Data Processing Agreement (DPA) – ORIVYS

This Data Processing Agreement (“Agreement”) forms part of the Terms and Conditions between:

Exoter Technologies Ltd
Company number: 16683767
Registered office: 5, Yard 12 Wildman Street, Kendal, Cumbria, LA9 6EN
(“Processor”)

and

the Customer identified in the Order Form
(“Controller”)


1. Purpose and Scope

This Agreement governs the processing of personal data by the Processor on behalf of the Controller in connection with the provision of the ORIVYS platform.

This Agreement is intended to comply with Article 28 of the UK GDPR and, where applicable, the EU GDPR.

2. Definitions

  • Personal Data: any information relating to an identified or identifiable individual
  • Processing: any operation performed on Personal Data
  • Controller: the entity determining the purposes and means of processing
  • Processor: the entity processing Personal Data on behalf of the Controller
  • Applicable Data Protection Law: UK GDPR, Data Protection Act 2018, and (where applicable) EU GDPR

3. Roles of the Parties

The Controller:

  • determines the purposes and means of processing
  • is responsible for lawful collection and use of Personal Data

The Processor:

  • processes Personal Data only on documented instructions from the Controller
  • does not determine purposes of processing

4. Processing Instructions

The Processor shall:

  • process Personal Data only on documented instructions from the Controller
  • not process Personal Data for its own purposes
  • immediately inform the Controller if an instruction appears to infringe applicable law

5. Confidentiality

The Processor shall ensure that all personnel authorised to process Personal Data:

  • are subject to confidentiality obligations
  • receive appropriate data protection training

6. Security Measures

The Processor shall implement appropriate technical and organisational measures, including:

  • encryption of data in transit and at rest
  • secure cloud infrastructure (Google Cloud Platform)
  • access controls and authentication mechanisms
  • monitoring and logging of system activity
  • regular security testing, including penetration testing

These measures are designed to ensure a level of security appropriate to the risk.

7. Sub-processors

The Controller authorises the Processor to use the following sub-processors:

  • Google Cloud Platform (UK – London region) – hosting
  • Stripe – payment processing
  • MailerSend – email delivery

The Processor shall:

  • ensure sub-processors are bound by data protection obligations equivalent to this Agreement
  • remain fully liable for the acts and omissions of sub-processors

The Processor may update the list of sub-processors upon reasonable notice.

8. International Transfers

Where Personal Data is transferred outside the UK or EEA, the Processor shall ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs), or
  • equivalent lawful transfer mechanisms

9. Assistance to the Controller

The Processor shall assist the Controller, where reasonably required, in:

  • responding to data subject requests
  • conducting data protection impact assessments (DPIAs)
  • consulting supervisory authorities
  • complying with data protection obligations

10. Personal Data Breach

The Processor shall:

  • notify the Controller without undue delay upon becoming aware of a Personal Data breach
  • provide reasonable information to assist the Controller in meeting its obligations

11. Data Subject Rights

Taking into account the nature of processing, the Processor shall assist the Controller in responding to requests relating to:

  • access
  • rectification
  • erasure
  • restriction
  • portability
  • objection

12. Data Retention, Return and Deletion

Upon termination of the Services:

  • Personal Data shall be retained for a limited period (typically up to 45 days)
  • during this period, restoration or access may be provided at the Processor’s discretion and subject to payment of outstanding fees

The Processor is not obliged to provide access, return, or restoration of Personal Data unless outstanding fees are paid in full.

After the retention period:

  • Personal Data may be permanently deleted

Personal Data may remain in secure backups for a limited additional period before being overwritten.

13. Audit and Compliance

The Processor shall make available information reasonably necessary to demonstrate compliance with this Agreement.

Audits shall:

  • be subject to reasonable notice
  • not unreasonably disrupt operations
  • be limited to once per year unless required by law

14. Liability

Liability shall be governed by the Terms and Conditions between the parties.

15. Duration

This Agreement shall remain in force for as long as the Processor processes Personal Data on behalf of the Controller.

Annex 1 – Details of Processing

Subject matter

Provision of ORIVYS SaaS platform

Duration

For the duration of the subscription and any applicable retention period

Nature of processing

  • storage
  • organisation
  • retrieval
  • transmission
  • deletion

Purpose

Provision of software services for operational, administrative, and data management purposes

Categories of data subjects

  • employees
  • contractors
  • students
  • service users
  • members
  • customers

Types of Personal Data

  • names
  • contact details (email, phone)
  • role and organisational data
  • operational records

Special category data (may be processed)

  • health-related data
  • care-related data

Children’s data (may be processed)

  • where the Controller uses the Service for educational or youth-related purposes

Annex 2 – Security Measures

The Processor implements:

  • encryption in transit (HTTPS/TLS)
  • encryption at rest (cloud infrastructure level)
  • role-based access controls
  • authentication and access management
  • system monitoring and logging
  • secure hosting in Google Cloud Platform (UK region)
  • periodic security testing