1. Roles: who controls what
The customer is always the controller of the operational data processed in its AtlasEye installation.
Self-hosted: the customer installs AtlasEye on infrastructure it controls. cdnCore does not host, replicate or receive that data. cdnCore acts as a processor only where the customer engages it for support or migration work that requires access, which the customer grants, scopes and time-limits.
Managed by cdnCore: cdnCore acts as processor. It operates a dedicated instance for the customer on its infrastructure in Portugal, connected to the customer's network over a site-to-site VPN, under a Data Processing Agreement.
cdnCore is a controller in its own right for website visitors, trial requests, commercial contacts and account administration.
2. Data subject rights, and how to exercise them
Requests about data held by cdnCore as controller go to [email protected]. We acknowledge on receipt and respond within one month.
Requests about data held inside a customer installation must be addressed to that customer, who is the controller. If such a request reaches us instead, we forward it to the customer or tell the requester who to contact, and we assist the customer as processor where the managed model applies.
- Access — a copy of the personal data and the information required by Article 15.
- Rectification — correction of inaccurate or incomplete data.
- Erasure — deletion where one of the Article 17 grounds applies.
- Restriction — processing paused while a dispute is resolved.
- Portability — a structured, machine-readable copy where Article 20 applies.
- Objection — to processing based on legitimate interests, including profiling.
- Withdrawal of consent — at any time, without affecting processing already carried out.
3. Security measures
Measures applied to cdnCore's own systems and to the software we ship:
- Encryption in transit for all product and corporate services; encryption at rest for records cdnCore holds.
- Role-based access control with least privilege, and a named account for every operator.
- Multi-factor authentication on administrative access.
- Audit logging of administrative actions, retained and reviewable.
- Segregated development, staging and production environments.
- Vulnerability management and dependency scanning in the release pipeline.
- Documented incident response with defined roles and escalation paths.
- Staff confidentiality undertakings and periodic data protection training.
If a certification status or a recent penetration-test summary is relevant to your own assessment, request the current position at [email protected].
4. Retention
Inside an installation, retention is configured by the customer. AtlasEye provides retention settings for metrics, backups, syslog and audit records so operational data can be aged out to the customer's policy.
For data cdnCore holds as controller, the schedule is the one set out in the Privacy Policy: 24 months for enquiries and trial requests, 10 years for contracts and invoices, 3 years for support records, 6 months for server logs.
At the end of a managed contract, the instance's data is returned or deleted on request within 30 days, backups included once they age out of their normal cycle.
5. Data Processing Agreement
Customers of the managed model, and customers who engage cdnCore for work involving access to their data, receive a Data Processing Agreement under Article 28. It sets out the subject matter, duration, nature and purpose of the processing, the categories of data and data subjects, and the obligations of both parties.
The DPA covers instructions, confidentiality, security, subprocessing and prior authorisation, assistance with data subject rights and impact assessments, breach notification, audit rights, and deletion or return of data at the end of the engagement.
Request a copy at [email protected].
6. Subprocessors
The current register — provider, purpose, location and transfer mechanism — is available at [email protected]. It covers the managed model and cdnCore's own processing for the website, communications and business administration.
Customers under a Data Processing Agreement are given at least 30 days' written notice before a new subprocessor is engaged, and may object on reasonable data protection grounds.
A model provider that the customer connects for AI features is chosen and contracted by the customer; it is not a cdnCore subprocessor.
7. International transfers
cdnCore's processing takes place inside the European Economic Area, and managed instances are hosted in Portugal. Where a transfer outside the EEA is unavoidable, it relies on an adequacy decision or on standard contractual clauses with a documented transfer impact assessment.
8. Personal data breach
cdnCore notifies affected customers without undue delay after becoming aware of a breach affecting their data, and reports to the CNPD within 72 hours where the regulation requires it.
In a self-hosted installation the customer detects and reports breaches in its own environment. AtlasEye's alerting, incident timeline and audit log are designed to support that duty.
9. NIS2 and operational practice
AtlasEye supports visibility, logging, alerting and incident workflows aligned with NIS2 requirements. It is a tool that helps an organisation meet its obligations; it does not certify compliance, and cdnCore makes no such certification on a customer's behalf.