Skip to main content
    Pritect

    Data Processing Agreement

    This Data Processing Agreement (the "DPA") sets out the additional terms, requirements and conditions under which Service Provider will process Customer Personal Data when providing Services under the Master Terms of Service (the "MSA").

    Version 1.0Effective: 1 February 2026

    1. Definitions

    1.1Capitalized terms used but not defined in this DPA will have the meanings provided in the MSA.
    1.2Other terms used but not defined in this DPA, such as "personal data breach", "processing", "controller", "processor", "personal data", "data subject", "data protection impact assessment", and "transfers of personal data to third countries" will have the same meaning as set forth in Article 4 of the GDPR (Definitions).
    1.3The following defined terms are used in this DPA:
    • (a) "Data Protection Laws" mean all laws and regulations, including laws and regulations of the European Union, the European Economic Area and their member states, Switzerland, the United Kingdom and the United Arab Emirates and the Kingdom of Saudi Arabia, to the extent applicable to the Processing of Personal Data under the Agreement;
    • (b) "EEA" means the European Economic Area including EU Member States and Norway, Liechtenstein and Iceland;
    • (c) "GDPR" means the EU General Data Protection Regulation 2016/679;
    • (d) "Customer Personal Data" is defined by the MSA and means all Personal Data Processed by Service Provider on behalf of the Customer in connection with the MSA and this DPA;
    • (e) "Sub-processor" means any legal person (including any third party and any Service Provider Affiliate) appointed by Processor or any of its Affiliates to process Customer Personal Data in connection with the MSA.

    2. Personal Data Types and Processing Purposes

    2.1The Customer and the Service Provider agree and acknowledge that for the purpose of the Data Protection Laws:
    • (a) The Customer is the Data Controller and the Service Provider is the Data Processor.
    • (b) Annex 1 describes the scope, subject, purpose, nature and type of the processing and the Personal Data categories and data subject types in respect of which Service Provider may process the Customer Personal Data.
    • (c) Annex 2 describes appropriate technical and organisational measures.
    2.2The subject-matter of this DPA is the processing carried out under the MSA, including processing operations with respect to:
    • (a) Data provided by the Customer to Processor,
    • (b) Data which the Service Provider is given access to by the Customer, and
    • (c) Data generated in connection with the Service Provider's performance of its obligations under the MSA.

    3. General Obligations

    3.1The Service Provider has implemented, and will throughout the term of this DPA maintain, appropriate technical and organisational measures, in such a manner that the processing will meet the requirements of applicable data protection law, ensure the protection of the rights of the data subjects and ensure a level of security appropriate to the risk of processing.
    3.2The Service Provider will process Customer Personal Data in accordance with the Customer's documented instructions and solely for the purpose of performing its obligations pursuant to the MSA. The Service Provider may rely on the MSA and this DPA as a standing instruction.
    3.3The Service Provider commits to ensuring that all the persons processing Customer Personal Data under the authority and supervision of the Service Provider have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, in addition to which such persons shall process Customer Personal Data only pursuant to this DPA, the MSA and the Customer's instructions.
    3.4The Service Provider will maintain an accurate and up to date record of processing activities with respect to the Customer Personal Data to the extent required by Data Protection Laws.
    3.5If the Service Provider considers an instruction from the Customer to be in violation of the Data Protection Laws, the Service Provider will inform the Customer in writing about this.

    4. Assistance to the Customer

    4.1The Service Provider will assist the Customer, insofar as this is possible, in the fulfilment of the controller's obligation to respond to requests for exercising the data subject's rights taking into account the nature of the processing.
    4.2The Service Provider will, taking into account the nature of processing and the information available to it, assist the Customer with data protection impact assessments, and prior consulting obligations pertaining to the Customer Personal Data processed by the Service Provider.
    4.3The Service Provider shall, taking into account the nature of the processing and the information available to it, assist the Customer in responding to lawful requests, inspections and investigations by competent supervisory authorities relating to the processing of Customer Personal Data under the MSA. Such assistance shall be provided through the Customer, unless the Service Provider is otherwise required by applicable law to respond directly to a supervisory authority.
    4.4The Service Provider shall not engage in any direct communication with data subjects or supervisory authorities in connection with the processing operations carried out under the MSA. The Service Provider shall forward to the Customer within 5 working days any request or complaint received from a data subject with respect to the processing operations carried out under the MSA. Moreover, the Service Provider shall forward within 5 working days, and without undue delay where required by law, any request from a supervisory authority requiring inspections, investigations, access to, or information regarding the personal data, unless prohibited under law (if so, the Service Provider shall inform the Customer as soon as permitted under such law).

