Legal

Data Processing Addendum

Processor terms governing Cogrion’s processing of personal data on behalf of customers.

Last Updated: 9 September 2026Version 1.0

This Data Processing Addendum (“DPA”) forms part of the agreement between Cogrion and Customer that incorporates it (the “Agreement”). It applies only to the extent Cogrion processes Customer Personal Data on behalf of Customer in connection with the Services.

This DPA does not apply to processing performed independently by Customer, within Customer-controlled systems without access by Cogrion, or by a cloud, model, integration or other provider selected, instructed, contracted or controlled by Customer. Customer is responsible for Customer Personal Data retained in Customer’s cloud environment and for Customer-selected cloud providers, model providers, data sources and integrations, except to the extent expressly stated otherwise in the Agreement.

1. Definitions

“Applicable Data Protection Law” means laws applicable to the processing of Customer Personal Data under the Agreement, including, where applicable, the Singapore Personal Data Protection Act 2012, Regulation (EU) 2016/679 (“GDPR”), the UK GDPR, India’s Digital Personal Data Protection Act, 2023 and applicable rules, and applicable UAE data protection law.

“Customer Personal Data” means personal data contained in Customer Data that Cogrion processes on behalf of Customer. “Controller”, “processor”, “personal data”, “processing”, “data subject” and “personal data breach” have the meanings given by Applicable Data Protection Law. “Subprocessor” means a third party engaged by Cogrion to process Customer Personal Data on Customer’s behalf.

2. Roles and scope

Customer is the controller or processor, as applicable, and Cogrion is the processor or subprocessor of Customer Personal Data. Each party will comply with its obligations under Applicable Data Protection Law. Customer determines the purposes and means of processing and is responsible for the lawfulness of Customer Personal Data, its instructions, notices, consents and configuration of the Services.

3. Customer instructions

Cogrion will process Customer Personal Data only to provide, secure and support the Services; comply with documented instructions in the Agreement and Order; and comply with applicable law. If Cogrion reasonably believes an instruction violates Applicable Data Protection Law, it will inform Customer unless prohibited by law. Additional instructions outside the agreed Services may require written agreement and reasonable fees.

4. Confidentiality

Cogrion will ensure that personnel authorised to process Customer Personal Data are bound by confidentiality obligations and receive appropriate privacy and security guidance relevant to their roles.

5. Security measures

Cogrion will maintain appropriate technical and organisational measures designed to protect Customer Personal Data, taking into account the nature, scope, context and purposes of processing and the risks to individuals. The Security Addendum describes the applicable control framework. Customer acknowledges that the Services may operate within Customer’s cloud environment and that Customer remains responsible for the controls allocated to Customer under the Agreement and Documentation.

6. Personal data breaches

Cogrion will notify Customer without undue delay after confirming a personal data breach affecting Customer Personal Data under Cogrion’s control. The notice will include available information reasonably required for Customer to meet applicable notification obligations. Cogrion may provide information in phases and will take reasonable steps to contain, investigate and remediate the breach. Notification is not an admission of fault or liability.

7. Third-party processing

Where Cogrion appoints a third party to process Customer Personal Data on Cogrion’s behalf, Cogrion will comply with applicable legal requirements concerning such appointment and provide any notice required under the Agreement or applicable law.

Customer-selected cloud providers, model providers, data sources and integrations are not appointed by Cogrion merely because the Services connect to or interoperate with them.

8. Data-subject requests

Taking into account the nature of processing, Cogrion will provide reasonable assistance for Customer to respond to a verified request from a data subject. If Cogrion receives a request relating to Customer Personal Data, it will refer the requester to Customer unless legally required to respond directly. Customer is responsible for responding to requests and for using available Service functionality.

9. Assessments and regulatory assistance

Taking into account the nature of processing and information available to Cogrion, Cogrion will provide reasonable assistance with Customer’s data-protection impact assessments, regulator consultations and compliance obligations relating to the Services. Assistance beyond standard documentation may be subject to mutually agreed scope and fees.

10. Demonstrating compliance and audits

Upon reasonable written request, Cogrion will provide available information reasonably necessary to demonstrate compliance with this DPA, such as relevant independent audit reports or security summaries, subject to confidentiality. If that information is insufficient and Applicable Data Protection Law requires an audit, Customer may request an audit no more than once annually, except after a confirmed breach or regulator request. Audits must be appropriately scoped, avoid disruption, protect other customers and Cogrion confidential information, and be performed by an independent qualified auditor under confidentiality obligations. Customer bears its audit costs and Cogrion’s reasonable costs for non-standard assistance.

11. Return and deletion

At the end of the applicable Service, Cogrion will return or delete Customer Personal Data under its control in accordance with the Agreement, unless law requires retention. This obligation does not apply to Customer Personal Data remaining in Customer’s cloud environment or systems under Customer’s control. Lawful backups may be retained until overwritten in the ordinary course, provided they remain protected and are not restored except for disaster recovery or legal purposes.

12. International transfers

Where processing involves a restricted transfer, the parties will use an applicable lawful transfer mechanism. For transfers governed by the GDPR, the applicable modules of the European Commission Standard Contractual Clauses adopted by Decision (EU) 2021/914 are incorporated by reference to the extent required. For transfers governed by the UK GDPR, the applicable UK transfer addendum or other recognised mechanism applies. For transfers from Singapore, the parties will implement measures intended to meet the transfer limitation obligation. If the parties execute a separate transfer addendum, it prevails for the relevant transfer.

13. Government requests

Unless prohibited by law, Cogrion will notify Customer of a legally binding request for Customer Personal Data and will assess the request for legal validity. Cogrion will disclose only the information legally required and may challenge a request where reasonable grounds exist.

14. Liability and precedence

Liability arising from this DPA is subject to the exclusions and limitations in the Agreement unless Applicable Data Protection Law prohibits that limitation. If this DPA conflicts with the Agreement regarding processing of Customer Personal Data, this DPA prevails. Standard Contractual Clauses prevail to the extent required by their terms.

Except where Applicable Data Protection Law expressly requires otherwise, this DPA does not create any separate or additional liability cap, indemnity, warranty, service credit or termination right. Customer remains responsible for acts and omissions of Customer’s users and Customer-selected providers.

Schedule 1 — Processing details

Item Description
Subject matter Provision, security, administration and support of the Services described in the Order.
Duration The applicable subscription term and limited post-termination period required by the Agreement or law.
Nature and purpose Hosting where applicable; collection, organisation, retrieval, transmission, analysis, troubleshooting, security monitoring, support and deletion, solely to provide the Services and follow Customer instructions.
Data subjects Customer personnel, authorised users, Customer end users and other individuals whose personal data Customer submits to the Services.
Data categories Account and contact data; identifiers; business and operational data; usage and diagnostic data; and other personal data selected by Customer.
Sensitive data Not intended unless expressly supported and agreed. Customer must apply appropriate configuration and safeguards before submitting sensitive or regulated data.
Frequency Continuous or as initiated by Customer during the Service term.
Retention As stated in the Agreement, Order or Customer configuration, subject to legal requirements and backup cycles.

Questions about these terms may be directed to admin@cogrion.com. Privacy requests may be directed to admin@cogrion.com.