Skip to content
EnableGRC
  • Our solution
  • Features
  • Pricing
Client login Register interest

Data Processing Agreement

Effective: 6 August 2026. Version: 1.0. Article 28 processor terms — UK GDPR & EU GDPR.

1. Introduction and incorporation

This Data Processing Agreement (“DPA”) forms part of, and is incorporated by reference into, the EnableGRC Subscription Terms & Conditions (the “Agreement”) between WislPort Compliance Limited (registered in Gibraltar, company number 124227), trading as EnableGRC (“we”, “us”, the “Processor”), and the customer organisation identified in the Agreement (the “Customer”, the “Controller”). It records the parties’ obligations under Article 28 of the UK GDPR and the EU GDPR in respect of Customer Personal Data processed through the EnableGRC platform (the “Service”).

Where this DPA conflicts with the body of the Agreement on the subject of data protection, this DPA prevails. Where this DPA conflicts with the Standard Contractual Clauses or the UK International Data Transfer Addendum incorporated under clause 11, those clauses prevail to the extent of the conflict.

Acceptance. This DPA is incorporated into and forms part of the Agreement; by accepting the Agreement (by starting a trial, placing an order, or using the Service) the Customer accepts this DPA. No separate signature is required.

2. Definitions

“Data Protection Laws” means all laws applicable to the processing of personal data under the Agreement, including the UK GDPR, the EU GDPR (Regulation 2016/679), the UK Data Protection Act 2018, and the Gibraltar Data Protection Act 2004, in each case as amended or replaced.

“Customer Personal Data” means any personal data contained in Customer Data (as defined in the Agreement) that we process on the Customer’s behalf as a processor in providing the Service.

“Sub-processor” means any third party engaged by us to process Customer Personal Data in connection with the Service.

“Standard Contractual Clauses” (“SCCs”) means the clauses annexed to European Commission Implementing Decision (EU) 2021/914; and “UK Addendum” / “UK IDTA” means the UK International Data Transfer Addendum or the UK International Data Transfer Agreement issued by the UK Information Commissioner.

The terms “controller”, “processor”, “data subject”, “personal data”, “processing” and “personal data breach” have the meanings given in the Data Protection Laws.

3. Roles and scope of processing

3.1 As between the parties, the Customer is the controller and we are the processor in respect of Customer Personal Data. Where the Customer is itself a processor for a third-party controller, the Customer warrants it has the third party’s authority for us to act as sub-processor on the terms of this DPA.

3.2 We will process Customer Personal Data only on the Customer’s documented instructions, including as to international transfers, unless required to do otherwise by a law to which we are subject; in that case we will inform the Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.

3.3 The Agreement, this DPA (including Annex I), the configuration options the Customer selects, and the Customer’s use of the Service constitute the Customer’s complete documented instructions. Any additional instruction must be agreed in writing and may be subject to charges where it requires material change to the Service.

3.4 We will inform the Customer if, in our opinion, an instruction infringes the Data Protection Laws (without obligation to provide legal advice).

4. Our obligations as processor

We will, in respect of Customer Personal Data:

  • (a) Instructions — process it only as set out in clause 3;
  • (b) Confidentiality — ensure that persons authorised to process it are bound by an appropriate duty of confidentiality (clause 5);
  • (c) Security — implement the technical and organisational measures required by Article 32 and set out in Annex II (clause 6);
  • (d) Sub-processing — engage Sub-processors only on the terms of clause 7;
  • (e) Data subject requests — assist the Customer under clause 8;
  • (f) Assistance — assist the Customer with security, breach notification, data protection impact assessments and prior consultation under clauses 9 and 10;
  • (g) Return / deletion — return or delete Customer Personal Data at the end of the Service under clause 12; and
  • (h) Audit — make available the information, and allow for and contribute to audits, described in clause 13.

5. Confidentiality of personnel

We limit access to Customer Personal Data to personnel who need it to provide, support or secure the Service, and we bind those personnel by written confidentiality obligations that survive the end of their engagement. Personnel receive data-protection and security awareness training appropriate to their role.

6. Security of processing

6.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk to data subjects, we implement and maintain the technical and organisational measures set out in Annex II to ensure a level of security appropriate to the risk.

