This Data Processing Agreement ("Agreement") is entered into between the Customer or Partner identified in the applicable Services or Licence Agreement ("Controller") and CyberSentriq ("Processor"). This Agreement forms part of, and is incorporated into, the Services Agreement between the parties.
The purpose of this Agreement is to set out the respective rights and obligations of the parties in connection with the Processing of Personal Data, in accordance with applicable Data Protection Laws, including Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and equivalent legislation.
This Agreement forms a fixed contractual schedule to the Services Agreement. The version executed by the parties shall remain binding for the duration of the Services Agreement unless amended in writing by authorised representatives of both parties.
For the purposes of this Agreement, the terms "Personal Data", "Processing", "Data Subject", and "Personal Data Breach" shall have the meanings given to them under applicable Data Protection Laws.
"Data Protection Laws" means all applicable laws, regulations and legally binding requirements relating to the Processing of Personal Data under this Agreement, including, where applicable, the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, the UK Data Protection Act 2018, the Protection of Personal Information Act, 2013 (POPIA), the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), and any successor or substantially equivalent privacy legislation applicable to the Services provided under this Agreement
"Services" means the security, monitoring, data protection, backup, recovery, and related services provided by CyberSentriq under the Services Agreement
This Agreement governs the Processing of Personal Data by the Processor on behalf of the Controller in connection with the Services.
This Agreement shall remain in effect for the duration of the Services Agreement, and thereafter for so long as the Processor Processes Personal Data on behalf of the Controller.
This Agreement is intended to support the parties' compliance with applicable privacy and data protection legislation governing the Processing of Personal Data. Where applicable to the Services or the Controller's regulatory obligations, this Agreement may also support compliance with sector-specific regulatory requirements, including the European Union Digital Operational Resilience Act ("DORA"), the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), and the California Consumer Privacy Act ("CCPA/CPRA"). Nothing in this Agreement shall be interpreted as limiting or replacing any additional contractual obligations agreed between the parties to satisfy such regulations.
The Processor shall Process Personal Data solely on behalf of the Controller and strictly in accordance with the Controller’s documented instructions.
Processing activities are limited to those necessary for the provision, maintenance, support, security, and improvement of the Services, including but not limited to cybersecurity monitoring, threat detection and response, data storage, backup, restoration, and system administration.
Under no circumstances shall the Processor Process Personal Data for its own purposes.
The Personal Data Processed may include, depending on the Services utilised by the Controller:
The specific categories of Personal Data will depend on the nature and scope of the Services and the data provided by the Controller.
The exact categories of Personal Data processed will depend on the nature of the Controller’s systems and the Services in use.
Personal Data Processed under this Agreement may relate to the following categories of Data Subjects:
The Controller shall be responsible for ensuring that:
The Controller remains solely responsible for responding to requests from Data Subjects and for determining appropriate retention periods for Personal Data.
The Processor shall:
Where the Processor considers that an instruction from the Controller infringes applicable Data Protection Laws, it shall promptly inform the Controller.
Where the California Consumer Privacy Act ("CCPA"), as amended by the California Privacy Rights Act ("CPRA"), applies to the Services, CyberSentriq shall Process Personal Information solely for the business purposes described in the applicable Services Agreement and this Agreement.
CyberSentriq shall not:
CyberSentriq shall implement reasonable security measures appropriate to the nature of the Personal Information processed and shall provide reasonable assistance to enable the Controller to respond to verified consumer requests where required.
Where the Services involve the Processing of Protected Health Information ("PHI") on behalf of a Covered Entity or Business Associate as defined under HIPAA, the parties acknowledge that a separate Business Associate Agreement ("BAA") shall govern such Processing.
Where a BAA has been executed between the parties, the obligations contained within the BAA shall apply in respect of PHI and shall prevail over any conflicting provisions contained within this Agreement solely in relation to HIPAA-regulated information.
Nothing within this Agreement shall be interpreted as creating Business Associate obligations where no BAA has been executed.
Where the Controller is subject to Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector ("DORA"), CyberSentriq shall maintain appropriate technical and organisational measures supporting operational resilience throughout the provision of the Services.
Such measures include, where applicable:
Upon reasonable request and subject to confidentiality obligations, CyberSentriq shall provide information reasonably necessary to assist the Controller in satisfying its regulatory oversight and supplier assurance obligations under DORA.
The Controller provides general written authorisation for the Processor to engage sub-processors for the provision of the Services.
The Processor shall ensure that:
A current list of authorised sub-processors may be made available to the Controller upon request and shall include, where applicable, the legal entity name, processing function and processing location.
