Data Processing Agreement
Effective: 6 August 2026. Version: 1.0. Article 28 processor terms — UK GDPR & EU GDPR.
1. Introduction and incorporation
This Data Processing Agreement (“DPA”) forms part of, and is incorporated by reference into, the EnableGRC Subscription Terms & Conditions (the “Agreement”) between WislPort Compliance Limited (registered in Gibraltar, company number 124227), trading as EnableGRC (“we”, “us”, the “Processor”), and the customer organisation identified in the Agreement (the “Customer”, the “Controller”). It records the parties’ obligations under Article 28 of the UK GDPR and the EU GDPR in respect of Customer Personal Data processed through the EnableGRC platform (the “Service”).
Where this DPA conflicts with the body of the Agreement on the subject of data protection, this DPA prevails. Where this DPA conflicts with the Standard Contractual Clauses or the UK International Data Transfer Addendum incorporated under clause 11, those clauses prevail to the extent of the conflict.
Acceptance. This DPA is incorporated into and forms part of the Agreement; by accepting the Agreement (by starting a trial, placing an order, or using the Service) the Customer accepts this DPA. No separate signature is required.
2. Definitions
“Data Protection Laws” means all laws applicable to the processing of personal data under the Agreement, including the UK GDPR, the EU GDPR (Regulation 2016/679), the UK Data Protection Act 2018, and the Gibraltar Data Protection Act 2004, in each case as amended or replaced.
“Customer Personal Data” means any personal data contained in Customer Data (as defined in the Agreement) that we process on the Customer’s behalf as a processor in providing the Service.
“Sub-processor” means any third party engaged by us to process Customer Personal Data in connection with the Service.
“Standard Contractual Clauses” (“SCCs”) means the clauses annexed to European Commission Implementing Decision (EU) 2021/914; and “UK Addendum” / “UK IDTA” means the UK International Data Transfer Addendum or the UK International Data Transfer Agreement issued by the UK Information Commissioner.
The terms “controller”, “processor”, “data subject”, “personal data”, “processing” and “personal data breach” have the meanings given in the Data Protection Laws.
3. Roles and scope of processing
3.1 As between the parties, the Customer is the controller and we are the processor in respect of Customer Personal Data. Where the Customer is itself a processor for a third-party controller, the Customer warrants it has the third party’s authority for us to act as sub-processor on the terms of this DPA.
3.2 We will process Customer Personal Data only on the Customer’s documented instructions, including as to international transfers, unless required to do otherwise by a law to which we are subject; in that case we will inform the Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.
3.3 The Agreement, this DPA (including Annex I), the configuration options the Customer selects, and the Customer’s use of the Service constitute the Customer’s complete documented instructions. Any additional instruction must be agreed in writing and may be subject to charges where it requires material change to the Service.
3.4 We will inform the Customer if, in our opinion, an instruction infringes the Data Protection Laws (without obligation to provide legal advice).
4. Our obligations as processor
We will, in respect of Customer Personal Data:
- (a) Instructions — process it only as set out in clause 3;
- (b) Confidentiality — ensure that persons authorised to process it are bound by an appropriate duty of confidentiality (clause 5);
- (c) Security — implement the technical and organisational measures required by Article 32 and set out in Annex II (clause 6);
- (d) Sub-processing — engage Sub-processors only on the terms of clause 7;
- (e) Data subject requests — assist the Customer under clause 8;
- (f) Assistance — assist the Customer with security, breach notification, data protection impact assessments and prior consultation under clauses 9 and 10;
- (g) Return / deletion — return or delete Customer Personal Data at the end of the Service under clause 12; and
- (h) Audit — make available the information, and allow for and contribute to audits, described in clause 13.
5. Confidentiality of personnel
We limit access to Customer Personal Data to personnel who need it to provide, support or secure the Service, and we bind those personnel by written confidentiality obligations that survive the end of their engagement. Personnel receive data-protection and security awareness training appropriate to their role.
6. Security of processing
6.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk to data subjects, we implement and maintain the technical and organisational measures set out in Annex II to ensure a level of security appropriate to the risk.
