Last Updated: 6 August 2026
This Data Processing Addendum forms part of the Agreement between, on the one hand, SiSo Technologies LLC-FZ and/or, as expressly agreed, its affiliate(s) (“SiSo”) and, on the other hand, the Subscriber.
This Data Processing Addendum (“DPA”) is entered into between SiSo and the Subscriber identified in the Order Form, or otherwise. It supplements and forms part of the Agreement and governs the Processing of Personal Data by SiSo on behalf of the Subscriber in connection with the Service.
This DPA is effective upon the Subscriber’s acceptance of the Agreement (including by clickwrap or continued use of the Service). Capitalised terms not defined in this DPA have the meaning given to them in the Agreement.
In the event of any conflict between this DPA and the Agreement in respect of the Processing of Personal Data, this DPA shall prevail. Where the EU SCCs or the IDTA apply, those instruments shall prevail over this DPA to the extent of any inconsistency.
1. Definitions
In this DPA, the following terms have the meanings set out below:
“Agreement” means, as applicable: either: (i) the Order Form and the Terms of Use (including this DPA) published at https://sisotechnologies.com/terms-of-use; (ii) such other agreement(s) between, on the one hand, SiSo and, on the other hand, the Subscriber, pursuant to which SiSo provides the Service to the Subscriber.
“Applicable Data Protection Law” means any of the following laws to the extent applicable to the relevant Processing: (a) the EU GDPR; (b) the UK GDPR; (c) the UAE Federal Personal Data Protection Law (Federal Decree-Law No. 45 of 2021); (d) US Privacy Laws; and (e) any other national or state data protection or privacy legislation applicable to SiSo’s Processing, in each case as amended, replaced or superseded from time to time.
“Controller” means the entity that determines the purposes and means of the Processing of Personal Data.
“Data Subject” means an identified or identifiable natural person to whom Personal Data relates.
“EU GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data.
“EU SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission pursuant to Commission Implementing Decision (EU) 2021/914.
“GDPR” means as applicable in context, the EU GDPR and/or the UK GDPR.
“IDTA” means the International Data Transfer Agreement issued by the UK Information Commissioner’s Office under section 119A of the Data Protection Act 2018, as updated or replaced from time to time.
“Instructions” means the Subscriber’s documented instructions to SiSo in respect of the Processing of Personal Data, comprising this DPA (including Schedule 1), the Agreement, the documentation for the Service, and any actions taken, inputs provided or configurations selected by the Subscriber or its authorised users within the Service.
“Personal Data” means any information relating to a Data Subject that is Processed by SiSo on behalf of the Subscriber in connection with the provision of the Service, as further described in Schedule 1.
“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed.
“Processing” means (and “Process”, “Processed”) any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
“Processor” means an entity that Processes Personal Data on behalf of a Controller.
“Restricted Transfer” means a transfer of Personal Data to a country outside the European Economic Area (in the context of the EU GDPR) or outside the United Kingdom (in the context of the UK GDPR) that is not subject to an adequacy decision.
“Service” means the licensing of a SaaS platform and provision of related services provided by SiSo to the Subscriber as described in the Agreement.
“Special Categories of Data” means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data (processed for the purpose of uniquely identifying a natural person), health data, and data concerning sex life or sexual orientation.
“Sub-Processor” means any third party engaged by SiSo to Process Personal Data on behalf of the Subscriber.
“Supervisory Authority” means the relevant data protection regulatory authority with jurisdiction over the relevant Processing.
“UK GDPR” means the retained EU law version of the EU GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 and as further amended from time to time.
“US Privacy Laws” means applicable US state or federal privacy laws, including the California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq.) as amended by the California Privacy Rights Act, and materially similar laws enacted or effective from time to time.
2. Roles and Processing Basis
2.1 Dual Role Structure
The Parties acknowledge that:
(a) where the Subscriber acts as a Controller of Personal Data, SiSo acts as a Processor; and
(b) where the Subscriber itself acts as a Processor of Personal Data on behalf of a third-party controller, SiSo acts as a Sub-Processor.
