Legal

# Data processing

How CubeERP handles the data your organisation puts into it, and what our data processing agreement commits us to.

- Updated 25/09/2026
- 7 min read
- For customers

## The short version

- You are the controller

We process your data only on your documented instructions, under a data processing agreement that is part of every customer contract.

- Security in the base product

Role-based permissions, single sign-on, an audit log that cannot be edited and encryption come with every subscription, not as an upgrade.

- UK storage, named providers

Databases, files and backups stay in the UK. The providers we use are named, and changes come with 30 days’ notice.

- Your data leaves when you do

Export it whenever you like, in open formats. When a contract ends, you have time to take it, and then it is deleted on a stated timetable.

A summary for convenience. The full text below is what applies.

## 1. Who is responsible for what

When your organisation uses CubeERP, you decide what data goes into it and what it is used for. You are the controller of that data, and Cube Systems Limited is your processor.

If you hold some of that data as a processor yourself, for example on behalf of one of your own customers, we act as your sub-processor for it, and the commitments on this page cover it in the same way.

Separately, we are a controller for the small amount of data we need to run our own business, such as the details of your account contacts and our billing records. That is covered by our [privacy policy](/legal/privacy-policy).

## 2. Our data processing agreement

Every customer agreement includes a data processing agreement that meets Article 28 of UK GDPR. Under it, we:

- process your data only on your documented instructions, which include using CubeERP as designed with the configuration you choose, and tell you if we believe an instruction breaks the law;
- make sure everyone with access to it is bound by confidentiality;
- maintain the technical and organisational measures described [below](#security);
- use sub-processors only under written contracts with equivalent obligations, and give you notice before any change;
- help you answer requests from people exercising their rights, and with data protection impact assessments and any consultation with the ICO;
- notify you of a personal data breach affecting your data without undue delay;
- delete or return your data when the contract ends; and
- make available the information you need to demonstrate compliance, and allow for audits, including inspections, by you or an auditor you appoint.

To review the agreement before you sign, email [hello@cubeerp.co.uk](mailto:hello@cubeerp.co.uk) and we will send you a copy.

## 3. What CubeERP holds

| Category | Examples |
| --- | --- |
| People | Your staff who use the system; your customers’ and suppliers’ contacts; people who use a trade portal you offer; people named on orders, deliveries and service jobs, such as delivery recipients and site contacts. |
| Commercial records | Customers and suppliers, enquiries, quotes, sales and purchase orders, price lists, invoices, credit control notes and correspondence filed against a record. |
| Operational records | Stock and warehouse movements, works orders and shop-floor time bookings, despatch and proof of delivery, batch and serial traceability, and field service jobs with engineers’ time, sign-off and site photographs. |
| Connected-service data | Orders, products, stock, ledger postings, tracking and calendar entries exchanged with services you connect, such as your accounting package, web shop or carriers. |
| Account and security records | Users, roles and permissions, sign-in history, API access tokens and call logs, and the audit log of every change. |

CubeERP does not need special category data to work. Notes and comments are free text and site photographs can show people, so please make sure your team does not record health or other sensitive information unless you have a lawful basis to do so.

## 4. Where it is held

Your data is stored in the United Kingdom:

- application servers, databases and backups in UK data centres operated by Crushed Ice, part of Crushed Ice Group; and
- uploaded files and attachments in Amazon S3, and system email sent through Amazon SES, both in the AWS London region.

None of our sub-processors stores or processes your CubeERP data outside the UK. If you choose to keep documents in SharePoint or OneDrive instead, they stay in your own Microsoft 365 tenant, and services you connect hold data under their own terms.

## 5. How it is protected

### Access and permissions

- Role-based permissions down to field level, and approval limits by value.
- Single sign-on through Microsoft Entra ID or Google Workspace, with your own multi-factor authentication and conditional access policies applied. When someone leaves and their account is disabled, their access to CubeERP ends with it.
- Your data kept separate from other customers’ data, and access by our staff limited to the people who need it to run and support the service.

### Audit and integrations

- An audit log of every change, recording who changed what and when, which cannot be edited.
- API access through tokens scoped to the endpoints and records an integration needs, revocable individually, with every call logged.
- A separate sandbox environment for integration work, so development never touches live records.

### Encryption and resilience

- Encryption in transit and at rest.
- Encrypted off-site backups held in the UK, with a documented, tested recovery process.
- Continuous, versioned updates, so no customer is left on a release too old to support.

## 6. Services you connect

CubeERP can connect to services your organisation already uses, including Xero, Sage, QuickBooks, Shopify, WooCommerce, Adobe Commerce (Magento), EDI, Carriers & Couriers, Microsoft 365 and Power BI & Reporting. You choose which to connect and what they can access, and you can disconnect them at any time.

Those services are not our sub-processors. You have your own agreement with each of them, and the data they hold is covered by their terms. What each connection is used for is listed on our [sub-processors](/legal/sub-processors#services-you-connect) page.

## 7. Sub-processors

We use a small number of sub-processors, each named on our [sub-processors](/legal/sub-processors) page with what it does, what it processes and where. We give customers at least 30 days’ notice by email before adding or replacing one, and you can object during that period. If we cannot resolve a reasonable objection, you may terminate the affected part of the service.

## 8. Requests from individuals

When someone asks you to exercise their data protection rights, you can find, correct, export and delete the records relating to them in CubeERP, and we will help you extract anything you cannot export yourself. If a request about your data comes to us directly, we will pass it to you without undue delay and will not answer it ourselves unless you ask us to.

## 9. Security incidents

If we become aware of a personal data breach affecting your data, we will notify your nominated contact without undue delay, and in any event within 48 hours, so that you can meet the 72-hour deadline for reporting to the ICO. We will tell you what happened, the data and people likely to be affected, the likely consequences and what we are doing about it, and keep you updated as we learn more.

## 10. When a contract ends

You can export your data in full at any time in open formats, not only at the end. When a contract ends:

- your system stays available for export for 30 days;
- we then delete your data from live systems within a further 60 days, including the audit log, and confirm in writing when we have; and
- copies in backups expire on their normal rotation within 90 days after that, and are not restored in the meantime.

We keep only what the law requires of us, such as invoices, which our privacy policy covers.

Contact

## Questions about this document

Email us and a person will reply. For anything about data a business holds in its CubeERP system, please contact that business first, as it decides how the data is used.

[Email us](mailto:hello@cubeerp.co.uk)
- **Company:** Cube Systems Limited, trading as CubeERP

- **Company number:** [17220899](https://find-and-update.company-information.service.gov.uk/company/17220899), registered in England and Wales

- **Registered office:** Unit 11, Olney Business Park, Osier Way, Olney, Buckinghamshire, MK46 5FP

- **Email:** [hello@cubeerp.co.uk](mailto:hello@cubeerp.co.uk)

- **Telephone:** [01234 672 617](tel:+441234672617)

- **ICO registration:** [ZC216972](https://ico.org.uk/ESDWebPages/Entry/ZC216972)

---

**URL:** https://cubeerp.co.uk/legal/data-processing
