Data Processing Addendum
Version 1.1 | Effective date: 23 August 2026
How this addendum applies
This Data Processing Addendum ( "DPA" ) forms part of the Cordaata End User Subscription Agreement ( "Agreement" ) between the Cordaata entity that is party to the Agreement ( "Cordaata" ) and the customer entity identified in the applicable Order ( "Customer" ). "Cordaata" means: (a) Cordaata BV (BE1031907675), Gaaienlaan 19, 2360 Oud-Turnhout, Belgium; or (b) Cordaata Inc., a Delaware corporation, 251 Little Falls Drive, Wilmington, Delaware 19808, USA, in each case as identified in the applicable Order or Agreement. This DPA applies wherever Cordaata processes personal data on Customer's behalf in the course of providing the Services.
Where Customer requires a countersigned version, it may request one by contacting legal@cordaata.com . In the absence of a countersigned version, Customer's acceptance of the Agreement constitutes acceptance of this DPA.
Capitalised terms not defined here have the meanings given in the Agreement.
This DPA is intended to apply under either the European or the United States form of the Agreement. In this DPA: British and United States spellings of the same word have the same meaning (for example, references to "Authorised Users" include "Authorized Users" ); where a term is defined in both this DPA and the Agreement, the definition in this DPA governs for the purposes of this DPA; and references in the Agreement to "Data Protection Laws" and references in this DPA to "Applicable Data Protection Law" each include the other.
1. Definitions
"Applicable Data Protection Law" means all laws and regulations applicable to the processing of Customer Personal Data under this DPA, including: (a) the GDPR and any national implementing legislation, including the Belgian Act of 30 July 2018, where applicable; (b) US State Privacy Laws, where applicable; and (c) any equivalent data protection laws applicable to the processing activities described in this DPA.
"Customer Personal Data" means any personal data contained within Customer Data that Cordaata processes on Customer's behalf in connection with the Services.
"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
"Personal data," "processing," "controller," "processor," "data subject," "personal data breach," and "supervisory authority" have the meanings given in the GDPR. Where US State Privacy Laws apply: "personal data" includes "personal information"; "controller" includes "business"; "processor" includes "service provider"; and "data subject" includes "consumer", in each case as defined in the applicable US State Privacy Law.
"SCCs" means the Standard Contractual Clauses for the transfer of personal data to processors established in third countries, as adopted by the European Commission in Decision C(2021) 3972 of 4 June 2021, Module 2 (controller to processor), as may be amended or replaced by the European Commission from time to time.
"Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data. A Security Incident does not include an unsuccessful attempt or activity that does not compromise the security of Customer Personal Data, including unsuccessful log-in attempts, pings, port scans, denial-of-service attacks, and other network attacks on firewalls or networked systems.
"Sub-processor" means any processor engaged by Cordaata to carry out processing activities on Customer Personal Data on Cordaata's behalf.
"US State Privacy Laws" means the US state privacy and data protection laws applicable to Customer Personal Data, including the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 ( "CCPA" ) and its implementing regulations, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Texas Data Privacy and Security Act, and other comparable US state laws, in each case as amended from time to time.
2. Roles of the parties
Customer is the controller of Customer Personal Data. Cordaata is the processor, processing Customer Personal Data solely on Customer's behalf and in accordance with Customer's documented instructions as set out in this DPA and the Agreement.
Where US State Privacy Laws apply to Customer Personal Data, Customer is the business or controller and Cordaata acts as Customer's service provider or processor within the meaning of those laws, and the additional provisions of Section 10 apply.
Nothing in this DPA prevents Cordaata from processing personal data for its own purposes as a controller, including personal data collected through its website, marketing activities, or its own business operations. Such processing is governed by Cordaata's Privacy Statement at cordaata.com/legal/privacy-policy.html , not this DPA.
As authorised by the Agreement, Cordaata may generate Aggregated Anonymous Data from Customer Personal Data as part of providing the Services. Once data has been aggregated and anonymised such that it can no longer reasonably identify Customer or any individual, it no longer constitutes Customer Personal Data and is not subject to this DPA.
3. Details of processing
The subject matter, nature, purpose, duration, categories of personal data, and categories of data subjects are set out in Schedule 1 to this DPA. Customer may update the description of processing activities in Schedule 1 with Cordaata's prior written agreement, not to be unreasonably withheld, where reasonably necessary to reflect changes in Customer's use of the Services.
4. Processing instructions
Cordaata will process Customer Personal Data only on Customer's documented instructions, which are: (a) as set out in this DPA and the Agreement; (b) as configured by Customer through the platform settings and integrations; and (c) as otherwise provided in writing by Customer's authorised representatives.
If Cordaata is required by applicable law to process Customer Personal Data in a manner other than as instructed, Cordaata will inform Customer before carrying out that processing unless prohibited from doing so by law.