This DPA governs SiSo’s Processing obligations in either case.
2.2 Subscriber’s Warranties and Obligations
The Subscriber warrants and represents that:
(a) it has a lawful basis for sharing Personal Data with SiSo and for directing SiSo to Process Personal Data as contemplated by this DPA;
(b) where it acts as a Processor, it has obtained the necessary authorisation from the relevant controller to enter into this DPA and to engage SiSo as a Sub-Processor on equivalent terms;
(c) it will comply, and will procure that its authorised users and affiliates comply, with Applicable Data Protection Law in connection with their use of the Service;
(d) it will notify SiSo without undue delay if it becomes aware of any non-compliance on its part (or that of its users or affiliates) that affects SiSo’s Processing obligations under this DPA; and
(e) it will limit the Personal Data it makes available to SiSo to what is necessary for the purposes of the Agreement, and will not include Personal Data (other than technical contact information) in support tickets, service requests or similar communications;
(f) it is responsible for the configuration and design decisions it makes in relation to the Service, including whether and how it uses optional features, access permissions, sharing settings and third-party integrations, and for implementing those decisions securely and in compliance with Applicable Data Protection Law.
2.3 US Service Provider
Where US Privacy Laws apply, SiSo processes Personal Data solely for the purposes of providing the Service as set out in this DPA and the Agreement. SiSo does not “sell” or “share” Personal Data as those terms are defined in applicable US Privacy Laws, and does not retain, use or disclose Personal Data for any purpose other than those specified in this DPA.
2.4 Account Data and Usage Data
SiSo Processes the following categories of Personal Data as an independent controller, and not as a Processor or Sub-Processor, and such Personal Data is not subject to the remainder of this DPA: (a) Account Data, being Personal Data relating to SiSo’s relationship with the Subscriber, including the names, business contact details and login credentials of authorised users and information used for billing, administration and technical support; and (b) Usage Data, being technical and analytical data generated by the operation of the Service, including logs, telemetry and feature-usage metrics. SiSo Processes such Personal Data in order to administer the Subscriber’s account, provide support, secure and monitor the Service, comply with its own legal and accounting obligations, and analyse and improve the Service, in each case in accordance with SiSo’s privacy notice. Account Data and Usage Data do not include the content of documents or other materials uploaded to the platform, and nothing in this clause 2.4 permits SiSo to train or fine-tune any machine learning or artificial intelligence model on such content.
3. SiSo’s Processing Obligations
SiSo shall, in respect of its Processing of Personal Data under this DPA:
3.1 Documented Instructions
Process Personal Data only in accordance with the Instructions, or otherwise to the extent required by applicable law (in which case SiSo shall, to the extent permitted by law, notify the Subscriber before any such Processing). If SiSo reasonably believes that an instruction from the Subscriber would breach Applicable Data Protection Law, SiSo shall notify the Subscriber promptly and shall not be obliged to act on that instruction until the Subscriber has provided written confirmation or clarification satisfactory to SiSo. Where the Subscriber amends or supplements its instructions in a manner that requires SiSo to incur additional cost or effort, SiSo shall be entitled to remuneration for its reasonable and verified additional costs, save where the amendment is directly required by Applicable Data Protection Law.
3.2 Confidentiality of Personnel
Ensure that all personnel authorised to Process Personal Data are subject to appropriate obligations of confidentiality, whether contractual or statutory.
3.3 Security Measures
Implement and maintain appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, as further described in Schedule 3. SiSo may update its security measures from time to time, provided that any update does not materially reduce the level of protection afforded to the Subscriber’s Personal Data.
3.4 Sub-Processors
Engage Sub-Processors only in accordance with clause 6 of this DPA.
