Data Processing Agreement (DPA) – ORIVYS
This Data Processing Agreement (“Agreement”) forms part of the Terms and Conditions between:
Exoter Technologies Ltd
Company number: 16683767
Registered office: 5, Yard 12 Wildman Street, Kendal, Cumbria, LA9 6EN
(“Processor”)
and
the Customer identified in the Order Form
(“Controller”)
1. Purpose and Scope
This Agreement governs the processing of personal data by the Processor on behalf of the Controller in connection with the provision of the ORIVYS platform.
This Agreement is intended to comply with Article 28 of the UK GDPR and, where applicable, the EU GDPR.
2. Definitions
- Personal Data: any information relating to an identified or identifiable individual
- Processing: any operation performed on Personal Data
- Controller: the entity determining the purposes and means of processing
- Processor: the entity processing Personal Data on behalf of the Controller
- Applicable Data Protection Law: UK GDPR, Data Protection Act 2018, and (where applicable) EU GDPR
3. Roles of the Parties
The Controller:
- determines the purposes and means of processing
- is responsible for lawful collection and use of Personal Data
The Processor:
- processes Personal Data only on documented instructions from the Controller
- does not determine purposes of processing
4. Processing Instructions
The Processor shall:
- process Personal Data only on documented instructions from the Controller
- not process Personal Data for its own purposes
- immediately inform the Controller if an instruction appears to infringe applicable law
5. Confidentiality
The Processor shall ensure that all personnel authorised to process Personal Data:
- are subject to confidentiality obligations
- receive appropriate data protection training
6. Security Measures
The Processor shall implement appropriate technical and organisational measures, including:
- encryption of data in transit and at rest
- secure cloud infrastructure (Google Cloud Platform)
- access controls and authentication mechanisms
- monitoring and logging of system activity
- regular security testing, including penetration testing
These measures are designed to ensure a level of security appropriate to the risk.
7. Sub-processors
The Controller authorises the Processor to use the following sub-processors:
- Google Cloud Platform (UK – London region) – hosting
- Stripe – payment processing
- MailerSend – email delivery
The Processor shall:
- ensure sub-processors are bound by data protection obligations equivalent to this Agreement
- remain fully liable for the acts and omissions of sub-processors
The Processor may update the list of sub-processors upon reasonable notice.
8. International Transfers
Where Personal Data is transferred outside the UK or EEA, the Processor shall ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs), or
- equivalent lawful transfer mechanisms
9. Assistance to the Controller
The Processor shall assist the Controller, where reasonably required, in:
- responding to data subject requests
- conducting data protection impact assessments (DPIAs)
- consulting supervisory authorities
- complying with data protection obligations
10. Personal Data Breach
The Processor shall:
- notify the Controller without undue delay upon becoming aware of a Personal Data breach
- provide reasonable information to assist the Controller in meeting its obligations
11. Data Subject Rights
Taking into account the nature of processing, the Processor shall assist the Controller in responding to requests relating to:
- access
- rectification
- erasure
- restriction
- portability
- objection
12. Data Retention, Return and Deletion
Upon termination of the Services:
- Personal Data shall be retained for a limited period (typically up to 45 days)
- during this period, restoration or access may be provided at the Processor’s discretion and subject to payment of outstanding fees
The Processor is not obliged to provide access, return, or restoration of Personal Data unless outstanding fees are paid in full.
After the retention period:
- Personal Data may be permanently deleted
Personal Data may remain in secure backups for a limited additional period before being overwritten.
13. Audit and Compliance
The Processor shall make available information reasonably necessary to demonstrate compliance with this Agreement.
Audits shall:
- be subject to reasonable notice
- not unreasonably disrupt operations
- be limited to once per year unless required by law
14. Liability
Liability shall be governed by the Terms and Conditions between the parties.
15. Duration
This Agreement shall remain in force for as long as the Processor processes Personal Data on behalf of the Controller.
Annex 1 – Details of Processing
Subject matter
Provision of ORIVYS SaaS platform
Duration
For the duration of the subscription and any applicable retention period
Nature of processing
- storage
- organisation
- retrieval
- transmission
- deletion
Purpose
Provision of software services for operational, administrative, and data management purposes
Categories of data subjects
- employees
- contractors
- students
- service users
- members
- customers
Types of Personal Data
- names
- contact details (email, phone)
- role and organisational data
- operational records
Special category data (may be processed)
- health-related data
- care-related data
Children’s data (may be processed)
- where the Controller uses the Service for educational or youth-related purposes
Annex 2 – Security Measures
The Processor implements:
- encryption in transit (HTTPS/TLS)
- encryption at rest (cloud infrastructure level)
- role-based access controls
- authentication and access management
- system monitoring and logging
- secure hosting in Google Cloud Platform (UK region)
- periodic security testing