Version 2.4 Effective: January 15, 2026 GDPR / CCPA / Global Framework

Data Processing Addendum

This Data Processing Addendum ("DPA") governs the processing of personal data by Aevum Zenth Conglomerate and its affiliated entities on behalf of client organizations under an applicable Master Services Agreement ("MSA") or Service Agreement.

1. Introduction & Scope

This DPA applies to all personal data processed by Aevum Zenth Conglomerate ("Processor") on behalf of the contracting organization ("Controller") in the course of providing the services described in the applicable Service Agreement. Where Aevum Zenth acts as a joint controller or independent controller for specific services, separate data protection agreements shall apply.

This addendum incorporates current requirements under the EU General Data Protection Regulation (GDPR), UK GDPR, CCPA/CPRA, LGPD, PIPL, and other applicable global data protection frameworks.

2. Definitions

Personal Data
Any information relating to an identified or identifiable natural person, as defined under applicable data protection laws.
Processing
Any operation performed on Personal Data, including collection, storage, modification, access, transmission, or deletion.
Controller
The client entity that determines the purposes and means of the Processing of Personal Data.
Processor
Aevum Zenth Conglomerate or any subsidiary processing Personal Data on behalf of the Controller.
Data Subject
The individual to whom the Personal Data relates.
Subprocessor
A third party engaged by Aevum Zenth to perform specific Processing activities under written instruction.

3. Roles & Processing Instructions

3.1 Controller Responsibilities

The Controller warrants that it has obtained all necessary consents, legal bases, and authorizations required to lawfully process and share Personal Data with Aevum Zenth. The Controller shall provide clear, documented Processing Instructions and promptly notify Aevum Zenth of any changes to applicable law or regulatory requirements.

3.2 Processor Obligations

Aevum Zenth shall:

  • Process Personal Data solely in accordance with documented instructions from the Controller.
  • Not disclose, transfer, or process Personal Data for unauthorized purposes.
  • Implement appropriate technical and organizational measures to ensure security.
  • Assist the Controller in fulfilling data subject requests and regulatory obligations.
  • Report any personal data breach to the Controller within twenty-four (24) hours of confirmation.

Processing Purpose Data Categories Legal Basis Retention Period
Service Delivery & Support Contact, Authentication, Usage Metadata Contract Performance / Legitimate Interest Duration of Service + 12 months
Compliance & Security Monitoring IP Addresses, Device IDs, Access Logs Legal Obligation / Legitimate Interest 24 months (anonymized thereafter)
Billing & Administrative Financial, Tax, Corporate Identity Contract Performance / Legal Obligation 7 years post-termination

4. Security Safeguards

Aevum Zenth maintains a comprehensive security program aligned with ISO 27001, SOC 2 Type II, NIST CSF, and industry best practices. Safeguards include:

  • Encryption: AES-256 at rest and TLS 1.3+ in transit.
  • Access Control: Role-based access control (RBAC), multi-factor authentication (MFA), and zero-trust architecture.
  • Monitoring & Logging: 24/7 SOC monitoring, immutable audit logs, and automated anomaly detection.
  • Vulnerability Management: Quarterly penetration testing, continuous patch management, and bug bounty program.
  • Physical Security: Biometric access, surveillance, and hardened data center environments across all Aevum Zenth facilities.

Full security documentation, including our Security Whitepaper and System Overview, is available upon request through the compliance portal or via the Data Protection Officer.

5. Subprocessors

Aevum Zenth may engage third-party subprocessors to perform specific functions (e.g., cloud infrastructure, payment processing, customer support). All subprocessors are bound by written data processing agreements that impose equivalent or greater data protection obligations.

A current list of approved subprocessors, including processing locations and purposes, is maintained at /compliance/subprocessors. Aevum Zenth will notify the Controller of material changes to the subprocessor list at least thirty (30) days prior to implementation. The Controller retains the right to object to the use of a specific subprocessor on reasonable legal grounds.

6. International Data Transfers

Personal Data may be processed or transferred across borders to support global service delivery. Where transfers occur to jurisdictions without an adequacy decision, Aevum Zenth relies on:

  • European Commission Standard Contractual Clauses (SCCs) (2021/914)
  • UK International Data Transfer Addendum (IDTA)
  • Applicable transfer impact assessments (TIAs) and supplementary technical measures

Transfer locations and legal safeguards are documented in the International Transfer Annex, incorporated by reference.

7. Data Subject Rights & Cooperation

Aevum Zenth shall assist the Controller in responding to data subject requests, including rights to access, rectification, erasure, restriction, portability, and objection. Requests shall be processed within statutory timeframes (typically 30 days). Aevum Zenth will not directly process data subject requests without the Controller's authorization unless required by applicable law.

8. Audits & Compliance Verification

The Controller may request compliance audits or third-party assessments once per calendar year, subject to reasonable notice, non-disclosure obligations, and minimal disruption to Aevum Zenth's operations. Aevum Zenth will promptly provide SOC 2 reports, ISO certifications, and audit findings upon written request.

9. Liability & Indemnification

Aevum Zenth shall be liable for breaches of its obligations under this DPA. Liability caps, exclusions, and indemnification provisions shall align with the governing Service Agreement, except where mandatory law provides otherwise. Neither party shall be liable for indirect, incidental, or consequential damages arising from data processing, to the extent permitted by applicable law.

10. Term & Termination

This DPA remains in effect for the duration of the Service Agreement and survives termination for purposes of data return, deletion, and ongoing statutory obligations. Upon termination or request, Aevum Zenth shall securely return or delete all Personal Data within thirty (30) days, certifying completion in writing, except where retention is required by law or contractual obligation.

11. DPO & Contact Information

Data Protection Office

Headquarters: Zenth Tower, Neo Geneva, Global Compliance Division

Email: dpo@aevumzenth.com

Secure Portal: /compliance/portal

Emergency Breach Hotline: Available 24/7 via the Security Operations Center

All communications regarding data processing, breach notification, or compliance inquiries should be directed to the DPO.

12. Execution & Acknowledgment

By signing below or executing the governing Service Agreement, both parties acknowledge that this DPA forms an integral and binding component of the contractual relationship. Electronic signatures hold equivalent legal validity under applicable e-signature statutes.