:
- Names and usernames of the people who exist in your Creatio;
- Role membership — which of your people sit in which roles and organisational units;
- Change attribution — who changed a piece of configuration, and when.
The email, phone and password columns on that table are excluded from the capture query itself, so those values never leave your Creatio at all. You can instruct us to switch that exclusion off for your workspace; until you do, it holds.
We never take your business records — contacts, accounts, leads, orders, the rows inside your Creatio. The full ledger of what is held and what is never taken is on the Data & privacy page, and how the read-only boundary is enforced is on the Security page. Both are part of this agreement's description of the processing; we would rather link to the page we keep current than copy it into a document that then drifts.
5. Only on your instructions
We process your index only on your documented instructions. Those instructions are the product as we document it — indexing, the Explorer, the MCP server, checks and reports — plus whatever your workspace is configured to do: whether live queries against your instance are switched on, whether the excluded columns stay excluded, and who has a key and what that key may do. Configuring the workspace is instructing us, which is why those switches belong to you and not to a support ticket.
Anything outside that comes to you first. If we ever believed an instruction of yours broke data-protection law, we would tell you rather than quietly carry it out. If a law we are subject to compelled us to process your data some other way, we would tell you before doing it, unless that same law forbids us from telling you.
6. Confidentiality
Everyone who can reach your data — our own personnel and the engineers who work through IT CAPACITIES — is bound to confidentiality in writing, and that obligation outlasts their engagement. Access is granted per person, only to the people who need it to run the service or to answer something you raised, and every access is logged.
7. Security
The measures we take are described in detail on the Security page — the four locks that make ctx10 read-only, the personal-data columns excluded at capture, captured rows scoped to your workspace or the query refused, per-seat keys that cannot grant themselves more, live access off until you turn it on, and a written record of every query.
Those statements are contractual, not marketing. Section 2 of the Terms already says so: if we ever needed to change them you would be told before it happened, not after. Where this agreement or the Standard Contractual Clauses need a description of our technical and organisational measures, that page is it.
8. Sub-processors
You give us general authorisation to use the sub-processors listed on the Data & privacy page. The list is published rather than available on request, and it says what each company can actually reach — which is the part that matters and the part most lists leave out.
If we add one, we say so on that page before it starts processing anything. The notice exists so you can object to a change before it happens rather than discover it afterwards; if you object and we cannot resolve it between us, you can cancel under section 5 of the Terms.
Every sub-processor is engaged under a written contract imposing the same obligations we owe you, and we remain fully liable to you for what they do with your data.
9. Helping you answer people
If one of your people exercises a right — access, correction, erasure, restriction, objection, portability — the request is yours to answer, because for the index you are the controller. We help you do it, with the tools in the product and by hand where the product does not reach.
If such a request arrives at us directly, we do not answer it ourselves. We pass it to the owner of the workspace it concerns without undue delay and tell the person we have done so. That is not us dodging: acting on it would be processing outside your instructions, which section 5 forbids.
We also help you meet your own obligations under Articles 32 to 36 — securing the processing, notifying breaches, and carrying out a data protection impact assessment or a prior consultation — with the information we hold and the scale of what we do. In practice that means we answer your questions properly and fast; see section 12.
10. If there is a breach
If we become aware of a personal-data breach affecting your data, we notify you without undue delay — at the account contact and at whatever security address you have given us. The first message says what we know, even when that is not yet much: what happened, what data is involved, what we are doing about it. The details follow as they exist rather than waiting for a complete picture.
Notifying your supervisory authority, and your people, is the controller's decision — yours, not ours. We give you what you need to make it, on the clock you are on.
11. Deletion at the end
When your subscription ends, or whenever you ask, we delete your index within 30 days and the account within 90. This is the same commitment as section 13 of the Terms and the same windows the Data & privacy page publishes, and it runs automatically rather than waiting on someone remembering.
Export what you want first — reports, evidence and exports about your configuration are yours to keep, and asking us for a copy before the end is a normal request, not a favour.
The one carve-out is tax and accounting: invoices and the records behind them are kept for as long as the law requires us to keep them, and no longer. Paddle is our merchant of record and holds the payment details; we never see your card. Nothing in that carve-out touches your index.
12. Audits and questionnaires
You are entitled to satisfy yourself that we do what this agreement says. Start with questions: send a security questionnaire, or ask about anything the Security and Data & privacy pages do not cover, to hello@ctx10.com. We answer in writing and we turn it around fast — most reviews end there, and if a question is worth asking once it is usually worth us publishing the answer.
Beyond that you may audit us, or have an auditor do it for you. On reasonable notice, in business hours, no more than once in any twelve months — unless a supervisory authority requires it, or there has been a breach affecting your data, in which case the limit does not apply. Remote and documentary review comes first where it answers the question. Your auditor is bound by confidentiality and may not be a competitor of ours, each side carries its own costs, and nothing in an audit may expose another customer's data.
13. Where the data goes
Three countries, and it is worth saying plainly which does what — the company, the servers and the people are not in the same place:
- Germany
- Servers and databases (Contabo).
- Türkiye
- The controller, EXPERCEO BİLİŞİM TEKNOLOJİLERİ LİMİTED ŞİRKETİ.
- Tunisia
- Operational access — engineering and support.
Neither Türkiye nor Tunisia has an EU adequacy decision. So where the data you send us is subject to the GDPR or the UK GDPR, the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two, controller to processor, are incorporated into this agreement by reference and apply to that transfer. For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to those clauses applies alongside them.
The annexes those clauses require are given by this agreement and the pages it points at: the parties are you as data exporter and controller and EXPERCEO BİLİŞİM TEKNOLOJİLERİ LİMİTED ŞİRKETİ as data importer and processor; the description of the transfer is sections 3 and 4 together with the ledger on Data & privacy; the technical and organisational measures are section 7 and the Security page; and the sub-processors are the list published on Data & privacy.
Onward transfer to IT CAPACITIES in Tunisia — the company our engineering and support team works through — is covered by a written data processing agreement between us and them that imposes obligations equivalent to these. Where the Standard Contractual Clauses and this agreement disagree about a transfer they cover, the clauses win.
14. Precedence
On the processing of personal data, this agreement prevails over the Terms & Conditions. Everything else in the Terms continues to apply — this document adds duties, it does not replace the agreement it sits inside.
Nothing here reduces what the Data & privacy page promises to individuals. If this agreement and that page could be read differently, the reading more favourable to the person whose data it is wins.
15. Contact and changes
Anything about this agreement, a countersigned copy, or a review that needs more than these pages give you: hello@ctx10.com, or the registered office in section 1 of the Terms.
The date at the top is the version in force. If we change something that materially affects you we tell you before it takes effect, the same way we do for a new sub-processor — the point of publishing specifics is that they cannot be edited quietly.