Data Processing Addendum
Last updated: 19 June 2026
1. Background and Roles
1.1 This Data Processing Addendum (this "Addendum") forms part of and is incorporated into the agreement between the Customer and [Klypse Ltd], a company incorporated in [England and Wales] under company number [Company No.] with its registered office at [Registered Office] ("Klypse", "we", "us" or "our"), under which Klypse provides the Customer with access to its B2B private-markets intelligence platform for the ultra-high-net-worth world (the "Service"), as set out in the Klypse Terms of Service or such other master agreement as governs the Customer's use of the Service (the "Terms").
1.2 Klypse provides the Service to professional firms (each a "Customer"). In the course of providing the Service, two distinct kinds of personal data are processed, and Klypse occupies a different role in respect of each. This dual role is fundamental to this Addendum and the parties acknowledge and agree to it expressly.
1.3 Klypse as Processor of Customer Data. The Customer creates and uploads notes, tags, lists, and CRM-style records in the Service, together with the account data of the individuals the Customer authorises to use the Service on its behalf ("Authorised Users"). In respect of this Customer Data (as defined below) and Authorised User account data processed on the Customer's instructions, the Customer is the Controller and Klypse is the Processor. Klypse processes Customer Data only on the Customer's behalf and on its documented instructions. Sections 3 to 6, 8, 9 and 10 and Annexes 1, 2 and 3 govern this relationship.
1.4 Klypse as independent Controller of Principal Intelligence. Separately, Klypse independently compiles intelligence on principals from public and licensed sources and provides it through the Service ("Principal Intelligence", as defined below). In respect of the compilation and provision of Principal Intelligence, Klypse acts as an independent Controller. When the Customer accesses and uses Principal Intelligence for its own purposes, the Customer becomes an independent Controller of that data for its downstream use. The parties are independent Controllers in respect of Principal Intelligence and are not joint Controllers. Section 7 sets out the parties' respective Controller responsibilities for Principal Intelligence.
1.5 Accordingly, this Addendum applies to Klypse's processing of Customer Data as Processor and sets out the Article 28 processor terms governing that processing. It also records the parties' respective responsibilities as independent Controllers in respect of Principal Intelligence. Where this Addendum refers to the parties' obligations, those obligations apply only to the role each party holds in respect of the relevant category of personal data.
1.6 This Addendum reflects the requirements of Applicable Data Protection Laws, and in particular Article 28 of the UK GDPR. It is intended to ensure that personal data is processed in accordance with those laws.
2. Definitions
2.1 In this Addendum, the following terms have the meanings set out below. Capitalised terms not defined here have the meanings given to them in the Terms.
"Applicable Data Protection Laws" means all laws and regulations relating to the processing of Personal Data and privacy that apply to a party in respect of its activities under the Terms, including, as applicable: (a) the UK GDPR; (b) the Data Protection Act 2018 (the "DPA 2018"); (c) the EU GDPR; (d) the Privacy and Electronic Communications Regulations 2003; and (e) to the extent applicable, the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (together, the "CCPA/CPRA"), in each case as amended, updated or replaced from time to time.
"Authorised User" means an individual whom the Customer authorises to access and use the Service on the Customer's behalf.
"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "processing" and "supervisory authority" have the meanings given to them in the UK GDPR, and "process", "processes" and "processed" shall be construed accordingly.
"Customer Data" means the notes, tags, lists, and CRM-style records that a Customer creates or uploads in the Service, together with Authorised User account data processed on the Customer's instructions, in each case to the extent such data constitutes Personal Data and is processed by Klypse on the Customer's behalf as Processor. Customer Data does not include Principal Intelligence.
"EU GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
"EU SCCs" means the standard contractual clauses for the transfer of personal data to third countries set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
"Principal Intelligence" means the data that Klypse independently compiles from public and licensed sources and provides through the Service, to the extent such data constitutes Personal Data. Klypse acts as an independent Controller in respect of the compilation and provision of Principal Intelligence, and the Customer acts as an independent Controller in respect of its downstream use of Principal Intelligence.
