Data Processing

Data Processing

EffectiveJanuary 1, 2026UpdatedJanuary 1, 2026Version1.0
Section 01

Agreement Overview

### Purpose of This Data Processing Agreement

This Data Processing Agreement ("DPA" or "Agreement") establishes the terms and conditions under which CryptoMize ("Processor" or "we"), operating the Perception X2 platform, processes personal data on behalf of clients and partners ("Controller" or "you"). This DPA forms an integral part of any service agreement, subscription, or contract between the Controller and Processor that references or incorporates this Agreement.

The Perception X2 platform is an autonomous perception amplification engine designed for communications intelligence, narrative analysis, and reputation management. In delivering these services, the Processor may process personal data as directed by the Controller. This DPA ensures that all such processing is conducted in compliance with applicable data protection legislation, including but not limited to the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and equivalent regulations across all jurisdictions in which the parties operate.

**Key Commitments:**

- Processing of personal data exclusively in accordance with documented instructions from the Controller - Implementation of robust technical and organizational security measures - Assistance with data subject rights requests and regulatory compliance - Transparent sub-processing practices with advance notification - Prompt notification of any personal data breach - Secure return or deletion of data upon termination of services

This DPA applies to all processing activities undertaken by the Processor in connection with the services provided to the Controller. It supplements and does not replace any other contractual arrangements between the parties, except where expressly stated. Both parties acknowledge their respective obligations under applicable data protection laws and commit to fulfilling them with the highest standard of diligence and professionalism.

---

Section 02

Definitions

### Key Terms Used in This Agreement

For the purposes of this Data Processing Agreement, the following terms shall have the meanings set out below. These definitions apply throughout this DPA and are consistent with the terminology used in the General Data Protection Regulation (GDPR) and other applicable data protection legislation.

**Personal Data** means any information relating to an identified or identifiable natural person ("data subject") that is processed by the Processor on behalf of the Controller in connection with the services. This includes names, identification numbers, location data, online identifiers, and factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

**Processing** means any operation or set of operations performed on personal data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.

**Controller** means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. In the context of this DPA, the Controller is the client or partner engaging the Processor's services.

**Processor** means the natural or legal person, public authority, agency, or other body which processes personal data on behalf of the Controller. In the context of this DPA, the Processor is CryptoMize, operating the Perception X2 platform.

**Sub-Processor** means any third party engaged by the Processor to process personal data on behalf of the Controller. Sub-processors may include cloud infrastructure providers, analytics services, and other technology vendors integral to service delivery.

**Data Subject** means the identified or identifiable natural person to whom the personal data relates.

**Personal Data Breach** means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.

**Supervisory Authority** means an independent public authority established by an EU or EEA member state pursuant to Article 51 of the GDPR, or any equivalent regulatory body in other applicable jurisdictions.

---

Section 03

Scope of Processing

### What This Agreement Covers

This DPA governs the processing of personal data by the Processor when performing services on behalf of the Controller through the Perception X2 platform. The scope of this Agreement encompasses all personal data processed in connection with the delivery, operation, maintenance, and support of the platform's capabilities, including narrative engineering, content intelligence, reputation monitoring, crisis response, and analytics.

**Subject Matter of Processing:**

The Processor processes personal data solely for the purpose of providing the services described in the applicable service agreement between the parties. This includes processing data necessary to deliver communications intelligence, generate narrative analysis, monitor reputation across digital platforms, and provide related analytics and reporting capabilities.

**Duration of Processing:**

Processing under this DPA commences upon the effective date of the applicable service agreement and continues for the duration of that agreement. Processing ceases upon termination of the services, subject to the data retention provisions set forth in Section 15 of this DPA.

**Nature and Purpose of Processing:**

The Processor will perform the following processing operations as necessary to deliver the services:

| Processing Operation | Purpose | |----------------------|---------| | Collection | Gathering data from authorized sources as directed by the Controller | | Storage | Secure retention of data within encrypted infrastructure | | Analysis | AI-powered processing to generate insights and reports | | Transmission | Secure transfer of data between authorized systems and recipients | | Retrieval | Accessing stored data to fulfill service requests and generate outputs | | Erasure | Secure deletion of data in accordance with retention policies |

**Geographical Scope:**

Processing may occur across the Processor's global infrastructure, subject to the international data transfer provisions set forth in Section 14. The Processor maintains data processing operations in jurisdictions that provide adequate safeguards for personal data, and all transfers are conducted in compliance with applicable data protection legislation.

