Trust Center
Data Processing Agreement
Last updated: 8 September 2026
Introduction
This Data Processing Agreement (“DPA”) forms part of the agreement between ASUME B.V. (“ASUME,” “Processor,” “we,” “us,” or “our”) and the customer that has accepted or entered into the applicable Terms of Service, Order Form, Master Services Agreement, Subscription Agreement, or other agreement governing use of the Service (“Customer,” “Controller,” “you,” or “your”) (the “Agreement”).
This DPA applies where ASUME Processes Personal Data on behalf of Customer as a Processor in connection with the Service. It is incorporated into and forms part of the Agreement automatically when Customer becomes bound by the Agreement or otherwise uses the Service in a manner involving ASUME’s Processing of Personal Data on Customer’s behalf. Unless ASUME expressly requires otherwise, this DPA does not need to be separately signed.
This DPA does not apply to Processing for which ASUME independently determines the purposes and essential means and acts as a Controller. Such Processing is governed by ASUME’s Privacy Policy and Applicable Data Protection Law.
ASUME B.V. is established in the Netherlands. This DPA is intended to satisfy the requirements of Article 28 of Regulation (EU) 2016/679 (“GDPR”) and other Applicable Data Protection Law.
1. Scope and Definitions
1.1. Scope
This DPA governs ASUME’s Processing of Processor Personal Data on behalf of Customer in connection with Customer’s use of the Service, including Customer Workspaces, Customer Data, Customer-authorised integrations and sources, APIs, AI-assisted functionality, Outputs, support, security, exports, reports, and other functionality that Customer configures or instructs ASUME to provide.
1.2. Processor Personal Data
“Processor Personal Data” means Personal Data that ASUME Processes solely on behalf of Customer as a Processor under this DPA. Processor Personal Data does not include Personal Data for which ASUME independently determines the purposes and essential means of Processing.
1.3. Definitions
“Applicable Data Protection Law” means data-protection and privacy laws applicable to the Processing governed by this DPA, including the GDPR, the Dutch Uitvoeringswet Algemene verordening gegevensbescherming (“UAVG”), and, where applicable, other laws governing Controller–Processor, business–service provider, or equivalent relationships. “Customer Data” has the meaning given in the Agreement. “Personal Data,” “Controller,” “Processor,” “Data Subject,” “Processing,” and “Personal Data Breach” have the meanings given under the GDPR or, where another Applicable Data Protection Law applies, the corresponding meaning under that law. “Subprocessor” means a third party engaged by ASUME to Process Processor Personal Data on behalf of Customer. “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses adopted by the European Commission under Commission Implementing Decision (EU) 2021/914, as amended or replaced.
1.4. Independent Controller Processing
Personal Data that ASUME Processes for independently determined purposes, including where applicable account administration, billing, security, fraud prevention, legal compliance, customer relationship management, public-source Processing, ASUME’s own marketing, or other purposes described in the Privacy Policy, is outside the scope of this DPA. Public Source Data independently obtained or otherwise Processed by ASUME for purposes determined by ASUME does not become Processor Personal Data merely because it contributes to an Output provided to Customer.
1.5. Order of Precedence
If this DPA conflicts with another part of the Agreement concerning Processing governed by this DPA, this DPA controls unless the conflicting provision is contained in a written Order Form or agreement that expressly identifies the provision of this DPA being modified. Where applicable SCCs conflict with this DPA or another part of the Agreement, the SCCs control solely with respect to the relevant Restricted Transfer.
2. Roles of the Parties
2.1. Customer as Controller
Customer is the Controller of Processor Personal Data and determines the purposes and means of the Processing for which ASUME acts as Processor, including what Processor Personal Data Customer submits, connects, makes available, or instructs ASUME to Process.
2.2. ASUME as Processor
ASUME Processes Processor Personal Data on behalf of Customer and only in accordance with Customer’s documented instructions, this DPA, the Agreement, Customer’s configuration of the Service, and Applicable Data Protection Law.
