Data Processing Agreement (DPA)

This Data Processing Agreement and its Annex (collectively, the "DPA") is part of the Terms of Service between You and Us (the "Terms") and sets forth the terms and conditions relating to the Processing of Personal Data by Us. For the purpose of this DPA, the Parties agree that We act as a Processor and You act as a Controller, as those terms are defined under applicable Data Protection Laws. In some cases where You act as a Processor for an end user, We will act as a Subprocessor. All capitalized terms not defined in this DPA will have the meaning set forth in the Terms and the Data Protection Laws.
1. Definitions
"CCPA" means the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq., and its implementing regulations, as amended from time to time.
"Controller" means the entity that determines the means and purposes of the Processing of Personal Data.
"Customer Personal Data" means any Personal Data that Sendigram processes on your behalf as a Processor in the course of providing Services, as more particularly described in this DPA.
"Data Protection Laws" means all laws and regulations applicable to the Processing of Personal Data under the DPA, including, without limitation, the CCPA and other laws and regulations of the United States and its states, the GDPR, and other EU Data Protection Laws and regulations, each as amended from time to time.
"Data Subject" means the identified or identifiable person to whom Personal Data relates.
"EEA" means, for the purposes of this DPA, the European Economic Area, the United Kingdom, and Switzerland.
"EU Data Protection Law" means: (i) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data (General Data Protection Regulation) ("GDPR"); and (ii) Directive 2002/58/EC concerning the processing of Personal Data and the protection of privacy in the electronic communications sector, and other applicable laws and regulations of the European Union, the European Economic Area and their member states, Switzerland, and the United Kingdom, as well as applicable national implementations thereof (as may be amended, superseded, or replaced).
"Personal Data" means any information that is protected as personal data or personally identifiable information under applicable Data Protection Laws, such as information describing or relating to: (i) an identified or identifiable natural person or household; or (ii) an identified or identifiable legal entity.
"Processing" or "Data Processing" has the meaning given to it in the GDPR, and "Process", "Processes", and "Processed" will be interpreted accordingly.
"Processor" means the party that Processes Personal Data on behalf of the Controller, including, as applicable, any "Service Provider" as that term is defined by the CCPA and comparable U.S. privacy laws.
"Security Incident" means any unauthorized or unlawful breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
"Subprocessor" means any Processor engaged by Us or our Affiliates to assist in fulfilling its obligations with respect to providing the Services pursuant to the terms or this DPA.
2. Relationship with the Terms
  1. 2.1. If there is any conflict between this DPA and any other provision of the Terms, this DPA will prevail to the extent of that conflict.
  2. 2.2. Any claims brought under or in connection with this DPA will be subject to the provisions of the Terms, including, but not limited to, the exclusions and limitations set forth in the Terms.
  3. 2.3. No one other than a Party to this DPA, its successors, and permitted assignees will have any right to enforce any of its terms.
  4. 2.4. This DPA will be governed by and construed in accordance with the governing law and jurisdiction provisions in the Terms, unless required otherwise by applicable Data Protection Laws.
  5. 2.5. This DPA applies where and only to the extent that Data Protection Laws are applicable to the Processing of Customer Personal Data.
3. Details of Data Processing
  1. 3.1. Role of Parties. The Parties acknowledge and agree that: (i) with regard to the Processing of Customer Personal Data, You are the Controller, and Sendigram is the Processor; and (ii) Sendigram will engage Subprocessors pursuant to the requirements set forth in Section 7 (Subprocessors) below. In some cases, Sendigram might process Customer Personal Data as a Subprocessor on behalf of You if You are using Sendigram's Services as a Processor on behalf of a third-party Controller. In this latter case, it is agreed that the instructions contained in this DPA are indirectly transmitted to Sendigram through You. We may Process Customer Personal Data as a Controller in accordance with our Privacy Policy (available on the Site) in order to manage your Account, provide billing, produce statistics, or defend our rights in court or in a settlement.