**Exclusions:**

This DPA does not apply to: (a) personal data that the Controller processes independently of the services; (b) data that does not constitute personal data under applicable law; or (c) processing activities that fall outside the scope of the services described in the applicable service agreement.

---

Section 04

Roles and Responsibilities

### Controller and Processor Obligations

Both parties acknowledge and agree to their respective roles and responsibilities under this Data Processing Agreement and applicable data protection legislation. Clear delineation of roles is essential to ensuring compliant processing and protecting the rights of data subjects.

**Controller Responsibilities:**

The Controller retains full responsibility for:

- Determining the purposes and legal bases for processing personal data through the services - Providing documented instructions to the Processor regarding the processing of personal data - Ensuring that a valid legal basis exists for all processing activities - Responding to data subject rights requests in a timely manner, with the Processor's assistance - Obtaining any necessary consents from data subjects prior to processing - Conducting data protection impact assessments where required by applicable law - Notifying the Processor of any changes to its processing instructions or requirements - Ensuring that the services are used in compliance with applicable data protection legislation

**Processor Obligations:**

The Processor agrees to:

- Process personal data only on documented instructions from the Controller - Ensure that personnel authorized to process personal data are bound by confidentiality obligations - Implement appropriate technical and organizational security measures as described in Section 12 - Engage sub-processors only in accordance with the provisions of Section 10 - Assist the Controller in fulfilling data subject rights requests as described in Section 11 - Notify the Controller without undue delay of any personal data breach as described in Section 13 - Delete or return all personal data to the Controller upon termination, subject to Section 15 - Make available all information necessary to demonstrate compliance and allow for audits as described in Section 17

**Joint Responsibilities:**

Both parties shall:

- Cooperate in good faith to ensure compliance with applicable data protection legislation - Maintain records of processing activities as required by applicable law - Respond promptly to inquiries from supervisory authorities regarding processing activities - Implement measures to protect the confidentiality, integrity, and availability of personal data

---

Section 05

Types of Personal Data Processed

### Categories of Data Processed

The types of personal data processed by the Processor depend on the specific services engaged by the Controller and the data provided or collected in the course of service delivery. The following categories represent the broad types of personal data that may be processed:

**Identity and Contact Data:**

| Data Type | Examples | Source | |-----------|----------|--------| | Full Name | First name, last name, professional title | Controller-provided, public sources | | Contact Information | Email address, phone number, mailing address | Controller-provided, public sources | | Professional Details | Job title, organization, professional affiliations | Controller-provided, public sources | | Authentication Data | Account credentials, API keys, access tokens | Controller-provided |

**Technical and Usage Data:**

| Data Type | Examples | Source | |-----------|----------|--------| | Device Information | Browser type, operating system, device identifiers | Automated collection | | Network Data | IP address, geolocation (country/region level), connection type | Automated collection | | Usage Patterns | Pages visited, features used, interaction metrics | Automated collection | | Platform Logs | API request logs, access logs, error logs | Automated collection |

**Content and Analysis Data:**

| Data Type | Examples | Source | |-----------|----------|--------| | Submitted Content | Text, documents, media uploaded for analysis | Controller-provided | | Generated Insights | Reports, analytics, sentiment analysis outputs | Processor-generated | | Monitoring Data | Media mentions, social media references, public content | Public sources, APIs |

**Communication Data:**

| Data Type | Examples | Source | |-----------|----------|--------| | Support Interactions | Tickets, correspondence, resolution records | Controller-initiated | | Account Communications | Notifications, preferences, settings | Controller-initiated |

The Processor does not intentionally process special categories of personal data (as defined under GDPR Article 9) unless explicitly instructed by the Controller and with appropriate safeguards in place. Any processing of special categories of data must be separately authorized in writing by the Controller prior to commencement of such processing.