2.3. Role Determination
The parties’ contractual description of their roles does not override a role assigned by Applicable Data Protection Law based on the actual purposes and means of a particular Processing activity. If a Processing activity changes such that ASUME independently determines its purposes or essential means, the parties will treat that Processing according to the role required by Applicable Data Protection Law.
3. Customer Instructions and Obligations
3.1. Documented Instructions
Customer instructs ASUME to Process Processor Personal Data as reasonably necessary to provide, operate, maintain, secure, support, troubleshoot, technically optimise, and administer the Service made available to Customer in accordance with the Agreement, applicable Order Forms, Customer’s Workspace configuration, Customer’s integration settings, Customer’s use of Service features, and written instructions from authorised Customer representatives.
3.2. Scope of Instructions
Customer’s instructions include Processing reasonably necessary to create and administer Customer Workspaces, process Customer Data and Customer-authorised integration data, generate Outputs requested or configured by Customer, provide APIs and exports, provide support and troubleshooting, maintain security and availability, prevent and investigate misuse or security incidents, and perform obligations under the Agreement and this DPA.
3.3. No Independent Expansion of Processor Instructions
General product development, reusable model Training, or other Processing undertaken by ASUME for independently determined purposes is not Processing performed on Customer’s behalf under this DPA unless Customer expressly instructs or authorises that Processing and the parties determine that ASUME continues to act solely as Processor for that purpose.
3.4. Legality of Instructions
Customer represents and warrants that its instructions and use of the Service comply with Applicable Data Protection Law. Customer is responsible for establishing a lawful basis for Processing Processor Personal Data, providing required notices, obtaining required consents or authorisations, ensuring that Customer is lawfully permitted to disclose Processor Personal Data to ASUME and its authorised Subprocessors, and ensuring that the Processing instructed through the Service is appropriate for Customer’s intended purpose.
3.5. Unlawful Instructions
ASUME will inform Customer if, in ASUME’s opinion, a Customer instruction infringes Applicable Data Protection Law. ASUME may suspend the affected Processing until Customer modifies, withdraws, or otherwise resolves the instruction in a manner that ASUME reasonably determines can be performed consistently with Applicable Data Protection Law. ASUME is not required to conduct an independent legal review of every Customer instruction, and Customer remains responsible for the lawfulness of its instructions.
3.6. Change in Lawfulness
Customer must notify ASUME without undue delay if Customer determines that Processor Personal Data can no longer lawfully be Processed as contemplated by the Agreement or that Customer no longer possesses the rights, lawful basis, authority, or permissions required for the Processing.
3.7. Accuracy and Minimisation
Customer is responsible for the accuracy, quality, relevance, and proportionality of Processor Personal Data submitted or connected to the Service and should not provide Personal Data that is unnecessary for Customer’s intended use of the Service.
3.8. Sensitive Personal Data
The Service is not intended for Processing special-category Personal Data, criminal-offence data, children’s Personal Data, health data, biometric data, precise location data, government identification numbers, payment-card data, or other highly sensitive or specially regulated Personal Data unless ASUME expressly agrees in writing and appropriate safeguards are established. If ASUME reasonably determines that Customer has submitted prohibited sensitive Personal Data without approval, ASUME may suspend the affected Processing, disable the relevant functionality, require Customer to remove the data, or delete or return the affected data where legally and technically appropriate.
4. ASUME Processing Obligations
4.1. Processing on Instructions
ASUME will Process Processor Personal Data only on Customer’s documented instructions unless Processing is required by Union or Member State law to which ASUME is subject. Where such law requires Processing, ASUME will inform Customer before Processing unless the law prohibits ASUME from doing so on important grounds of public interest.
4.2. Confidentiality
ASUME will ensure that persons authorised to Process Processor Personal Data are subject to appropriate contractual or statutory confidentiality obligations.
