Skip to content

Hit enter to search or ESC to close

This Data Processing Agreement ("Agreement") is entered into between the Customer or Partner identified in the applicable Services or Licence Agreement ("Controller") and CyberSentriq ("Processor"). This Agreement forms part of, and is incorporated into, the Services Agreement between the parties.

The purpose of this Agreement is to set out the respective rights and obligations of the parties in connection with the Processing of Personal Data, in accordance with applicable Data Protection Laws, including Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and equivalent legislation.

This Agreement forms a fixed contractual schedule to the Services Agreement. The version executed by the parties shall remain binding for the duration of the Services Agreement unless amended in writing by authorised representatives of both parties.

1. Definitions

For the purposes of this Agreement, the terms "Personal Data", "Processing", "Data Subject", and "Personal Data Breach" shall have the meanings given to them under applicable Data Protection Laws.

"Data Protection Laws" means all applicable laws, regulations and legally binding requirements relating to the Processing of Personal Data under this Agreement, including, where applicable, the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, the UK Data Protection Act 2018, the Protection of Personal Information Act, 2013 (POPIA), the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), and any successor or substantially equivalent privacy legislation applicable to the Services provided under this Agreement 

"Services" means the security, monitoring, data protection, backup, recovery, and related services provided by CyberSentriq under the Services Agreement

2. Subject Matter and Duration

This Agreement governs the Processing of Personal Data by the Processor on behalf of the Controller in connection with the Services.

This Agreement shall remain in effect for the duration of the Services Agreement, and thereafter for so long as the Processor Processes Personal Data on behalf of the Controller.

This Agreement is intended to support the parties' compliance with applicable privacy and data protection legislation governing the Processing of Personal Data. Where applicable to the Services or the Controller's regulatory obligations, this Agreement may also support compliance with sector-specific regulatory requirements, including the European Union Digital Operational Resilience Act ("DORA"), the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), and the California Consumer Privacy Act ("CCPA/CPRA"). Nothing in this Agreement shall be interpreted as limiting or replacing any additional contractual obligations agreed between the parties to satisfy such regulations.

3. Nature and Purpose of Processing

The Processor shall Process Personal Data solely on behalf of the Controller and strictly in accordance with the Controller’s documented instructions.

Processing activities are limited to those necessary for the provision, maintenance, support, security, and improvement of the Services, including but not limited to cybersecurity monitoring, threat detection and response, data storage, backup, restoration, and system administration.

Under no circumstances shall the Processor Process Personal Data for its own purposes.

4. Categories of Personal Data

The Personal Data Processed may include, depending on the Services utilised by the Controller:

  • Identification and contact information, such as names, email addresses, and user identifiers
  • Technical and usage data, including IP addresses, device identifiers, system logs, and metadata
  • Security-related data, including threat intelligence indicators and system activity logs
  • Content data submitted to or generated within the Services, including emails, files, and backup data

The specific categories of Personal Data will depend on the nature and scope of the Services and the data provided by the Controller.

The exact categories of Personal Data processed will depend on the nature of the Controller’s systems and the Services in use.

5. Categories of Data Subjects

Personal Data Processed under this Agreement may relate to the following categories of Data Subjects:

  • Employees and contractors of the Controller
  • Customers and end-users of the Controller
  • Other individuals whose Personal Data is Processed through the Controller’s systems

6. Obligations of the Controller

The Controller shall be responsible for ensuring that:

  • The Processing of Personal Data complies with applicable Data Protection Laws,
  • A valid legal basis exists for the Processing,
  • Data Subjects are provided with appropriate privacy notices,
  • All instructions provided to the Processor are lawful and proportionate.

The Controller remains solely responsible for responding to requests from Data Subjects and for determining appropriate retention periods for Personal Data.

7. Obligations of the Processor

The Processor shall:

  • Process Personal Data only on documented instructions from the Controller,
  • Ensure that persons authorised to Process Personal Data are bound by confidentiality obligations,
  • Implement and maintain appropriate technical and organisational measures to protect Personal Data, considering the risks associated with the Processing,
  • Notify the Controller without undue delay upon becoming aware of a Personal Data Breach,
  • Provide reasonable assistance to the Controller in fulfilling its obligations relating to Data Subject rights, data protection impact assessments, and regulatory consultations,
  • Maintain records of Processing activities as required by applicable Data Protection Laws.

