Data Processing Addendum
This Data Processing Addendum ("DPA") governs the processing of personal data by Aevum Zenth Conglomerate and its affiliated entities on behalf of client organizations under an applicable Master Services Agreement ("MSA") or Service Agreement.
1. Introduction & Scope
This DPA applies to all personal data processed by Aevum Zenth Conglomerate ("Processor") on behalf of the contracting organization ("Controller") in the course of providing the services described in the applicable Service Agreement. Where Aevum Zenth acts as a joint controller or independent controller for specific services, separate data protection agreements shall apply.
This addendum incorporates current requirements under the EU General Data Protection Regulation (GDPR), UK GDPR, CCPA/CPRA, LGPD, PIPL, and other applicable global data protection frameworks.
2. Definitions
- Personal Data
- Any information relating to an identified or identifiable natural person, as defined under applicable data protection laws.
- Processing
- Any operation performed on Personal Data, including collection, storage, modification, access, transmission, or deletion.
- Controller
- The client entity that determines the purposes and means of the Processing of Personal Data.
- Processor
- Aevum Zenth Conglomerate or any subsidiary processing Personal Data on behalf of the Controller.
- Data Subject
- The individual to whom the Personal Data relates.
- Subprocessor
- A third party engaged by Aevum Zenth to perform specific Processing activities under written instruction.
3. Roles & Processing Instructions
3.1 Controller Responsibilities
The Controller warrants that it has obtained all necessary consents, legal bases, and authorizations required to lawfully process and share Personal Data with Aevum Zenth. The Controller shall provide clear, documented Processing Instructions and promptly notify Aevum Zenth of any changes to applicable law or regulatory requirements.
3.2 Processor Obligations
Aevum Zenth shall:
- Process Personal Data solely in accordance with documented instructions from the Controller.
- Not disclose, transfer, or process Personal Data for unauthorized purposes.
- Implement appropriate technical and organizational measures to ensure security.
- Assist the Controller in fulfilling data subject requests and regulatory obligations.
- Report any personal data breach to the Controller within twenty-four (24) hours of confirmation.
| Processing Purpose | Data Categories | Legal Basis | Retention Period |
|---|---|---|---|
| Service Delivery & Support | Contact, Authentication, Usage Metadata | Contract Performance / Legitimate Interest | Duration of Service + 12 months |
| Compliance & Security Monitoring | IP Addresses, Device IDs, Access Logs | Legal Obligation / Legitimate Interest | 24 months (anonymized thereafter) |
| Billing & Administrative | Financial, Tax, Corporate Identity | Contract Performance / Legal Obligation | 7 years post-termination |
4. Security Safeguards
Aevum Zenth maintains a comprehensive security program aligned with ISO 27001, SOC 2 Type II, NIST CSF, and industry best practices. Safeguards include:
- Encryption: AES-256 at rest and TLS 1.3+ in transit.
- Access Control: Role-based access control (RBAC), multi-factor authentication (MFA), and zero-trust architecture.
- Monitoring & Logging: 24/7 SOC monitoring, immutable audit logs, and automated anomaly detection.
- Vulnerability Management: Quarterly penetration testing, continuous patch management, and bug bounty program.
- Physical Security: Biometric access, surveillance, and hardened data center environments across all Aevum Zenth facilities.
Full security documentation, including our Security Whitepaper and System Overview, is available upon request through the compliance portal or via the Data Protection Officer.
5. Subprocessors
Aevum Zenth may engage third-party subprocessors to perform specific functions (e.g., cloud infrastructure, payment processing, customer support). All subprocessors are bound by written data processing agreements that impose equivalent or greater data protection obligations.
A current list of approved subprocessors, including processing locations and purposes, is maintained at /compliance/subprocessors. Aevum Zenth will notify the Controller of material changes to the subprocessor list at least thirty (30) days prior to implementation. The Controller retains the right to object to the use of a specific subprocessor on reasonable legal grounds.
6. International Data Transfers
Personal Data may be processed or transferred across borders to support global service delivery. Where transfers occur to jurisdictions without an adequacy decision, Aevum Zenth relies on:
- European Commission Standard Contractual Clauses (SCCs) (2021/914)
- UK International Data Transfer Addendum (IDTA)
- Applicable transfer impact assessments (TIAs) and supplementary technical measures
Transfer locations and legal safeguards are documented in the International Transfer Annex, incorporated by reference.
7. Data Subject Rights & Cooperation
Aevum Zenth shall assist the Controller in responding to data subject requests, including rights to access, rectification, erasure, restriction, portability, and objection. Requests shall be processed within statutory timeframes (typically 30 days). Aevum Zenth will not directly process data subject requests without the Controller's authorization unless required by applicable law.
8. Audits & Compliance Verification
The Controller may request compliance audits or third-party assessments once per calendar year, subject to reasonable notice, non-disclosure obligations, and minimal disruption to Aevum Zenth's operations. Aevum Zenth will promptly provide SOC 2 reports, ISO certifications, and audit findings upon written request.
9. Liability & Indemnification
Aevum Zenth shall be liable for breaches of its obligations under this DPA. Liability caps, exclusions, and indemnification provisions shall align with the governing Service Agreement, except where mandatory law provides otherwise. Neither party shall be liable for indirect, incidental, or consequential damages arising from data processing, to the extent permitted by applicable law.
10. Term & Termination
This DPA remains in effect for the duration of the Service Agreement and survives termination for purposes of data return, deletion, and ongoing statutory obligations. Upon termination or request, Aevum Zenth shall securely return or delete all Personal Data within thirty (30) days, certifying completion in writing, except where retention is required by law or contractual obligation.
11. DPO & Contact Information
Data Protection Office
Headquarters: Zenth Tower, Neo Geneva, Global Compliance Division
Email: dpo@aevumzenth.com
Secure Portal: /compliance/portal
Emergency Breach Hotline: Available 24/7 via the Security Operations Center
All communications regarding data processing, breach notification, or compliance inquiries should be directed to the DPO.
12. Execution & Acknowledgment
By signing below or executing the governing Service Agreement, both parties acknowledge that this DPA forms an integral and binding component of the contractual relationship. Electronic signatures hold equivalent legal validity under applicable e-signature statutes.