---

Section 06

Categories of Data Subjects

### Whose Data Is Processed

The personal data processed by the Processor may relate to various categories of data subjects depending on the services engaged by the Controller. The Processor processes data on behalf of the Controller about the following categories of natural persons:

**Primary Data Subject Categories:**

| Category | Description | Typical Data Elements | |----------|-------------|----------------------| | Clients and Prospects | Individuals engaging with or being evaluated by the Controller's services | Names, contact details, professional information, communications | | Employees and Contractors | Personnel of the Controller or third-party organizations | Names, roles, professional activity, public communications | | Media Personnel | Journalists, editors, influencers, and content creators | Names, publications, professional profiles, public content | | Public Figures | Individuals with public presence across digital platforms | Public statements, media appearances, professional activity | | Stakeholders | Investors, partners, vendors, and other business contacts | Professional affiliations, public activity, communications |

**Data Subject Groups:**

- **End Users** -- Individuals who interact with digital platforms monitored or analyzed by the Processor's services - **Target Audiences** -- Groups defined by the Controller for monitoring, analysis, or engagement purposes - **Contact Lists** -- Individuals whose data is provided by the Controller for communications or outreach purposes - **Public Individuals** -- Persons whose data is collected from publicly available sources including social media, news, and public records

**Data Minimization:**

The Processor commits to processing only the minimum amount of personal data necessary to fulfill the services. The Processor shall not process personal data about data subjects beyond what is required to deliver the contracted services, and shall promptly notify the Controller if it determines that processing instructions would result in excessive or unnecessary data collection.

**Children's Data:**

The services are not directed at individuals under the age of 16. The Processor does not knowingly process personal data of children. If the Controller provides personal data relating to a minor, the Processor will take immediate steps to delete such data and notify the Controller.

---

Section 07

Purpose and Methods of Processing

### How and Why Data Is Processed

The Processor processes personal data exclusively for the purposes described in this section and in accordance with the Controller's documented instructions. Processing is conducted using a combination of automated systems and manual oversight to ensure accuracy, security, and compliance.

**Purposes of Processing:**

| Purpose | Description | Legal Basis | |---------|-------------|-------------| | Service Delivery | Providing the contracted Perception X2 services as specified in the service agreement | Contractual necessity | | Platform Operation | Maintaining, operating, and securing the platform infrastructure | Legitimate interest | | Analytics and Reporting | Generating insights, reports, and analytics for the Controller | Contractual necessity | | Security Monitoring | Detecting and preventing unauthorized access, fraud, and abuse | Legitimate interest, legal obligation | | Technical Support | Providing customer support and resolving technical issues | Contractual necessity | | Compliance | Meeting legal and regulatory obligations applicable to the Processor | Legal obligation |

**Methods of Processing:**

Processing is conducted through the following methods:

- **Automated Processing** -- AI-powered algorithms analyze data to generate insights, sentiment analysis, narrative mapping, and reputation assessments. Automated processing is subject to human oversight and review as described in the service agreement.

- **Semi-Automated Processing** -- Combination of automated analysis with manual review and validation by qualified personnel to ensure accuracy and quality of outputs.

- **Manual Processing** -- Limited manual processing occurs in the context of customer support, account management, and quality assurance activities.

- **Secure Storage** -- All personal data is stored on encrypted infrastructure using AES-256 encryption at rest and is accessible only through authenticated, role-based access controls.

- **Secure Transmission** -- Data in transit is protected using TLS 1.3 encryption. All API communications are authenticated and encrypted.

**Processing Limitations:**

The Processor shall not:

- Process personal data for purposes other than those specified in this DPA without prior written authorization from the Controller - Use personal data for the Processor's own purposes or for the benefit of third parties - Make decisions about data subjects using automated processing that produces legal or similarly significant effects without human oversight - Sell, rent, or commercially exploit personal data

---

Section 09

Processor Obligations

### Comprehensive Processor Commitments

The Processor accepts the following obligations in connection with the processing of personal data under this DPA. These obligations supplement and do not limit any other obligations imposed by applicable data protection legislation.

**Documented Instructions:**

The Processor shall process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to third countries or international organizations, unless required to do so by applicable law. In such cases, the Processor shall inform the Controller of the legal requirement before processing, unless prohibited from doing so by law.

**Confidentiality:**

The Processor shall ensure that all persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. The Processor shall ensure that access to personal data is limited to those personnel who require access to perform the services.