4.3. Access Limitation
ASUME will limit access to Processor Personal Data to personnel, contractors, and Subprocessors that require access to perform authorised functions and will apply appropriate access controls according to role and need.
4.4. Records
ASUME will maintain records of Processing activities to the extent required by Applicable Data Protection Law. Customer remains responsible for maintaining records of Processing activities applicable to Customer’s use of the Service.
4.5. Compliance Cooperation
ASUME will provide the assistance expressly required under this DPA, taking into account the nature of Processing, the functionality available within the Service, the information reasonably available to ASUME, and the responsibilities assigned to Customer under Applicable Data Protection Law.
5. Security and Confidentiality
5.1. Technical and Organisational Measures
ASUME will implement and maintain appropriate technical and organisational measures designed to protect Processor Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Those measures will take into account the state of the art, implementation costs, the nature, scope, context, and purposes of Processing, and risks of varying likelihood and severity to the rights and freedoms of individuals.
5.2. Security Measures
ASUME’s current technical and organisational measures are described in Schedule 2 and in ASUME’s Security Measures, which are incorporated into this DPA by reference.
5.3. Changes to Security Measures
ASUME may update its technical and organisational measures to reflect technological developments, security risks, Service changes, provider changes, and generally accepted security practices, provided that ASUME does not materially reduce the overall level of protection for Processor Personal Data during the applicable Subscription Term.
5.4. Customer Security Responsibilities
Customer remains responsible for security measures under Customer’s control, including Account permissions, authentication settings, credentials, API keys, connected systems, devices, networks, integrations, and User access.
6. Personal Data Breaches
6.1. Notification
ASUME will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Processor Personal Data.
6.2. Information
Where available, ASUME’s notification will describe the nature of the Personal Data Breach, categories and approximate number of affected Data Subjects and records, likely consequences, measures taken or proposed to address or mitigate the breach, and a contact point for further information.
6.3. Phased Information
Where complete information is not immediately available, ASUME may provide information in phases without undue further delay.
6.4. Response
ASUME will take reasonable steps to investigate, contain, mitigate, and remediate a Personal Data Breach within ASUME’s systems.
6.5. Customer Notifications
Customer is responsible for determining whether a Personal Data Breach requires notification to a Supervisory Authority, Data Subjects, customers, business partners, or other persons, except where Applicable Data Protection Law directly requires ASUME to make such notification.
6.6. No Admission
ASUME’s notification of or response to a Personal Data Breach does not constitute an acknowledgement of fault, wrongdoing, or liability.
7. Data Subject and Compliance Assistance
7.1. Data Subject Requests
Taking into account the nature of the Processing, ASUME will provide reasonable assistance through appropriate technical and organisational measures, insofar as possible, to enable Customer to respond to requests from Data Subjects exercising rights under Applicable Data Protection Law.
7.2. Direct Requests
If ASUME receives a request directly from a Data Subject concerning Processor Personal Data, ASUME will, where reasonably possible and legally permitted, redirect the request to Customer, forward the request to Customer, or refrain from responding substantively except on Customer’s documented instruction or where required by law.
7.3. Customer Responsibility
Customer is responsible for evaluating and responding to Data Subject Requests where Customer is Controller.
7.4. DPIAs and Prior Consultation
Taking into account the nature of Processing and information reasonably available to ASUME, ASUME will provide reasonable assistance with Customer’s obligations concerning data-protection impact assessments, prior consultations, security of Processing, and breach-related obligations where the Processing performed by ASUME is relevant to those obligations.
7.5. Method of Assistance
ASUME may provide assistance through Service functionality, Documentation, Security Measures, the Subprocessor List, audit reports, compliance documentation, questionnaires, support channels, or other reasonably appropriate means.