    5. Audits

    5.1The Service Provider shall provide the Customer with information necessary to demonstrate compliance with the obligations concerning the processing of Customer Personal Data. The Service Provider shall allow the Customer, either on their own or with a third party (which shall not be a competitor to the Service Provider), to conduct audits in the presence of the Service Provider. The Service Provider shall have the right to determine whether such third party is a competitor to the Service Provider or not.
    5.2The audit shall be carried out in a manner which does not compromise the business secrets of the Service Provider, of its sub-processors or of other customers, or the Service Provider's undertakings towards other customers. Customer's auditor shall sign a separate confidentiality undertaking in order to duly protect the Service Provider's confidential information.
    5.3The Customer shall notify the Service Provider at least thirty (30) days in advance, after which the Parties shall mutually agree on the extent and timing of the audit, always conducted during the Service Provider's normal working hours. The Customer is liable for the audit costs of the third party, otherwise each Party is liable for its part of the audit costs.
    5.4The Customer may conduct an audit under this Section no more than once in any twelve (12) month period, unless required by a competent supervisory authority or following a material personal data breach affecting the Customer Personal Data.

    6. Personal Data Breaches

    6.1In the event of a personal data breach, the Service Provider shall without undue delay and within 72 hours after becoming aware of such breach notify the Customer thereof in writing. To the extent information is available to the Service Provider, the personal data breach notification shall contain the following:
    • (a) a description of the nature of the personal data breach including, the categories and approximate number of data subjects concerned, and the categories and approximate number of data records concerned;
    • (b) the name and contact details of the Data Protection Officer or other person able to provide additional information;
    • (c) a description of likely consequences or realized consequences of the personal data breach; and
    • (d) a description of the measures taken by the Service Provider to address the personal data breach and to mitigate its possible adverse effects.
    6.2Taking into account the nature of processing and the information available to the Service Provider, the Service Provider shall assist the Customer in submitting data breach notifications to the supervisory authority and the data subjects.
    6.3The Customer shall without undue delay inform the Service Provider if the Customer becomes aware of a personal data breach which could have an impact on Service Provider or its processing of personal data. Should the Service Provider need information in the event of a personal data breach in order to fulfil its obligations under this DPA and the Data Protection Laws, the Customer shall provide such information to the Service Provider without undue delay.

    7. Use of Sub-Processors

    7.1The Service Provider may subcontract parts of its processing operations to sub-processors, which the Customer authorises. The Service Provider will maintain a list of sub-processors available here.
    7.2Prior to engaging any sub-processor, the Service Provider will carry out due diligence to ensure that the sub-processor is capable of providing the level of protection required by this DPA.
    7.3From time to time, Service Provider may engage a new sub-processor. Service Provider will give Customer notice (by updating the linked website and notifying of the change) of any new sub-processor at least thirty (30) days in advance of engaging that new sub-processor.
    7.4Where the Customer reasonably objects, on data protection grounds, to the engagement of a new sub-processor, the Customer may terminate the Agreement by providing written notice to the Service Provider within fourteen (14) days of the Service Provider's notification. If the Customer does not exercise this right within such period, the Service Provider shall be entitled to engage the new sub-processor. Any termination under this Section shall take effect in accordance with the termination provisions of the MSA.
    7.5Subcontracting shall only be done by way of a written agreement with the sub-processor which shall not impose on the sub-processor less onerous data protection obligations as set out in this DPA.
    7.6The Service Provider remains liable to the Controller for the performance of the sub-processors' obligations.

