Data Processing Agreement
This Data Processing Agreement (the "DPA") sets out the additional terms, requirements and conditions under which Service Provider will process Customer Personal Data when providing Services under the Master Terms of Service (the "MSA").
1. Definitions
- (a) "Data Protection Laws" mean all laws and regulations, including laws and regulations of the European Union, the European Economic Area and their member states, Switzerland, the United Kingdom and the United Arab Emirates and the Kingdom of Saudi Arabia, to the extent applicable to the Processing of Personal Data under the Agreement;
- (b) "EEA" means the European Economic Area including EU Member States and Norway, Liechtenstein and Iceland;
- (c) "GDPR" means the EU General Data Protection Regulation 2016/679;
- (d) "Customer Personal Data" is defined by the MSA and means all Personal Data Processed by Service Provider on behalf of the Customer in connection with the MSA and this DPA;
- (e) "Sub-processor" means any legal person (including any third party and any Service Provider Affiliate) appointed by Processor or any of its Affiliates to process Customer Personal Data in connection with the MSA.
2. Personal Data Types and Processing Purposes
- (a) The Customer is the Data Controller and the Service Provider is the Data Processor.
- (b) Annex 1 describes the scope, subject, purpose, nature and type of the processing and the Personal Data categories and data subject types in respect of which Service Provider may process the Customer Personal Data.
- (c) Annex 2 describes appropriate technical and organisational measures.
- (a) Data provided by the Customer to Processor,
- (b) Data which the Service Provider is given access to by the Customer, and
- (c) Data generated in connection with the Service Provider's performance of its obligations under the MSA.
3. General Obligations
4. Assistance to the Customer
5. Audits
6. Personal Data Breaches
- (a) a description of the nature of the personal data breach including, the categories and approximate number of data subjects concerned, and the categories and approximate number of data records concerned;
- (b) the name and contact details of the Data Protection Officer or other person able to provide additional information;
- (c) a description of likely consequences or realized consequences of the personal data breach; and
- (d) a description of the measures taken by the Service Provider to address the personal data breach and to mitigate its possible adverse effects.
7. Use of Sub-Processors
8. International Transfers of Personal Data
9. Data Deletion
10. Liability for Damage and Limitation of Liability
- (a) the written instructions of the Customer that complies with applicable data protection law in connection with the Service Provider processing of Customer Personal Data,
- (b) its obligations under this Data Processing Agreement or
- (c) provisions of applicable data protection law that are directly applicable to the Service Provider when it processes personal data on behalf of the Controller.
11. Governing Law and Dispute Resolution
12. Term and Termination
Annex 1. Description of Services and Personal Data
Purpose(s) of Processing
- •Provision of Pritect.ai: SaaS-based compliance and governance platform,
- •User account management, authentication and access control,
- •Delivery of platform functionalities,
- •Maintenance of audit trails and activity logs,
- •Platform security and monitoring,
- •Provision of customer support and service communications.
Nature of Processing
The nature of the processing is set out in the MSA and includes providing access to the Platform features, enabling data subjects to interact with the Platform, processing and storing data entered into the Platform, maintaining audit logs, providing notifications and communications, and providing customer support.
Processing is carried out in accordance with and for the purposes of the agreement concluded between the Parties (including the Master Service Agreement governing the use of the platform and related documents and on instruction of the Customer who is the data controller).
Categories of Personal Data
- •Identification and contact data (e.g. first and last name, business email address, business phone number, organisation, role),
- •Account and access data (e.g. user ID, username, authentication data, access rights),
- •Usage and log data (e.g. login timestamps, activity logs, IP address, device and browser information),
- •Communication data (e.g. support requests and related correspondence),
- •Content data entered by Users into the Platform, which may include references to identifiable individuals as determined by the Customer.
Categories of Data Subjects
- •Platform users (including client employees, authorized users, and administrators)
- •Client representatives (e.g. account owners and billing contacts)
- •Individuals referenced within compliance records created by users in the platform
- •Support and communication contacts
Processor Contact Point
privacy@pritect.aiController Contact Point
Pursuant to the MSA, the Customer shall provide and keep up to date accurate contact details for designated points of contact.