7.6. Extraordinary Assistance
To the extent permitted by Applicable Data Protection Law, ASUME may charge reasonable fees for assistance that is unusually burdensome, repetitive, bespoke, or outside standard Service functionality, except to the extent the assistance is required because ASUME breached this DPA.
8. Subprocessors
8.1. General Authorisation
Customer grants ASUME general written authorisation to engage Subprocessors to Process Processor Personal Data for purposes permitted under this DPA.
8.2. Subprocessor List
ASUME will maintain a current list of material Subprocessors, including the nature of their Processing and relevant Processing locations where appropriate, in ASUME’s Subprocessor List.
8.3. Subprocessor Contracts
ASUME will enter into written agreements with Subprocessors that impose data-protection obligations appropriate to the services performed and no less protective in material respects than the obligations imposed on ASUME under this DPA to the extent required by Article 28(4) GDPR.
8.4. Responsibility
ASUME remains responsible to Customer for the performance of a Subprocessor’s Processor obligations to the extent required by Applicable Data Protection Law.
8.5. Notice of Changes
ASUME will provide at least thirty (30) calendar days’ prior notice before authorising a new material Subprocessor to Process Processor Personal Data, whether by email, the Service, updates to the Subprocessor List with a subscription mechanism, or another reasonable method.
8.6. Urgent Changes
Where an urgent Subprocessor appointment is reasonably necessary to address a security incident, provider failure, service disruption, legal requirement, emergency, or comparable circumstance, ASUME may appoint the Subprocessor before expiry of the standard notice period and will provide notice without undue delay.
8.7. Objections
Customer may object to a new material Subprocessor during the applicable notice period only on reasonable and documented data-protection grounds. The parties will work in good faith to resolve a valid objection.
8.8. Unresolved Objections
If an objection cannot reasonably be resolved, ASUME may make available a commercially reasonable alternative, modify or disable affected functionality, or terminate the affected Service. If a paid Service is terminated solely because an unresolved data-protection objection prevents ASUME from lawfully continuing to provide that Service, ASUME will refund prepaid fees attributable to the unused terminated period. Customer has no right to object to a Subprocessor for reasons unrelated to data protection under this DPA.
9. International Transfers
9.1. Processing Locations
ASUME is established in the Netherlands. Processor Personal Data may be Processed within the European Economic Area, in countries subject to a valid adequacy decision, and in other countries where ASUME or its authorised Subprocessors operate, subject to the requirements of Applicable Data Protection Law.
9.2. Restricted Transfers
Where ASUME transfers Processor Personal Data from the EEA to a recipient in a country that is not subject to an applicable adequacy decision, ASUME will implement an appropriate transfer mechanism under Chapter V GDPR.
9.3. Standard Contractual Clauses
Such safeguards may include the SCCs under Commission Implementing Decision (EU) 2021/914. Where ASUME transfers Processor Personal Data to a non-EEA Subprocessor, SCC Module Three (Processor to Processor) will apply where appropriate.
9.4. Direct Customer-to-ASUME Transfers
Where a Restricted Transfer occurs directly between Customer and ASUME and Applicable Data Protection Law requires the parties to enter into the SCCs, the appropriate SCC module is incorporated into this DPA and completed using information contained in this DPA, the Agreement, relevant Order Form, Schedules, Security Measures, and Subprocessor List.
9.5. Supplementary Measures
Where required, ASUME will conduct or support transfer impact assessments and implement supplementary contractual, technical, or organisational safeguards appropriate to the relevant transfer, which may include encryption, access controls, minimisation, contractual commitments, and security review.
9.6. Other Transfer Regimes
Where the UK GDPR, Swiss data-protection law, or another applicable transfer regime applies, the relevant UK Addendum, Swiss adaptations, adequacy mechanism, or other legally recognised transfer safeguard will apply as necessary.
10. Return and Deletion
10.1. End of Processing
Following termination or expiry of the relevant Service, ASUME will, at Customer’s choice and in accordance with available Service functionality, return or delete Processor Personal Data in accordance with Article 28 GDPR, unless applicable Union or Member State law requires continued storage.
