Data processing addendum
A summary of how we process data on your behalf in the hosted edition. The signed addendum is the document that binds.
Updated
What this page is, and what it is not
This is a summary of our data processing terms, written so that a reviewer can see the shape of them without waiting for a contract.
It is not the agreement. The data processing addendum your organisation signs is the document that binds, and where the two differ, the signed addendum governs.
Ask for it at privacy@boreon.com and we will send it.
Who is the controller and who is the processor
On Boreon Cloud you are the controller for the data you bring, and Boreon Industries LLC is your processor. We process it to provide the service, on your instructions.
On Boreon Server we are not a processor of your data at all. The software runs in infrastructure you control, and your content never reaches us. There is no addendum to sign for the self-hosted edition, because there is nothing for us to be entrusted with.
If your review is about the self-hosted edition, this document is not the one you need. The license and the security page are.
What is processed, and for how long
Set out the way a processing register asks for it:
- Subject matter
- Providing Boreon Cloud: governing, auditing and documenting the Tableau environment and warehouse metadata you connect.
- Duration
- For as long as your subscription runs, plus the period agreed for return and deletion afterwards.
- Nature and purpose
- Reading metadata and, where you ask for it, data; producing findings, lineage, reports and audit evidence; routing proposed changes into an approval gate that a person operates.
- Types of personal data
- Account identifiers for your users, such as an email address and a role. Tableau metadata that names people, such as content owners, subscribers and permission holders. Warehouse metadata such as catalogs, schemas, columns and certified definitions. Audit records of who did what. And any personal data that happens to sit in the content you point it at.
- Categories of data subject
- Your own workforce users, and any individual whose personal data appears in the Tableau content or the data you connect.
- Special categories
- None is required by the service. Whether any is present depends entirely on the content you connect, which is under your control and not ours.
We process on your instructions
We process your data to provide the service and for nothing else. Your instructions are your use of the product and anything else you tell us in writing.
We do not sell your data, share it for anybody’s marketing, or use it for our own purposes. We do not train or fine-tune models on it, and we do not use it to improve the product.
Where AI is switched on, it runs on the key you supply and sends to the provider you chose. That is your instruction and your contract with them, which is why the choice sits with you and is made per run.
The measures that protect it
These are controls the product is built with rather than settings somebody has to find:
- Two factors at sign-in, every time. A password hashed with scrypt at N=2^17, and a code from your authenticator tool.
- Or your own identity provider, over SAML 2.0, with each assertion bound to the email domain it was issued for so that one organisation’s provider mints one organisation’s session.
- Sessions that end: thirty minutes idle, twelve hours absolute, and a disabled account or reset factor that takes effect on the next request rather than at token expiry.
- Roles read fresh on every request. No role ever travels inside a token.
- Credentials handled server-side and held for the session. Nothing reaches the browser.
- Encryption at rest with a separately derived key for each purpose, so one secret never quietly does two jobs, and files written atomically at 0600.
- A CSRF token on every change, bound to your own session.
- A container that runs as an unprivileged user, never as root, behind a web application firewall.
- Dependencies pinned to exact commits, and a vulnerability scan that fails the build against an ignore list that is empty.
- A hash-chained audit ledger using plain SHA-256 with no secret key, so your own auditor can re-verify its integrity from the export with their own tools.
Access to production is held by the smallest number of people who can keep the service running, each under a confidentiality obligation, and it is reviewed rather than granted once and forgotten. The specific undertakings and the review cadence are set out in the signed addendum.
Sub-processors
The companies we engage are listed on the sub-processors page, and that list is deliberately short.
Where we engage one, it is bound by terms no weaker than these, and we stay responsible to you for what it does.
Adding one is a change you hear about before it happens rather than after. How that notice is given, and how you may object to a new sub-processor, is set out in the signed addendum.
Helping you meet your own obligations
If one of your people exercises a right against you, we help you answer. If a request reaches us directly, we do not answer it ourselves. We pass it to you and tell the person we have, because you are the controller and the decision is yours.
We help with impact assessments and with prior consultation where the service is in scope, and we will answer a due-diligence questionnaire rather than send you a brochure.
If there is a personal data breach affecting your data, we tell you without undue delay, with what we know and what we are doing about it.
The deadline we commit to, and the scope of the assistance we give, are set out in the signed addendum. What is true regardless is that you hear it from us, with what we know at the time, rather than reading it somewhere else first.
Where the processing happens
Boreon Cloud runs on dedicated Infomaniak infrastructure in Geneva, Switzerland. Your data sits under Swiss data protection law, and there is no United States hyperscaler anywhere in the serving path.
A transfer out of that footprint happens in one case: you switch AI on and choose a provider outside Switzerland. You control that, per run, and leaving AI off or pointing it at your own endpoint avoids it entirely.
Where a transfer does occur, the mechanism that covers it is set out in the signed addendum, and it is attached to that document rather than described here. A transfer mechanism is only worth anything as an executed term.
Audit and evidence
We will give you the information you need to show that we meet these terms, and we will answer specific questions with specific answers.
It is worth being clear about what we can and cannot hand over. Boreon holds no audited certification of its own, so there is no report to send you in place of an answer. What the product does produce is your own audit evidence, hash-chained and re-verifiable by your auditor without taking our word for anything.
What we can hand over is the evidence the product itself produces: the hash-chained ledger your own auditor can re-verify, and specific answers to specific questions. The audit and inspection rights themselves, including how often and on what notice, are set out in the signed addendum.
Return and deletion at the end
When the service ends you can take your data out, and after that we delete it. Evidence you already exported is yours and is unaffected.
The export window, the deletion deadline, and anything we are obliged to keep by law after that are set out in the signed addendum.
Questions about any of this go to privacy@boreon.com.