Annex 2. Security Measures
Aligned to ISO/IEC 27001:2022 Annex A
The Service Provider maintains an Information Security Management System ("ISMS") aligned with ISO/IEC 27001:2022 principles and implements the technical and organisational measures described below. These controls apply to the Platform and to all Processing of Customer Personal Data carried out under the Agreement.
1. Information Security Governance (A.5, A.6)
- •The Service Provider operates an ISMS aligned to ISO/IEC 27001:2022 and maintains policies governing information security, data protection, access control, incident handling, and secure development.
- •Policies are reviewed at least annually and communicated to relevant personnel.
- •Roles and responsibilities for security and data protection are defined and documented.
- •Security responsibilities include ensuring that activities are performed by qualified personnel.
2. Human Resources Security & Training (A.7)
- •All personnel with access to Customer Personal Data are subject to confidentiality obligations.
- •Security and data protection awareness training is provided during onboarding and periodically thereafter.
- •Personnel with roles involving software development or testing receive additional secure development training.
- •Personnel are subject to appropriate background checks in accordance with applicable law.
3. Access Control & Identity Management (A.8)
- •Access to systems and data is granted on a need-to-know basis following the principle of least privilege.
- •Role-based access control (RBAC) is applied, and access rights are reviewed periodically.
- •Privileged accounts are restricted, monitored, and logged.
- •Multi-factor authentication (MFA) is used for administrative access and enforced for customer user accounts where platform capabilities or tier configuration require it.
- •Segregation of duties is applied where appropriate.
4. Physical & Environmental Security (A.9)
- •This section applies to cloud hosting provider-level controls.
- •Customer Personal Data is hosted in secure data centres operated by reputable cloud providers with industry-standard physical security controls (e.g., multifactor entry controls, 24/7 monitoring, environmental protections).
5. Operations Security (A.10, A.12, A.13)
- •Vulnerability management processes include automated scanning, risk-based prioritisation, and timely remediation.
- •Patching and updates for systems and third-party components follow a risk-based schedule.
- •Anti-malware and integrity controls are implemented within relevant components.
- •Logging and monitoring are applied to user activity, administrative operations, authentication events, security events, and system activity.
- •Logs are retained for an appropriate period, and access to logs is restricted.
6. Communications & Network Security (A.13)
- •Customer Personal Data is protected in transit using strong encryption (e.g., TLS).
- •Network boundaries and internal services are protected through access controls, encryption, and segmentation where appropriate.
- •Secure channels are used for integrations, APIs, and external connections.
7. Cryptographic Controls (A.14)
- •Customer Personal Data stored within the Platform is encrypted at rest using industry-standard cryptography.
- •Backups containing Customer Personal Data are encrypted.
- •Cryptographic keys, secrets, and credentials are stored securely using appropriate key management mechanisms.
8. Secure Development & Change Management (A.8, A.12, A.14, A.20)
- •A secure development life cycle (SDLC) is followed, including code review, testing, and security validation prior to release.
- •Development, test, and production environments are separated.
- •Changes to the Platform undergo formal review and approval before deployment.
- •Security testing following a comprehensive test management regime is conducted as part of release processes.
9. Supplier & Third-Party Management (A.5, A.15)
- •Sub-processors undergo security due diligence.
- •Contractual terms require appropriate data protection and security measures.
- •Supplier risks are periodically reviewed.
10. Incident Management (A.16)
- •A documented incident response process governs detection, reporting, investigation, and remediation of security incidents.
- •All incidents are assessed for severity and potential impact on Customer Personal Data.
- •Where a Personal Data Breach affecting Customer Personal Data occurs, the Service Provider notifies the Customer without undue delay and provides relevant information as it becomes available.
- •Incident records and closure reports are maintained.
11. Business Continuity & Disaster Recovery (A.17)
- •The Service Provider maintains business continuity and disaster recovery capabilities appropriate to the Platform, including regular backups, geographically redundant hosting, and defined recovery time and recovery point objectives (RTO/RPO).
- •Continuity and recovery procedures are periodically reviewed and tested.
12. Compliance & Monitoring (A.18)
- •Controls are periodically reviewed for effectiveness and alignment with legal, regulatory, and contractual requirements.
- •The Service Provider maintains documentation demonstrating the operation and maturity of its security programme.