10.2. Export
Customer is responsible for exporting Processor Personal Data it wishes to retain before termination or during any export period expressly made available under the Agreement.
10.3. Active Systems
Unless otherwise agreed in writing, ASUME may delete Processor Personal Data from active systems after expiry of the applicable export period.
10.4. Backups
Processor Personal Data may remain in backups, disaster-recovery systems, or immutable logs until deleted or overwritten through ASUME’s ordinary retention cycle. While retained in those systems, Processor Personal Data remains protected under this DPA and will not ordinarily be actively Processed except for restoration, security, business continuity, or where required by law.
10.5. Independent Retention Purpose
To the extent ASUME lawfully retains particular Personal Data after Processor Processing ends for an independently determined legal, security, fraud-prevention, compliance, or claims purpose, ASUME will act as an independent Controller for that subsequent Processing, and that Processing will be governed by ASUME’s Privacy Policy and Applicable Data Protection Law rather than this DPA.
11. Audits and Compliance Information
11.1. Compliance Information
ASUME will make available information reasonably necessary to demonstrate compliance with its obligations under Article 28 GDPR and this DPA.
11.2. Documentation First
ASUME may first satisfy an audit or compliance request by providing available independent audit reports, certifications, security documentation, technical and organisational measures, penetration-test summaries, vendor-security responses, questionnaires, or other compliance documentation reasonably sufficient to address Customer’s obligations.
11.3. Additional Audit
Customer may request an additional audit only where information made available under Section 11.2 is not reasonably sufficient to satisfy Customer’s obligations under Applicable Data Protection Law, a Supervisory Authority requires additional verification, or a confirmed Personal Data Breach affecting Customer reasonably justifies further review.
11.4. Audit Conditions
Any permitted audit must be conducted on reasonable prior written notice, during normal business hours, in a manner that does not unreasonably disrupt ASUME’s operations, and subject to appropriate confidentiality and security obligations. Audits may not occur more than once per twelve-month period unless required by a Supervisory Authority or reasonably necessary following a confirmed Personal Data Breach affecting Processor Personal Data.
11.5. Auditor
An auditor must be independent, appropriately qualified, and subject to confidentiality obligations. ASUME may object to an auditor that is a competitor of ASUME or that reasonably presents a security, confidentiality, independence, or conflict-of-interest risk.
11.6. Protected Information
No audit requires ASUME to provide access to another customer’s data, source code, model weights, credentials, secrets, privileged legal materials, vulnerability details, security-sensitive infrastructure, or other information whose disclosure would create an unreasonable security, confidentiality, or legal risk, except to the extent mandatory Applicable Data Protection Law expressly requires such access.
11.7. Penetration Testing
Customer or its auditor may not conduct penetration testing, vulnerability exploitation, intrusive security testing, or similar technical testing against ASUME systems without ASUME’s prior written authorisation.
11.8. Costs
Customer bears its own audit costs. ASUME may charge reasonable fees for extraordinary audit support to the extent permitted by Applicable Data Protection Law, except where the audit identifies a material breach of this DPA by ASUME.
12. AI, Model Use, and Processor Data Restrictions
12.1. AI-Assisted Processing
Customer authorises ASUME to Process Processor Personal Data through artificial intelligence, machine-learning systems, language models, statistical methods, retrieval systems, and related technologies where reasonably necessary to provide Service functionality configured or requested by Customer.
12.2. Customer Data Training
ASUME will not use Processor Personal Data or Customer Data Processed under this DPA to train or fine-tune generally reusable ASUME or third-party AI models unless Customer expressly opts in or otherwise provides documented authorisation for that Processing.
12.3. Service Processing Is Not Training
Model inference, retrieval, temporary context Processing, security filtering, debugging, support, troubleshooting, abuse detection, and evaluation reasonably necessary to provide the Service do not constitute reusable model Training solely because an AI or machine-learning system is involved.