  2. 3.2. Description of the Processing. The description of the Processing is detailed in Annex 1 of this DPA.
  3. 3.3. Instructions. We will Process, retain, use, store, or disclose Customer Personal Data only according to your written, documented instructions to perform a specific or general action with regard to Customer Personal Data for the purpose of providing the Services to You pursuant to the Terms ("Instructions"). The Parties agree that the Terms (including this DPA), together with your use of our Services in accordance with the Terms, constitute your complete and final Instructions to Sendigram in relation to the Processing of Customer Personal Data. We will inform You without delay if, in our opinion, an Instruction violates applicable Data Protection Laws or We are unable to follow an Instruction and, where necessary, We will cease all Processing until You issue new Instructions with which We are able to comply.
4. Your obligations
  1. 4.1. Your Processing. You will, when using the Services, Process Personal Data in accordance with the requirements of all applicable Data Protection Laws. You represent and warrant that You have established a lawful basis to Process Personal Data, your use of our Services will not violate the rights of any Data Subject, and You have the right to transfer, or provide access to, the Personal Data to Us for Processing in accordance with the provisions of the Terms (including this DPA). You also warrant that You will Process all Data Subjects' requests within the deadlines required by applicable Data Protection Laws.
  2. 4.2. Your responsibilities. You will have sole responsibility for the accuracy, quality, and lawfulness of Personal Data and the means by which You acquired Personal Data. If You are established in a jurisdiction governed by Data Protection Law(s), or if your Customer Content contains Personal Data of citizens of one or more jurisdictions governed by Data Protection Law(s), You agree to: (i) comply with your obligations as a Controller under applicable Data Protection Laws in respect of your Processing of Customer Personal Data and any Processing Instructions You issue to Us; and (ii) provide notice and obtain all consents from Data Subjects and rights necessary under Data Protection Laws for Us to process Customer Personal Data and provide the Services pursuant to the Terms and this DPA.
  3. 4.3. Data retention. The Parties agree that You (including your Additional Users), and not Sendigram, are responsible for managing the retention periods of Personal Data that You upload onto our Application, and that it is incumbent on You to delete such Personal Data as and when the applicable retention period expires. We are responsible only for deleting or anonymizing data at the end of its contractual relationship with You.
  4. 4.4. No sensitive Personal Data. You undertake not to include in the distribution lists uploaded onto the Application any Personal Data known as "sensitive" within the meaning of Article 9 of the GDPR or as defined in Cal. Civ. Code § 1798.140(ae) of the CCPA or comparable U.S. Data Protection Laws.
  5. 4.5. Notice to Sendigram. You will inform Us without undue delay if You are not able to comply with your obligations under this DPA or any applicable Data Protection Laws. For the avoidance of doubt, We are not responsible for compliance with any Data Protection Laws applicable to You or your industry that are not generally applicable to Us.
5. Our obligations
  1. 5.1. Our Processing. You hereby appoint Us to Process Customer Personal Data on your behalf for the purposes described in the Terms (including this DPA) and our Privacy Policy. We will Process Customer Personal Data in accordance with your Instructions, as further specified in the Terms and this DPA. All Customer Personal Data Processed under the Terms (including this DPA) will be stored, organized, and made available to You as the Controller.
  2. 5.2. Record. We will maintain a record with a list of the Processing operations carried out on behalf of the Controller as required by applicable Data Protection Laws. Such a record will include all the information listed in Article 30(2) of the GDPR.
  3. 5.3. Data destruction or export. You may, at any time during the performance of the Terms: (i) access or delete Customer Personal Data Processed by Us directly via the Site; or (ii) retrieve the data that You have uploaded on the Site or reports relating to the data by clicking on the "Export" button in your Sendigram Account. Upon termination of the Terms, We will, upon your request, destroy all Customer Personal Data within three (3) months of termination. Upon your request, We will provide You with written confirmation of such destruction. Notwithstanding the foregoing, We reserve the right to retain Customer Personal Data for longer periods where a longer retention period is required by applicable law.
