This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("you" or the "Controller") and Omegamatrix Software Computer Trading LLC SPC of Abu Dhabi, United Arab Emirates, operating the PrivMatrix service (the "Processor", "we" or "us"), under which we provide the PrivMatrix service (the "Service"). It sets out how we process personal data on your behalf. Where you require a counter-signed copy, email info@privmatrix.com.
"Personal data", "processing", "controller", "processor", "sub-processor", "data subject" and "personal data breach" have the meanings given in applicable data protection law. "Applicable data protection law" means the data protection and privacy laws that apply to your use of the Service, which may include the EU and UK GDPR, the UAE Personal Data Protection Law, the Saudi PDPL, India's Digital Personal Data Protection Act and other laws in the markets you operate in. "Customer personal data" means personal data we process on your behalf under the agreement, described in Annex 1.
You are the controller of the customer personal data and we are your processor. Each party will comply with its own obligations under applicable data protection law. Where you are yourself a processor acting for a third-party controller, you appoint us as a sub-processor and confirm you have the authority to do so.
We process customer personal data only on your documented instructions, including as set out in this DPA, the agreement and your use of the Service's features. If we believe an instruction breaches applicable data protection law, we will tell you (unless the law prevents us). The subject matter, duration, nature and purpose of the processing, and the categories of data and data subjects, are described in Annex 1.
We will: (a) process customer personal data only on your instructions; (b) ensure that people authorised to process it are bound by confidentiality; (c) implement the technical and organisational measures in Annex 2; (d) respect the conditions in clause 6 for engaging sub-processors; (e) assist you as set out in clause 7; (f) make available the information reasonably needed to show compliance with this DPA; and (g) delete or return the data as set out in clause 10.
We keep customer personal data confidential and only give access to staff and sub-processors who need it to provide the Service. Those people are subject to appropriate confidentiality obligations and receive guidance on their responsibilities.
We maintain appropriate technical and organisational measures to protect customer personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Our current measures are described in Annex 2 and summarised on our Trust Center. We may update them as the Service evolves, provided the level of protection is not reduced.
You give us general authorisation to engage sub-processors to help provide the Service. Our current sub-processors are listed on our Trust Center and in Annex 3. We impose data protection obligations on each sub-processor that are no less protective than this DPA, and we remain responsible to you for their performance.
We will give you a reasonable opportunity to be notified of any intended change involving the addition or replacement of a sub-processor by maintaining the published list and, where you have asked to be added to our notice list, by emailing you. If you have a reasonable data protection objection, we will work with you in good faith to address it.
Taking into account the nature of the processing, we will assist you with appropriate technical and organisational measures, so far as reasonably possible, to: (a) respond to requests from data subjects exercising their rights; and (b) meet your obligations around security, breach notification, data protection impact assessments and prior consultation with regulators. Because the Service lets you view, export and delete much of the customer personal data yourself, that self-service functionality is a primary way we provide this assistance.
We will notify you without undue delay after becoming aware of a personal data breach affecting customer personal data, and provide the information reasonably available to help you meet any notification duties you have. We will take reasonable steps to contain and remediate the breach.
Customer personal data is primarily hosted in the United Kingdom. Where providing the Service involves transferring customer personal data to a country that applicable data protection law treats as not providing an adequate level of protection, we will put an appropriate safeguard in place, such as standard contractual clauses, or rely on another lawful transfer mechanism.
On the end of the Service, or on your written request, we will delete or return customer personal data and delete existing copies, unless applicable law requires us to keep it. Our standard retention periods, after which data is deleted in the ordinary course, are published on our Trust Center and in our Privacy Notice.
We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and no more than once a year (unless a regulator requires otherwise or following a breach), allow for and contribute to an audit conducted by you or an independent auditor you appoint, subject to confidentiality and to reasonable measures that protect the security and privacy of our other customers.
This DPA forms part of and is subject to the agreement. If there is a conflict on the subject of data protection, this DPA prevails. Our total liability under this DPA is subject to the limitations of liability in the agreement. This DPA does not create any greater liability than applicable data protection law imposes on a processor. If any provision is found unenforceable, the rest continues in effect.
| Subject matter | Provision of the PrivMatrix privacy-compliance service, including generating compliance documents from your inputs. |
|---|---|
| Duration | For the term of the agreement, plus the retention periods on our Trust Center. |
| Nature and purpose | Collecting, storing, organising and generating documents from the data you enter, and operating your account. |
| Categories of data subjects | Your personnel who use the Service, and any individuals referenced in the intake information you choose to enter. |
| Categories of personal data | Contact and account details (name, work email, company, role, phone); assessment answers; intake and processing-activity information you provide; billing details. Do not enter special-category data unless necessary. |
The current sub-processor list, kept up to date, is published at the Trust Center. It covers our cloud hosting provider (United Kingdom), our transactional email provider and Stripe (payments).
← Back to the Trust Center