12.4. Role Change for General Training
Where Customer authorises use of Customer Data for Training that is intended to improve generally reusable ASUME models or systems for ASUME’s broader purposes, such Processing may involve purposes independently determined by ASUME and may therefore fall outside the scope of this DPA. Any such Processing will be governed by the applicable Customer agreement, product setting, Privacy Policy, and Applicable Data Protection Law according to the legally applicable roles.
12.5. Customer-Controlled Sources
Processing of content from a Customer-Controlled Source for ASUME’s independent reusable model-development or general product-improvement purposes is outside the scope of this DPA to the extent ASUME independently determines the purposes and essential means of that Processing. The contractual authorisations governing Customer-Controlled Sources are set out in the Terms of Service.
12.6. Aggregation, Pseudonymisation, and Anonymisation
ASUME may aggregate, pseudonymise, de-identify, or anonymise Processor Personal Data where consistent with Customer’s instructions and Applicable Data Protection Law. Information that remains Personal Data after such Processing remains subject to this DPA. Once information has been rendered anonymous such that it no longer constitutes Personal Data under Applicable Data Protection Law, this DPA no longer applies to that anonymous information.
12.7. Anonymous Information
ASUME may use anonymous information for lawful analytics, research, security, evaluation, benchmarking, statistical analysis, and Service improvement.
12.8. Sale and Advertising Restrictions
ASUME will not sell Processor Personal Data. To the extent required by Applicable Data Protection Law, ASUME will not share Processor Personal Data for cross-context behavioural advertising or targeted advertising, retain, use, or disclose Processor Personal Data outside the direct business relationship with Customer except as permitted by the Agreement and Applicable Data Protection Law, or combine Processor Personal Data with unrelated Personal Data obtained from other sources except where reasonably necessary to provide the Service on Customer’s instructions or otherwise permitted by Applicable Data Protection Law.
12.9. No Other Customers
ASUME will not make Customer Data available to another customer except where Customer expressly instructs or enables such sharing.
13. Government and Regulatory Requests
13.1. Requests for Processor Personal Data
If ASUME receives a legally binding request from a public authority, court, regulator, or law-enforcement body for Processor Personal Data, ASUME will, where legally permitted, notify Customer without undue delay and redirect the requesting authority to Customer where appropriate.
13.2. Review of Requests
ASUME will review the validity and scope of a request and, where ASUME reasonably determines that appropriate legal grounds exist, may take reasonable steps to challenge, narrow, redirect, or otherwise limit an unlawful, excessive, or disproportionate request.
13.3. Minimum Disclosure
ASUME will disclose only Processor Personal Data that ASUME reasonably determines it is legally required to disclose.
13.4. No Voluntary Government Access
ASUME will not voluntarily provide government or law-enforcement authorities with direct access to Processor Personal Data except where Customer authorises such access or ASUME is legally required to provide it.
14. Liability, Term, and General Provisions
14.1. Liability
Liability arising under this DPA is subject to the exclusions, limitations, indemnities, and allocation of liability in the Agreement except to the extent Applicable Data Protection Law prohibits such limitation or allocation.
14.2. Term
This DPA becomes effective when Customer becomes bound by the Agreement or ASUME begins Processing Processor Personal Data on Customer’s behalf, whichever occurs first, and remains effective for as long as ASUME Processes Processor Personal Data on Customer’s behalf.
14.3. Changes
ASUME may update this DPA where reasonably necessary to reflect changes in Applicable Data Protection Law, regulatory guidance, the Service, security measures, Processing arrangements, transfer mechanisms, or legally required contractual terms, provided that an update does not materially diminish Customer’s data-protection rights or materially increase Customer’s obligations during the applicable Subscription Term unless required by law.
