Data Processing Agreement

Effective date: 1 March 2026

1. Definitions

2. Scope and roles

3. Controller obligations

4. Processor obligations — instructions

5. Confidentiality

6. Security measures

7. Sub-processors

8. Data subject rights

9. Data breach notification

10. International data transfers

11. Audit rights

12. Deletion and return of data

13. Liability

14. Term and termination

15. Governing law

16. Appendix A — Processing details

17. Appendix B — Technical and organisational measures

18. Appendix C — Approved sub-processors

19. Appendix D — US / CCPA Service Provider Addendum

20. Execution