Data & Trust

Your responsibilities as a controller

Your responsibilities as a controller

When you build an app on Emergent, you are the controller for the personal data your app collects from its end users, and Emergent is the processor for that data. This page covers the four situations where that distinction matters: an end user exercising their rights, special category data, a regulator enquiry, and a government or law-enforcement request.

Data subject rights (your end users)

How we support you

Taking into account the nature of the processing, Emergent assists you in fulfilling your obligation to respond to data-subject rights requests (DPA Section 7.2).

If an end user contacts Emergent directly

We will not respond to their request other than to redirect them to you, and we'll notify you without undue delay (DPA Section 7.3).

Note

Requests about your app's end users should come to you first. For help coordinating a response, contact privacy@emergent.sh.

Special category data

The Services are not designed for special category data (for example health, children's or biometric data), and none is requested or required.

Any such data is submitted at your election and is subject to Clause 4.6 of the DPA (see app.emergent.sh/dpa).

Warning

If your app handles special category data, contact privacy@emergent.sh before you build, these cases need a closer look rather than a standard answer.

Emergent does not currently offer a Business Associate Agreement (BAA) or special terms for HIPAA-regulated workloads. If your app would process protected health information, contact privacy@emergent.sh before you build.

Regulators & supervisory authorities

Emergent will promptly notify you of any measure taken or investigation conducted by a supervisory authority in respect of the processing, and will cooperate with them under Article 31 GDPR (DPA Section 7.5).

Note

If you receive a regulator enquiry that touches data processed by Emergent, contact privacy@emergent.sh and we'll help coordinate.

Government & law-enforcement requests

Emergent will not disclose your customer data in response to a request from a government, law-enforcement or intelligence authority unless legally compelled to do so. If that happens, we will: (a) inform you of the request unless the law prohibits it, (b) seek to redirect the authority to you, and (c) disclose only the minimum required (DPA Section 9.4). As at the date of the DPA, Emergent has received no such request.

Was this page helpful?

Related pages