This describes the roles of the parties when CiteraHub processes data on your behalf. It is a draft and has not been reviewed by a lawyer.
You are the controller of the data on your sites and in your repositories. CiteraHub is a processor of it, acting on your instructions, which take the form of the audits you request and the changes you approve.
CiteraHub processes that data to produce a report and to apply a change you approved. It does not process it for any other purpose, and in particular does not use it to train a model.
Sub-processing: the deployment's database and hosting provider process data on CiteraHub's behalf. A current list belongs in the subprocessors document, which is also unwritten.
Security measures implemented and testable today: row level security enforced and forced at the database, so a query carrying one tenant's identity cannot read another's; envelope encryption of connector credentials; an egress guard that refuses private address ranges; and a filesystem containment check on every read and every write.
On termination, applied changes remain in your repository and audit data is deleted according to the retention setting.
Audit rights, breach notification periods, transfer mechanisms and liability allocation are not drafted here. A qualified reviewer must write them.