3.5 Assistance with Data Subject Rights
Provide reasonable assistance to the Subscriber to enable it to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law, taking into account the nature of the Processing and the information available to SiSo. If a Data Subject submits a request directly to SiSo, SiSo shall promptly forward it to the Subscriber without responding directly, unless required to do so by applicable law. Such assistance shall be provided at the Subscriber’s reasonable expense, unless the need for the assistance arises directly from an act or omission of SiSo or its Sub-Processors.
3.6 Personal Data Breach Notification
Notify the Subscriber of any confirmed Personal Data Breach affecting the Subscriber’s Personal Data without undue delay and, where feasible, within 72 hours of SiSo becoming aware of the Breach. The notification shall include such information as is reasonably available at the time and as the Subscriber reasonably requires to meet its own reporting obligations to Supervisory Authorities and Data Subjects. SiSo shall not be required to notify the Subscriber of security incidents that do not constitute a Personal Data Breach. Any costs associated with such assistance shall be subject to the limitations and exclusions of liability in clause 11.
3.7 Data Protection Impact Assessments
Provide reasonable assistance to the Subscriber, at the Subscriber’s reasonable expense, in carrying out any data protection impact assessment (“DPIA”) and, where applicable, prior consultation with a Supervisory Authority, to the extent required by Applicable Data Protection Law and to the extent that such assistance falls within SiSo’s reasonable control and relates to SiSo’s own Processing activities.
3.8 Records of Processing
Maintain records of the categories of Processing activities carried out on behalf of the Subscriber to the extent required by Article 30(2) GDPR (or equivalent provision of Applicable Data Protection Law).
3.9 Aggregated and Anonymised Data
SiSo may create, use and retain anonymised and aggregated data derived from its Processing under this DPA, provided that such data is rendered anonymous in such a manner that no Data Subject is or can be identified from it, directly or indirectly, and that it cannot be reversed or re-identified. SiSo may use such data for the purposes of operating, securing, monitoring, analysing and improving the Service. Such data does not constitute Personal Data and its use is not subject to this DPA.
4. Confidentiality
SiSo shall keep Personal Data confidential and shall not disclose it to any third party except:
(a) to its directors, officers, personnel and/or third-party contractors and/or Sub-Processors to the extent necessary for the provision of the Service, subject to appropriate confidentiality obligations;
(b) as expressly authorised by the Subscriber in writing; or
(c) as required by applicable law, court order or binding demand of a competent authority, in which case SiSo shall (to the extent permitted by law) notify the Subscriber before disclosure and disclose only the minimum information necessary.
The obligation of confidentiality in this clause 4 shall survive the termination or expiry of this DPA.
5. International Transfers
5.1 Data Residency
Unless otherwise expressly agreed in the Order Form or otherwise in writing, SiSo determines the geographic region in which Personal Data associated with the Subscriber's account is hosted. SiSo's current default regions are the European Economic Area for non-US-based Subscribers, and the United States for US-based Subscribers. SiSo does not proactively transfer Personal Data between regions as part of its standard service delivery.
5.2 User-Initiated Access
The Subscriber acknowledges that users of the Service (including clients, advisors and counterparties authorised by the Subscriber) may access the platform from jurisdictions outside the region where their data is hosted. Such access occurs at the direction of the Subscriber and its authorised users. SiSo does not initiate or control such cross-border access and takes the position that it does not constitute a Restricted Transfer initiated by SiSo for the purposes of Chapter V of the GDPR. To the extent any such access is nonetheless considered to constitute a Restricted Transfer, the mechanisms set out in clause 5.3 shall apply. The Subscriber acknowledges that it bears responsibility for ensuring that access permissions it grants to its authorised users are consistent with its own obligations under Applicable Data Protection Law.