**Security Measures:**

The Processor shall implement and maintain appropriate technical and organizational measures as described in Section 12 of this DPA. These measures shall be regularly evaluated and updated to address evolving threats and vulnerabilities.

**Sub-Processor Management:**

The Processor shall not engage another processor without prior specific or general written authorization of the Controller. Where the Processor engages a sub-processor, the Processor shall impose the same data protection obligations as set out in this DPA through a binding written contract.

**Assistance to Controller:**

The Processor shall assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Controller's obligation to respond to data subject rights requests.

**Breach Notification:**

The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach, and shall provide sufficient information to enable the Controller to meet any obligations to report or inform data subjects of the breach.

**Data Protection Impact Assessment:**

The Processor shall provide reasonable assistance to the Controller with data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of processing and the information available to the Processor.

**Records of Processing:**

The Processor shall maintain records of all categories of processing activities carried out on behalf of the Controller, including the information required under GDPR Article 30(2).

---

Section 10

Sub-Processing

### Third-Party Processing Arrangements

The Processor engages third-party sub-processors to support the delivery of services. All sub-processing activities are governed by the provisions of this section to ensure that personal data receives an equivalent level of protection throughout the processing chain.

**General Authorization:**

The Controller provides general written authorization for the Processor to engage sub-processors, subject to the conditions set forth in this section. This authorization covers the sub-processors listed in the Processor's current sub-processor register, which is made available to the Controller upon request.

**Sub-Processor Register:**

| Sub-Processor Category | Purpose | Location | |------------------------|---------|----------| | Cloud Infrastructure Providers | Data hosting, storage, and compute services | Multiple regions | | Content Delivery Networks | Performance optimization and content distribution | Global | | Analytics Platforms | Platform analytics and usage monitoring | Regional | | Security Services | Threat detection, monitoring, and incident response | Regional | | Communication Services | Email delivery, notifications, and messaging | Regional |

**Notification of Changes:**

The Processor shall notify the Controller in writing at least thirty (30) days before engaging any new sub-processor or making material changes to existing sub-processing arrangements. The notification shall include:

- The identity and location of the proposed sub-processor - The nature of the processing to be carried out - The types of personal data to be processed - The categories of data subjects affected - The proposed date of commencement of processing

**Right to Object:**

The Controller shall have the right to object to the engagement of a new sub-processor within fifteen (15) days of receiving the Processor's notification. If the Controller objects on reasonable data protection grounds, the parties shall discuss the objection in good faith and seek a mutually acceptable resolution. If the parties cannot reach a resolution within a reasonable period, either party may terminate the affected services without penalty.

**Sub-Processor Obligations:**

The Processor shall ensure that all sub-processors are bound by written contracts that impose data protection obligations equivalent to those set out in this DPA, including obligations relating to:

- Processing only on documented instructions from the Processor - Implementation of appropriate security measures - Confidentiality of personnel - Assistance with data subject rights requests - Breach notification obligations - Data return and deletion upon termination

---

Section 11

Data Subject Rights

### Assisting Controllers with Data Subject Requests

The Processor shall provide reasonable assistance to the Controller in fulfilling data subject rights requests under applicable data protection legislation. The specific rights and the Processor's corresponding obligations are described below.

**Data Subject Rights Supported:**

| Right | Description | Processor Assistance | |-------|-------------|---------------------| | Right of Access | Data subjects may request access to their personal data | Provide data export and processing information | | Right to Rectification | Data subjects may request correction of inaccurate data | Update or correct data upon Controller instruction | | Right to Erasure | Data subjects may request deletion of their data | Delete or anonymize data upon Controller instruction | | Right to Restriction | Data subjects may request limitation of processing | Restrict processing as instructed by Controller | | Right to Data Portability | Data subjects may request data in a structured format | Export data in commonly used machine-readable format | | Right to Object | Data subjects may object to certain processing activities | Cease processing upon Controller instruction | | Rights re: Automated Decisions | Data subjects may contest automated decision-making | Provide information about automated processing logic |

**Request Handling Process:**

1. The Controller notifies the Processor of a data subject request, including the specific right being exercised and the data subject's identity 2. The Processor verifies the data subject's identity through the Controller's verification process 3. The Processor executes the requested action within the timeframe required by applicable law 4. The Processor notifies the Controller upon completion of the requested action

**Timeframe:**

The Processor shall respond to data subject request assistance requests from the Controller within five (5) business days and shall complete the requested action within thirty (30) days, unless a shorter timeframe is required by applicable law or the nature of the request necessitates urgent action.