"Restricted Transfer" means: (a) where the UK GDPR applies, a transfer of Personal Data from the United Kingdom to a country or territory outside the United Kingdom that is not subject to adequacy regulations made under section 17A of the DPA 2018; and (b) where the EU GDPR applies, a transfer of Personal Data from the European Economic Area to a country outside the European Economic Area that is not the subject of an adequacy decision under Article 45 of the EU GDPR.
"Sub-processor" means any third party engaged by Klypse (or by a Klypse affiliate) to process Customer Data in connection with the Service.
"UK GDPR" has the meaning given to it in section 3(10) (as supplemented by section 205(4)) of the DPA 2018.
"UK IDTA" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner under section 119A of the DPA 2018 and in force from 21 March 2022, as may be amended or replaced from time to time.
3. Scope and Roles of the Parties
3.1 This Addendum applies to the processing of Personal Data by Klypse in connection with the provision of the Service.
3.2 In respect of Customer Data, the parties acknowledge and agree that the Customer is the Controller and Klypse is the Processor. Where the Customer itself acts as a Processor on behalf of a third party Controller in respect of Customer Data, the Customer warrants that it has the authority of the relevant Controller to appoint Klypse as a Sub-processor on the terms of this Addendum, and Klypse's obligations under this Addendum apply accordingly.
3.3 In respect of Principal Intelligence, the parties acknowledge and agree that each acts as an independent Controller as described in Section 1 and Section 7. The parties are not joint Controllers in respect of Principal Intelligence, and nothing in this Addendum or the Terms shall be construed as establishing a joint Controller relationship.
3.4 The subject matter, duration, nature and purpose of the processing of Customer Data, the types of Personal Data and the categories of Data Subjects are set out in Annex 1.
3.5 Each party shall comply with its respective obligations under Applicable Data Protection Laws in respect of the processing it carries out under or in connection with the Terms.
4. Processor Obligations for Customer Data
In respect of Customer Data, and for the duration of the processing, Klypse shall comply with the following obligations under Article 28 of the UK GDPR.
4.1 Processing on documented instructions
4.1.1 Klypse shall process Customer Data only on the documented instructions of the Customer, including with regard to Restricted Transfers, unless required to do so by domestic law to which Klypse is subject. Where Klypse is so required, it shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
4.1.2 The Customer's documented instructions are set out in this Addendum, the Terms, and the Customer's configuration and use of the Service. The Customer may issue further reasonable written instructions consistent with the nature of the Service. Klypse shall promptly inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Laws, without obligation to conduct a legal review of the lawfulness of the Customer's instructions.
4.1.3 If Klypse is unable to comply with an instruction, or if compliance would require Klypse to act outside the scope of the Service or would entail material additional cost, the parties shall discuss the matter in good faith.
4.2 Confidentiality of personnel
4.2.1 Klypse shall ensure that persons authorised to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4.2.2 Klypse shall ensure that access to Customer Data is limited to those personnel who require access in order to provide the Service, and that such personnel receive appropriate training on their responsibilities under Applicable Data Protection Laws.
4.3 Security measures (Article 32)
4.3.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Klypse shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including as appropriate the measures referred to in Article 32(1) of the UK GDPR.
4.3.2 The technical and organisational measures implemented by Klypse as at the date of this Addendum are described in Annex 2. Klypse may update those measures from time to time, provided that any such update does not result in a material reduction of the overall level of security of the Service.
4.4 Sub-processors
4.4.1 The Customer grants Klypse general written authorisation to engage Sub-processors to process Customer Data in connection with the Service. Klypse's current Sub-processors are described in Annex 3 and in a maintained sub-processor list made available to the Customer (the "Sub-processor List").
4.4.2 Klypse shall maintain the Sub-processor List and shall make it available to the Customer, including through the Service or on request to [privacy@klypse-uhnw.com].
4.4.3 Klypse shall give the Customer prior notice of the addition or replacement of any Sub-processor, by updating the Sub-processor List and notifying the Customer (which notification may be by email or through the Service), giving the Customer at least [SUB-PROCESSOR NOTICE PERIOD, e.g. 30 days] to object.