If Cordaata considers that any instruction from Customer infringes Applicable Data Protection Law, Cordaata will promptly notify Customer. Cordaata is not obliged to carry out an instruction it reasonably considers to be unlawful.
Customer represents that it will not submit special categories of personal data or personal data of third parties to the Services except as strictly necessary and in compliance with applicable data protection law. Cordaata is not responsible for personal data incidentally submitted to the Services outside the scope described in Schedule 1.
5. Cordaata's processor obligations
Cordaata will, in relation to Customer Personal Data:
(a) Confidentiality. Ensure that personnel authorised to process Customer Personal Data are subject to appropriate confidentiality obligations, whether by contract or professional duty.
(b) Security. Implement and maintain the technical and organisational security measures described in Schedule 2, in accordance with Article 32 of the GDPR and any equivalent requirements of Applicable Data Protection Law, taking into account the nature, scope, context, and purposes of processing and the risks to data subjects.
(c) Sub-processing. Comply with the requirements of Section 6 before engaging any Sub-processor.
(d) Data subject rights. Taking into account the nature of the processing, provide Customer with reasonable assistance through appropriate technical and organisational measures to fulfil Customer's obligations to respond to data subject and consumer requests under Applicable Data Protection Law, including requests for access, rectification or correction, erasure or deletion, restriction, portability, objection, and opt-out of the sale or sharing of personal information. Cordaata will promptly forward to Customer any data subject or consumer request received directly by Cordaata that relates to Customer Personal Data, and will not respond to such a request itself except to confirm that the request relates to Customer.
(e) Compliance assistance. Provide Customer with reasonable assistance in ensuring compliance with Articles 32 to 36 of the GDPR and any equivalent obligations under Applicable Data Protection Law, including in relation to security, breach notification, data protection impact assessments and data protection assessments, and prior consultation with supervisory authorities.
(f) Deletion and return. On termination or expiry of the Agreement, and in accordance with its termination provisions, at Customer's choice either delete or return all Customer Personal Data, and delete existing copies, unless applicable law requires continued storage. Copies of Customer Personal Data held in routine backups will be deleted or overwritten in the ordinary course of Cordaata's backup rotation, and will remain protected by the measures in Schedule 2 and inaccessible for active processing until deleted. Where Customer requests written confirmation of deletion, Cordaata will provide it within thirty (30) days of completing deletion.
(g) Records and audit. Maintain records of processing activities carried out on Customer's behalf in accordance with Article 30(2) of the GDPR, and make available to Customer all information reasonably necessary to demonstrate compliance with this DPA in accordance with Section 8.
(h) No sale. Not sell Customer Personal Data or share it for cross-context behavioural advertising, and not use Customer Personal Data for advertising purposes.
6. Sub-processors
6.1 General authorisation. Customer provides general written authorisation to Cordaata to engage Sub-processors, subject to the requirements of this Section.
6.2 Current sub-processors. The list of Cordaata's current Sub-processors, including their name, location, and the services they provide, is set out in Schedule 3. Customers may request an up-to-date copy of the sub-processor list at any time by contacting legal@cordaata.com .
6.3 New Sub-processors. Cordaata will notify Customer at least ten (10) days before a new Sub-processor begins processing Customer Personal Data. Notice may be given by email to the Notices contact specified in the applicable Order, or by updating the sub-processor list in Schedule 3 and notifying Customers who have subscribed to sub-processor change notices. Customer may object to a new Sub-processor on reasonable, documented data protection grounds by written notice to legal@cordaata.com within ten (10) days of notification. If Customer objects and Cordaata cannot reasonably accommodate the objection, Customer may terminate the affected Order on written notice, and Cordaata will refund any prepaid fees covering the period after termination on a pro-rata daily basis.
6.4 Sub-processor obligations. Cordaata will impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, by written agreement. Where US State Privacy Laws apply, each such agreement will satisfy the contractual requirements of those laws for engagements with sub-processors or subcontractors. Cordaata remains liable to Customer for the acts and omissions of its Sub-processors to the same extent Cordaata would be liable if performing the services directly.
7. Security incidents
7.1 Notification. Cordaata will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. Notification will be made to both the Notices contact and the Technical contact specified in the applicable Order, and to any additional security contact designated by Customer in the platform settings.
7.2 Content of notification. Where reasonably ascertainable at the time of notification, Cordaata will include in its notification: (a) a description of the nature of the Security Incident, including the categories and approximate number of data subjects and personal data records concerned; (b) the name and contact details of Cordaata's data protection contact; (c) the likely consequences of the Security Incident; and (d) the measures taken or proposed to address the Security Incident. Where information is not available at the time of initial notification, Cordaata will provide it in further communications without undue delay.