14.4. Notice of Material Changes
ASUME will provide at least thirty (30) days’ notice of a material change where reasonably practicable, unless a shorter period is required to address law, regulation, security, urgent Subprocessor changes, or another circumstance requiring earlier effectiveness.
14.5. Objection to Material Changes
If Customer objects to a material change on reasonable data-protection grounds, Customer must notify ASUME during the applicable notice period. The parties will work in good faith to resolve the objection. If the parties cannot resolve an objection and continued Processing is no longer commercially or legally feasible, ASUME may terminate the affected Service and provide any refund required under the Agreement or mandatory law.
14.6. Governing Law
This DPA is governed by the laws of the Netherlands unless Applicable Data Protection Law requires another law to apply.
14.7. Jurisdiction
The dispute-resolution and jurisdiction provisions in the Agreement apply to this DPA except where Applicable Data Protection Law or the SCCs require another forum.
14.8. Entire Processing Agreement
This DPA, its Schedules, applicable SCCs, the Agreement, Security Measures, and Subprocessor List constitute the parties’ agreement concerning Processing governed by this DPA.
Schedule 1 — Details of Processing
1. Subject Matter
ASUME Processes Processor Personal Data on Customer’s behalf to provide Customer-configured B2B company-understanding, account analysis, company matching, evidence-linked Outputs, AI-assisted analysis, Workspace functionality, integrations, APIs, reports, exports, support, security, and related Service functionality.
2. Duration
ASUME Processes Processor Personal Data for the duration of the applicable Agreement and thereafter only for the period reasonably necessary to complete Customer export or deletion, complete ordinary backup deletion cycles, comply with applicable legal requirements, maintain required security or audit records, or perform other Processing permitted under this DPA.
3. Nature of Processing
Processing may include collection or receipt from Customer-authorised sources, recording, organisation, structuring, hosting, storage, retrieval, consultation, analysis, comparison, classification, summarisation, transformation, enrichment, inference, generation of Customer-requested Outputs, transmission, disclosure to authorised recipients, restriction, return, deletion, aggregation, pseudonymisation, and anonymisation.
4. Purposes
The purpose of Processing is to provide, operate, maintain, secure, support, troubleshoot, and technically optimise the Service provided to Customer in accordance with Customer’s documented instructions, including creating and administering Workspaces, processing Customer Data, operating Customer-authorised integrations, generating Customer-requested Outputs, providing support, maintaining security, preventing misuse, and satisfying Processor obligations under the Agreement.
General reusable model Training, independently determined public-source Processing, and other ASUME-controller purposes are not purposes of Processor Processing under this DPA unless expressly agreed and legally classified otherwise.
5. Categories of Data Subjects
Depending on Customer’s use of the Service, Processor Personal Data may relate to Customer’s employees, contractors, administrators, Users, customers, prospects, leads, suppliers, business partners, business contacts, meeting participants, communication participants, individuals referenced in Customer Data, and individuals whose Personal Data Customer specifically makes available through a Customer-Authorised Source.
Individuals appearing in Public Source Data independently obtained and Processed by ASUME for ASUME-determined purposes are not included in this Schedule merely because their information contributes to an Output.
6. Categories of Processor Personal Data
Processor Personal Data may include names, business email addresses, business telephone numbers, employer information, job titles, professional roles, business profile information, CRM records, account data, sales notes, meeting notes, call or meeting transcripts, communication records, document content, User identifiers, Workspace activity, login information, IP addresses, device and browser metadata, usage information, integration metadata, support communications, and other Personal Data Customer submits, connects, or specifically instructs ASUME to Process.
7. Sensitive Personal Data
The Service is not intended for special-category Personal Data, criminal-offence data, children’s data, health data, biometric data, precise location information, government identification numbers, payment-card data, or comparable highly sensitive information unless ASUME expressly agrees in writing and appropriate lawful bases and safeguards are established.