6.2 We may update those measures from time to time provided the update does not materially reduce the overall level of security of the Service.
7. Sub-processors
7.1 The Customer gives a general authorisation for us to engage the Sub-processors listed in Annex III (also published and kept current at enablegrc.ai/subprocessors), and to engage further Sub-processors subject to this clause.
7.2 We will give the Customer at least 30 days’ prior notice of the addition or replacement of a Sub-processor that processes Customer Personal Data, by email and by updating the sub-processors page. The Customer may object on reasonable data-protection grounds within the notice period; if we cannot resolve the objection, the Customer may terminate the affected part of the Service as set out in the Agreement.
7.3 We impose on each Sub-processor, by written contract, data-protection obligations no less protective than those in this DPA, and we remain fully liable to the Customer for each Sub-processor’s performance of those obligations.
8. Assisting with data subject rights
Taking into account the nature of the processing, we will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests by data subjects exercising their rights under the Data Protection Laws (including access, rectification, erasure, restriction, portability and objection). Where a data subject makes such a request to us directly, we will, unless legally prohibited, promptly forward it to the Customer and not respond ourselves except to confirm the request has been passed on.
9. Personal data breach
9.1 We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.
9.2 Our notification will describe, to the extent known and as it becomes available, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it, so as to assist the Customer in meeting its own notification obligations. We will not make notifications to a supervisory authority or data subjects on the Customer’s behalf unless required by law or expressly instructed.
10. Impact assessments and prior consultation
Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to the Customer with data protection impact assessments and any prior consultation with a supervisory authority that the Customer is required to carry out under Articles 35 and 36.
11. International transfers
11.1 The Service is hosted in the EU (Frankfurt), with object storage in the EU. Where providing the Service involves a restricted transfer of Customer Personal Data (a transfer to a country without an adequacy decision applicable to the transfer), that transfer is made subject to appropriate safeguards under the Data Protection Laws.
11.2 For such transfers the parties incorporate, as applicable, the EU Standard Contractual Clauses (Module Two, controller-to-processor, and Module Three where we onward-transfer to a Sub-processor) and the UK International Data Transfer Addendum. Annex I completes the SCC Annex I; Annex II completes SCC Annex II; Annex III lists the sub-processors for the purpose of the SCCs.
11.3 Each Sub-processor located outside the UK/EEA is engaged under its own SCCs, UK Addendum, or an applicable adequacy mechanism (including the EU–US Data Privacy Framework and its UK Extension), as summarised in Annex III.
12. Return and deletion
12.1 On expiry or termination of the Service, the Customer may export Customer Data for a limited window as set out in the Agreement.
12.2 After that window we will delete or irreversibly anonymise Customer Personal Data in our production systems, and instruct Sub-processors to do the same, unless retention is required by a law to which we are subject (in which case we will protect it and process it only as required by that law). Trial data that is not converted to a subscription is retained for 30 days after the trial ends and then deleted. Backups are overwritten on their normal cycle.
12.3 On request we will certify in writing that deletion has been completed.
13. Information and audit
13.1 We will make available to the Customer the information reasonably necessary to demonstrate compliance with Article 28 and this DPA, which may be satisfied by our security documentation, certifications and third-party reports where available.
13.2 We will allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor it mandates, on reasonable prior written notice (normally at least 30 days), no more than once in any 12-month period except where required by a supervisory authority or following a personal data breach, during business hours, subject to confidentiality and without compromising the security of other customers’ data.
14. The Customer’s obligations
The Customer warrants that: (a) it has a lawful basis and any required notices or consents for the Customer Personal Data it processes through the Service; (b) its instructions comply with the Data Protection Laws; and (c) it is responsible for the accuracy, quality and legality of Customer Personal Data and for the categories of data and data subjects it chooses to input, including any special-category or criminal-offence data.
15. Liability
Each party’s liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this DPA limits either party’s liability to a data subject or a supervisory authority under the Data Protection Laws.
16. Term
This DPA takes effect on the effective date of the Agreement and continues while we process Customer Personal Data, after which clauses 12 (return and deletion), 13 (audit, to the extent of records retained) and 15 (liability) survive.