7.3 Cooperation. Cordaata will cooperate with Customer and take such reasonable steps as are directed by Customer to assist in the investigation, mitigation, and remediation of a Security Incident, including providing information reasonably required for Customer to meet its notification obligations under Applicable Data Protection Law and applicable US state breach notification laws.
7.4 No acknowledgement of fault. Notification of a Security Incident under this Section does not constitute an acknowledgement of fault or liability by Cordaata.
8. Audit rights
8.1 Information and certifications. On Customer's written request, Cordaata will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, including summaries of relevant third-party audit reports, certifications (such as ISO 27001 or SOC 2 Type II where obtained), and summaries of security testing outcomes, where available. Cordaata will provide such information within thirty (30) days of a written request.
8.2 On-site audits. Customer will first seek to satisfy its audit rights through the information, reports, and certifications made available under Section 8.1. Where those do not reasonably resolve a specific, documented compliance concern, Customer or its appointed independent auditor (who must not be a competitor of Cordaata) may conduct an audit of Cordaata's processing activities no more than once per calendar year, on at least thirty (30) days' prior written notice, during normal business hours, and subject to reasonable confidentiality obligations. Audits will be conducted remotely where practicable, with on-site access only where remote review cannot reasonably resolve the concern. The scope of any audit will be limited to Cordaata's processing of Customer Personal Data. Customer will bear the costs of any audit unless the audit reveals a material non-compliance with this DPA, in which case Cordaata will bear reasonable audit costs.
8.3 Certification in lieu of audit. Where Cordaata holds a current ISO 27001 certification or SOC 2 Type II report covering the relevant processing activities, Customer agrees to accept that certification or report as satisfying Customer's audit rights under Section 8.2 in respect of the period covered, unless Customer has reasonable grounds to suspect a specific compliance failure not addressed by the certification or report.
9. International transfers
This Section 9 applies only to Customer Personal Data that is subject to the GDPR.
9.1 EEA transfers. Where Cordaata transfers Customer Personal Data outside the European Economic Area, it will ensure an adequate level of protection by relying on one of the following mechanisms: (a) an adequacy decision by the European Commission in respect of the destination country; (b) the SCCs, incorporated into this DPA by reference and set out in Schedule 4; or (c) another transfer mechanism recognised as adequate under Chapter V of the GDPR.
9.2 SCCs. Where the SCCs apply: Customer is the data exporter and Cordaata or the relevant Sub-processor is the data importer. The optional clauses and Annexes of the SCCs are completed as set out in Schedule 4. In the event of any conflict between the SCCs and this DPA, the SCCs prevail to the extent of that conflict in respect of restricted transfers.
9.3 Transfer impact. Cordaata will carry out and document transfer impact assessments where required under Applicable Data Protection Law and will make relevant summaries available to Customer on request.
10. US State Privacy Laws
This Section 10 applies to the extent US State Privacy Laws apply to the processing of Customer Personal Data under this DPA.
10.1 Service provider certifications. Cordaata certifies that it understands and will comply with the restrictions and obligations applicable to it as a service provider or processor under US State Privacy Laws. In particular, Cordaata will not: (a) sell Customer Personal Data or share it for cross-context behavioural advertising; (b) retain, use, or disclose Customer Personal Data for any purpose other than providing the Services under the Agreement, including any commercial purpose other than the business purposes specified in this DPA, or as otherwise permitted by US State Privacy Laws; (c) retain, use, or disclose Customer Personal Data outside the direct business relationship between Cordaata and Customer; or (d) combine Customer Personal Data with personal information that Cordaata receives from or on behalf of another person, or collects from its own interactions with consumers, except as permitted by US State Privacy Laws for a service provider.
10.2 Compliance and notification. Cordaata will comply with the obligations applicable to it under US State Privacy Laws and will provide the same level of privacy protection for Customer Personal Data as is required of Customer under those laws. Cordaata will notify Customer promptly if it determines that it can no longer meet its obligations under US State Privacy Laws.
10.3 Remediation. Customer may take reasonable and appropriate steps, in accordance with this DPA, to ensure that Cordaata uses Customer Personal Data in a manner consistent with Customer's obligations under US State Privacy Laws, and to stop and remediate any unauthorised use of Customer Personal Data.
10.4 Consumer requests. Cordaata will assist Customer in responding to verifiable consumer requests under US State Privacy Laws in accordance with Section 5(d).
10.5 De-identified data. Where Cordaata receives or generates de-identified data (including Aggregated Anonymous Data) from Customer Personal Data, Cordaata will maintain and use that data only in de-identified form, will not attempt to re-identify it except as permitted by US State Privacy Laws to test the effectiveness of de-identification, and will contractually obligate any recipients to comply with the same restrictions.
11. Data protection contact and supervisory authority
Cordaata's data protection contact is reachable at legal@cordaata.com .
