Data Processing Addendum.Data Processing Addendum.
The terms on which CryptoMize processes Personal Data on behalf of the customer, in compliance with GDPR and analogous data-protection frameworks.
Template — Not Legal Advice
This is a template legal document. The Sovereignty Infinium platform is operated by CryptoMize. The final version of this document, including any jurisdiction-specific adaptations, is provided in your engagement documentation. Use of the website is governed by your engagement terms.
Table of Contents
- 1.Purpose
- 2.Definitions
- 3.Scope and Roles
- 4.Processing Details
- 5.Processor Obligations
- 6.Sub-Processors
- 7.Security Measures
- 8.Audit Rights
- 9.International Data Transfers
- 10.Breach Notification
- 11.Data Subject Rights
- 12.Return and Deletion
- 13.Liability
- 14.General Provisions
- 15.Signatures
Purpose
This Data Processing Addendum supplements the engagement terms between CryptoMize, the operator of the Sovereignty Infinium Intelligence Platform ("Processor", "we", "us"), and the customer identified in the engagement terms ("Controller", "you"), and sets out the terms on which the Processor will process Personal Data on behalf of the Controller in connection with the Services. This DPA is intended to reflect the requirements of the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR") and analogous data-protection frameworks.
In the event of any conflict between this DPA and the engagement terms, this DPA will control with respect to the processing of Personal Data.
Definitions
Capitalized terms not otherwise defined in this DPA have the meanings given in the engagement terms or, where applicable, in GDPR or analogous law. In this DPA:
- Controller: the entity that, alone or jointly with others, determines the purposes and means of the processing of Personal Data.
- Processor: the entity that processes Personal Data on behalf of the Controller.
- Personal Data: any information relating to an identified or identifiable natural person that is processed by the Processor on behalf of the Controller under the engagement terms.
- Processing: has the meaning given in GDPR (or analogous law) and includes any operation or set of operations performed on Personal Data.
- Sub-processor: any third party engaged by the Processor to process Personal Data on behalf of the Controller.
- Data Subject: an identified or identifiable natural person to whom Personal Data relates.
- Supervisory Authority: an independent public authority established under GDPR or analogous law.
- Security Incident: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
Scope and Roles
The Processor will process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data, unless required to do so by applicable law. The Controller appoints the Processor as a Processor of Personal Data, and the Processor accepts this appointment, on the terms of this DPA.
Where the Processor processes Personal Data for its own purposes (for example, to maintain the security of the Platform, to produce aggregated analytics, or to comply with legal obligations), the Processor acts as a Controller with respect to such processing and will comply with applicable law.
Processing Details
The parties acknowledge that the details of the processing are as follows:
The Controller is responsible for the accuracy, quality, and lawfulness of the Personal Data and the means by which the Controller acquired the Personal Data.
Processor Obligations
The Processor will:
- Process Personal Data only on documented instructions from the Controller, including with regard to transfers, unless required to do so by applicable law, in which case the Processor will inform the Controller of that legal requirement before processing.
- Ensure that persons authorized to process Personal Data are subject to appropriate confidentiality obligations.
- Implement appropriate technical and organizational measures as further described in Section 7.
- Engage Sub-processors only in accordance with Section 6.
- Assist the Controller, by appropriate technical and organizational measures, in fulfilling the Controller's obligations to respond to requests from Data Subjects exercising their rights under Section 11.
- Notify the Controller of a Security Incident in accordance with Section 10.
- Assist the Controller in ensuring compliance with the Controller's obligations relating to security of processing, breach notification, data protection impact assessments, and prior consultation with Supervisory Authorities.
- At the end of the provision of the Services, return or delete the Personal Data in accordance with Section 12.
- Make available to the Controller all information necessary to demonstrate compliance with this DPA and allow audits in accordance with Section 8.
Sub-Processors
General Authorization. The Controller provides a general authorization for the Processor to engage Sub-processors. The Processor maintains a list of Sub-processors at a URL provided in the engagement documentation, which the Processor will update from time to time.
Notification of Changes. The Processor will give the Controller at least thirty (30) days' prior notice (by email or through the Platform) of any addition or replacement of a Sub-processor. The Controller may object to a new Sub-processor on reasonable, documented data-protection grounds by notifying the Processor in writing within the notice period. The parties will work in good faith to resolve the objection. If the objection is not resolved, the Controller may terminate the affected Services.
Sub-processor Obligations. The Processor will enter into a written contract with each Sub-processor that imposes data-protection obligations no less protective than those set out in this DPA, including appropriate technical and organizational measures. The Processor remains fully liable to the Controller for the performance of the Sub-processor's obligations.
Current Sub-Processors. The list of Sub-processors in effect at the commencement of the engagement is set out in the engagement documentation and is available on request from privacy@sovereignty.co.in.
Security Measures
The Processor will implement and maintain technical and organizational measures appropriate to the nature, scope, context, and purposes of the processing, and the risks to Data Subjects. These measures include, as appropriate:
7.1 Technical Measures
- Encryption in transit using TLS 1.3 and mutual TLS (mTLS).
- Encryption at rest using AES-256-GCM (or equivalent).
- Use of FIPS 140-3 validated cryptographic modules where operationally feasible.
- Key management with hardware-backed or managed key custody.
- Role-based access control (RBAC), least-privilege principles, and segregation of duties.
- Multi-factor authentication (MFA) for administrative access.
- Network segmentation, Web Application Firewalls (WAF), and intrusion detection / prevention systems.
