1. Who is responsible for what
When your organisation uses CubeERP, you decide what data goes into it and what it is used for. You are the controller of that data, and Cube Systems Limited is your processor.
If you hold some of that data as a processor yourself, for example on behalf of one of your own customers, we act as your sub-processor for it, and the commitments on this page cover it in the same way.
Separately, we are a controller for the small amount of data we need to run our own business, such as the details of your account contacts and our billing records. That is covered by our privacy policy.
2. Our data processing agreement
Every customer agreement includes a data processing agreement that meets Article 28 of UK GDPR. Under it, we:
- process your data only on your documented instructions, which include using CubeERP as designed with the configuration you choose, and tell you if we believe an instruction breaks the law;
- make sure everyone with access to it is bound by confidentiality;
- maintain the technical and organisational measures described below;
- use sub-processors only under written contracts with equivalent obligations, and give you notice before any change;
- help you answer requests from people exercising their rights, and with data protection impact assessments and any consultation with the ICO;
- notify you of a personal data breach affecting your data without undue delay;
- delete or return your data when the contract ends; and
- make available the information you need to demonstrate compliance, and allow for audits, including inspections, by you or an auditor you appoint.
To review the agreement before you sign, email hello@cubeerp.co.uk and we will send you a copy.
3. What CubeERP holds
| Category | Examples |
|---|---|
| People | Your staff who use the system; your customers’ and suppliers’ contacts; people who use a trade portal you offer; people named on orders, deliveries and service jobs, such as delivery recipients and site contacts. |
| Commercial records | Customers and suppliers, enquiries, quotes, sales and purchase orders, price lists, invoices, credit control notes and correspondence filed against a record. |
| Operational records | Stock and warehouse movements, works orders and shop-floor time bookings, despatch and proof of delivery, batch and serial traceability, and field service jobs with engineers’ time, sign-off and site photographs. |
| Connected-service data | Orders, products, stock, ledger postings, tracking and calendar entries exchanged with services you connect, such as your accounting package, web shop or carriers. |
| Account and security records | Users, roles and permissions, sign-in history, API access tokens and call logs, and the audit log of every change. |
CubeERP does not need special category data to work. Notes and comments are free text and site photographs can show people, so please make sure your team does not record health or other sensitive information unless you have a lawful basis to do so.
4. Where it is held
Your data is stored in the United Kingdom:
- application servers, databases and backups in UK data centres operated by Crushed Ice, part of Crushed Ice Group; and
- uploaded files and attachments in Amazon S3, and system email sent through Amazon SES, both in the AWS London region.
None of our sub-processors stores or processes your CubeERP data outside the UK. If you choose to keep documents in SharePoint or OneDrive instead, they stay in your own Microsoft 365 tenant, and services you connect hold data under their own terms.
5. How it is protected
Access and permissions
- Role-based permissions down to field level, and approval limits by value.
- Single sign-on through Microsoft Entra ID or Google Workspace, with your own multi-factor authentication and conditional access policies applied. When someone leaves and their account is disabled, their access to CubeERP ends with it.
- Your data kept separate from other customers’ data, and access by our staff limited to the people who need it to run and support the service.
Audit and integrations
- An audit log of every change, recording who changed what and when, which cannot be edited.
- API access through tokens scoped to the endpoints and records an integration needs, revocable individually, with every call logged.
- A separate sandbox environment for integration work, so development never touches live records.
Encryption and resilience
- Encryption in transit and at rest.
- Encrypted off-site backups held in the UK, with a documented, tested recovery process.
- Continuous, versioned updates, so no customer is left on a release too old to support.
6. Services you connect
CubeERP can connect to services your organisation already uses, including Xero, Sage, QuickBooks, Shopify, WooCommerce, Adobe Commerce (Magento), EDI, Carriers & Couriers, Microsoft 365 and Power BI & Reporting. You choose which to connect and what they can access, and you can disconnect them at any time.
Those services are not our sub-processors. You have your own agreement with each of them, and the data they hold is covered by their terms. What each connection is used for is listed on our sub-processors page.
7. Sub-processors
We use a small number of sub-processors, each named on our sub-processors page with what it does, what it processes and where. We give customers at least 30 days’ notice by email before adding or replacing one, and you can object during that period. If we cannot resolve a reasonable objection, you may terminate the affected part of the service.
8. Requests from individuals
When someone asks you to exercise their data protection rights, you can find, correct, export and delete the records relating to them in CubeERP, and we will help you extract anything you cannot export yourself. If a request about your data comes to us directly, we will pass it to you without undue delay and will not answer it ourselves unless you ask us to.
9. Security incidents
If we become aware of a personal data breach affecting your data, we will notify your nominated contact without undue delay, and in any event within 48 hours, so that you can meet the 72-hour deadline for reporting to the ICO. We will tell you what happened, the data and people likely to be affected, the likely consequences and what we are doing about it, and keep you updated as we learn more.
10. When a contract ends
You can export your data in full at any time in open formats, not only at the end. When a contract ends:
- your system stays available for export for 30 days;
- we then delete your data from live systems within a further 60 days, including the audit log, and confirm in writing when we have; and
- copies in backups expire on their normal rotation within 90 days after that, and are not restored in the meantime.
We keep only what the law requires of us, such as invoices, which our privacy policy covers.
Contact
Questions about this document
Email us and a person will reply. For anything about data a business holds in its CubeERP system, please contact that business first, as it decides how the data is used.
- Company
- Cube Systems Limited, trading as CubeERP
- Company number
- 17220899, registered in England and Wales
- Registered office
- Unit 11, Olney Business Park, Osier Way, Olney, Buckinghamshire, MK46 5FP
- hello@cubeerp.co.uk
- Telephone
- 01234 672 617
- ICO registration
- ZC216972