  4. 5.4. Security. We undertake to take all commercially reasonable and legally necessary precautions, in respect of the nature of Personal Data and the risks presented by the Processing, to preserve the security of Personal Data and, in particular, to prevent it from being distorted, damaged, or accessed by unauthorized third parties. We will implement and maintain appropriate technical and organizational security and confidentiality measures as detailed in the Security Measures Appendix.
  5. 5.5. Confidentiality. We will treat Customer Personal Data as Confidential Information. We will ensure that only our employees authorized to process Personal Data for the purpose of performing the Services have access to it within the strict limits of what is necessary for the performance of their duties, and these employees undertake to respect the confidentiality of Personal Data.
  6. 5.6. Required disclosure. If We are required by applicable law to disclose Customer Personal Data for a purpose unrelated to the Terms, We will first inform You of the legal requirement and give You an opportunity to object or challenge the requirement, unless the law prohibits such notice. Notwithstanding the foregoing, We will have the right to collect and use Personal Data contained in Customer Personal Data to investigate a use of the Services that is unlawful or violates the Terms, provide and develop the Services, respond to legal actions, or for administrative purposes such as accounting and compliance.
  7. 5.7. Security Incident. We will notify You without undue delay at your email address on file or via your Account on the Site after becoming aware of a Security Incident occurring on our Site or information systems or information systems of our Subprocessor. We will provide such notification in compliance with applicable Data Protection Laws, and such notification will include, at a minimum, the details listed in Article 33(3) of the GDPR.
  8. We will make reasonable efforts to identify the cause of such Security Incident and take such steps as We deem necessary and reasonable to remediate the cause of such a Security Incident to the extent the remediation is within our reasonable control. At your reasonable request, and to the extent We are required to do so under applicable Data Protection Laws, We will promptly provide You with commercially reasonable assistance as necessary to enable You to meet your obligations under applicable Data Protection Laws to notify authorities and/or affected Data Subjects. The obligations herein will not apply to incidents that are caused by You or other users.
6. Assistance and audit
  1. 6.1. Assistance. To the extent You are unable to independently access the relevant Customer Personal Data via the Application, upon your written request and at your expense, We will provide reasonable assistance, taking into account the nature of the Processing and the information available to Us, to enable You to respond to a Data Subject request to exercise rights under applicable Data Protection Laws, or a request from a competent supervisory authority relating to the Processing of Personal Data under the Terms. If any such request is made directly to Us, We will not respond to it ourselves but will assist the Data Subject, where necessary, in identifying You as the Controller and will provide them with your contact details. If We are legally required to directly respond to such a request, We will, without undue delay, notify You and provide You with a copy of the request unless legally prohibited from doing so.
  2. You further instruct Us to directly execute automatic unsubscription requests. In case We receive requests relating to unsolicited communications, prohibited uses of the Services, or potential breaches of these Terms by You or one of our customers, You accept that We may suspend the possibility of sending any electronic communication to the Data Subject's domain.
7. Subprocessors
  1. 7.1. Authorized Subprocessors. You expressly authorize Us to engage the Subprocessors on the List of Subprocessors in Annex 2 as of the start of your Subscription to Process Customer Personal Data pursuant to the Terms (including this DPA). We have entered into a written agreement with each Subprocessor containing data protection obligations not less protective than those in this DPA with respect to the protection of Customer Personal Data to the extent applicable to the nature of the services provided by such Subprocessor.
  2. 7.2. Subprocessor obligations. We will: (i) enter into a written agreement with each Subprocessor imposing data protection terms that require the Subprocessor to protect the Customer Personal Data to the standard required by Data Protection Laws; and (ii) remain responsible for Subprocessor compliance with the obligations of this DPA and for any acts or omissions of the Subprocessor that cause Us to breach any of our obligations under this DPA.