5.3 Restricted Transfers
Where a Restricted Transfer arises in connection with the provision of the Service, SiSo shall ensure that such transfers are made using an appropriate safeguard under Applicable Data Protection Law, which may include:
a) the EU SCCs, incorporating the applicable module in accordance with clause 5.4;
b) the IDTA or the UK Addendum to the EU SCCs, as applicable for transfers subject to the UK GDPR;
c) in the case of intragroup transfers within the SiSo Group, an executed intragroup data transfer agreement incorporating the EU SCCs and/or the UK IDTA as applicable;
d) in the case of Sub-Processors, the transfer mechanism included in or adopted pursuant to the Sub-Processor's own standard terms of service or data processing agreement, where SiSo has taken reasonable steps to confirm that such mechanism is consistent with Applicable Data Protection Law; or
e) such other transfer mechanism as is permitted under Applicable Data Protection Law.
The Subscriber acknowledges that SiSo may rely on transfer mechanisms agreed directly with Sub-Processors as part of those Sub-Processors' standard terms, without the need for separate bilateral arrangements between SiSo and the Subscriber in respect of such Sub-Processors.
5.4 EU SCC Module Selection
The Parties agree that the following modules of the EU SCCs are incorporated into this DPA by reference:
(a) Module 2 (Controller to Processor) applies where the Subscriber is a Controller and SiSo is a Processor; and
(b) Module 3 (Processor to Processor) applies where the Subscriber is a Processor and SiSo is a Sub-Processor.
The EU SCCs are completed as follows: Clause 7 (optional docking clause) – not included; Clause 11 (optional redress mechanism) – not included; Clause 13 – the supervisory authority of the EU/EEA Member State in which the Subscriber (as data exporter) is established or, where the Subscriber is not established in the EU/EEA, the supervisory authority of the Member State in which the data subjects whose Personal Data is transferred are predominantly located; Clause 17 – laws of Ireland; Clause 18 – courts of Ireland. The Annexes are as set out in the Schedules to this DPA.
Where UK GDPR applies and a Restricted Transfer arises, the IDTA (or, where permissible, the UK Addendum to the EU SCCs) shall apply, completed with the information set out in the Schedules to this DPA and as notified by SiSo on request.
6. Sub-Processors
6.1 General Authorisation
The Subscriber provides general written authorisation for SiSo to engage Sub-Processors to Process Personal Data on the Subscriber’s behalf. SiSo’s current list of approved Sub-Processors is set out in Schedule 2 and/or available at https://sisotechnologies.com/subprocessors.
6.2 Notification of New Sub-Processors
SiSo shall notify the Subscriber of any intended addition or replacement of a Sub-Processor by updating the list available at https://sisotechnologies.com/subprocessors and may provide additional notification via email or other reasonable means. SiSo will provide at least fourteen (14) days’ prior notice before the new Sub-Processor begins Processing Personal Data.
6.3 Objection
If the Subscriber has reasonable, documented grounds to object to the appointment of a proposed new Sub-Processor on data protection grounds, the Subscriber must notify SiSo in writing within 14 days of receiving notice of the proposed change. SiSo may resolve the objection by any of the following means, at SiSo’s election: (a) offering an alternative means of providing the affected part of the Service without that Sub-Processor; (b) taking corrective steps that address the objection and proceeding to engage that Sub-Processor; or (c) ceasing to provide, or the Subscriber agreeing not to use, the particular feature or aspect of the Service that involves that Sub-Processor. Where the Subscriber’s objection would result in additional or increased costs or expenses for SiSo, SiSo shall be entitled to adjust its fees under the Agreement so as to be compensated for those costs or expenses. If, in SiSo’s reasonable judgment, none of the above options is commercially feasible and the objection has not been resolved within 30 days of SiSo’s receipt of it, either Party may terminate the affected part of the Service on 30 days’ written notice. Save for accepting a resolution offered by SiSo under this clause 6.3, such termination is the Subscriber’s sole and exclusive remedy in respect of any objection to a Sub-Processor. Failure to notify an objection within the 14-day period constitutes acceptance.
6.4 Removal of Sub-Processors
SiSo may remove a Sub-Processor at any time without prior notice to the Subscriber.
