Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the agreement between Ryniqo OÜ (“Processor”) and the customer entity (“Controller”) for the RynIQ™ Platform and related services. It gives effect to Article 28 of the GDPR and, where applicable, the UK GDPR and the Swiss FADP.
| Version | 2.0 | Effective | On publication |
|---|---|---|---|
| Supersedes | — | Governing law | Estonia · EU |
Subject matter and duration
The Processor processes personal data on behalf of the Controller solely to deliver the services set out in the agreement between the parties, including the Executive Decision Snapshot, the Executive Decision Review and the Executive Decision Brief. Processing continues for the term of that agreement and thereafter only as strictly required by law or Section 10.
Nature and purpose of processing
- Collection of executive assessment responses through the Platform.
- Structuring, clustering and summarisation using AI models under human oversight.
- Delivery of Snapshots and Briefs to the Controller.
- Retention and access management, security monitoring, and audit logging.
- Support and account management on Controller instruction.
Types of personal data and categories of data subjects
| Categories of data subjects | Types of personal data |
|---|---|
| Controller's executives, employees, workshop participants | Name, business email, role, company, responses to executive questions, workshop notes, meeting metadata |
| Controller's business contacts | Name, business email, role, correspondence |
Processor obligations
- Process personal data only on documented instructions of the Controller (including as set out in the agreement).
- Ensure persons authorised to process personal data are bound by written confidentiality obligations.
- Implement the technical and organisational measures in Annex II.
- Assist the Controller in fulfilling data subject requests and DPIAs where reasonably required.
- Notify the Controller of a personal data breach affecting Controller Data without undue delay and, where feasible, within 72 hours.
- Make available all information necessary to demonstrate compliance and, on reasonable notice and under confidentiality, contribute to audits (once per year, or where required by a supervisory authority).
Controller obligations
- Establish and maintain a valid lawful basis for its processing.
- Provide required notices to its data subjects.
- Instruct the Processor only to process personal data that is lawful, adequate, relevant and limited to what is necessary.
- Refrain from submitting special-category data or payment card data to the Platform.
Subprocessors
The Controller provides general authorisation for the Processor to engage the subprocessors listed at /legal/subprocessors. The Processor will notify the Controller of any intended change to the list, giving 30 days for the Controller to object on reasonable, documented data protection grounds. If the parties cannot agree, the Controller may terminate the affected service, receiving a pro-rata refund of prepaid Fees for undelivered periods.
The Processor imposes on each subprocessor data protection obligations no less protective than those in this DPA.
International transfers
Where a transfer takes place to a country outside the EEA that is not the subject of an adequacy decision, the parties enter into the applicable modules of the 2021 EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), the UK IDTA or Addendum where the UK GDPR applies, and equivalent instruments for Switzerland. Docking clauses are accepted where relevant.
Security
The Processor implements and maintains the measures set out in Annex II. Measures are reviewed at least annually and updated in line with the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing.
Incident notification
The Processor notifies the Controller of a confirmed personal data breach affecting Controller Data via email to the Controller's designated contact. Notifications include, to the extent known: nature of the breach, categories and approximate number of data subjects and records affected, likely consequences and measures taken or proposed.
Return and deletion
On termination, the Processor deletes or returns all Controller personal data within 30 days at the Controller's option, unless retention is required by law. Backups are overwritten according to the standard backup rotation and are not restored.
Liability
Each party's liability under this DPA is subject to the limitations of liability in the master agreement between the parties, except for liabilities that cannot be limited by law (including data subject damages under Article 82 GDPR).
Order of precedence
In the event of a conflict, the SCCs prevail over this DPA, this DPA prevails over the master agreement in respect of data protection, and the master agreement prevails on all other matters.
Details of processing
| Item | Value |
|---|---|
| Controller | The customer identified in the applicable order form |
| Processor | Ryniqo OÜ, Republic of Estonia |
| Nature of processing | SaaS delivery of RynIQ™ platform and associated executive services |
| Purpose | Executive Decision Intelligence: Snapshot, Review, Brief |
| Duration | Term of the master agreement and any legally required retention thereafter |
| Frequency | Continuous during the term |
| Data subjects | See Section 03 |
| Data categories | See Section 03 |
| Special categories | None. Controller undertakes not to submit special-category data |
| Retention | As set out in the Privacy Policy §05 |
Technical and organisational measures
- Encryption of personal data in transit (TLS 1.2 or higher) and at rest (AES-256).
- Multi-factor authentication for all administrative access.
- Least-privilege access control with quarterly review of privileged accounts.
- Row-level authorisation enforced at the database layer for tenant isolation.
- Structured audit logging with a minimum 12-month retention.
- Regular encrypted backups with tested restoration procedures.
- Documented incident response process with named responder.
- Secure software development lifecycle with code review, dependency scanning and security testing before release.
- Vendor assessment of subprocessors before engagement.
- Personnel confidentiality obligations and security training on hire and annually.
- Environment separation for development, staging and production.
- Business continuity plan tested at least annually.
List of subprocessors
The current list is published at /legal/subprocessors and is incorporated by reference.