Data Processing Information
How we act as a processor for client data, and what that means in practice.
How we act as a processor for client data, and what that means in practice.
Prepared August 20, 2026. Last reviewed September 8, 2026. Issued by CHEFFUSION TECHNOLOGIES LLC, referred to on this site as Cheffusion Technologies. Questions about this document can be sent to support@cheffusiontech.com.
When you engage CHEFFUSION TECHNOLOGIES LLC, referred to on this site as Cheffusion Technologies, to build or operate a system that handles personal data belonging to your customers, staff or service users, you are normally the controller — you decide why and how that data is processed — and we act as a processor, acting on your documented instructions.
This page describes how we operate in that role. The binding terms are the data processing terms contained in, or attached to, your engagement agreement. Where the law that applies to you requires specific processor terms — for example Article 28 of the EU or UK GDPR, or the service-provider terms required by United States state privacy laws — we will enter into terms that meet that requirement as part of the engagement.
Act on instruction. We process personal data only as needed to deliver the agreed services, and only as you have instructed. If an instruction appears to conflict with data protection law, we will say so rather than carry it out quietly.
Limit access. Access is granted to the individuals who need it for the work and is removed when they no longer do. Access is role-based and logged.
Use production data carefully. We do not copy production personal data into development environments as a matter of routine. Where realistic data is genuinely necessary for a task, it is anonymised or pseudonymised first, or the work is done in a controlled environment with access logged and the copy destroyed afterwards.
Engage sub-processors transparently. Hosting, email delivery and error monitoring providers act as sub-processors. We maintain a current list, and will give you notice of an intended change so you have an opportunity to object.
Support your obligations. We will help you respond to access, correction and deletion requests, and to your own regulatory notifications, within the scope of the systems we operate for you.
Report incidents. If we become aware of a personal data breach affecting your data, we will notify you without undue delay with what we know, what we are doing, and what we recommend. Deciding whether a regulator or data subject must be told is your decision as controller; we will give you the technical facts you need to make it.
Return or delete at the end. When an engagement ends, we return or delete the personal data we hold on your behalf, as you direct, and confirm when it is done.
We do not use your data for our own purposes. We do not use it to train models. We do not sell it, and we do not share it with anyone other than the sub-processors listed in your agreement or where the law compels us.
Data we process on your behalf is stored on servers operated by our hosting provider in the United States or the European Union. Where your engagement needs data to stay in a particular region, say so before work starts and we will confirm in the agreement whether we can meet that requirement.
Our sub-processors are the hosting, email delivery and error monitoring providers used to deliver your engagement. Because they can differ between engagements, the list that applies to you is set out in your agreement, and a current copy is available at any time from support@cheffusiontech.com. We give notice before adding or replacing a sub-processor so that you have an opportunity to object.
Questions about data processing, and requests relating to data we process on your behalf, can be sent to support@cheffusiontech.com.
CHEFFUSION TECHNOLOGIES LLC
974 Covington Hwy Apt K2, Decatur, Georgia 30032, United States
Email: support@cheffusiontech.com
Telephone: +1 605 468 2191 (Monday to Friday, 9:00 AM to 5:30 PM Eastern Time)