  3. 7.3. Changes to Subprocessors. We will provide notification to You by email or via your Account on the Site of any new Subprocessors before authorizing such new Subprocessor(s) to Process Customer Personal Data. You will have the possibility, in the event of an objection that is justified by a violation of an applicable Data Protection Law, to terminate the Terms within thirty (30) days following the email or notification.
8. U.S. data subjects
  1. 8.1. Definitions. This Section 8 applies to the extent that We Process Personal Data on your behalf that is subject to the protections of the CCPA or comparable U.S. state consumer privacy law ("Personal Information"). For the purposes of this section: (i) "Business", "Service Provider", "Sell", and "Share" will have the meanings given to them in the CCPA or other applicable U.S. state Data Protection Laws; and (ii) the term "Controller" will be interpreted as "Business", the term "Processor" will be interpreted as "Service Provider", and the term "Personal Data" will be interpreted as "Personal Information" throughout this DPA to the extent necessary for alignment with applicable U.S. Data Protection Laws.
  2. 8.2. Responsibilities. The Parties agree that We will Process Personal Information contained in Customer Personal Data as your Service Provider in accordance with the CCPA or other applicable U.S. Data Protection Laws strictly for the business purpose of performing the Services under the Terms. We will not: (i) sell Personal Information contained in Customer Personal Data; (ii) share Personal Information contained in Customer Personal Data with third parties for cross-context behavioral advertising purposes; (iii) retain, use, or disclose Personal Information contained in Customer Personal Data for a commercial purpose other than for such business purpose or as otherwise permitted by applicable U.S. Data Protection Laws; or (iv) retain, use, or disclose Personal Information contained in Customer Personal Data outside of the direct business relationship between You and Us. You agree to remain solely liable for your compliance with applicable Data Protection Laws in your use of our Services.
  3. 8.3. Certification. We certify that We understand and will comply with the restrictions of Section 8.2.
  4. 8.4. No sale of Personal Information. The Parties agree that You do not sell Personal Information to Us because, as a Service Provider, We may only use Personal Information contained in Customer Personal Data for the purposes of providing You with the Services.
9. International transfers
The Services may at times require the Processing of Customer Personal Data outside the EEA where Sendigram, its Affiliates, or our Subprocessors maintain operations. We will at all times provide an adequate level of protection of the Customer Personal Data Processed, in accordance with the requirements of applicable Data Protection Laws, including Standard Contractual Clauses (standardized, pre-approved data protection clauses adopted by the European Commission or other relevant competent authorities to safeguard international data transfers) and supplementary measures. We may rely on the EU-U.S. Data Privacy Framework for transfers to the U.S., as long as this framework remains valid.
ANNEX 1: Description of the Processing
The table below describes the Processing operations carried out by Sendigram on your behalf in connection with the provision of the Services.
Provision of the Services by Sendigram
On your Instructions, We:
  • Organize and segment Customer Personal Data;
  • Automate digital marketing;
  • Send electronic communications via various channels;
  • Make Usage Data available to You to provide analytics and reporting features;
  • Collect, host, analyze, display, and aggregate Customer Personal Data;
  • Modify, update, or delete Customer Personal Data or Usage Data from the Application.
Any Sendigram plan We provide You with the means to implement tracking technologies (pixel and URL tracking) within electronic communications that We send on your behalf. These tracking technologies are necessary to provide the Services and allow the collection of metadata, including Personal Data related to the recipient's email address: IP address, timestamp, click log, and open log. We use the data collected from this tracking to: (i) provide features that allow You to analyze your mailings and know when to send electronic communications at the best time; (ii) monitor the security and availability of the Services; and (iii) create statistics and evaluate the use of the Services. Acting as a Processor, We do not inform the Data Subjects and do not collect their consent on your behalf. For marketing campaigns, the Services allow You to anonymize the data Processed by these tracking technologies and to collect aggregated results. This provision constitutes your written agreement to the deployment of these tracking technologies.
We also provide You with the means to implement online tracking devices necessary for the provision of certain functionalities, such as marketing automation. You are responsible for setting the parameters of these tracking devices, informing the Data Subjects, and obtaining their consent.