Where the Processor considers that an instruction from the Controller infringes applicable Data Protection Laws, it shall promptly inform the Controller.

7.1. California Privacy Requirements (CCPA/CPRA)

Where the California Consumer Privacy Act ("CCPA"), as amended by the California Privacy Rights Act ("CPRA"), applies to the Services, CyberSentriq shall Process Personal Information solely for the business purposes described in the applicable Services Agreement and this Agreement.

CyberSentriq shall not:

  • Sell or share Personal Information except where expressly instructed by the Controller or required by law; 
  • Retain, use or disclose Personal Information for any purpose other than providing the contracted Services; 
  • Combine Personal Information received from different customers except where it is permitted by applicable law. 

CyberSentriq shall implement reasonable security measures appropriate to the nature of the Personal Information processed and shall provide reasonable assistance to enable the Controller to respond to verified consumer requests where required.

7.2. HIPAA Processing

Where the Services involve the Processing of Protected Health Information ("PHI") on behalf of a Covered Entity or Business Associate as defined under HIPAA, the parties acknowledge that a separate Business Associate Agreement ("BAA") shall govern such Processing.

Where a BAA has been executed between the parties, the obligations contained within the BAA shall apply in respect of PHI and shall prevail over any conflicting provisions contained within this Agreement solely in relation to HIPAA-regulated information.

Nothing within this Agreement shall be interpreted as creating Business Associate obligations where no BAA has been executed.

7.3. Digital Operational Resilience Act (DORA)

Where the Controller is subject to Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector ("DORA"), CyberSentriq shall maintain appropriate technical and organisational measures supporting operational resilience throughout the provision of the Services.

Such measures include, where applicable:

  • Information security governance; 
  • Incident detection and response processes; 
  • Business continuity and disaster recovery capabilities; 
  • Security monitoring and logging;
  • Vulnerability management; 
  • Supplier and sub-processor oversight. 

Upon reasonable request and subject to confidentiality obligations, CyberSentriq shall provide information reasonably necessary to assist the Controller in satisfying its regulatory oversight and supplier assurance obligations under DORA.

8. Sub-processing

The Controller provides general written authorisation for the Processor to engage sub-processors for the provision of the Services.

The Processor shall ensure that:

  • Each sub-processor is bound by written contractual obligations that provide a level of data protection no less protective than those set out in this Agreement,
  • It remains fully liable to the Controller for the performance of each sub-processor,
  • The Controller is notified of any intended changes concerning the addition or replacement of sub-processors,
  • The Controller is given the opportunity to object to such changes on reasonable grounds.

A current list of authorised sub-processors may be made available to the Controller upon request and shall include, where applicable, the legal entity name, processing function and processing location. 

9. International Data Transfers

Where Personal Data is transferred outside the EEA, UK or other jurisdiction requiring transfer safeguards, the Processor shall ensure that an appropriate transfer mechanism is implemented, including Standard Contractual Clauses or another lawful transfer mechanism recognised under applicable Data Protection Laws. 

Information regarding applicable transfer mechanisms shall be made available to the Controller upon reasonable request. 

10. Security of Processing

The Processor shall implement appropriate technical and organisational measures designed to ensure a level of security appropriate to the risk, including measures relating to:

  • Access control and authentication
  • Encryption and data protection controls
  • System monitoring and logging
  • Incident detection and response
  • Backup and recovery procedures
  • Access management and multi-factor authentication for privileged accounts 
  • Encryption of Personal Data in transit and, where appropriate, at rest 
  • Vulnerability and patch management processes 
  • Periodic access reviews 
  • Backup integrity and recovery testing procedures

CyberSentriq shall maintain an Information Security Management System supported by documented security policies, risk management processes, employee security awareness programmes, vulnerability management, secure change management, incident response procedures and business continuity arrangements appropriate to the Services provided. Security controls shall be periodically reviewed and updated to address changes in technology, emerging threats and applicable regulatory obligations.

11. Personal Data Breach

In the event of a Personal Data Breach, the Processor shall notify the Controller without undue delay and, where reasonably practicable, within forty-eight (48) hours of becoming aware of the Personal Data Breach.

