Ryniqo OÜ · Legal Pack
Legal · DPA

Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of the agreement between Ryniqo OÜ (“Processor”) and the customer entity (“Controller”) for the RynIQ™ Platform and related services. It gives effect to Article 28 of the GDPR and, where applicable, the UK GDPR and the Swiss FADP.

Version2.0EffectiveOn publication
SupersedesGoverning lawEstonia · EU
Section 01

Subject matter and duration

The Processor processes personal data on behalf of the Controller solely to deliver the services set out in the agreement between the parties, including the Executive Decision Snapshot, the Executive Decision Review and the Executive Decision Brief. Processing continues for the term of that agreement and thereafter only as strictly required by law or Section 10.

Section 02

Nature and purpose of processing

  • Collection of executive assessment responses through the Platform.
  • Structuring, clustering and summarisation using AI models under human oversight.
  • Delivery of Snapshots and Briefs to the Controller.
  • Retention and access management, security monitoring, and audit logging.
  • Support and account management on Controller instruction.
Section 03

Types of personal data and categories of data subjects

Categories of data subjectsTypes of personal data
Controller's executives, employees, workshop participantsName, business email, role, company, responses to executive questions, workshop notes, meeting metadata
Controller's business contactsName, business email, role, correspondence
Section 04

Processor obligations

  • Process personal data only on documented instructions of the Controller (including as set out in the agreement).
  • Ensure persons authorised to process personal data are bound by written confidentiality obligations.
  • Implement the technical and organisational measures in Annex II.
  • Assist the Controller in fulfilling data subject requests and DPIAs where reasonably required.
  • Notify the Controller of a personal data breach affecting Controller Data without undue delay and, where feasible, within 72 hours.
  • Make available all information necessary to demonstrate compliance and, on reasonable notice and under confidentiality, contribute to audits (once per year, or where required by a supervisory authority).
Section 05

Controller obligations

  • Establish and maintain a valid lawful basis for its processing.
  • Provide required notices to its data subjects.
  • Instruct the Processor only to process personal data that is lawful, adequate, relevant and limited to what is necessary.
  • Refrain from submitting special-category data or payment card data to the Platform.
Section 06

Subprocessors

The Controller provides general authorisation for the Processor to engage the subprocessors listed at /legal/subprocessors. The Processor will notify the Controller of any intended change to the list, giving 30 days for the Controller to object on reasonable, documented data protection grounds. If the parties cannot agree, the Controller may terminate the affected service, receiving a pro-rata refund of prepaid Fees for undelivered periods.

The Processor imposes on each subprocessor data protection obligations no less protective than those in this DPA.

Section 07

International transfers

Where a transfer takes place to a country outside the EEA that is not the subject of an adequacy decision, the parties enter into the applicable modules of the 2021 EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), the UK IDTA or Addendum where the UK GDPR applies, and equivalent instruments for Switzerland. Docking clauses are accepted where relevant.

Section 08

Security

The Processor implements and maintains the measures set out in Annex II. Measures are reviewed at least annually and updated in line with the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing.

Section 09

Incident notification

The Processor notifies the Controller of a confirmed personal data breach affecting Controller Data via email to the Controller's designated contact. Notifications include, to the extent known: nature of the breach, categories and approximate number of data subjects and records affected, likely consequences and measures taken or proposed.

Section 10

Return and deletion

On termination, the Processor deletes or returns all Controller personal data within 30 days at the Controller's option, unless retention is required by law. Backups are overwritten according to the standard backup rotation and are not restored.

Section 11

Liability

Each party's liability under this DPA is subject to the limitations of liability in the master agreement between the parties, except for liabilities that cannot be limited by law (including data subject damages under Article 82 GDPR).

Section 12

Order of precedence

In the event of a conflict, the SCCs prevail over this DPA, this DPA prevails over the master agreement in respect of data protection, and the master agreement prevails on all other matters.

Appendix I

Details of processing

ItemValue
ControllerThe customer identified in the applicable order form
ProcessorRyniqo OÜ, Republic of Estonia
Nature of processingSaaS delivery of RynIQ™ platform and associated executive services
PurposeExecutive Decision Intelligence: Snapshot, Review, Brief
DurationTerm of the master agreement and any legally required retention thereafter
FrequencyContinuous during the term
Data subjectsSee Section 03
Data categoriesSee Section 03
Special categoriesNone. Controller undertakes not to submit special-category data
RetentionAs set out in the Privacy Policy §05
Appendix II

Technical and organisational measures

  • Encryption of personal data in transit (TLS 1.2 or higher) and at rest (AES-256).
  • Multi-factor authentication for all administrative access.
  • Least-privilege access control with quarterly review of privileged accounts.
  • Row-level authorisation enforced at the database layer for tenant isolation.
  • Structured audit logging with a minimum 12-month retention.
  • Regular encrypted backups with tested restoration procedures.
  • Documented incident response process with named responder.
  • Secure software development lifecycle with code review, dependency scanning and security testing before release.
  • Vendor assessment of subprocessors before engagement.
  • Personnel confidentiality obligations and security training on hire and annually.
  • Environment separation for development, staging and production.
  • Business continuity plan tested at least annually.
Appendix III

List of subprocessors

The current list is published at /legal/subprocessors and is incorporated by reference.

Execution

Signed copy on request

A counter-signed copy of this Data Processing Agreement is available upon request for enterprise customers. Please contact privacy@ryniqo.com with your entity name, registered address, and the name and title of the authorised signatory. Where a customer prefers to execute its own DPA, we will negotiate against this document as the reference text.