- Centralized logging, anomaly detection, and continuous security monitoring.
- Vulnerability management, regular patching, and periodic third-party penetration testing.
- Secure software-development practices.
7.2 Organizational Measures
- Information security policies, standards, and procedures aligned with ISO 27001 and SOC 2 Type II.
- Background checks for personnel with access to Personal Data, where lawfully permitted.
- Security awareness and data-protection training for personnel.
- Confidentiality obligations in employment and contractor agreements.
- Incident response and breach-management procedures.
- Business continuity and disaster recovery planning, with defined RTO and RPO.
- Vendor risk management for Sub-processors.
- Regular internal and external audits of security controls.
The Processor may update these measures from time to time, provided that the level of protection is not materially decreased.
Audit Rights
Right to Audit. The Processor will make available to the Controller, on request, all information necessary to demonstrate compliance with this DPA. The Controller (or an independent auditor mutually agreed by the parties) may audit the Processor's compliance with this DPA, subject to the following conditions:
- The audit will be conducted during normal business hours, with reasonable prior notice (at least thirty (30) days, except in the case of a Security Incident or regulatory investigation).
- The audit will be conducted in a manner that does not unreasonably interfere with the Processor's operations.
- The audit will be subject to confidentiality obligations.
- The Controller will bear the costs of the audit, except where the audit reveals a material breach by the Processor, in which case the Processor will bear its reasonable costs.
Alternative Evidence. The Processor may satisfy the audit obligation by providing the Controller with a current SOC 2 Type II report (or equivalent) covering the relevant processing. Such reports will be treated as Confidential Information.
International Data Transfers
The Processor may transfer Personal Data to, and process Personal Data in, countries other than the Controller's country of residence. Where required by applicable law, the Processor will transfer Personal Data subject to appropriate safeguards, which may include:
- Standard Contractual Clauses (SCCs) approved by the European Commission (Module 2 or Module 3, as applicable) or other relevant authority
- Adequacy decisions recognized by the relevant Supervisory Authority
- Binding Corporate Rules, where applicable
- Other lawful transfer mechanisms under applicable law
Where required, the parties will execute the relevant SCCs (or analogous instrument) and implement supplementary technical, organizational, and contractual measures, including encryption in transit and at rest, access controls, and transparency about processing.
Breach Notification
Timing. The Processor will notify the Controller of a Security Incident without undue delay, and in any event within seventy-two (72) hours, after the Processor becomes aware of the Security Incident.
Content. The notification will include, to the extent known: (a) the nature of the Security Incident; (b) the name and contact details of the Processor's contact point; (c) the likely consequences of the Security Incident; and (d) the measures taken or proposed to be taken to address the Security Incident.
Cooperation. The Processor will reasonably cooperate with the Controller, including by providing information needed to enable the Controller to fulfill its obligations to notify Supervisory Authorities and affected Data Subjects. The Processor will not publicly disclose a Security Incident that concerns Controller Personal Data without the Controller's prior written consent, except as required by applicable law.
No Acknowledgment of Fault. Notification of a Security Incident is not an admission of fault or liability by the Processor.
Data Subject Rights
The Processor will, taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures, to the extent possible, in fulfilling the Controller's obligation to respond to requests for exercising Data Subjects' rights under applicable law.
If the Processor receives a request directly from a Data Subject in connection with the Services, the Processor will promptly forward the request to the Controller and will not respond to the Data Subject without the Controller's prior written instructions, except as required by applicable law.
Return and Deletion
Upon termination or expiration of the engagement terms, or earlier upon the Controller's written request, the Processor will, at the Controller's election:
- Return the Personal Data to the Controller in a structured, commonly used, and machine-readable format; or
- Securely Delete the Personal Data from the Processor's systems, including all copies, except as required to be retained by applicable law.
The Processor will complete the return or deletion within thirty (30) days of the end of the engagement, and will provide written certification of deletion upon the Controller's request. Where Personal Data must be retained by applicable law, the Processor will isolate and protect that Personal Data from further processing except to the extent required by such law.
Liability
Cap. Each party's liability arising out of or relating to this DPA is subject to the limitations and exclusions of liability set out in the engagement terms, except that any liability of the Processor for damages incurred by the Controller as a result of the Processor's breach of this DPA is included in, and not in addition to, the liability cap set out in the engagement terms.
Indemnification. The Controller will indemnify and hold the Processor harmless from claims arising from the Controller's instructions, the Controller's failure to obtain necessary rights or consents, or the Controller's use of the Services in violation of applicable law. The Processor will indemnify and hold the Controller harmless from third-party claims to the extent caused by the Processor's breach of this DPA or its gross negligence or willful misconduct.
General Provisions
Order of Precedence. In the event of any conflict, the following order of precedence applies: (a) any SCCs or other transfer mechanism executed under Section 9; (b) this DPA; and (c) the engagement terms.
Amendments. This DPA may be amended only by a written agreement signed by both parties.
Severability. If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions will remain in full force and effect.
Governing Law. This DPA is governed by the laws specified in the engagement terms. Any disputes will be resolved in accordance with the dispute-resolution provisions of the engagement terms.
Notices. Notices under this DPA will be sent to the contact addresses set out in the engagement terms, or to privacy@sovereignty.co.in and legal@sovereignty.co.in.
Signatures
By executing the engagement terms, the parties acknowledge and agree to the terms of this DPA.
Signatures are recorded against the executed engagement terms; a countersigned copy of this DPA is delivered alongside the engagement letter.