    8. International Transfers of Personal Data

    8.1The Service Provider is entitled to transfer personal data outside the European Union or the European Economic Area, provided that the Service Provider commits to ensuring that the Service Provider itself and its sub-processors transfer personal data in compliance with the applicable data protection legislation, including provisions stipulated in chapter V of the GDPR.
    8.2In particular, the Parties acknowledge that in cases of any transfers of Customer Personal Data outside the European Union or the European Economic Area, the Service Provider shall commit to transferring the data to any sub-processors only in accordance with a valid data transfer mechanism as per Article 46 of the GDPR, such as, but not limited to the Standard Contractual Clauses ("Standard Contractual Clauses"), and that the Service Provider has taken appropriate measures to ensure compliance of the transfer with the applicable data protection legislation including, where required, assessing the impact of such transfer on the Customer Personal Data.

    9. Data Deletion

    9.1The Customer is responsible for exporting, before the term of the MSA expires, any personal data it wishes to retain. If Customer is unable to export personal data, the Service Provider shall, upon Customer's written request, return personal data to the Customer at no additional cost. Such a request shall be made prior to expiry of the term of the MSA.
    9.2On expiry of the term of the MSA, Customer instructs the Service Provider to delete all Customer Personal Data (including existing copies) in accordance with applicable legislation. The Service Provider and its sub-processors shall comply with this instruction as soon as reasonably practicable, unless applicable legislation requires storage.

    10. Liability for Damage and Limitation of Liability

    10.1Each Party is liable for any administrative fines imposed by the supervisory authority and/or any damages adjudged by the competent court against such Party based on its infringement of the applicable data protection legislation. If a Party has paid full compensation to a data subject for the damage suffered pursuant to Article 82(4) of the GDPR, such Party shall be entitled to claim back from the other Party the part of the compensation corresponding to its part of the responsibility for such damage.
    10.2The Service Provider shall be liable to the Customer only insofar as it has breached:
    • (a) the written instructions of the Customer that complies with applicable data protection law in connection with the Service Provider processing of Customer Personal Data,
    • (b) its obligations under this Data Processing Agreement or
    • (c) provisions of applicable data protection law that are directly applicable to the Service Provider when it processes personal data on behalf of the Controller.
    10.3Any liability arising out of or in connection with this DPA shall be subject to the limitations of liability set out in the MSA.

    11. Governing Law and Dispute Resolution

    11.1This DPA shall be governed and construed in accordance with the laws set out in the MSA. Any dispute arising out of or in connection with this DPA shall be resolved in accordance with the dispute resolution clause set out in the MSA.

    12. Term and Termination

    12.1This DPA enters into force on the effective date of the MSA and remains in force as long as the Service Provider processes Customer Personal Data as the Customer's data processor.

    Annex 1. Description of Services and Personal Data

    Purpose(s) of Processing

    • Provision of Pritect.ai: SaaS-based compliance and governance platform,
    • User account management, authentication and access control,
    • Delivery of platform functionalities,
    • Maintenance of audit trails and activity logs,
    • Platform security and monitoring,
    • Provision of customer support and service communications.

    Nature of Processing

    The nature of the processing is set out in the MSA and includes providing access to the Platform features, enabling data subjects to interact with the Platform, processing and storing data entered into the Platform, maintaining audit logs, providing notifications and communications, and providing customer support.

    Processing is carried out in accordance with and for the purposes of the agreement concluded between the Parties (including the Master Service Agreement governing the use of the platform and related documents and on instruction of the Customer who is the data controller).

    Categories of Personal Data

    • Identification and contact data (e.g. first and last name, business email address, business phone number, organisation, role),
    • Account and access data (e.g. user ID, username, authentication data, access rights),
    • Usage and log data (e.g. login timestamps, activity logs, IP address, device and browser information),
    • Communication data (e.g. support requests and related correspondence),
    • Content data entered by Users into the Platform, which may include references to identifiable individuals as determined by the Customer.

    Categories of Data Subjects

    • Platform users (including client employees, authorized users, and administrators)
    • Client representatives (e.g. account owners and billing contacts)
    • Individuals referenced within compliance records created by users in the platform
    • Support and communication contacts

    Processor Contact Point

    privacy@pritect.ai

    Controller Contact Point

    Pursuant to the MSA, the Customer shall provide and keep up to date accurate contact details for designated points of contact.