6.5 Sub-Processor Obligations
SiSo shall take reasonable steps to ensure that each Sub-Processor is subject to data protection obligations that are appropriate to the nature of the services they provide and consistent with Applicable Data Protection Law. Where a Sub-Processor provides services under its own standard published terms or data processing agreement (including those of cloud infrastructure, hosting or technology providers), SiSo's obligations under this clause shall be satisfied by acceptance of those standard terms, provided SiSo has conducted reasonable due diligence that such terms are materially consistent with Applicable Data Protection Law. SiSo shall remain responsible to the Subscriber for the acts and omissions of its Sub-Processors under this DPA, subject always to the limitations of liability in clause 11.
SiSo further represents that, in respect of each model-path Sub-Processor (meaning any foundation model provider, large language model provider, or cloud platform on which such models are run), SiSo has subscribed to or contracted for an enterprise or API configuration that does not use Personal Data, prompts, outputs or any derivatives thereof for model training, fine-tuning or evaluation, and SiSo will use commercially reasonable efforts to maintain such configuration during the term. SiSo will notify the Subscriber of any change to such configuration that materially affects this representation.
7. Audit Rights
7.1 The Subscriber may, no more than once per calendar year (or, following a confirmed Personal Data Breach affecting the Subscriber’s Personal Data, on one additional occasion during the twelve (12) months following that Breach), request an audit of SiSo’s compliance with its data protection and security obligations under this DPA by giving at least thirty (30) days’ prior written notice. Audits may not occur more than once in any twelve (12) month period unless required by applicable law or a competent supervisory authority.
7.2 Any audit under clause 7.1 shall be:
(a) conducted by an independent third party agreed between the Parties, who is not a direct competitor of SiSo and who is bound by appropriate confidentiality obligations;
(b) carried out at the Subscriber’s cost, including SiSo’s reasonable internal costs incurred in supporting the audit; and
(c) conducted during normal business hours and in a manner that minimises disruption to SiSo’s operations and does not compromise the confidentiality or security of other customers’ data.
7.3 SiSo shall cooperate with any such audit and shall use commercially reasonable efforts to remedy any material non-compliance identified within thirty (30) days of written notice, or within such other reasonable period as may be agreed between the Parties, taking into account the nature and severity of the issue and the risks to Personal Data.
7.4 The Subscriber agrees that it will primarily rely on SiSo’s security certifications and independent third-party audit reports (such as ISO 27001 certification), where available and provided subject to confidentiality obligations, to verify SiSo’s compliance with this DPA. The Subscriber may request an audit under clause 7.1 only where it has reasonable grounds to believe that such certifications or reports do not adequately demonstrate compliance with the requirements of this DPA.
7.5 The Subscriber acknowledges that SiSo’s customers include entities that are subject to statutory and/or professional obligations of confidentiality in respect of their own clients and matters (including law firms, banks, financial institutions and professional advisers). Accordingly, no audit under this clause 7 shall extend to information pertaining or belonging to SiSo’s other customers, and SiSo may withhold or redact such information.
7.6 All reports, certifications, documentation and other information provided by SiSo in connection with an audit, assessment or diligence request under this clause 7 constitute SiSo’s Confidential Information under the Agreement.
8. Government and Law Enforcement Requests
Unless prohibited by applicable law, if SiSo receives a binding order, request or demand from a government authority or law enforcement agency requiring disclosure of Personal Data, SiSo shall:
(a) notify the Subscriber promptly before complying, to the extent permitted by law;
(b) disclose only the minimum Personal Data strictly necessary to satisfy the request; and
(c) use reasonable efforts to obtain confidential treatment of the request and to seek a waiver of any notification prohibition where possible.
SiSo shall not voluntarily disclose Personal Data to any government authority or law enforcement agency without the Subscriber’s prior written consent, unless required by applicable law.
9. Return and Deletion of Personal Data
9.1 The Service provides functionality enabling the Subscriber to export Personal Data throughout the term of the Agreement, and the Subscriber is responsible for exporting any Personal Data it wishes to retain. For thirty (30) days after expiry or termination of the Agreement (the “Retrieval Period”), the Subscriber may elect by written notice to have Personal Data returned to it; SiSo shall satisfy that election by making the Personal Data available via the standard export functionality of the Service. Return by any other means shall be in SiSo’s standard export format and at the Subscriber’s reasonable expense.