6.2 We may update those measures from time to time provided the update does not materially reduce the overall level of security of the Service.

7. Sub-processors

7.1 The Customer gives a general authorisation for us to engage the Sub-processors listed in Annex III (also published and kept current at enablegrc.ai/subprocessors), and to engage further Sub-processors subject to this clause.

7.2 We will give the Customer at least 30 days’ prior notice of the addition or replacement of a Sub-processor that processes Customer Personal Data, by email and by updating the sub-processors page. The Customer may object on reasonable data-protection grounds within the notice period; if we cannot resolve the objection, the Customer may terminate the affected part of the Service as set out in the Agreement.

7.3 We impose on each Sub-processor, by written contract, data-protection obligations no less protective than those in this DPA, and we remain fully liable to the Customer for each Sub-processor’s performance of those obligations.

8. Assisting with data subject rights

Taking into account the nature of the processing, we will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests by data subjects exercising their rights under the Data Protection Laws (including access, rectification, erasure, restriction, portability and objection). Where a data subject makes such a request to us directly, we will, unless legally prohibited, promptly forward it to the Customer and not respond ourselves except to confirm the request has been passed on.

9. Personal data breach

9.1 We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.

9.2 Our notification will describe, to the extent known and as it becomes available, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it, so as to assist the Customer in meeting its own notification obligations. We will not make notifications to a supervisory authority or data subjects on the Customer’s behalf unless required by law or expressly instructed.

10. Impact assessments and prior consultation

Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to the Customer with data protection impact assessments and any prior consultation with a supervisory authority that the Customer is required to carry out under Articles 35 and 36.

11. International transfers

11.1 The Service is hosted in the EU (Frankfurt), with object storage in the EU. Where providing the Service involves a restricted transfer of Customer Personal Data (a transfer to a country without an adequacy decision applicable to the transfer), that transfer is made subject to appropriate safeguards under the Data Protection Laws.

11.2 For such transfers the parties incorporate, as applicable, the EU Standard Contractual Clauses (Module Two, controller-to-processor, and Module Three where we onward-transfer to a Sub-processor) and the UK International Data Transfer Addendum. Annex I completes the SCC Annex I; Annex II completes SCC Annex II; Annex III lists the sub-processors for the purpose of the SCCs.

11.3 Each Sub-processor located outside the UK/EEA is engaged under its own SCCs, UK Addendum, or an applicable adequacy mechanism (including the EU–US Data Privacy Framework and its UK Extension), as summarised in Annex III.

12. Return and deletion

12.1 On expiry or termination of the Service, the Customer may export Customer Data for a limited window as set out in the Agreement.

12.2 After that window we will delete or irreversibly anonymise Customer Personal Data in our production systems, and instruct Sub-processors to do the same, unless retention is required by a law to which we are subject (in which case we will protect it and process it only as required by that law). Trial data that is not converted to a subscription is retained for 30 days after the trial ends and then deleted. Backups are overwritten on their normal cycle.

12.3 On request we will certify in writing that deletion has been completed.

13. Information and audit

13.1 We will make available to the Customer the information reasonably necessary to demonstrate compliance with Article 28 and this DPA, which may be satisfied by our security documentation, certifications and third-party reports where available.

13.2 We will allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor it mandates, on reasonable prior written notice (normally at least 30 days), no more than once in any 12-month period except where required by a supervisory authority or following a personal data breach, during business hours, subject to confidentiality and without compromising the security of other customers’ data.

14. The Customer’s obligations

The Customer warrants that: (a) it has a lawful basis and any required notices or consents for the Customer Personal Data it processes through the Service; (b) its instructions comply with the Data Protection Laws; and (c) it is responsible for the accuracy, quality and legality of Customer Personal Data and for the categories of data and data subjects it chooses to input, including any special-category or criminal-offence data.

15. Liability

Each party’s liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this DPA limits either party’s liability to a data subject or a supervisory authority under the Data Protection Laws.

16. Term

This DPA takes effect on the effective date of the Agreement and continues while we process Customer Personal Data, after which clauses 12 (return and deletion), 13 (audit, to the extent of records retained) and 15 (liability) survive.