You are solely responsible for managing the retention periods for Customer Personal Data and Usage Data in connection with the provision of the Services. It is your responsibility to delete the data as and when the retention period expires. Our sole responsibility is to delete or anonymize such data at the end of the contractual relationship with You.
User data, Customer Personal Data, Usage Data, and Logs.
Any Sendigram plans. If You exclusively use the user interface for marketing features, the following data of the Contact is Processed: identification and contact data as downloaded and entered by the user (name, email address, telephone number, notes, imported documents, contact attributes, or any contact information added by You), as well as Usage Data, which consists of technical information and logs: IP addresses; ratio of openings and clicks collected by pixel tracking and URL tracking; date/time of the email sent; recipient; subject; and content of the email (the email previews of transactional messages can be disabled in the settings). We can also Process other categories of Personal Data if You instruct Us to do so, in particular via the Contact attributes and objects.
If You exclusively use the transactional feature (SMTP or API), Sendigram will only store the above Usage Data. You can choose to deactivate the preview of those logs in the settings.
  • Users
  • Contacts, including any person: (i) whose email address and/or telephone number is included in the Customer Content; (ii) whose information is stored or collected through the Services; or (iii) to whom users send emails or with whom they communicate through the Services.
ANNEX 2: List of Subprocessors
The following Subprocessors are necessary for Us to provide the Services. When marked as "optional", the relevant features will be available to You via the Site, but the listed entity will only be considered your Subprocessor in the event You actually use those specific features of our Services.
Company Subprocessed Activity Company location Server Location Safeguards for the Transfer of Personal Data
Sendigram Infrastructure Subprocessors
OVH US LLC Provision of server hosting and infrastructure services USA Vint Hill (VIN1), USA Standard Contractual Clauses and supplementary measures
Amazon Web Services Australia Pty Ltd (Amazon SES) Email delivery and processing of delivery events Australia EU/USA/Australia Standard Contractual Clauses and supplementary measures
Cobisi Research (trading as Verifalia) Email address validation USA USA Standard Contractual Clauses and supplementary measures
MAIL TESTER LLC (Mail-Tester) Pre-send email testing and deliverability analysis USA USA Standard Contractual Clauses and supplementary measures
Linode LLC Provision of server hosting and infrastructure services USA Dallas, TX, USA Standard Contractual Clauses and supplementary measures
Specific features (optional) These entities become your Subprocessors only if You decide to use these specific features.
OpenAI OpCo, LLC Provision of AI-powered email content and image generation, complete email generation, campaign performance prediction and analysis, and campaign recommendations. USA EU/USA Standard Contractual Clauses and supplementary measures
Google Australia Pty Ltd (Gemini API) Provision of AI-powered email content and image generation, complete email generation, campaign performance prediction and analysis, and campaign recommendations. Australia EU/USA/Australia EU-U.S. Data Privacy Framework; Standard Contractual Clauses and supplementary measures
Anthropic, PBC Provision of AI-powered email content and image generation, complete email generation, campaign performance prediction and analysis, and campaign recommendations. USA USA Standard Contractual Clauses and supplementary measures
Annex 3: Regulatory provisions (DORA)
This Annex applies where We provide You and, as the case may be, your Affiliates, with ICT Services that are subject to DORA, provided that You and said Affiliates are Regulated Financial Institutions and are subject to oversight by a Regulator in relation to the ICT Services being provided under these Terms.
As an exception to the above, this Annex related to DORA will not apply to You if You registered for a Sendigram Free plan. If You are on a Free plan and assess nonetheless that this Annex should be applicable to You, any required adjustments linked to DORA will be subject to additional fees. We then invite you to reach out to the Sales team to request an appropriate quotation.
a. Definitions and interpretation
i) Definitions. Unless otherwise set out below, each capitalized term in this Annex will have the meaning set forth in the Terms. If capitalized terms of this Annex are not defined in the Terms nor in this Annex, they will bear the same meaning as in DORA. In this Annex, unless the context requires otherwise:
"DORA" means the Digital Operational Resilience Act (Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector), as well as any mandatory sector-specific regulation, law, circular, communication, guidance, or industry standard applicable to You.