Where the GDPR applies to the processing of Customer Personal Data, Customers may lodge complaints with the Belgian supervisory authority, the Gegevensbeschermingsautoriteit (GBA), at gegevensbeschermingsautoriteit.be , or with the supervisory authority in their own EU Member State.
12. Term and termination
This DPA remains in force for the duration of the Agreement and terminates automatically on termination or expiry of the Agreement, subject to any obligations that survive termination as set out herein and in the Agreement.
13. Order of precedence
In the event of any conflict between this DPA and the Agreement on matters relating to the processing of personal data, this DPA prevails. In the event of any conflict between this DPA and the SCCs in respect of a restricted transfer, the SCCs prevail.
14. Liability
Each party's liability arising out of or in connection with this DPA, whether in contract, tort (including negligence), or otherwise, is subject to the exclusions and limitations of liability set out in the Agreement. Any reference in the Agreement to the liability of a party means the aggregate liability of that party under the Agreement and this DPA taken together.
Nothing in this Section limits or excludes the rights of any data subject under Applicable Data Protection Law, or, in respect of a restricted transfer, the rights of data subjects or the liability of the parties under the SCCs.
Schedule 1 — Details of processing
Schedule 2 — Technical and organisational security measures
Cordaata maintains a written information security programme comprising technical and organisational measures designed to protect Customer Personal Data against Security Incidents, appropriate to the nature, scope, context, and purposes of processing and the risks to data subjects, in accordance with Article 32 of the GDPR and equivalent requirements of Applicable Data Protection Law. Cordaata may update or modify these measures from time to time as its Services, infrastructure, and the threat landscape evolve, provided that no update materially reduces the overall level of protection for Customer Personal Data during the Subscription Term. The programme includes the following:
Access control. Role-based access controls limiting access to Customer Personal Data to personnel who require it for their job function. Multi-factor authentication required for access to production systems. Access rights reviewed periodically and revoked promptly on departure or role change.
Encryption. Customer Personal Data encrypted in transit using TLS 1.2 or higher. Customer Personal Data encrypted at rest using AES-256 or equivalent. Encryption keys managed through a dedicated key management service.
Network security. Production infrastructure segregated from development and test environments. Network security controls, which may include firewalls, intrusion detection, and web application firewall technologies, applied as appropriate to the risk. Vulnerability scanning of externally accessible services conducted on a regular basis.
Incident response. Documented security incident response plan with designated response personnel, reviewed and tested periodically. Notification procedures consistent with Section 7 of this DPA.
Personnel security. Security awareness training provided to personnel on joining and periodically thereafter. Personnel with access to Customer Personal Data subject to contractual confidentiality obligations. Background screening conducted where permitted by applicable law and proportionate to the role.
Physical security. Customer Personal Data processed and stored in data centres operated by infrastructure Sub-processors with physical access controls, monitoring, and environmental controls. Physical security obligations are passed through to those Sub-processors by contract.
Availability and resilience. Infrastructure designed for redundancy across multiple availability zones. Automated backups with documented recovery procedures. Business continuity and disaster recovery arrangements reviewed periodically.
Testing and assessment. Periodic security testing proportionate to risk, which may include vulnerability scanning, configuration review, and penetration testing conducted by qualified internal or external resources. Material findings remediated on a risk-prioritised basis within timelines appropriate to their severity.
Supplier management. Sub-processors subject to security due diligence before engagement and periodically thereafter. Contractual security requirements imposed on Sub-processors handling Customer Personal Data.
Schedule 3 — Approved sub-processors
Current as of 23 August 2026. Customers will be notified of changes by email in accordance with Section 6.3. To request the current list, contact legal@cordaata.com .
Complete and up-to-date sub-processor details, including entity names, addresses, and applicable transfer mechanisms, are available on request by contacting legal@cordaata.com .
Schedule 4 — Standard Contractual Clauses
The SCCs (Module 2: Controller to Processor) adopted by the European Commission in Decision C(2021) 3972 are incorporated into this DPA by reference and apply only to restricted transfers of Customer Personal Data subject to the GDPR.
Clause 7 (Docking clause): The optional docking clause applies.
Clause 9 (Use of sub-processors): Option 2 (general written authorisation) applies, with the notice period set at ten (10) days as specified in Section 6.3 of this DPA.
Clause 11 (Redress): The optional language does not apply.
Clause 17 (Governing law): Belgian law.
Clause 18 (Choice of forum and jurisdiction): The courts of Belgium.
Annex I (List of parties): Completed by reference to the Agreement and Schedule 1 of this DPA.
Annex II (Technical and organisational measures): The measures in Schedule 2 of this DPA.
Annex III (Sub-processors): Schedule 3 of this DPA.
For questions about this DPA or to request a countersigned version, contact legal@cordaata.com .