4.4.4 The Customer may object to the appointment or replacement of a Sub-processor on reasonable grounds relating to data protection by giving written notice to Klypse within the notice period. The parties shall work together in good faith to resolve the objection. If the parties are unable to reach a resolution, the Customer may, as its sole and exclusive remedy, terminate the affected part of the Service that cannot be provided without the objected-to Sub-processor, in accordance with the termination provisions of the Terms.
4.4.5 Where Klypse engages a Sub-processor, it shall do so by way of a written contract that imposes on the Sub-processor data-protection obligations that are substantially the same as, and in any event no less protective than, those imposed on Klypse under this Addendum, in particular providing sufficient guarantees to implement appropriate technical and organisational measures. Klypse remains fully liable to the Customer for the performance of each Sub-processor's obligations.
4.5 Assistance with Data Subject requests
4.5.1 Taking into account the nature of the processing, Klypse shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Customer's obligation to respond to requests by Data Subjects exercising their rights under Chapter III of the UK GDPR in respect of Customer Data.
4.5.2 If Klypse receives a request from a Data Subject in respect of Customer Data, Klypse shall promptly notify the Customer and shall not respond to the request itself, except on the documented instructions of the Customer or as required by applicable law.
4.6 Assistance with security, breach, DPIAs and prior consultation
Taking into account the nature of processing and the information available to Klypse, Klypse shall provide reasonable assistance to the Customer in ensuring compliance with the Customer's obligations under Articles 32 to 36 of the UK GDPR, namely the security of processing, the notification of a Personal Data Breach to the supervisory authority and to Data Subjects, the carrying out of data protection impact assessments ("DPIAs"), and prior consultation with the supervisory authority, in each case in respect of Customer Data.
4.7 Deletion or return of Customer Data
4.7.1 On termination or expiry of the Service, Klypse shall, at the choice of the Customer, delete or return all Customer Data to the Customer, and delete existing copies, unless applicable law requires storage of the Customer Data.
4.7.2 The Customer may export or retrieve Customer Data through the functionality of the Service prior to termination. Unless the Customer requests return or deletion within [POST-TERMINATION RETENTION PERIOD, e.g. 30 days] of termination or expiry, Klypse may delete Customer Data in the ordinary course. Klypse may retain Customer Data to the extent required by applicable law, and any such retained Customer Data shall remain subject to the confidentiality and security obligations of this Addendum.
4.8 Information and audits
4.8.1 Klypse shall make available to the Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 of the UK GDPR and this Section 4, and shall allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.
4.8.2 The Customer's right to audit is subject to the following conditions: (a) the Customer shall give Klypse at least [AUDIT NOTICE PERIOD, e.g. 30 days] prior written notice, save where an audit is required by a supervisory authority or follows a Personal Data Breach affecting Customer Data; (b) audits shall be conducted during normal business hours, no more than once in any twelve month period (save where required by a supervisory authority or following a Personal Data Breach), and in a manner that minimises disruption to Klypse's business; (c) the Customer and its auditors shall comply with Klypse's reasonable security and confidentiality requirements and shall enter into appropriate confidentiality undertakings; and (d) the Customer shall bear its own costs of any audit, and shall reimburse Klypse's reasonable costs of assistance beyond the provision of standard documentation.
4.8.3 Klypse may satisfy the audit obligation in Section 4.8.1 by providing the Customer with copies of relevant third party certifications, audit reports, or summaries (for example, reports under recognised industry standards) where these reasonably address the subject matter of the requested audit.
5. Personal Data Breach
5.1 Klypse shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data.
5.2 Such notification shall, to the extent then known to Klypse and taking into account the nature of the processing and the information available to Klypse, include: (a) a description of the nature of the Personal Data Breach, including, where possible, the categories and approximate number of Data Subjects concerned and the categories and approximate number of personal data records concerned; (b) the name and contact details of Klypse's data protection contact or other relevant point of contact from whom more information may be obtained; (c) a description of the likely consequences of the Personal Data Breach; and (d) a description of the measures taken or proposed to be taken by Klypse to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.
5.3 Where, and insofar as, it is not possible to provide the information at the same time, the information may be provided in phases without further undue delay.
