HomeLegal → Data Processing Agreement

Data Processing Agreement

Effective Date: January 15, 2026
Version: 3.2.1
Jurisdiction: Global / EU / US

P Preamble & Parties

This Data Processing Agreement (the "Agreement") is entered into by and between Aevum Zenth Conglomerate, a multinational corporate entity with its principal place of business at Zenth Tower, Neo Geneva (hereinafter referred to as the "Data Controller" or "Controller"), and the entity listed on the executed counterpart signature page (hereinafter referred to as the "Data Processor" or "Processor").

This Agreement governs the processing of personal data carried out by the Processor on behalf of the Controller in accordance with applicable data protection legislation, including but not limited to the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other relevant global privacy frameworks.

1 Definitions & Interpretation

For the purposes of this Agreement, the following terms shall have the meanings set forth below:

  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Processing" means any operation performed on Personal Data, including collection, storage, use, alteration, disclosure, or deletion.
  • "Data Subject" means the individual to whom the Personal Data relates.
  • "Supplementary Agreement" refers to the primary commercial contract between the parties that incorporates this DPA by reference.

Capitalized terms not defined herein shall retain the definitions assigned to them in the Supplementary Agreement.

2 Scope & Purpose of Processing

The Processor shall process Personal Data strictly in accordance with the documented instructions of the Controller, as detailed in the attached Processing Schedule, unless required to do so by applicable law. Processing activities are limited to:

  1. Provision of cloud infrastructure and enterprise software services
  2. Automated data analytics and AI model training (pseudonymized where applicable)
  3. Customer relationship management and support ticketing
  4. Financial reconciliation and payroll processing

Any processing outside the scope defined herein requires prior written authorization from the Controller.

3 Roles & Responsibilities

The parties acknowledge their respective roles and obligations under applicable data protection law:

Controller Responsibilities:

The Controller warrants that it has obtained all necessary consents and lawful bases for collecting and transferring Personal Data to the Processor. The Controller shall provide accurate documentation regarding processing purposes, categories of data, and retention periods.

Processor Responsibilities:

The Processor shall implement appropriate technical and organizational measures, process data only on documented instructions, assist the Controller with compliance obligations, and promptly notify the Controller of any suspected breaches.

\n

4 Data Subject Rights

The Processor shall assist the Controller in fulfilling its obligations to respond to Data Subject requests, including but not limited to:

  • Right of access and portability
  • Right to rectification and erasure
  • Right to restrict or object to processing
  • Right to withdraw consent

Upon receipt of a request from a Data Subject or the Controller, the Processor shall take reasonable steps to verify the identity of the requester and respond within the statutory timeframe (typically thirty days). The Processor shall not charge the Controller or Data Subject for reasonable assistance costs unless otherwise agreed.

5 Security Measures

The Processor shall implement and maintain industry-standard technical and organizational safeguards commensurate with the risk level of the processing activities. Minimum baseline controls include:

  • End-to-end encryption (AES-256 at rest, TLS 1.3+ in transit)
  • Role-based access control (RBAC) and multi-factor authentication (MFA)
  • Continuous vulnerability scanning and penetration testing
  • Immutable audit logging with tamper-evident storage
  • Employee data protection training and background verification

Full technical specifications are maintained in Aevum Zenth's publicly available Security Whitepaper and may be requested under NDA.

6 Sub-processors & Third Parties

The Processor may engage third-party sub-processors to perform specific functions, provided that:

  1. Written prior notice is provided to the Controller at least thirty (30) days before onboarding
  2. Sub-processors are bound by data protection obligations at least as protective as this Agreement
  3. The Processor retains full liability for the acts and omissions of its sub-processors
  4. The Controller retains the right to object to new sub-processors based on documented risk assessment

An updated list of approved sub-processors is maintained in the Processing Schedule and updated quarterly.

7 International Data Transfers

Where Personal Data is transferred outside the European Economic Area (EEA), United Kingdom, or other regulated jurisdictions, the Processor shall ensure adequate safeguards are in place, including:

  • Reliance on European Commission Adequacy Decisions where applicable
  • Execution of Standard Contractual Clauses (SCCs) adopted under Commission Implementing Decision (EU) 2021/914
  • Conduct of Transfer Impact Assessments (TIAs) to evaluate destination country legal frameworks
  • Implementation of supplementary technical measures (e.g., pseudonymization, encryption key retention within controller jurisdiction)

8 Audit & Compliance

Upon reasonable notice (minimum 14 business days), the Controller or its independent third-party auditor shall have the right to audit the Processor's compliance with this Agreement. Audits shall be conducted during normal business hours, in a manner that minimizes disruption to operations, and subject to confidentiality obligations.

The Processor shall maintain current certifications (e.g., ISO 27001, SOC 2 Type II, GDPR compliance reports) and provide updated documentation annually or upon material change to security posture.

9 Data Breach Protocol

In the event of a confirmed or suspected Personal Data breach, the Processor shall:

  1. Notify the Controller without undue delay, and in any case within seventy-two (72) hours of becoming aware of the incident
  2. Provide immediate details regarding the nature of the breach, categories of data affected, approximate number of records, and likely consequences
  3. Implement immediate containment measures to prevent further unauthorized access
  4. Cooperate fully with the Controller's investigation and regulatory notification obligations
  5. Provide a post-incident forensic report within fifteen (15) business days

10 Term & Termination

This Agreement shall remain in effect for the duration of the Supplementary Agreement and survive termination until all processing obligations are fully discharged. Upon termination or expiration, the Processor shall, at the Controller's election:

  • Return all Personal Data in a structured, commonly used, and machine-readable format
  • Permanently delete or securely destroy all copies of Personal Data within thirty (30) days, except where retention is required by applicable law
  • Provide a written certificate of destruction signed by an authorized officer

11 Governing Law & Dispute Resolution

This Agreement shall be governed by and construed in accordance with the laws of Switzerland, without regard to its conflict of law principles. Any disputes arising under this Agreement that cannot be resolved through good-faith negotiation within thirty (30) days shall be submitted to binding arbitration in Geneva under the Rules of Arbitration of the Swiss Rules of International Arbitration. The language of arbitration shall be English.

12 Data Protection Officer & Contact

For inquiries, compliance requests, or breach notifications related to this Agreement, please contact Aevum Zenth's Global Data Protection Office:

Global DPO Office
Aevum Zenth Conglomerate
Zenth Tower, Level 42
Neo Geneva, 1202, Switzerland

Email: dpo@aevumzenth.global
Secure Portal: https://compliance.aevumzenth.global/dpo-request
Phone: +41 22 000 ZENTH

All communications regarding Personal Data processing must reference the applicable contract ID and processing schedule version.