EvRiskoEvRiskoIT risk managementmade simple
HomeHow to usePricingBlogContact Us
☰
HomeHow to usePricingBlogContact Us
Sign InSign Up
Sign InSign Up
Legal

Data Processing Addendum

Effective date: 01 October 2026 · Last updated: 01 October 2026
General
Terms and conditions Acceptable use policy Refund & cancellation policy
Privacy and Security
Privacy notice Cookie notice Data Processing Addendum Security annex

This Data Processing Addendum (“DPA”) forms part of the SaaS Terms between TechComply (“Processor”) and the client that has accepted the Terms (“Controller”).

1. Scope

This DPA applies where Processor processes Personal Data on behalf of Controller in providing the Services.

2. Instructions

Processor will process Personal Data only:

•to provide, secure, support, and improve the Services;
•on Controller’s documented instructions;
•as described in the Terms and this DPA; or
•as required by applicable law.

Processor will notify Controller if it believes an instruction violates applicable data-protection law, unless prohibited by law.

3. Processing details

Subject matter: Provision of an IT-risk assessment and remediation-management SaaS platform.

Duration: The term of the applicable subscription plus the applicable deletion period.

Nature of processing: Collection, storage, organization, retrieval, analysis, display, transmission, sharing, reporting, deletion.

Purpose: Account administration, questionnaire processing, dashboard generation, report creation, client support, security, service maintenance, and related business operations.

Types of Personal Data: Names, business contact details, job titles, account credentials, user activity, technical identifiers, and information included by client in free-text fields or documents.

Categories of data subjects: client personnel, contractors, suppliers, clients, users, and other individuals whose information the client submits.

Client must not submit special category Personal Data (e.g. health, religion,sexual orientation data etc.), as those types of data are not needed for the provision of the Services. Should the Client provide any such data in the open text fields, they are solely liable for its sharing and processing,

4. Confidentiality

Processor will ensure that persons authorized to process Personal Data are subject to confidentiality obligations.

5. Security measures

Processor will maintain reasonable safeguards, including where appropriate:

•access controls and least-privilege permissions;
•authentication controls (including multi-factor authentication for logging in the Application);
•encryption in transit and at rest;
•logging and monitoring;
•secure development and change-management practices;
•vulnerability management;
•backups and disaster-recovery procedures;
•personnel confidentiality and security training;
•incident-response procedures; and
•secure deletion procedures.

Further measures may be described in the Security Annex.

6. Subprocessors

Controller authorizes Processor to use the subprocessors listed below:

Processor will:

•impose data protection obligations on its subprocessors;
•remain responsible for their performance;
•notify Controller of new or replacement subprocessors where required; and
•provide a reasonable opportunity to object on data protection grounds.

If the parties cannot resolve a valid objection, Controller may terminate the affected Services on written notice.

7. Assistance

Taking into account the nature of processing, Processor will reasonably assist Controller with:

•data subject requests;
•security and breach notifications;
•data protection impact assessments;
•consultations with regulators;
•deletion and export requests; and
•information reasonably needed to demonstrate compliance.

Processor may charge reasonable costs for unusual or excessive assistance.

8. Personal data breaches

Processor will notify Controller without undue delay after becoming aware of a Personal Data breach affecting Controller Data.

The notification will include, where available:

•the nature of the breach;
•categories and approximate number of affected individuals;
•likely consequences;
•measures taken or proposed to remediate the incident; and
•a contact point for further information.

Processor will not notify affected individuals or regulators unless required by law or instructed by Controller.

9. International transfers

Processor may transfer Personal Data internationally using a lawful transfer mechanism, including an adequacy decision, standard contractual clauses, UK transfer arrangements, or another legally recognized safeguard.

10. Compliance checks

Processor will make available information reasonably necessary to demonstrate compliance.

11. Deletion and return

At the end of the Services, Processor will delete or return Controller Data at Controller’s choice, unless applicable law requires retention. Data stored in routine backups may be deleted according to Processor’s normal backup lifecycle.

12. Controller responsibilities

Controller is responsible for:

•providing lawful instructions;
•determining the purposes and legal bases for processing;
•giving required privacy notices;
•obtaining required consents;
•ensuring data accuracy;
•responding to data-subject requests where appropriate; and
•ensuring that its instructions and use of the Services comply with applicable law.

13. Priority

If this DPA conflicts with the Terms & Conditions, this DPA controls regarding Personal Data processing supersede the Terms & Conditions. If the standard contractual clauses or another mandatory transfer mechanism applies, it takes precedence over the rest of the data protection agreements to the extent of a conflict.

EvRiskoEvRiskoIT risk managementmade simple
GeneralPrivacy and Security
© 2026 EvRisko