    Annex 2. Security Measures

    Aligned to ISO/IEC 27001:2022 Annex A

    The Service Provider maintains an Information Security Management System ("ISMS") aligned with ISO/IEC 27001:2022 principles and implements the technical and organisational measures described below. These controls apply to the Platform and to all Processing of Customer Personal Data carried out under the Agreement.

    1. Information Security Governance (A.5, A.6)

    • The Service Provider operates an ISMS aligned to ISO/IEC 27001:2022 and maintains policies governing information security, data protection, access control, incident handling, and secure development.
    • Policies are reviewed at least annually and communicated to relevant personnel.
    • Roles and responsibilities for security and data protection are defined and documented.
    • Security responsibilities include ensuring that activities are performed by qualified personnel.

    2. Human Resources Security & Training (A.7)

    • All personnel with access to Customer Personal Data are subject to confidentiality obligations.
    • Security and data protection awareness training is provided during onboarding and periodically thereafter.
    • Personnel with roles involving software development or testing receive additional secure development training.
    • Personnel are subject to appropriate background checks in accordance with applicable law.

    3. Access Control & Identity Management (A.8)

    • Access to systems and data is granted on a need-to-know basis following the principle of least privilege.
    • Role-based access control (RBAC) is applied, and access rights are reviewed periodically.
    • Privileged accounts are restricted, monitored, and logged.
    • Multi-factor authentication (MFA) is used for administrative access and enforced for customer user accounts where platform capabilities or tier configuration require it.
    • Segregation of duties is applied where appropriate.

    4. Physical & Environmental Security (A.9)

    • This section applies to cloud hosting provider-level controls.
    • Customer Personal Data is hosted in secure data centres operated by reputable cloud providers with industry-standard physical security controls (e.g., multifactor entry controls, 24/7 monitoring, environmental protections).

    5. Operations Security (A.10, A.12, A.13)

    • Vulnerability management processes include automated scanning, risk-based prioritisation, and timely remediation.
    • Patching and updates for systems and third-party components follow a risk-based schedule.
    • Anti-malware and integrity controls are implemented within relevant components.
    • Logging and monitoring are applied to user activity, administrative operations, authentication events, security events, and system activity.
    • Logs are retained for an appropriate period, and access to logs is restricted.

    6. Communications & Network Security (A.13)

    • Customer Personal Data is protected in transit using strong encryption (e.g., TLS).
    • Network boundaries and internal services are protected through access controls, encryption, and segmentation where appropriate.
    • Secure channels are used for integrations, APIs, and external connections.

    7. Cryptographic Controls (A.14)

    • Customer Personal Data stored within the Platform is encrypted at rest using industry-standard cryptography.
    • Backups containing Customer Personal Data are encrypted.
    • Cryptographic keys, secrets, and credentials are stored securely using appropriate key management mechanisms.

    8. Secure Development & Change Management (A.8, A.12, A.14, A.20)

    • A secure development life cycle (SDLC) is followed, including code review, testing, and security validation prior to release.
    • Development, test, and production environments are separated.
    • Changes to the Platform undergo formal review and approval before deployment.
    • Security testing following a comprehensive test management regime is conducted as part of release processes.

    9. Supplier & Third-Party Management (A.5, A.15)

    • Sub-processors undergo security due diligence.
    • Contractual terms require appropriate data protection and security measures.
    • Supplier risks are periodically reviewed.

    10. Incident Management (A.16)

    • A documented incident response process governs detection, reporting, investigation, and remediation of security incidents.
    • All incidents are assessed for severity and potential impact on Customer Personal Data.
    • Where a Personal Data Breach affecting Customer Personal Data occurs, the Service Provider notifies the Customer without undue delay and provides relevant information as it becomes available.
    • Incident records and closure reports are maintained.

    11. Business Continuity & Disaster Recovery (A.17)

    • The Service Provider maintains business continuity and disaster recovery capabilities appropriate to the Platform, including regular backups, geographically redundant hosting, and defined recovery time and recovery point objectives (RTO/RPO).
    • Continuity and recovery procedures are periodically reviewed and tested.

    12. Compliance & Monitoring (A.18)

    • Controls are periodically reviewed for effectiveness and alignment with legal, regulatory, and contractual requirements.
    • The Service Provider maintains documentation demonstrating the operation and maturity of its security programme.