**Limitations:**

The Processor's obligation to assist with data subject rights requests is subject to: (a) the Controller providing sufficient information to identify the data subject and the relevant data; (b) the request being technically feasible given the architecture of the services; and (c) the request not conflicting with applicable law or the Processor's own legal obligations.

---

Section 12

Data Security Measures

### Technical and Organizational Safeguards

The Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing, including the measures described in this section. These measures are regularly evaluated and updated to address evolving threats.

**Technical Measures:**

| Measure | Implementation | Standard | |---------|---------------|----------| | Encryption at Rest | AES-256 encryption for all stored personal data | Industry standard | | Encryption in Transit | TLS 1.3 for all data transmissions | Industry standard | | Access Control | Role-based access control with least privilege principle | Zero-trust architecture | | Authentication | Multi-factor authentication for all system access | NIST 800-63B | | Network Security | Firewalls, intrusion detection and prevention systems | Defense in depth | | Monitoring | 24/7 security monitoring and automated threat detection | Continuous monitoring | | Vulnerability Management | Regular assessments and penetration testing | OWASP guidelines | | Backup and Recovery | Encrypted backups with tested restoration procedures | Business continuity |

**Organizational Measures:**

| Measure | Implementation | |---------|---------------| | Personnel Security | Background checks for all personnel with data access | | Confidentiality Agreements | Binding confidentiality obligations for all personnel | | Security Training | Annual security awareness training for all staff | | Incident Response | Documented incident response procedures with defined roles | | Access Management | Regular access reviews and prompt revocation upon role change | | Change Management | Formal change control procedures for system modifications | | Physical Security | SOC 2 Type II certified data center facilities | | Vendor Management | Security assessments of all third-party service providers |

**Security Certification:**

The Processor maintains the following security certifications, which attest to the effectiveness of its security measures:

- SOC 2 Type II (annually audited) - ISO 27001 (annually audited)

**Security Review:**

The Processor shall conduct regular security assessments, including annual penetration testing and quarterly vulnerability scans, and shall make summary results available to the Controller upon request.

---

Section 13

Data Breach Notification

### Breach Detection, Reporting, and Response

The Processor shall maintain a comprehensive incident response program to detect, assess, and respond to personal data breaches. The following provisions govern the notification and response process.

**Detection and Assessment:**

The Processor shall implement monitoring systems designed to detect potential personal data breaches, including unauthorized access, data exfiltration, system compromise, and accidental data loss. Upon detection of a potential breach, the Processor shall immediately commence assessment to determine:

- The nature and scope of the breach - The categories and approximate number of data subjects affected - The categories and approximate number of personal data records affected - The likely consequences of the breach - The measures taken or proposed to address the breach

**Notification to Controller:**

The Processor shall notify the Controller of a personal data breach without undue delay and no later than forty-eight (48) hours after becoming aware of the breach. The notification shall include, to the extent known:

| Information Element | Description | |---------------------|-------------| | Nature of Breach | Description of the event, including categories and approximate number of data subjects and records affected | | Contact Details | Designated contact point for further information | | Consequences | Likely consequences of the breach | | Measures Taken | Steps taken or proposed to address the breach and mitigate adverse effects | | Timeline | Estimated timeline for further updates and resolution |

**Ongoing Communication:**

Following initial notification, the Processor shall:

- Provide regular updates to the Controller on the status of the investigation and remediation - Deliver a comprehensive post-incident report within thirty (30) days of the breach - Implement corrective measures to prevent recurrence and provide a summary of such measures

**Cooperation:**

The Processor shall cooperate fully with the Controller in responding to the breach, including assisting with:

- Notifications to supervisory authorities as required by applicable law - Notifications to affected data subjects where required - Investigation of the root cause of the breach - Implementation of remedial measures

**No Admission of Liability:**

Notification of a breach or participation in any investigation shall not be construed as an admission of liability by the Processor.

