Version dated 16 September 2026. This page sets the general B2B layer for an Organisation using Cicora through a Workspace, API, or other corporate order. The specific B2B order and data-processing addendum determine applicable roles, routes, audit, periods, transfer conditions, and special settings. These terms apply to a Customer where they are expressly incorporated into that Customer's B2B agreement with RIZZ TRADE.
For an ordinary personal Account, RIZZ TRADE generally determines the purposes of Account, payment, security, and support processing as an independent controller; the Privacy Policy applies. For Personal Data an Organisation Customer provides through Cicora about its personnel, customers, or other individuals, where that Customer determines the purposes and material means, the framework below applies as “Customer as controlling party — RIZZ TRADE as processor” within the B2B agreement actually concluded.
1. Roles, scope, and hierarchy
In this page:
- Customer means an Organisation or entrepreneur that has concluded a B2B Cicora order with RIZZ TRADE;
- Controlling Party means the Customer when it determines the purposes and material means of processing Personal Data about its users, personnel, customers, or other individuals;
- Processor means RIZZ TRADE where it processes Customer Personal Data on the Customer's documented instructions to provide Cicora;
- Customer Data means data that a Customer, its administrator, API user, or Workspace participant provides to Cicora for the Customer, including Personal Data;
- Customer Personal Data means the part of Customer Data that is Personal Data under applicable law;
- Subprocessor means a party engaged by RIZZ TRADE to process Customer Personal Data for the Customer in the applicable role; and
- Documented Instructions means the written agreement/order, configuration selected by the Customer, Workspace/API settings, and other instructions of an authorised person that RIZZ TRADE can lawfully and technically perform.
The individual B2B order or DPA prevails over this general page for matters it specifically regulates. For Personal Data matters, the DPA prevails over general commercial terms to the extent of a conflict. Mandatory law prevails over the agreement. Nothing in this page removes data-subject rights under applicable law or makes every external provider automatically a Subprocessor: the role follows the actual data flow, agreement, and processing purpose.
RIZZ TRADE remains an independent controller for the minimum data needed to administer its own agreement and product: creating and administering the Customer Account, billing and taxes, preventing fraud and violations, protecting infrastructure, maintaining mandatory records, resolving disputes, and defending legal claims. The Cicora Privacy Policy applies to those independent purposes rather than an unlimited Customer instruction.
2. Processing only on instructions and for permitted purposes
Where RIZZ TRADE acts as Processor, it processes Customer Personal Data only to provide, support, protect, and perform Cicora under the B2B agreement, order, selected configuration, and lawful Customer instructions. Processing can include collection, recording, organisation, storage, access, transmission to a selected route, presentation of a result, limited caching, deletion/de-identification, technical diagnostics, and security measures, only to the extent needed for the relevant feature.
The Customer is responsible for ensuring that its instructions are lawful, transparent to data subjects, do not infringe third-party rights, match its legal basis, and include necessary notices and consents. The Customer instructs Cicora only to process data it is entitled to process and does not use the interface to make a hidden transfer of special, biometric, medical, children's, or other high-risk information without suitable assessment, agreement, and protection.
RIZZ TRADE informs the Customer where it reasonably considers an express instruction inconsistent with applicable law or the B2B agreement, except where disclosure is prohibited by law. RIZZ TRADE may process Customer Personal Data differently where mandatory law requires it and, where law permits, notifies the Customer before that processing or without undue delay after it.
The Customer designates authorised administrators and keeps their contact information current. An instruction changing the model, route, retention, administrator access, export, data type, or international transfer must come from that authorised person and be expressly reflected in an available configuration or order. An unclear email, an instruction from an ordinary participant, or a request outside documented configuration is not required to be performed as an instruction of the Controlling Party.
3. Processing details: required schedule for each B2B order
Each B2B order contains a factual Customer Personal Data processing schedule. The schedule identifies particular data and purposes and does not extend to an undefined scope of “any data for any purpose.” At a minimum, it includes:
| Schedule field | Required content |
|---|---|
| Parties and contacts | Customer, RIZZ TRADE, authorised administrators, privacy/incident contacts; a representative or DPO where actually appointed and needed |
| Product and features | Workspace, API, files, search, connectors, public features, models, and other actually enabled scope |
| Subject matter and duration | order/agreement period, start point, applicable end criteria, export/return/delete path |
| Purposes | provision of selected product, documented instructions, support, security, legal obligations; RIZZ TRADE's independent-controller purposes separately identified |
| Data-subject categories | for example, Customer users, personnel, customers, partners, or other persons, but only actually expected groups |
| Data categories | Account/Workspace identifiers, prompt, file, output, technical records, support, and other data actually needed by the feature |
| Special or sensitive data | prohibition or specifically agreed processing type, legal basis, safeguards, permitted models/routes; absence of a record does not grant permission |
| Operations and frequency | collection, storage, routing, access, result delivery, cache, deletion, and regularity, without false precision |
| Recipients and routes | verified Subprocessor/model-provider register, countries and functions, or a reference to a maintained contractual register |
| Security, transfer, and deletion | applicable measures, incident contact, agreed international-transfer mechanism, return/deletion rules, and exceptions |
A Model Provider receives Customer Data only through the selected applicable Route. The Model and Policy Directory provides access to published provider terms. It does not replace the information agreed with the Customer about actual recipients, data handling, and international transfers. A no-training, limited-retention, or particular-territory arrangement applies to the Customer when expressly included in the applicable configuration or B2B agreement.