5.4 Klypse shall take reasonable steps to contain, investigate and mitigate any Personal Data Breach affecting Customer Data, and shall provide the Customer with reasonable cooperation and assistance in connection with the Customer's obligations to notify the supervisory authority and affected Data Subjects, where applicable.
5.5 Klypse's notification of or response to a Personal Data Breach under this Section 5 shall not be construed as an acknowledgement by Klypse of any fault or liability in respect of the Personal Data Breach.
6. International Transfers
6.1 Klypse shall not make a Restricted Transfer of Customer Data except where it has taken such measures as are necessary to ensure the transfer is in compliance with Applicable Data Protection Laws.
6.2 Where a transfer of Customer Data from Klypse (as data exporter) or from the Customer to Klypse takes place and constitutes a Restricted Transfer, the parties agree that the following transfer mechanisms shall apply to the extent required to provide appropriate safeguards under Applicable Data Protection Laws:
(a) for transfers subject to the EU GDPR, the EU SCCs shall apply and are incorporated into this Addendum by reference, with the relevant module completed in accordance with the nature of the relationship between the parties, the optional docking clause applying, and the annexes of the EU SCCs populated by reference to Annexes 1, 2 and 3 of this Addendum and the parties' details in the Terms; and
(b) for transfers subject to the UK GDPR, the UK IDTA shall apply to and amend the EU SCCs as referred to in Section 6.2(a), and is incorporated into this Addendum by reference, with the tables of the UK IDTA completed by reference to the parties' details in the Terms and Annexes 1, 2 and 3 of this Addendum.
6.3 If any of the transfer mechanisms referred to in Section 6.2 is held invalid, is replaced, or ceases to provide an appropriate safeguard, the parties shall work together in good faith to put in place an alternative lawful transfer mechanism so as to ensure that Restricted Transfers may continue in compliance with Applicable Data Protection Laws.
6.4 The parties shall, where required by Applicable Data Protection Laws, conduct a transfer risk assessment in respect of Restricted Transfers and shall implement such supplementary technical, organisational and contractual measures as are reasonably necessary to ensure that the transferred Customer Data is afforded a level of protection essentially equivalent to that guaranteed within the United Kingdom or the European Economic Area, as applicable.
6.5 In the event of any conflict between the transfer mechanisms referred to in Section 6.2 and the other provisions of this Addendum, the transfer mechanisms shall prevail to the extent of the conflict in respect of the relevant Restricted Transfer.
7. Controller Arrangements for Principal Intelligence
7.1 This Section 7 governs the parties' respective responsibilities in respect of Principal Intelligence. The parties acknowledge and agree that each acts as an independent Controller in respect of Principal Intelligence and that the parties are not joint Controllers.
7.2 Klypse as Controller. In respect of its compilation of Principal Intelligence from public and licensed sources and its provision of Principal Intelligence through the Service, Klypse is an independent Controller and shall:
(a) determine the purposes and means of its own processing of Principal Intelligence and comply with its obligations as a Controller under Applicable Data Protection Laws;
(b) ensure that it has a lawful basis under Applicable Data Protection Laws for compiling and providing Principal Intelligence;
(c) maintain appropriate transparency information in respect of its processing of Principal Intelligence, to the extent required by Applicable Data Protection Laws;
(d) implement appropriate technical and organisational measures in respect of its processing of Principal Intelligence; and
(e) handle requests from Data Subjects and from supervisory authorities relating to Klypse's own processing of Principal Intelligence.
7.3 Customer as Controller. When the Customer accesses, retains, or otherwise uses Principal Intelligence for its own purposes, the Customer becomes an independent Controller of that data and shall:
(a) determine the purposes and means of its own downstream use of Principal Intelligence and comply with its obligations as a Controller under Applicable Data Protection Laws;
(b) ensure that it has a valid lawful basis under Applicable Data Protection Laws for its downstream use of Principal Intelligence, and, where it relies on legitimate interests, that it has carried out any assessment required by Applicable Data Protection Laws;
(c) provide such transparency information to Data Subjects as is required by Applicable Data Protection Laws in respect of its downstream use, including, where required, information about the source and categories of the Personal Data it has obtained;
(d) handle, and honour, any objection, restriction, erasure, rectification, or other request made by a Data Subject in respect of the Customer's downstream use of Principal Intelligence, and honour any objection it is required to honour under Applicable Data Protection Laws; and
(e) not use Principal Intelligence in any manner that would cause Klypse to be in breach of Applicable Data Protection Laws.