---

Section 14

International Data Transfers

### Cross-Border Data Transfer Safeguards

The Processor may transfer personal data to jurisdictions outside the country of collection in connection with the services. All international transfers are conducted in compliance with applicable data protection legislation and subject to the safeguards described in this section.

**Transfer Mechanisms:**

| Mechanism | Application | |-----------|-------------| | Standard Contractual Clauses (SCCs) | EU-approved contractual clauses for transfers outside the EEA | | Adequacy Decisions | Reliance on European Commission adequacy decisions where applicable | | Binding Corporate Rules | Where applicable within the Processor's corporate group | | Additional Safeguards | Supplementary technical measures including encryption and pseudonymization |

**Supplementary Measures:**

Where the legal framework of a recipient jurisdiction may not provide an essentially equivalent level of protection, the Processor implements supplementary technical measures, including:

- **End-to-end encryption** -- All personal data is encrypted in transit and at rest using AES-256 and TLS 1.3, ensuring that data remains encrypted even if accessed by unauthorized parties in the recipient jurisdiction - **Pseudonymization** -- Where technically feasible, personal data is pseudonymized before transfer to reduce identifiability - **Access controls** -- Strict role-based access controls limit access to personal data to authorized personnel only - **Data minimization** -- Only the minimum amount of personal data necessary for the specified purpose is transferred

**Transfer Impact Assessment:**

The Processor conducts transfer impact assessments to evaluate the legal framework in recipient jurisdictions and to determine whether supplementary measures are necessary to ensure an essentially equivalent level of protection.

**Controller Obligations:**

The Controller shall:

- Inform the Processor of any restrictions on international data transfers applicable to the personal data being processed - Provide instructions regarding permitted jurisdictions for data processing - Notify the Processor of any changes to the Controller's requirements for international data transfers

---

Section 15

Data Retention and Deletion

### Retention Periods and Deletion Procedures

The Processor shall retain personal data only for as long as necessary to fulfill the purposes for which it was processed, or as required by applicable law. Upon expiry of the retention period or termination of the services, personal data shall be securely deleted or returned to the Controller as described below.

**Retention Schedule:**

| Data Category | Retention Period | Basis | |---------------|-----------------|-------| | Service Delivery Data | Duration of service agreement + 30 days | Contractual necessity | | Account and Configuration Data | Duration of service agreement + 30 days | Contractual necessity | | Transaction and Billing Data | 7 years from transaction date | Legal obligation | | Support and Communication Records | 3 years from last interaction | Contractual necessity | | Security and Audit Logs | 2 years from creation | Legal obligation, legitimate interest | | Analytics and Usage Data | 12 months from collection | Legitimate interest | | Backup Data | 90 days from creation | Disaster recovery |

**Deletion Procedures:**

Upon expiration of the retention period or upon the Controller's request, the Processor shall:

1. Identify all personal data subject to deletion 2. Execute secure deletion using industry-standard methods that render data irrecoverable 3. Verify deletion through automated confirmation systems 4. Provide written confirmation of deletion to the Controller within thirty (30) days

**Deletion Methods:**

| Method | Application | |--------|-------------| | Cryptographic Erasure | Destruction of encryption keys rendering encrypted data unreadable | | Secure Overwrite | Multiple-pass overwrite meeting NIST 800-88 guidelines | | Physical Destruction | Physical destruction of storage media where applicable |

**Exceptions:**

The Processor may retain personal data beyond the stated retention periods where: (a) required by applicable law; (b) necessary for the establishment, exercise, or defense of legal claims; or (c) necessary for the performance of a contract with the Controller. In such cases, the Processor shall notify the Controller and limit retention to the minimum extent necessary.

**Controller Data Export:**

Prior to deletion, the Processor shall make personal data available to the Controller in a commonly used machine-readable format upon request.

---

Section 16

Confidentiality

### Protecting Confidential Information

Both parties acknowledge that in the course of performing their obligations under this DPA, they may have access to confidential information belonging to the other party or to data subjects. The following provisions govern the treatment of such confidential information.