The public model-terms directory does not replace the actual processing schedule or the recipient register agreed with the Customer for its B2B order.
4. Confidentiality and access by authorised persons
RIZZ TRADE permits processing of Customer Personal Data only by persons who need access to provide the service, security, support, legal compliance, or the B2B agreement. Those persons are bound by confidentiality obligations applicable to the nature of the data and no less protective than required by the agreement and law. Access is organised according to necessity and proportionality for the function.
The Customer also limits access to its configuration, API keys, administrator credentials, and Workspace. Giving a key to an unauthorised person, using a shared Account without role-based control, or using another Organisation's data outside the instruction can create risk for which RIZZ TRADE is not responsible as for its own action. This does not release RIZZ TRADE from protecting systems and responding to a confirmed incident within its control.
Confidential information does not include information that becomes publicly available other than through the recipient's breach, is lawfully obtained from a third party without a confidentiality duty, is independently developed without access to confidential information, or must be disclosed by law. Where disclosure is mandatory, RIZZ TRADE notifies the Customer where lawful and limits the disclosure to what is necessary.
5. Subprocessors, Model Providers, and route changes
RIZZ TRADE may engage Subprocessors where needed to provide, support, secure, or perform Cicora. Before a Subprocessor accesses Customer Personal Data, RIZZ TRADE applies relevant contractual obligations for confidentiality, security, and processing only for the permitted purpose. RIZZ TRADE remains responsible to the Customer within the B2B agreement for performance of its Subprocessor obligations, unless mandatory law provides otherwise.
The individual DPA/order identifies how to obtain the current register of material Subprocessors and model routes. The register contains confirmed information as of the record date about the recipient/category, function, route status, and country/transfer where disclosure is required. The register is determined by the Customer's product, model, and configuration.
Where a B2B agreement provides Customer notice or a right to reasonably object to a new material Subprocessor, it defines the channel, period, required rationale, possible alternatives, and consequences if no technically permissible solution is available. That right operates within law, security, provider availability, and the product. Where the individual B2B agreement does not provide the right, a route change is governed by the general terms and applicable law.
A model or route change that materially changes Customer Personal Data conditions is treated as a configuration change: RIZZ TRADE discloses it to the authorised Customer to the extent of the agreement and obtains the required confirmation/action before use where law, the order, or an agreed setting requires it. An automatic fallback is not used to circumvent an agreed data restriction.
6. Security and personal-data incidents
RIZZ TRADE applies measures proportionate to the risk of actual Customer Personal Data processing. The B2B addendum contains a verified set of applicable organisational and technical measures. Certification, a particular algorithm, audit, infrastructure country, recovery time, or independent assessment is included in RIZZ TRADE's obligations only where expressly stated in the B2B agreement or addendum.
When it becomes aware of a personal-data incident within RIZZ TRADE's control, it takes reasonable measures to contain, investigate, and mitigate the effects. Where the incident affects Customer Personal Data and notification is required by law or the B2B agreement, RIZZ TRADE notifies the Customer without undue delay after it has sufficient initial information. The notice includes known information at that time about the nature of the event, affected categories/systems, measures taken or planned, and a channel for further contact. Information can be supplemented as the investigation progresses.
The Customer determines whether it must notify data subjects or a supervisory authority in its role as Controlling Party, unless law imposes another duty directly on RIZZ TRADE. RIZZ TRADE provides reasonable assistance within available information, the actual product, and the agreement. Notification timing is determined by applicable law, the B2B agreement, and the agreed incident process.
7. Data-subject requests, public authorities, and cooperation
If RIZZ TRADE receives a data-subject request concerning Customer Personal Data for which the Customer is responsible as Controlling Party, RIZZ TRADE where possible forwards it to the Customer or directs the data subject to the Customer. It provides reasonable assistance within the B2B agreement, available information, and law. RIZZ TRADE limits its response so it does not disclose another person's data, Customer confidential information, security measures, or information protected by law.