17. Governing law

This DPA is governed by the laws of Gibraltar and subject to the exclusive jurisdiction of the courts of Gibraltar, consistent with the Agreement, except that the SCCs and the UK Addendum are governed by, and disputes concerning them determined under, the law and forum those instruments specify.

18. Contact

Data-protection contact: privacy@enablegrc.ai. Principal address: as stated in the EnableGRC Privacy Notice.


Annex I — Description of the processing

Parties. Controller / data exporter: the Customer identified in the Agreement. Processor / data importer: WislPort Compliance Limited t/a EnableGRC, Gibraltar (company 124227).

ElementDetail
Subject matterProvision of the EnableGRC governance, risk and compliance (GRC) SaaS platform to the Customer.
DurationFor the term of the subscription and the return/deletion period in clause 12.
Nature & purposeHosting, storage, transmission, display, analysis and processing of Customer Data to deliver GRC functionality (governance, risk, compliance obligations, policies, controls, evidence, workflows, reporting and AI-assisted insights) as configured by the Customer.
FrequencyContinuous, for the duration of the subscription.
Categories of personal dataIdentification and business-contact data of the Customer’s users and personnel (name, work email, job title, role, business unit); user-generated content that may contain personal data (e.g. named owners, reviewers and approvers, assignees, attestation and audit-trail records); and any further personal data the Customer chooses to input.
Special-category / sensitive dataNone processed as part of the Service at present. This description will be updated before the Ethics & Conduct (whistleblowing / conflicts-of-interest) pack — which may involve such data — is made available.
Categories of data subjectsThe Customer’s employees, officers, directors, workers and contractors; and other individuals whose data the Customer inputs (for example third-party or business contacts).

Annex II — Technical and organisational measures

We maintain the following measures appropriate to the risk (Article 32):

  • Encryption — data encrypted in transit (TLS) and at rest.
  • Tenant isolation — logical separation of each customer’s data, enforced at the database layer (row-level security), so one customer cannot access another’s data.
  • Access control — role-based access control and least-privilege administration; multi-factor authentication for administrative access; access reviews.
  • Hosting — EU (Frankfurt) managed PostgreSQL and application compute; EU object storage.
  • Resilience & recovery — encrypted off-site backups, point-in-time recovery, and a disaster-recovery process with tested restores.
  • Auditability — append-only audit logging of security-relevant events.
  • Secure development — secure software development lifecycle, change control, dependency and vulnerability management.
  • Sub-processor assurance — Sub-processors engaged under written data-processing terms incorporating SCCs / UK Addendum as applicable.
  • People — confidentiality obligations and security-awareness training for personnel.
  • Incident response — documented personal-data-breach response and notification process (clause 9).

Annex III — Sub-processors

Current as at the effective date; the authoritative, maintained list is at enablegrc.ai/subprocessors.

Sub-processorPurposeLocation / residencyTransfer safeguard
NeonManaged PostgreSQL — primary application data storeEU — Frankfurt (eu-central-1)EU-hosted; Neon DPA incorporating SCCs
RenderApplication hosting & computeEU — FrankfurtEU-hosted; Render DPA incorporating SCCs
Cloudflare R2Object storage — uploaded documents, evidence, attachmentsEU (Europe)Cloudflare DPA incorporating SCCs
CloudflareCDN, DNS, DDoS / bot protection (WAF)Global edge networkSCCs; no application data stored beyond edge logs
StripePayment processing & subscription billingUK / EU / USSCCs; PCI-DSS (card data handled by Stripe)
ResendTransactional email deliveryUnited StatesEU–US Data Privacy Framework + UK Extension (SCCs backstop)
Anthropic (Claude)AI features (insights, anomaly detection, report narrative)United StatesEU SCCs (Modules 2/3) + UK Addendum; content not used for training; API logs auto-delete after 7 days

Sentry (error monitoring) is provisioned but not enabled in production; no data flows to it and it will be added here when activated.

EnableGRC

Simplify complexity. Power growth.

  • Privacy notice
  • Terms of use
  • Subscription T&Cs
  • Cookie policy
  • Sub-processors
  • DPA