**Confidential Information Defined:**

Confidential information under this DPA includes:

- Personal data processed under this DPA - The terms and conditions of this DPA and the service agreement - Technical information about the Processor's systems and security measures - Business information disclosed by either party in connection with the services - Any information marked as confidential or that a reasonable person would understand to be confidential

**Confidentiality Obligations:**

Each party agrees to:

- Hold all confidential information in strict confidence - Not disclose confidential information to any third party without prior written consent, except as permitted under this DPA - Use confidential information solely for the purposes of performing obligations under this DPA - Protect confidential information using the same degree of care used to protect its own confidential information, but not less than reasonable care

**Permitted Disclosures:**

Confidential information may be disclosed to:

- Personnel who have a need to know and are bound by confidentiality obligations - Sub-processors engaged in accordance with Section 10, subject to equivalent confidentiality obligations - Professional advisors (legal, accounting, audit) subject to professional duty of confidentiality - Supervisory authorities or courts where required by applicable law, with prior notice to the other party where permitted

**Duration:**

Confidentiality obligations under this section shall survive termination of this DPA for a period of five (5) years, or for so long as the relevant information remains confidential, whichever is longer.

---

Section 17

Audit Rights

### Demonstrating Compliance

The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations set out in this DPA and applicable data protection legislation. Audit rights are a critical component of the Processor's accountability framework.

**Right to Audit:**

The Controller shall have the right to conduct audits of the Processor's compliance with this DPA, subject to the following conditions:

| Condition | Detail | |-----------|--------| | Notice | Minimum thirty (30) days written notice before commencing an audit | | Frequency | No more than one audit per calendar year, unless required by a supervisory authority | | Scope | Limited to the processing activities covered by this DPA | | Duration | Audits shall be completed within a reasonable timeframe, not to exceed ten (10) business days | | Disruption | Audits shall be conducted in a manner that minimizes disruption to the Processor's operations |

**Types of Assurance:**

The Processor may satisfy audit requests through one or more of the following mechanisms:

- **Independent Third-Party Audit Reports** -- SOC 2 Type II reports, ISO 27001 certification, and other relevant audit reports made available to the Controller upon request - **On-Site Audits** -- Physical inspections of the Processor's facilities and systems, subject to reasonable scheduling and security requirements - **Remote Audits** -- Remote inspections of systems, controls, and documentation, subject to appropriate security protocols - **Questionnaires and Assessments** -- Completion of security and compliance questionnaires by the Processor

**Cooperation:**

The Processor shall cooperate fully with audits conducted by the Controller or its authorized representatives, including providing access to relevant systems, personnel, documentation, and records.

**Costs:**

Audits conducted at the request of the Controller shall be at the Controller's expense, unless the audit reveals material non-compliance by the Processor, in which case the Processor shall bear the reasonable costs of the audit.

**Confidentiality:**

Auditors shall be bound by confidentiality obligations and shall not access personal data beyond what is necessary for the audit.

---

Section 18

Liability and Indemnification

### Allocation of Liability

The parties agree to the following provisions regarding liability and indemnification in connection with this DPA. These provisions supplement, and do not limit, any liability provisions in the applicable service agreement.

**Processor Liability:**

The Processor shall be liable for:

- Damage caused by processing not in compliance with applicable data protection legislation to the extent attributable to the Processor's failure to fulfill its obligations under this DPA - Damage caused by the Processor's act or omission where it has not complied with obligations specifically directed by the Processor of the Controller's processing instructions - Any processing carried out by the Processor outside of or contrary to the Controller's lawful instructions

**Controller Liability:**

The Controller shall be liable for:

- Damage caused by processing not in compliance with applicable data protection legislation to the extent attributable to the Controller's failure to fulfill its obligations under this DPA - Damage caused by processing instructions that are unlawful, incomplete, or inaccurate - Failure to obtain valid legal bases for processing or to fulfill data subject rights obligations

**Indemnification:**

Each party ("Indemnifying Party") agrees to indemnify, defend, and hold harmless the other party ("Indemnified Party") from and against any claims, damages, losses, liabilities, and expenses (including reasonable attorneys' fees) arising from:

- The Indemnifying Party's breach of this DPA - The Indemnifying Party's violation of applicable data protection legislation - Any processing activities conducted outside the scope of this DPA by the Indemnifying Party

**Limitation of Liability:**

Each party's total aggregate liability under this DPA shall not exceed the total fees paid or payable under the applicable service agreement in the twelve (12) months preceding the event giving rise to the liability. Neither party shall be liable for any indirect, incidental, special, consequential, or punitive damages, except where prohibited by applicable law.

