Data Processing Addendum
Updated 6 October 2026
These are the processing terms for the content a customer puts in its workspace. They form part of the Terms of Use, which the person who creates the workspace accepts for the customer. A separately signed DPA is not available during early access; if your company needs one before it uploads personal data, write to us and we will tell you when it is ready.
Roles
For workspace content the customer is the controller (GDPR) or data fiduciary (India's DPDP Act) and Crossruled is the processor, acting on the customer's documented instructions: the instructions are the customer's use of the product, its settings, and written requests to us. The customer decides whether employee, client and proposal data may be uploaded and is responsible for the notice to the people in it.
What is processed
Employee and contractor records with their roles, skills, capacity and, for cost roles, monthly cost; projects, clients, allocations and bill rates; role salary bands; proposals and pricing assumptions; the audit log of who changed what; and the accounts of the customer's users. Data subjects are the customer's employees and contractors, its users, and named contacts at its clients. The full list is on the privacy page.
Subprocessors and location
Google LLC provides Firebase Authentication and Cloud Firestore; the database is in the multi-region location nam5 in the United States. Vercel Inc. provides hosting, serverless functions and logs. No other party holds workspace content. Data is stored and processed in the United States; there is no India or EU option today. Google's Firebase data-processing terms include the EU standard contractual clauses. Vercel's data-processing terms apply to its Pro and Enterprise plans, not to the hosting plan used during early access, so we do not take workspaces from the EU or UK until the hosting plan and our own transfer clauses are in place. We email each workspace owner at least 14 days before adding or replacing a subprocessor. If the customer objects, it may stop using the service and we delete its workspace after it takes its export. We also keep backup copies of the database, made to test that restores work, on the operator's encrypted computer in India. We delete each one within 30 days of making it, and when a workspace is deleted we delete it from every backup we hold.
Demo data only during early access. Do not upload real employee data. Use demo data only until we tell you the hosting plan is ready for it.
Security measures
Per-tenant isolation enforced in database rules and proven by an automated test suite on every push; role-scoped access to cost and salary data; one-use, email-bound access codes; passwords set only by their owner; HTTPS with security headers; an audit log of changes; encrypted storage at rest and in transit as provided by Google Cloud and Vercel. An AI-assisted security review (not a third-party audit) ran on 29 and 30 September 2026. Crossruled holds no SOC 2 report or ISO 27001 certificate. The current state is always the trust page. On request we share the security audit and re-verification records, answer one security questionnaire a year, and walk the customer's security team through the controls on a video call.
Requests, deletion and return
The customer's owner or admin can export the whole workspace as JSON at any time and edit or delete any person's record. Requests from data subjects that reach us are passed to the customer within a few working days unless the customer instructs otherwise. On termination or on written request we delete the workspace, including any backup copy we hold, after the customer has taken its export.
Breach notice
If we become aware of unauthorised access to, or loss of, a customer's workspace content, we tell the workspace owner by email without undue delay and in any case within 24 hours of becoming aware, with what we know at the time: what was affected, what we have done, and what we will do next. We send updates as we learn more. The customer remains responsible for its own notices to regulators and to the people affected.
Confidentiality and assistance
Only the operator of Crossruled, Rajan Agarwal, can access workspace content, only to provide or support the service or when the customer asks, and is bound to keep it confidential. We help the customer answer data-subject requests, meet its breach-notice duties and carry out impact assessments, using the export, the audit records and written answers. Questions about these terms go to codingrajan@gmail.com.