8. Processing Locations
Processor Personal Data may be Processed in the EEA, countries covered by an applicable adequacy decision, and other jurisdictions in which authorised Subprocessors operate, subject to Section 9 and Schedule 4.
9. Authorised Recipients
Processor Personal Data may be Processed by authorised ASUME personnel, authorised contractors subject to confidentiality obligations, authorised Subprocessors, Customer’s authorised Users and Administrators, and other recipients Customer instructs ASUME to make the data available to.
Schedule 2 — Technical and Organisational Measures
ASUME maintains technical and organisational measures designed to provide a level of security appropriate to the risk associated with Processor Personal Data.
Those measures may include appropriate controls concerning identity and access management, least-privilege access, authentication, encryption in transit and where appropriate at rest, network and infrastructure security, logging and monitoring, secrets management, secure software development, vulnerability management, incident detection and response, backup and resilience, availability, tenant separation, employee confidentiality, vendor management, physical security applicable to relevant infrastructure, and procedures for deletion and secure disposal.
ASUME’s current technical and organisational measures are described in greater detail in the Security Measures, which are incorporated into this Schedule by reference.
ASUME may modify individual measures as technology, threats, architecture, providers, and industry standards evolve, provided that the overall level of protection is not materially reduced during the applicable Subscription Term.
Schedule 3 — Subprocessor List
ASUME uses Subprocessors to provide, host, secure, support, and operate Service functionality.
The current list of material Subprocessors, including the purpose of Processing, Processing location where appropriate, and applicable transfer information, is maintained in the Subprocessor List.
The Subprocessor List forms part of this DPA and is updated in accordance with Section 8.
Schedule 4 — International Transfers
Where ASUME transfers Processor Personal Data from the EEA to a recipient in a country that does not benefit from an applicable adequacy decision, ASUME will use a transfer mechanism permitted under Chapter V GDPR.
Where appropriate, the SCCs under Commission Implementing Decision (EU) 2021/914 will apply. For onward transfers by ASUME as Processor to a Subprocessor located outside the EEA, Module Three — Processor to Processor will generally apply where the SCCs are the applicable mechanism.
If a Restricted Transfer takes place directly between Customer and ASUME and the SCCs are legally required, the applicable module will be incorporated into this DPA. The information required to complete the SCCs will be deemed provided by this DPA, Schedule 1, Schedule 2, the applicable Order Form, the Security Measures, and the Subprocessor List to the extent permitted by the SCCs.
Where required, ASUME will assess the circumstances of a Restricted Transfer and implement supplementary safeguards appropriate to the risks of the transfer.
For Personal Data protected by UK or Swiss data-protection law, applicable UK transfer addenda, Swiss adaptations, or other legally recognised safeguards will apply where required.
Schedule 5 — Additional Terms for Applicable U.S. Privacy Laws
This Schedule applies only where Processor Personal Data is subject to a U.S. state privacy law that applies to ASUME’s Processing and ASUME qualifies as a “processor,” “service provider,” “contractor,” or equivalent regulated recipient under that law.
ASUME will Process such Processor Personal Data only for the limited and specified business purposes described in the Agreement and this DPA and will comply with obligations applicable to ASUME in its regulated role.
To the extent required by applicable U.S. privacy law, ASUME will not sell Processor Personal Data, share Processor Personal Data for cross-context behavioural advertising, use Processor Personal Data for purposes outside the direct business relationship except as legally permitted, or combine Processor Personal Data with Personal Data received from another source except where permitted by applicable law.
ASUME will notify Customer if ASUME determines that it can no longer meet an obligation applicable to ASUME under this Schedule and will take reasonable and appropriate steps to stop and remediate unauthorised Processing where required.
Customer may take reasonable and appropriate steps to verify ASUME’s compliance with this Schedule through the audit and information mechanisms provided in Section 11.
Nothing in this Schedule requires ASUME to undertake obligations that do not apply to it under the relevant U.S. privacy law.