Where required by applicable Data Protection Laws or other applicable regulatory requirements, CyberSentriq shall provide reasonable information relating to the nature of the incident, the categories of information affected, the likely impact, containment measures implemented and planned remediation activities to enable the Controller to fulfil its own legal and regulatory notification obligations.

12. Data Subject Rights

Considering the nature of the Processing, the Processor shall assist the Controller, where reasonably possible, in responding to requests from Data Subjects to exercise their rights under applicable Data Protection Laws.

13. Audit and Compliance

The Controller may, at its own cost and no more than once in any twelve (12) month period (unless required by law or following a material Personal Data Breach), request information necessary to demonstrate the Processor’s compliance with this Agreement.

The Processor may satisfy such requests by providing:

  • Relevant certifications (including ISO 27001 or equivalent)
  • Independent audit reports (including SOC 2 or equivalent)
  • Security policies, summaries, or responses to reasonable questionnaires

On-site audits shall only be permitted where strictly necessary and shall be subject to reasonable prior notice, confidentiality obligations, and appropriate safeguards to protect the Processor’s confidential information and that of its other customers.

Where reasonably required to support applicable legal or regulatory obligations, CyberSentriq shall provide relevant documentation describing its information security, operational resilience and privacy controls, including independent audit reports, certifications, security policies and responses to reasonable due diligence questionnaires, subject to confidentiality obligations and the protection of CyberSentriq's confidential information.

14. Data Retention and Deletion

Upon termination or expiry of the Services, the Processor shall delete or return Personal Data in accordance with the terms of the Services Agreement, unless retention is required by applicable law.
Upon request and where technically feasible, the Controller shall be provided with a reasonable opportunity to export its Personal Data before deletion. Following termination of the Services, Personal Data shall be deleted, returned or anonymised in accordance with the Services Agreement and the Processor's documented retention procedures, unless retention is required by law.

15. Demonstration of Compliance

The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with this Agreement and applicable Data Protection Laws.

16. Liability

Each party shall be responsible for its own compliance with applicable Data Protection Laws.

The Processor shall be liable only where it has failed to comply with its obligations under this Agreement or has acted outside or contrary to the lawful instructions of the Controller, and in all cases subject to the limitations and exclusions of liability set out in the Services Agreement.

This clause shall be subject to review and alignment with the underlying Services Agreement.

17. Governing Law

This Agreement shall be governed by and construed in accordance with the law specified in the Services Agreement, being the jurisdiction of CyberSentriq’s principal place of business, unless otherwise agreed in writing between the parties

18. Information Security @ CyberSentriq

CyberSentriq operates a formal Information Security Management System (ISMS) to ensure that information assets are appropriately protected.

Information is recognised as a critical business asset and is safeguarded in accordance with the principles of:

  • Confidentiality – ensuring that information is accessible only to authorised individuals
  • Integrity – safeguarding the accuracy and completeness of information
  • Availability – ensuring that information is accessible when required

Responsibility for the implementation and maintenance of the ISMS is delegated to the Information Security and Compliance function.

19. Exceptions

Any exception to this Agreement must:

  • Be formally documented,
  • Be subject to risk assessment,
  • Be approved in accordance with CyberSentriq’s exception management process.

Each party shall reasonably cooperate with the other in responding to enquiries from competent supervisory authorities relating to the Processing of Personal Data under this Agreement. Such cooperation shall be limited to information reasonably necessary to demonstrate compliance with applicable contractual, legal and regulatory obligations and shall remain subject to confidentiality obligations, legal privilege and the protection of confidential business information.
----

Revision and Approval

Version

Revision Date

Summary of Change

Approved By

0.1

07 April 2026

Initial CyberSentriq Merged DPA

GRC Specialist

0.2

08 April 2026

Review and comments

VP of Information & Security

0.3

13 April 2026

Amendments and alignments made to draft.

GRC Specialist

1.0

14 April 2026

Final Review and Approval

GRC Specialist

1.1

05 June 2026

Policy Update and Amendments

GRC Specialist

1.2

15 June 2026

Explicit alignment to legislation

GRC Specialist

 

 

 

 

 

 

 

Effective Date and Review Date

Effective Date:                 Date of Execution 

Review Date:                    05 June 2026 

Next Review Date:          05 June 2027