On a reasonable Customer request, RIZZ TRADE may provide proportionate assistance with a data-protection impact assessment, consultation with an authority, or another Controlling Party obligation where connected to the actual service provided. Scope, costs, timing, and permissible materials follow the B2B agreement, request nature, and security. Such assistance does not make RIZZ TRADE the Customer's legal adviser.
For a lawful public-authority request, RIZZ TRADE assesses it within its competence and discloses only what is necessary. Where the agreement and law permit, RIZZ TRADE notifies the Customer before disclosure or promptly after it. Notification can be delayed or omitted where prohibited, where it could interfere with an investigation, create risk, or breach a legal obligation.
8. Compliance information and audit
The Customer may request information reasonably needed to confirm performance of the agreed B2B layer. RIZZ TRADE considers the request with regard to confidentiality, security, other-customer rights, available evidence, and the nature of processing. Available documents, questionnaire responses, a summary of measures, or independent evidence can serve as an alternative to an audit where they actually exist and are sufficient for the purpose.
An on-site or remote audit is conducted where expressly provided by the B2B agreement and where scope, period, auditor independence, confidentiality, system protection, frequency, and costs are agreed. An audit does not provide access to infrastructure, source code, keys, other-customer data, Model Provider security, or other material whose disclosure would breach confidentiality, security, third-party rights, or law.
9. Return, deletion, and termination of a B2B order
At B2B-order termination, the Customer receives a reasonable opportunity to request return or export of Customer Data in an available format where technically feasible and where it does not breach third-party rights, security, law, or provider terms. The B2B order or processing addendum identifies the period, format, cost, scope, and contact for that request.
After the applicable return/export period, RIZZ TRADE deletes or de-identifies Customer Personal Data within its role unless law, security, a dispute, accounting, defence of rights, or the agreement requires limited retention. Backup and isolated copies are cleared through their actual cycle, do not return to ordinary use, and do not provide access to a restored Workspace without an independent basis. Model Providers can retain data under their own contractual conditions; the relevant path and available assistance are identified in the register/addendum.
Return and deletion follow the criteria of the B2B order, actual product, backup cycle, and applicable law. A special period, data residency, retention lock, destruction certificate, or separate export applies where agreed before processing and stated in the addendum.
10. International transfers
For Customer Personal Data subject to international-transfer restrictions, the parties first identify the actual flow: exporter, importer, roles, countries, data categories, recipients, model route, and applicable law. They then enter into an individual addendum or use another recognised mechanism where necessary. This can include contractual conditions for the EEA, United Kingdom, Switzerland, or another territory, but only after the required parties, appendices, and information are completed.
An individual international-transfer addendum becomes part of the B2B agreement after the applicable mechanism and necessary information about parties, route, and data have been determined. The general Privacy Policy operates as public notice; a specific single-country processing guarantee, SCC, UK Addendum, or other transfer mechanism applies only where expressly stated in the individual addendum.
11. Liability, changes, and relationship to other terms
Data-processing obligations and remedies apply within the B2B agreement and mandatory law. A liability limit, indemnity, confidentiality duty, and dispute process apply to the extent expressly established by the B2B agreement. A B2B limitation does not apply to a consumer where law does not allow it and does not limit non-waivable data-subject rights.
RIZZ TRADE may update the general B2B layer when law, product, an actual Subprocessor, or security requirements change. A material change applies under the notice and prospective-effect procedure agreed with the Customer and does not retroactively alter an already agreed route, processing addendum, or mandatory-law rights. Organisation questions may be sent to support@cicora.ai; a B2B order can specify a separate working contact.
Appendix: minimum form of a processing schedule
The following form is completed with current information for the specific B2B order:
| Field | Content to complete |
|---|---|
| Customer / Controlling Party contact | name, address/contact, privacy and incident contact, authorised administrator |
| RIZZ TRADE / Processor contact | contracting legal party, working privacy/incident contact |
| Service and order | specific Workspace/API/features, agreement version, start and end date |
| Instructions | agreement, order, settings, API documentation, authorised administrator; lawful mandatory exceptions |
| Purposes and operations | service provision, selected features, support, security, deletion/export |
| Data subjects and data | actual categories, sensitive-data restriction, expected volume and frequency |
| Subprocessors and models | current register, roles, functions, countries/transfers, change rule |
| Security / incident | verified measures, contact, notice, and assistance procedure |
| Retention / return / deletion | criteria, export format, backup/legal exceptions, completion evidence |
| Transfers | applicable law, exporter/importer, individual mechanism and appendices where needed |