"ICT Incident" means a single unplanned event or a series of linked unplanned events that compromises the security of the network and information systems and has an adverse impact on the availability, authenticity, integrity, or confidentiality of data, or on the Services provided by You.
"Regulated Financial Institution" means any financial entity as defined in Article 2 of DORA that is authorized, registered, or otherwise regulated by a competent Regulator under applicable European Union or national law.
"Regulator" means any competent authority and resolution authority within the meaning of DORA, entitled to exercise prudential supervision over You and thereby having the legal power to assess your compliance with applicable laws.
"Services" means those tasks, operations, and functions that: (i) qualify as an ICT Service under DORA; and (ii) are to be performed by Us under these Terms.
"Subcontracting" or "Subcontract" means any arrangement whereby We assign, transfer, or otherwise dispose of these Terms (even under a universal transfer) or delegate our rights, obligations, and/or duties hereunder in whole or in part to a third party. For the avoidance of doubt, any acquisition, purchase, or licensing of equipment such as hardware or software does not constitute Subcontracting hereunder.
"Subcontractor" means the third party that has entered into a Subcontracting arrangement with Us.
ii) Interpretation. In the event of inconsistencies or ambiguities in relation to any provision of the Terms, the provision shall be interpreted in such a manner that it is compliant with DORA.
b. Obligations applicable to all Services
The following obligations shall apply to all ICT Services provided under the Terms.
The Parties acknowledge that the ICT Services as provided by Us under the Terms do not support Critical or Important Functions and that We do not provide critical services to You under these Terms.
If You assess nonetheless that Sendigram supports Critical or Important Functions or provides critical services to You, You will be subject to additional fees. In this case, We invite You to reach out directly to our Sales team via the Site to find an approach better suited to your needs.
i) Services. We will provide those Services that are expressly described in the Terms. Such Services will be performed in the manner set forth in the Terms and, as the case may be, the Service Level Agreement.
ii) Service performance and service levels. Unless expressly provided otherwise in the Terms, We will perform the Services at least in accordance with good industry practices, with appropriate diligence and care.
For Services for which a service level is defined in the Service Level Agreement, We will provide such Services in accordance with the agreed-upon service levels.
iii) Subcontracting, service location, and data residency
1. Subcontracting. Unless expressly stated otherwise in the Agreement and without prejudice to the specific provisions regarding the subprocessing of Personal Data as set forth in Annex 2 of this DPA, We are authorized to Subcontract the Services or parts thereof.
2. Service location. We will provide the Services from the locations as described in the Terms or, as the case may be, with regard to the Personal Data, the DPA.
Should We aim to change the location from where the Services are being provided to a location outside the European Economic Area, We will inform You thereof in advance. In any case, We will ensure that such change in location would not prevent your compliance with DORA.
3. Data residency. We will store and Process your data in the location(s) as set forth in the Data Protection Agreement.
Should We aim to change the location where the data is being stored or processed, We will inform You thereof in advance and will ensure that such change in location would not prevent your compliance with DORA.
iv) Confidentiality and security of Customer Personal Data
1. Confidentiality. We, our Subcontractor(s), and their personnel will be bound by appropriate obligations regarding security and confidentiality. We ensure our Subcontractor(s) and all personnel involved in the performance of the Terms are at all times bound by confidentiality undertakings that are no less protective than the confidentiality undertakings set forth in the Terms.
2. Security. We will implement the security, integrity, and authenticity mechanisms that are appropriate in light of the Services to be performed and, as the case may be, will implement the security requirements and policies as communicated to You.
c. Data protection. Please see the main body of this DPA.
d. Restitution of data. Upon any event of termination of the Terms or any event of discontinuity of our business operations or insolvency (an "Exit Event"), We will, in accordance with the modalities agreed upon between You and Us as stated in section 5.3 of the DPA, permit You to retrieve your data in the limits agreed in the Terms and to the extent permitted by DORA.