7.4 Each party shall, on reasonable request and to the extent reasonably practicable, provide the other with reasonable cooperation and assistance to enable the other to comply with its obligations as an independent Controller in respect of Principal Intelligence, including in responding to Data Subject requests and supervisory authority enquiries, provided that nothing in this Section 7 requires either party to disclose its confidential or proprietary information, its sources, or information it is prohibited from disclosing by law.
7.5 Where a Data Subject request, complaint, or supervisory authority enquiry relates to a matter for which the other party is responsible as Controller, the receiving party shall, to the extent permitted by law, promptly forward it to the other party or direct the relevant individual or authority to the other party.
8. Customer Warranties and Instructions
8.1 The Customer warrants and undertakes that:
(a) it has provided, and will at all relevant times have provided, all notices and obtained all consents, and otherwise established a valid lawful basis under Applicable Data Protection Laws, as are necessary to enable: (i) the lawful uploading and processing of Customer Data through the Service by Klypse as Processor in accordance with this Addendum; and (ii) the Customer's own downstream use of Principal Intelligence as an independent Controller;
(b) its instructions to Klypse in respect of the processing of Customer Data are, and will remain, lawful, and that the processing of Customer Data in accordance with those instructions will not cause Klypse to breach Applicable Data Protection Laws;
(c) it has the right to transfer, or provide access to, Customer Data to Klypse for processing in accordance with the Terms and this Addendum; and
(d) it shall not upload to or process through the Service any special categories of personal data within the meaning of Article 9 of the UK GDPR, or personal data relating to criminal convictions and offences within the meaning of Article 10 of the UK GDPR, except to the extent the Service is expressly designed to process such data and the Customer has established a lawful basis and met any applicable conditions for doing so.
8.2 The Customer is responsible for the accuracy, quality, and legality of Customer Data and of the means by which the Customer acquired Customer Data.
9. United States Service-Provider Terms
9.1 This Section 9 applies to the extent the CCPA/CPRA applies to the Customer's use of the Service in respect of Customer Data. Terms used in this Section 9 and defined in the CCPA/CPRA have the meanings given to them in the CCPA/CPRA.
9.2 In respect of Customer Data that is subject to the CCPA/CPRA, the parties acknowledge and agree that the Customer is a "business" and Klypse acts as a "service provider". Klypse processes such Customer Data solely on behalf of the Customer and for the limited and specified business purpose of providing the Service in accordance with the Terms and this Addendum (the "Business Purpose").
9.3 Klypse shall not: (a) sell or share Customer Data within the meaning of the CCPA/CPRA; (b) retain, use, or disclose Customer Data for any purpose other than the Business Purpose, including for any commercial purpose other than the Business Purpose, except as permitted by the CCPA/CPRA; (c) retain, use, or disclose Customer Data outside the direct business relationship between the parties; or (d) combine Customer Data with personal information that Klypse receives from, or on behalf of, any other person, or collects from its own interaction with any consumer, except as permitted by the CCPA/CPRA for a service provider.
9.4 Klypse certifies that it understands the restrictions set out in this Section 9 and shall comply with them. Klypse shall provide the Customer with reasonable assistance to enable the Customer to respond to verifiable consumer requests under the CCPA/CPRA in respect of Customer Data, taking into account the nature of Klypse's processing.
10. Liability and Order of Precedence
10.1 This Addendum forms part of and is subject to the Terms. Except as expressly modified by this Addendum, the Terms remain in full force and effect.
10.2 In the event of any conflict or inconsistency between this Addendum and the Terms, this Addendum shall prevail in respect of the subject matter of data protection. In the event of any conflict or inconsistency between this Addendum and the transfer mechanisms referred to in Section 6.2, those transfer mechanisms shall prevail in respect of the relevant Restricted Transfer.