9.2 SiSo has no obligation to retain Personal Data after the end of the Retrieval Period, and may securely delete or destroy it within a further sixty (60) days unless applicable law requires longer retention. If requested in writing during the Retrieval Period, SiSo shall provide one written confirmation that deletion has been completed.
9.3 Personal Data contained in backup or archival copies shall be deleted in the ordinary course of SiSo’s backup rotation schedule. Where deletion or return is deferred by applicable law or is technically impracticable, SiSo shall inform the Subscriber, block the affected Personal Data from any further Processing, continue to protect it in accordance with this DPA for so long as it is retained, and shall not Process it for any other purpose.
9.4 SiSo is not required to delete or return Personal Data during the term of the Agreement where doing so would prevent or materially impair its provision of the Service. Any such request shall be treated as an amendment to the Instructions under clause 3.1.
10. Term
This DPA is effective from the date of acceptance of the Agreement and shall continue for so long as the Agreement remains in force. Provisions that by their nature should survive termination – including confidentiality, return and deletion, audit rights and liability – shall continue in force after termination.
This DPA applies to all Processing of Personal Data carried out by SiSo on behalf of the Subscriber in connection with the Service, including Processing that took place before the Effective Date (for example during any trial, pilot, proof of concept or evaluation). Nothing in this clause extends any limitation period, or gives rise to any claim in respect of that earlier Processing that could not have been brought under the arrangements in place at the time.
SiSo may update this DPA from time to time to reflect changes in Applicable Data Protection Law, regulatory guidance or SiSo’s processing activities. SiSo will provide Subscribers with at least 30 days’ prior written notice of any material changes (or such shorter notice as is required to comply with applicable law or regulatory guidance). Changes required by applicable law may take effect immediately. The Subscriber’s continued use of the Service after the effective date of any update constitutes acceptance of the updated DPA. If the Subscriber does not accept a material change, it may terminate the Agreement on written notice within the notice period without liability for early termination fees.
11. Liability
The liability of each Party under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Each Party’s total aggregate liability arising under or in connection with this DPA shall not exceed the liability cap set out or incorporated in in the Agreement.
Nothing in this DPA limits or excludes any liability that cannot lawfully be limited or excluded, including liability for death or personal injury caused by negligence or for fraud or fraudulent misrepresentation.
Where the EU SCCs or IDTA apply, their liability provisions shall take precedence over this clause 11 to the extent of any conflict.
12. General
12.1 Governing Law and Jurisdiction
This DPA is governed by the laws of England and Wales. The Parties submit to the exclusive jurisdiction of the courts of England and Wales in respect of any dispute arising out of or in connection with this DPA, save that where the EU SCCs require a different governing law or jurisdiction, those provisions shall govern the SCCs themselves.
12.2 Order of Precedence
In the event of any conflict or inconsistency relating to the Processing of Personal Data, the following order of precedence shall apply: (1) the EU SCCs or IDTA (as applicable); (2) this DPA; (3) the Agreement.
12.3 Severability
If any provision of this DPA is held to be invalid, illegal or unenforceable by a court of competent jurisdiction, the remaining provisions shall continue in full force and effect.
12.4 Entire Agreement
This DPA, together with the Agreement and (where applicable) the EU SCCs and IDTA, constitutes the entire agreement between the Parties with respect to the Processing of Personal Data in connection with the Service and supersedes all prior representations and agreements relating to the same subject matter.
12.5 No Third-Party Rights
Except as provided in the EU SCCs or the IDTA, this DPA does not confer any rights on any third party.
12.6 Electronic Acceptance
This DPA forms part of and is incorporated into the Terms of Service. By accepting the Terms of Service, entering into a Order Form, or using the Services, the Subscriber agrees to be bound by this DPA.
