Your responsibilities as a controller
Your responsibilities as a controller
When you build an app on Emergent, you are the controller for the personal data your app collects from its end users, and Emergent is the processor for that data. This page covers the four situations where that distinction matters: an end user exercising their rights, special category data, a regulator enquiry, and a government or law-enforcement request.
Data subject rights (your end users)
How we support you
Taking into account the nature of the processing, Emergent assists you in fulfilling your obligation to respond to data-subject rights requests (DPA Section 7.2).
If an end user contacts Emergent directly
We will not respond to their request other than to redirect them to you, and we'll notify you without undue delay (DPA Section 7.3).
Note
Requests about your app's end users should come to you first. For help coordinating a response, contact privacy@emergent.sh.
Special category data
The Services are not designed for special category data (for example health, children's or biometric data), and none is requested or required.
Any such data is submitted at your election and is subject to Clause 4.6 of the DPA (see app.emergent.sh/dpa).
Warning
If your app handles special category data, contact privacy@emergent.sh before you build, these cases need a closer look rather than a standard answer.
Emergent does not currently offer a Business Associate Agreement (BAA) or special terms for HIPAA-regulated workloads. If your app would process protected health information, contact privacy@emergent.sh before you build.
Regulators & supervisory authorities
Emergent will promptly notify you of any measure taken or investigation conducted by a supervisory authority in respect of the processing, and will cooperate with them under Article 31 GDPR (DPA Section 7.5).
Note
If you receive a regulator enquiry that touches data processed by Emergent, contact privacy@emergent.sh and we'll help coordinate.
Government & law-enforcement requests
Emergent will not disclose your customer data in response to a request from a government, law-enforcement or intelligence authority unless legally compelled to do so. If that happens, we will: (a) inform you of the request unless the law prohibits it, (b) seek to redirect the authority to you, and (c) disclose only the minimum required (DPA Section 9.4). As at the date of the DPA, Emergent has received no such request.