10.3 Each party's liability arising out of or in connection with this Addendum, whether in contract, tort (including negligence), breach of statutory duty, or otherwise, is subject to the exclusions and limitations of liability set out in the Terms, and any reference in those exclusions and limitations to the Terms or the agreement shall be deemed to include this Addendum.
10.4 This Addendum shall remain in effect for so long as Klypse processes Customer Data. The provisions of this Addendum that by their nature should survive termination shall survive termination or expiry of this Addendum and the Terms.
10.5 This Addendum is governed by, and shall be construed in accordance with, the law that governs the Terms, and the parties submit to the jurisdiction provided for in the Terms, save where Applicable Data Protection Laws, the EU SCCs, or the UK IDTA require otherwise in respect of a Restricted Transfer.
ANNEX 1: Details of Processing (Customer Data)
This Annex 1 describes the processing of Customer Data by Klypse as Processor on behalf of the Customer as Controller, as required by Article 28(3) of the UK GDPR.
Subject matter of the processing
The provision of the Service by Klypse to the Customer, namely a B2B private-markets intelligence platform, and the processing of Customer Data (notes, tags, lists, and CRM-style records created or uploaded by the Customer, together with Authorised User account data) necessary for that purpose.
Duration of the processing
For the term of the Terms, and thereafter for so long as is necessary to comply with Klypse's obligations under Section 4.7 of this Addendum (deletion or return of Customer Data) and any retention required by applicable law.
Nature and purpose of the processing
The hosting, storage, organisation, structuring, retrieval, display, transmission, back-up, and (on the Customer's instructions) deletion or return of Customer Data, together with such other operations as are necessary to provide the Service and its features to the Customer and its Authorised Users, including the operation of the platform's assistant functionality on Customer Data in accordance with the Customer's use of the Service. The purpose of the processing is to enable Klypse to provide the Service to the Customer in accordance with the Terms and this Addendum, and to process Customer Data on the Customer's documented instructions.
Types of personal data
- Identifiers and contact details contained in the Customer's notes, tags, lists, and CRM-style records (for example, names, business contact details, and professional identifiers of the individuals the Customer chooses to record).
- Professional, relationship-management, and commercial information that the Customer chooses to record about its own contacts and relationships (for example, notes, tags, categorisations, interaction records, and free-text content).
- Authorised User account data (for example, name, business email address, login credentials, role, and usage and access logs).
- [ANY FURTHER CATEGORIES OF PERSONAL DATA AS APPLICABLE TO THE CUSTOMER'S USE OF THE SERVICE].
The Customer determines the content of its Customer Data and is responsible for ensuring it does not include categories of data beyond those contemplated by the Service and this Addendum (see Section 8.1(d)).
Categories of Data Subjects
- The Customer's business contacts, prospects, clients, and relationships recorded by the Customer in the Service.
- The Customer's Authorised Users (personnel and other individuals authorised by the Customer to access the Service).
- [ANY FURTHER CATEGORIES OF DATA SUBJECTS AS APPLICABLE TO THE CUSTOMER'S USE OF THE SERVICE].
ANNEX 2: Technical and Organisational Security Measures
This Annex 2 describes the technical and organisational security measures implemented by Klypse in respect of Customer Data pursuant to Article 32 of the UK GDPR and Section 4.3 of this Addendum. These measures may be updated from time to time in accordance with Section 4.3.2, provided that the overall level of security is not materially reduced.
Encryption
- Encryption of Customer Data in transit using industry-standard transport encryption (for example, TLS [VERSION]).
- Encryption of Customer Data at rest using industry-standard encryption (for example, AES [KEY LENGTH]).
- [KEY MANAGEMENT PRACTICES, INCLUDING KEY ROTATION AND STORAGE].
Access control
- Role-based access controls restricting access to Customer Data to authorised personnel on a least-privilege, need-to-know basis.
- Unique user accounts, with multi-factor authentication for administrative and privileged access.
- [PASSWORD AND CREDENTIAL POLICY DETAILS].
- Timely revocation of access rights on change of role or termination of engagement.