This DPA may be accepted electronically (including by clickwrap or online agreement), and such acceptance shall be as legally effective as a physically signed document.
SCHEDULE 1
Processing Details
Controller/Processor Relationship: As described in clause 2.1.
Subject Matter: SiSo provides a SaaS platform for M&A-related services, including transaction management and due diligence, enabling the Subscriber and its authorised users to, amongst other things, upload, store, access, manage and share information, documents and transaction materials. Personal Data may be incidentally present in materials uploaded to the platform.
Nature of Processing: Storage, access control, retrieval, sharing and deletion of information, documents and other materials uploaded to the platform; user account management; platform administration; technical support.
Purpose of Processing: To provide the Service to the Subscriber in accordance with the Agreement, as instructed by the Subscriber. SiSo does not Process Personal Data for any purpose beyond provision of the Service.
Duration: For the term of the Agreement and thereafter as required by applicable law, or until deletion is completed in accordance with clause 9.
Categories of Data Subjects:
As determined and controlled by the Subscriber. May include:
Categories of Personal Data:
As determined and controlled by the Subscriber in its sole discretion. The platform is not designed as a personal data processing tool and Personal Data typically appears incidentally in information and documents. Categories may include:
Special Categories of Data:
The platform is not designed or intended for the Processing of Special Categories of Data. If the Subscriber uploads materials containing Special Categories of Data, the Subscriber is solely responsible for ensuring that an appropriate legal basis and suitable safeguards exist for their Processing. SiSo does not knowingly target or specifically seek to Process Special Categories of Data.
SCHEDULE 2
Approved Sub-Processors
See list maintained at www.sisotechnologies.com/subprocessors.
SCHEDULE 3
Technical and Organisational Security Measures
SiSo holds ISO/IEC 27001:2022 certification in respect of its information security management system. The following measures form part of SiSo's certified ISMS and are reviewed and updated in accordance with that framework.
SiSo implements and maintains the following technical and organisational measures to protect Personal Data against the risks described in Article 32 GDPR.
| Category | Measures |
|---|---|
| Access Controls | Role-based access controls (RBAC) restricting access to Personal Data to authorised personnel only; multi-factor authentication (MFA) required for access to production systems; principle of least privilege applied to all system and database access; periodic access reviews. |
| Encryption | Encryption of Personal Data in transit using TLS 1.2 or higher; encryption of Personal Data at rest using AES-256 or equivalent industry-standard algorithm. |
| Data Segregation | Logical segregation between Subscriber environments on the platform to prevent cross-Subscriber access to data. |
| Availability and Resilience | Redundant cloud infrastructure with automated failover capabilities; regular automated backups with tested restoration procedures; business continuity and disaster recovery plans maintained and tested periodically. |
| Incident Management | Security incident detection, classification and response procedures; Personal Data Breach identification, containment, investigation and notification processes aligned with clause 3.6 of this DPA. |
| Vulnerability Management | Regular automated vulnerability scanning; periodic penetration testing by qualified third parties; patch management process for known vulnerabilities in systems Processing Personal Data. |
| Secure Development | Secure development lifecycle (SDLC) incorporating security requirements analysis, secure coding standards, and security testing in development and acceptance; secure system architecture and engineering principles applied to all software development activities; annual secure coding and security awareness training for all software developers. |
| Personnel | Confidentiality obligations imposed on all personnel with access to Personal Data; role-appropriate security awareness training. |
| Sub-Processor Oversight | Security and data protection due diligence conducted on Sub-Processors prior to engagement; contractual security obligations imposed on Sub-Processors consistent with this DPA. |
| Monitoring and Logging | Audit logging of access to systems Processing Personal Data; monitoring for anomalous or suspicious activity; log retention in accordance with SiSo's security policies. |
| Physical Security | Data centre physical access controls (locked facilities, access card controls, CCTV monitoring) operated by SiSo's infrastructure providers; SiSo relies on its hosting providers' physical security controls for data centre facilities. |