**Joint and Several Liability:**

Where both parties are jointly responsible for processing that causes damage, each party shall be jointly and severally liable for the full amount of the damage, without prejudice to the right of each party to seek recourse from the other in accordance with their respective liabilities.

---

Section 19

Term and Termination

### Duration and Termination of This Agreement

This Data Processing Agreement commences on the effective date of the applicable service agreement and continues in effect for the duration of that service agreement, unless terminated earlier in accordance with the provisions of this section.

**Commencement:**

This DPA takes effect upon the earlier of: (a) the date of execution by both parties; or (b) the date on which the Processor first processes personal data on behalf of the Controller under the applicable service agreement.

**Termination:**

This DPA shall terminate automatically upon the termination or expiration of the applicable service agreement. Either party may terminate this DPA earlier in the event of:

- Material breach by the other party that remains uncured for thirty (30) days after written notice - Insolvency, bankruptcy, or similar proceedings affecting the other party - Suspension or cessation of the Processor's services

**Effects of Termination:**

Upon termination of this DPA:

1. The Processor shall cease all processing of personal data on behalf of the Controller 2. The Controller shall provide instructions regarding the return or deletion of personal data 3. The Processor shall, at the Controller's choice, return all personal data in a commonly used machine-readable format or securely delete all personal data within thirty (30) days 4. The Processor shall provide written confirmation of deletion upon completion 5. All confidentiality, liability, and audit rights obligations shall survive termination

**Retention Following Termination:**

The Processor may retain personal data to the extent required by applicable law or for the establishment, exercise, or defense of legal claims. In such cases, the Processor shall: (a) notify the Controller of the retained data and the legal basis for retention; (b) limit retention to the minimum extent necessary; and (c) securely delete the data as soon as the retention requirement expires.

**Transition Assistance:**

The Processor shall provide reasonable transition assistance to the Controller to facilitate the migration of data to a successor service provider, subject to the terms of the applicable service agreement.

---

Section 20

Contact Information

### Reaching Our Data Protection Team

For questions, concerns, or requests related to this Data Processing Agreement, the Processor's data protection practices, or to exercise any rights under this DPA, please contact the appropriate team below.

**Data Protection Officer (DPO):**

| Detail | Information | |--------|-------------| | Email | dpo@perception.ac | | Subject Line | DPO Inquiry -- [Brief Description] | | Response Time | Within 5 business days |

**General Data Processing Inquiries:**

| Detail | Information | |--------|-------------| | Email | privacy@perception.ac | | Subject Line | DPA Inquiry -- [Brief Description] | | Response Time | Within 5 business days |

**Data Subject Requests:**

| Detail | Information | |--------|-------------| | Email | privacy@perception.ac | | Subject Line | Data Subject Request -- [Type of Right] | | Response Time | Within 30 days (GDPR) / 45 days (CCPA) |

**Security and Breach Reporting:**

| Detail | Information | |--------|-------------| | Email | security@perception.ac | | Subject Line | Security Incident -- [Brief Description] | | Response Time | Within 24 hours |

**Legal and Compliance:**

| Detail | Information | |--------|-------------| | Email | legal@perception.ac | | Subject Line | Legal Inquiry -- [Brief Description] | | Response Time | Within 5 business days |

**Supervisory Authority Complaints:**

If you are not satisfied with our response to your data protection inquiry, you have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction. The Processor will cooperate fully with any supervisory authority investigation.

---

### Related Legal Documents

- [Terms of Service](/legal/terms) -- Platform usage terms and conditions - [Privacy Policy](/legal/privacy) -- How we collect, use, and protect your data - [Compliance](/legal/compliance) -- Regulatory compliance and certifications - [Security](/legal/security) -- Our security architecture and practices - [Cookie Policy](/legal/cookies) -- How we use cookies and tracking technologies

---

**CryptoMize** | Perception X2 Platform Global operations across multiple continents 15+ years of operational excellence | 300+ elite clients | Zero security incidents

15+ Years
300+ Clients
50+ Platforms
99.9999% Uptime
Zero Incidents