Where Personal Data is transferred outside the EEA, UK or other jurisdiction requiring transfer safeguards, the Processor shall ensure that an appropriate transfer mechanism is implemented, including Standard Contractual Clauses or another lawful transfer mechanism recognised under applicable Data Protection Laws.
Information regarding applicable transfer mechanisms shall be made available to the Controller upon reasonable request.
The Processor shall implement appropriate technical and organisational measures designed to ensure a level of security appropriate to the risk, including measures relating to:
CyberSentriq shall maintain an Information Security Management System supported by documented security policies, risk management processes, employee security awareness programmes, vulnerability management, secure change management, incident response procedures and business continuity arrangements appropriate to the Services provided. Security controls shall be periodically reviewed and updated to address changes in technology, emerging threats and applicable regulatory obligations.
In the event of a Personal Data Breach, the Processor shall notify the Controller without undue delay and, where reasonably practicable, within forty-eight (48) hours of becoming aware of the Personal Data Breach.
Where required by applicable Data Protection Laws or other applicable regulatory requirements, CyberSentriq shall provide reasonable information relating to the nature of the incident, the categories of information affected, the likely impact, containment measures implemented and planned remediation activities to enable the Controller to fulfil its own legal and regulatory notification obligations.
Considering the nature of the Processing, the Processor shall assist the Controller, where reasonably possible, in responding to requests from Data Subjects to exercise their rights under applicable Data Protection Laws.
The Controller may, at its own cost and no more than once in any twelve (12) month period (unless required by law or following a material Personal Data Breach), request information necessary to demonstrate the Processor’s compliance with this Agreement.
The Processor may satisfy such requests by providing:
On-site audits shall only be permitted where strictly necessary and shall be subject to reasonable prior notice, confidentiality obligations, and appropriate safeguards to protect the Processor’s confidential information and that of its other customers.
Where reasonably required to support applicable legal or regulatory obligations, CyberSentriq shall provide relevant documentation describing its information security, operational resilience and privacy controls, including independent audit reports, certifications, security policies and responses to reasonable due diligence questionnaires, subject to confidentiality obligations and the protection of CyberSentriq's confidential information.
Upon termination or expiry of the Services, the Processor shall delete or return Personal Data in accordance with the terms of the Services Agreement, unless retention is required by applicable law.
Upon request and where technically feasible, the Controller shall be provided with a reasonable opportunity to export its Personal Data before deletion. Following termination of the Services, Personal Data shall be deleted, returned or anonymised in accordance with the Services Agreement and the Processor's documented retention procedures, unless retention is required by law.
The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with this Agreement and applicable Data Protection Laws.
Each party shall be responsible for its own compliance with applicable Data Protection Laws.
The Processor shall be liable only where it has failed to comply with its obligations under this Agreement or has acted outside or contrary to the lawful instructions of the Controller, and in all cases subject to the limitations and exclusions of liability set out in the Services Agreement.
This clause shall be subject to review and alignment with the underlying Services Agreement.
This Agreement shall be governed by and construed in accordance with the law specified in the Services Agreement, being the jurisdiction of CyberSentriq’s principal place of business, unless otherwise agreed in writing between the parties
CyberSentriq operates a formal Information Security Management System (ISMS) to ensure that information assets are appropriately protected.
Information is recognised as a critical business asset and is safeguarded in accordance with the principles of:
Responsibility for the implementation and maintenance of the ISMS is delegated to the Information Security and Compliance function.
Any exception to this Agreement must:
Each party shall reasonably cooperate with the other in responding to enquiries from competent supervisory authorities relating to the Processing of Personal Data under this Agreement. Such cooperation shall be limited to information reasonably necessary to demonstrate compliance with applicable contractual, legal and regulatory obligations and shall remain subject to confidentiality obligations, legal privilege and the protection of confidential business information.
----
|
Version |
Revision Date |
Summary of Change |
Approved By |
|
0.1 |
07 April 2026 |
Initial CyberSentriq Merged DPA |
GRC Specialist |
|
0.2 |
08 April 2026 |
Review and comments |
VP of Information & Security |
|
0.3 |
13 April 2026 |
Amendments and alignments made to draft. |
GRC Specialist |
|
1.0 |
14 April 2026 |
Final Review and Approval |
GRC Specialist |
|
1.1 |
05 June 2026 |
Policy Update and Amendments |
GRC Specialist |
|
1.2 |
15 June 2026 |
Explicit alignment to legislation |
GRC Specialist |
|
|
|
|
|
Effective Date and Review Date
Effective Date: Date of Execution
Review Date: 05 June 2026
Next Review Date: 05 June 2027