Notwithstanding anything provided to the contrary either by contract or by law, We and, as the case may be, our receiver or any party acting for and on behalf of Us or our creditors, will abstain from exercising any retention rights that would prevent you from extracting your data.
e. ICT Incident support. To the extent that an ICT Incident occurs in relation to the Services provided by Us, We agree to provide You with all reasonable assistance, subject to pre-agreed additional costs beyond assistance that is already provided for in the Terms, when an ICT Incident occurs that potentially or otherwise will have or has an adverse impact on the Services provided to You. We will notify You without undue delay, after becoming aware of an ICT Incident, at your contact address, and provide You with all reasonable information necessary for You to comply with DORA.
The costs associated with the reasonable assistance mentioned herein will be subject to an order form issued by Us. This order form will encompass the scope of the assistance, as well as the required personnel involved, and will set the professional services fees. These additional fees will be determined in accordance with either one of the following pricing arrangements as agreed in writing between us: fixed fees and/or time & material fees. In the latter case, We apply the current Average Daily Rate (ADR) for each man-day required to perform the assistance.
f. Cooperation with Regulators. We hereby acknowledge that the Regulators, or any persons appointed by them, having jurisdiction over You (or, as the case may be, your clients), have investigative powers enabling them to directly seek assistance and cooperation from Us. To that end, We will, in accordance with applicable laws, comply and, as the case may be, reasonably cooperate with and respond to any requests issued by the Regulator.
We will use best efforts to cooperate with such authorities in the context of their inspections or, more generally, for all requests that they may have in the context of their supervisory or resolution powers. In particular, where You are a credit institution, We acknowledge the information-gathering and investigatory powers of the Regulators (including the resolution authorities), namely:
  • The information-gathering power of resolution authorities under Article 63(1)(a) of Directive 2014/59/EU establishing a framework for the recovery and resolution of credit institutions and investment firms; and
  • The information-gathering and investigatory powers of competent authorities under Article 65(3) of Directive 2013/36/EU on access to the activity of credit institutions and the prudential supervision of credit institutions and investment firms.
To the extent possible, You will provide Us with reasonable notice not less than thirty (30) days ahead of any inspection or audit that would be conducted by the Regulators.
It is specified that in the context of this reasonable assistance, it should not exceed reasonable cooperation nor disturb our ongoing business activity, and that certain measures requested by You may be subject to additional invoicing proportional to the time spent by our teams in handling requests. However, We will agree upfront on the costs regarding the request.
g. Specific termination rights. Without prejudice to your right to terminate the Terms in whole or in part, as already set forth in the Terms, You may terminate them, in whole or in part at Your sole discretion, if the following situations remain uncured by Us within thirty (30) days from receipt of a formal notice, unless remediation is no longer possible. The termination notice shall be provided by electronic means with acknowledgement of receipt, if:
  • We significantly and materially breach applicable laws or DORA-related regulations;
  • Circumstances arise, identified throughout the monitoring of ICT risks, that are deemed capable of adversely and materially impacting the performance of the Services provided by Us, including, but not limited to: (i) material changes that affect the Terms; (ii) any event of discontinuity of our business operations; or (iii) insolvency proceedings against Us, provided these circumstances cannot be corrected within the duration mentioned above;
  • Any evidenced weaknesses arise which pertain to our overall ICT risk management and, in particular, in the way it ensures the availability, authenticity, integrity, and confidentiality of data that is Processed by Us for You, whether Personal Data or otherwise non-personal data. You must provide written evidence of such weakness before terminating the Terms; or
  • The Regulator can no longer effectively supervise You as a result of the conditions of, or circumstances related to, the Terms.
This Data Processing Agreement (DPA) was last updated on: 01/08/2026