Parties and roles
The customer is controller and Arctic Parade Ltd (company number 17033806) is processor for personal data submitted to the hosted service on the customer’s behalf. Each party remains an independent controller for its own account, commercial and legal records.
Instructions and purpose
We process customer personal data only on documented instructions to provide, secure, support and improve the contracted service, or as required by law. The subject matter, duration and purpose are the customer’s use of CS Code; data subjects are authorised users and people identifiable in submitted release metadata.
Data categories
Account identifiers, business contact details, roles, authentication identifiers, audit events, support correspondence, release metadata and optional evidence files. Customers must not submit special-category data, criminal-offence data, credentials, classified material or source code unless separately agreed in writing.
Confidentiality and security
Personnel with access are bound by confidentiality. Measures include least-privilege tenant-scoped RBAC, strong authentication options, hashed credentials and tokens, audit logging, encrypted transport, protected backups, restricted administrative access, vulnerability management and a local-first metadata allowlist.
Subprocessors and transfers
We may use subprocessors listed on the Subprocessor page and remain responsible for equivalent data-protection obligations. We will provide reasonable prior notice of new subprocessors. Restricted transfers use a UK adequacy regulation or appropriate safeguards.
Assistance
Taking account of the processing, we will reasonably assist with data-subject requests, impact assessments, regulator consultation and evidence of compliance. Additional work may be chargeable where permitted by the customer agreement.
Incidents
We will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data and provide available information needed for the customer’s assessment and notifications.
Deletion and return
At contract end, and at the customer’s choice where technically feasible, we will delete or return customer personal data unless law requires retention. Backups expire through the published rotation schedule.
Audit
We will provide relevant security documentation and reasonable audit assistance. On-site audits require reasonable notice, confidentiality, minimal disruption and no access to other customers’ data.
Contact and execution
Contact arran@cs-code.com to obtain an execution copy with the customer, service, processing details and any international-transfer schedules completed.

