Data Processing Addendum
Last updated: June 16, 2026
1. Scope and order of precedence
This Data Processing Addendum (the "DPA") forms part of, and is incorporated into, the agreement between Assenture and the customer for the use of the Service (the "Agreement", which includes our Terms of Service). It applies to the extent that Assenture processes personal data on behalf of the customer in the course of providing the Service. In the event of a conflict between the body of the Agreement and this DPA in relation to the processing of personal data, this DPA prevails.
2. Definitions
Capitalised terms used but not defined here have the meaning given in the Agreement or in Applicable Data Protection Law. "Applicable Data Protection Law" means all laws and regulations applicable to the processing of personal data under the Agreement, including the Singapore Personal Data Protection Act 2012 (PDPA), the EU General Data Protection Regulation 2016/679 (GDPR), the UK Data Protection Act 2018 and the UK GDPR, the California Consumer Privacy Act as amended by the CPRA (CCPA), and any equivalent laws. "Customer Personal Data" means personal data contained in customer content processed by Assenture under the Agreement. "Sub-processor" means any third party engaged by Assenture to process Customer Personal Data.
3. Roles of the parties
With respect to Customer Personal Data, the customer is the controller (or, where the customer is itself a processor, the processor acting on behalf of its own controller) and Assenture is the processor (or sub-processor, as applicable). Each party will comply with its obligations under Applicable Data Protection Law. Assenture acts as an independent controller in respect of account, billing, support, and security telemetry data, which is described in our Privacy Policy.
4. Subject matter and details of processing
Subject matter: provision of the Service. Duration: the term of the Agreement plus any period during which Assenture retains Customer Personal Data in accordance with section 11. Nature and purpose: hosting, storage, transmission, indexing, analysis, backup, and related processing necessary to provide and support the Service. Types of personal data: as determined by the customer, typically including names, contact details, employment and financial information of the customer's employees, contractors, suppliers, customers and other contacts, and any other categories the customer chooses to submit. Categories of data subjects: the customer's employees, contractors, suppliers, customers, and other contacts.
5. Customer instructions
Assenture will process Customer Personal Data only on documented instructions from the customer, including with regard to transfers to a third country, unless required to do otherwise by law (in which case Assenture will, where legally permitted, inform the customer of that requirement before processing). The Agreement, the customer's configuration of the Service, and the customer's use of supported features constitute the customer's documented instructions.
6. Confidentiality
Assenture ensures that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations, are trained in data protection and security, and access Customer Personal Data only on a need to know basis.
7. Security (Annex II)
Assenture implements and maintains appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, the data. These measures include, at a minimum:
- encryption of Customer Personal Data in transit using TLS 1.2 or higher;
- encryption of Customer Personal Data at rest using industry standard algorithms;
- logical separation of customer data;
- role based access control and least privilege for personnel;
- multi factor authentication for administrative access;
- centralised logging and tamper evident audit trails;
- regular vulnerability scanning and at least annual penetration testing;
- change management, secure software development, and code review;
- backup, restore testing, and documented business continuity and disaster recovery plans;
- vendor risk management for sub-processors;
- security awareness training for personnel;
- an incident response plan with defined roles and timelines.
Assenture may update these measures from time to time provided that the level of security is not materially decreased.
8. Sub-processors
The customer authorises Assenture to engage sub-processors to process Customer Personal Data in connection with providing the Service. The current list of sub-processors, including their function and the country in which they operate, is set out in our Privacy Policy and is available on request. Assenture will impose, by written contract, data protection obligations on each sub-processor that are no less protective than those in this DPA, and remains liable to the customer for the acts and omissions of its sub-processors as if they were its own.
Assenture will give the customer at least 30 days prior notice (by email or in the Service) before adding or replacing a sub-processor. If the customer reasonably objects on data protection grounds within that period, the parties will work in good faith to find a resolution. If no resolution is reached, the customer may terminate the affected portion of the Service for convenience without penalty and receive a pro rata refund of prepaid fees for the unused portion.
9. International transfers
Where Customer Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland is transferred to a country that has not been the subject of an adequacy decision, the parties agree that the Standard Contractual Clauses approved by the European Commission in Decision 2021/914 (as amended), the UK International Data Transfer Addendum, and the Swiss equivalent (as applicable) are incorporated into this DPA by reference. The customer is the data exporter and Assenture is the data importer. Module Two (controller to processor) applies between the customer and Assenture; Module Three (processor to processor) applies where the customer is itself a processor. Optional clauses are not selected unless we expressly agree in writing.
Personal data originating in Singapore is transferred in accordance with the PDPA. Where required, Assenture takes appropriate steps to ensure that overseas recipients are bound by legally enforceable obligations to provide a standard of protection comparable to that under the PDPA.
10. Data subject requests and cooperation
Assenture provides functionality within the Service to enable the customer to access, correct, delete, restrict, and export Customer Personal Data. To the extent the customer cannot achieve a required action using the Service, Assenture will, taking into account the nature of the processing, provide reasonable assistance to the customer in responding to requests from data subjects. If a data subject contacts Assenture directly in relation to Customer Personal Data, Assenture will, where lawful, refer them to the customer.
Assenture will also provide reasonable assistance to the customer with data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of the processing and the information available to Assenture.
11. Personal data breach
Assenture will notify the customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will include the information required by Applicable Data Protection Law to the extent reasonably available, and Assenture will provide updates as more information becomes known. Assenture will take reasonable steps to contain and mitigate the breach. This DPA does not require Assenture to admit fault or liability.
12. Audits
Assenture makes available to the customer information reasonably necessary to demonstrate compliance with this DPA, including summary results of third party audits and certifications it holds. On reasonable prior written notice and no more than once per twelve month period (unless required by a supervisory authority or following a substantiated personal data breach), the customer may carry out an audit of Assenture's compliance with this DPA, at the customer's expense, during business hours, in a manner that does not interfere with Assenture's operations and that respects the confidentiality of other customers.
13. Return and deletion
On termination or expiry of the Agreement the customer may, within 30 days, export Customer Personal Data through the Service. After that period, Assenture will delete or anonymise Customer Personal Data within 90 days, except where retention is required by law. Backups containing Customer Personal Data are deleted in accordance with our documented backup rotation schedule, after which they are overwritten in the ordinary course of operations.
14. Liability
Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this DPA limits any data subject's rights under Applicable Data Protection Law.
15. Conflict and survival
If any part of this DPA is held to be invalid or unenforceable, the remainder remains in full force and effect. This DPA survives termination or expiry of the Agreement for as long as Assenture processes Customer Personal Data.
16. Acceptance
By using the Service the customer accepts this DPA. Customers who require a countersigned copy may request one by writing to business@assenture.app.