Logging and monitoring
- Logging of access to, and significant operations on, systems processing Customer Data.
- Monitoring of systems for security events and anomalies, and retention of logs for [LOG RETENTION PERIOD].
- [INTRUSION DETECTION OR PREVENTION ARRANGEMENTS].
Data minimisation and segregation
- Logical separation of Customer Data belonging to different Customers.
- Processing of Customer Data limited to what is necessary to provide the Service.
- Pseudonymisation or de-identification where appropriate and practicable.
Confidentiality, integrity, availability, and resilience
- Measures designed to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services.
- Network security controls, including firewalls and segmentation. [FURTHER NETWORK SECURITY DETAILS].
- Secure software development practices, including code review and vulnerability management. [DETAILS, INCLUDING PATCHING CADENCE].
- Regular vulnerability scanning and [PENETRATION TESTING FREQUENCY] penetration testing.
Vendor and Sub-processor management
- Due diligence on Sub-processors prior to engagement, and the imposition of data-protection and security obligations by written contract in accordance with Section 4.4.
- Periodic review of Sub-processors' security posture. [DETAILS OF REVIEW CADENCE].
Business continuity and back-up
- Regular back-up of Customer Data, with [BACK-UP FREQUENCY AND RETENTION].
- Business continuity and disaster recovery arrangements, tested periodically. [RECOVERY OBJECTIVES: RPO/RTO].
Personnel and organisational measures
- Confidentiality obligations binding on personnel with access to Customer Data (Section 4.2).
- Data protection and security awareness training for relevant personnel. [TRAINING CADENCE].
- Background checks on personnel where lawful and appropriate. [DETAILS].
Incident response
- A documented Personal Data Breach and security-incident response process, including procedures for detection, containment, investigation, notification, and remediation in accordance with Section 5.
Physical security
- Reliance on the physical and environmental security controls of the hosting and cloud infrastructure Sub-processor's data centres. [FURTHER DETAILS, INCLUDING RELEVANT CERTIFICATIONS].
Certifications and assurance
- [LIST OF RELEVANT CERTIFICATIONS, ATTESTATIONS, OR INDEPENDENT AUDIT REPORTS, FOR EXAMPLE ISO/IEC 27001, SOC 2, WHERE HELD].
ANNEX 3: Sub-processors
This Annex 3 sets out the categories of Sub-processors engaged by Klypse to process Customer Data as at the date of this Addendum. The current and complete list of Sub-processors is maintained in the Sub-processor List referred to in Section 4.4. The named providers below are placeholders, to be completed and kept current in the Sub-processor List.
| Sub-processor | Purpose | Location | Safeguards |
|---|---|---|---|
| [HOSTING / CLOUD INFRASTRUCTURE PROVIDER] | Hosting and cloud infrastructure for the Service, including storage and processing of Customer Data | [LOCATION / REGION] | Written sub-processor terms per Section 4.4; appropriate technical and organisational measures (Annex 2); [EU SCCs / UK IDTA where there is a Restricted Transfer]; [CERTIFICATIONS, e.g. ISO/IEC 27001, SOC 2] |
| [AI / LLM PROVIDER] | Powering the in-Service assistant functionality applied to Customer Data | [LOCATION / REGION] | Written sub-processor terms per Section 4.4; no use of Customer Data to train the provider's models except as permitted by the parties; appropriate technical and organisational measures; [EU SCCs / UK IDTA where there is a Restricted Transfer] |
| [ANALYTICS PROVIDER] | Product and usage analytics to operate, secure, and improve the Service | [LOCATION / REGION] | Written sub-processor terms per Section 4.4; data minimisation and, where practicable, pseudonymisation; appropriate technical and organisational measures; [EU SCCs / UK IDTA where there is a Restricted Transfer] |
| [EMAIL / COMMUNICATIONS PROVIDER] | Transactional and service-related email and communications to Authorised Users | [LOCATION / REGION] | Written sub-processor terms per Section 4.4; appropriate technical and organisational measures; [EU SCCs / UK IDTA where there is a Restricted Transfer] |
End of Data Processing Addendum.