17. Governing law
This DPA is governed by the laws of Gibraltar and subject to the exclusive jurisdiction of the courts of Gibraltar, consistent with the Agreement, except that the SCCs and the UK Addendum are governed by, and disputes concerning them determined under, the law and forum those instruments specify.
18. Contact
Data-protection contact: privacy@enablegrc.ai. Principal address: as stated in the EnableGRC Privacy Notice.
Annex I — Description of the processing
Parties. Controller / data exporter: the Customer identified in the Agreement. Processor / data importer: WislPort Compliance Limited t/a EnableGRC, Gibraltar (company 124227).
| Element | Detail |
|---|---|
| Subject matter | Provision of the EnableGRC governance, risk and compliance (GRC) SaaS platform to the Customer. |
| Duration | For the term of the subscription and the return/deletion period in clause 12. |
| Nature & purpose | Hosting, storage, transmission, display, analysis and processing of Customer Data to deliver GRC functionality (governance, risk, compliance obligations, policies, controls, evidence, workflows, reporting and AI-assisted insights) as configured by the Customer. |
| Frequency | Continuous, for the duration of the subscription. |
| Categories of personal data | Identification and business-contact data of the Customer’s users and personnel (name, work email, job title, role, business unit); user-generated content that may contain personal data (e.g. named owners, reviewers and approvers, assignees, attestation and audit-trail records); and any further personal data the Customer chooses to input. |
| Special-category / sensitive data | None processed as part of the Service at present. This description will be updated before the Ethics & Conduct (whistleblowing / conflicts-of-interest) pack — which may involve such data — is made available. |
| Categories of data subjects | The Customer’s employees, officers, directors, workers and contractors; and other individuals whose data the Customer inputs (for example third-party or business contacts). |
Annex II — Technical and organisational measures
We maintain the following measures appropriate to the risk (Article 32):
- Encryption — data encrypted in transit (TLS) and at rest.
- Tenant isolation — logical separation of each customer’s data, enforced at the database layer (row-level security), so one customer cannot access another’s data.
- Access control — role-based access control and least-privilege administration; multi-factor authentication for administrative access; access reviews.
- Hosting — EU (Frankfurt) managed PostgreSQL and application compute; EU object storage.
- Resilience & recovery — encrypted off-site backups, point-in-time recovery, and a disaster-recovery process with tested restores.
- Auditability — append-only audit logging of security-relevant events.
- Secure development — secure software development lifecycle, change control, dependency and vulnerability management.
- Sub-processor assurance — Sub-processors engaged under written data-processing terms incorporating SCCs / UK Addendum as applicable.
- People — confidentiality obligations and security-awareness training for personnel.
- Incident response — documented personal-data-breach response and notification process (clause 9).
Annex III — Sub-processors
Current as at the effective date; the authoritative, maintained list is at enablegrc.ai/subprocessors.
| Sub-processor | Purpose | Location / residency | Transfer safeguard |
|---|---|---|---|
| Neon | Managed PostgreSQL — primary application data store | EU — Frankfurt (eu-central-1) | EU-hosted; Neon DPA incorporating SCCs |
| Render | Application hosting & compute | EU — Frankfurt | EU-hosted; Render DPA incorporating SCCs |
| Cloudflare R2 | Object storage — uploaded documents, evidence, attachments | EU (Europe) | Cloudflare DPA incorporating SCCs |
| Cloudflare | CDN, DNS, DDoS / bot protection (WAF) | Global edge network | SCCs; no application data stored beyond edge logs |
| Stripe | Payment processing & subscription billing | UK / EU / US | SCCs; PCI-DSS (card data handled by Stripe) |
| Resend | Transactional email delivery | United States | EU–US Data Privacy Framework + UK Extension (SCCs backstop) |
| Anthropic (Claude) | AI features (insights, anomaly detection, report narrative) | United States | EU SCCs (Modules 2/3) + UK Addendum; content not used for training; API logs auto-delete after 7 days |
Sentry (error monitoring) is provisioned but not enabled in production; no data flows to it and it will be added here when activated.