Data Processing Addendum
DATA PROCESSING ADDENDUM
Last updated: 17 June 2026
This Data Processing Addendum (“DPA”) sets out the terms on which the Zartis entity that is party to the relevant Services Agreement (“Zartis”, “Supplier”, “Data Processor”) processes personal data on behalf of clients (“Client”, “Data Controller”) in connection with the delivery of the Agentify the C-Suite programme. “Zartis” refers to AssemblyPoint Limited and its Subsidiaries trading as Zartis.com, and this DPA applies regardless of which Zartis entity has entered into the Services Agreement with the Client. This DPA is incorporated by reference into the Services Agreement between the parties (the “Agreement”) and forms part of it. In the event of any conflict between this DPA and the Agreement, this DPA shall prevail in respect of the processing of personal data.
DEFINITIONS
“Subsidiaries” means any entity that directly or indirectly is controlled by or is under common control with the subject entity.
“Controller” means the entity which determines the purposes and means of the Processing of Personal Data.
“Data Protection Laws and Regulations” means all laws and regulations, including laws and regulations of the European Union, the European Economic Area and their member states, Switzerland and the United Kingdom, applicable to the Processing of Personal Data under the DPA.
“Data Subject” means the identified or identifiable person to whom Personal Data relates.
“GDPR” means the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation).
“International Organisation” means an organisation and its subordinate bodies governed by public international law, or any other body which is set up by, or on the basis of, an agreement between two or more countries
“Personal Data” means any information relating to an identified or identifiable natural person (‘Data Subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
“Processing” means any operation or set of operations which is performed upon Personal Data, whether or not by automatic means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
“Processor” means the entity which processes Personal Data on behalf of the Controller.
“ZARTIS Group” or “Group” means AssemblyPoint Limited and its Subsidiaries engaged in the Processing of Personal Data.
“Contract” means the primary Service(s) Agreement or Master Service(s) Agreement between the two Parties. This DPA is an ancillary contract aiming to govern the processing between Controller and Processor.
“Sub-processor” means any Processor engaged by Data Processor or a member of the ZARTIS Group.
“Supervisory Authority” means an independent public authority which is established by an EU Member State pursuant to the GDPR.
“Third Country” means any country outside of the European Economic Area, without an adequacy decision from the EU commission.
1. PURPOSE OF THE DPA
1.1 By virtue of this DPA, Supplier and its Subsidiaries, acting as Data Processor, shall process Client’s Personal Data according to the instructions provided in ANNEX A by the Client, who will act as Data Controller, unless such instructions conflict with Regulation (UE) 2016/679 or any other provision related to Data Protection in the European Union. Whenever the Supplier may consider any of the instructions are infringing Supplier shall promptly inform the Client. Supplier shall not use these Data for its own purposes.
1.2 Such processing activities as described in ANNEX A, may include, but are not limited to collection, recording, structuration, modification, conservation, extraction, consultation, communication, diffusion, interconnection, comparison, limitation, erasure and destruction.
1.3 Data Processor may, in connection with the provision of the Services, or in the normal course of business, make international transfers of the Personal Data to its Subsidiaries and/or Subprocessors. When making such transfers, Data Processor shall ensure appropriate protection is in place to safeguard the Personal Data transferred under or in connection with the Contract and this Data Processing Addendum. In the event of transfers to a third country or international organisation Data Processor shall ensure at least one of the following is fulfilled:
1.3.1 The European Commission has decided that the third country, a territory or one or more specified sectors within that third country, or the international organisation in question ensures an adequate level of protection. Such a transfer shall not require any specific authorization.
1.3.2 Recipient offers an adequate level of guarantees in the absence of a decision pursuant to Article 45 (3) GDPR, a controller or processor may transfer Personal Data to a third country or an international organisation only if the controller or processor has provided appropriate safeguards, and on condition that enforceable Data Subject rights and effective legal remedies for Data Subjects are available.
1.3.3 The Data Subject has given consent to such transfer after being informed of the risks for those transfers due to the absence of an adequacy decision and appropriate safeguards.
2. DURATION
2.1 This DPA remains in force for the duration of the Agreement.
OBLIGATIONS FOR THE DATA PROCESSOR
3.1 The Data Processor is bound to:
3.1.1 Process the data according only to documented instructions of the Data Controller, including with regard to transfers of Personal Data to a third country or international organisation, unless required to do so by Union or Member State law to which the processor is subject; in such case the processor shall inform the controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
3.1.2 Ensure that personnel authorised to process Personal Data is committed expressly and in writing to keep this confidentiality and observe the corresponding security measures.
3.1.3 Provide access to GDPR training for the personnel authorised to process Personal Data. Any additional data protection training needed, is to be agreed between the Parties.
3.1.4 Collect necessary consent for the purpose of the data processing. The wording and format for the information to be provided on consent collection shall be agreed by the Data Controller and the Data Processor before starting the collection of Personal Data.
3.1.5 Not disclose any data to third Parties unless expressly authorised by the Data Controller, or in the cases legally admitted. The Data Processor may communicate data to other Data Processors of the same Data Controller, according to the instructions of the latter. In this case, the Data Controller shall identify in advance and in writing the recipients to whom the data will be communicated, the data to be communicated and the applicable security measures to proceed with the communication.
3.1.6 Observe, at any time, in relation with the data files whose access had been granted or handed by the Data Controller for the performance of the services agreed, the utmost confidentiality and professional secrecy. This obligation shall survive this agreement.
4. SECURITY MEASURES
4.1 Implement appropriate technical and organisational measures to ensure the level of security appropriate to the risk according to article 32 of the GDPR.
4.2 Supplier shall implement adequate security measures to guarantee:
4.2.1 Confidentiality, integrity, availability and permanent resilience of the processing systems and services.
4.2.2 Restoration of the availability and access to Personal Data in a timely manner in the event of physical or technical incidence.
4.2.3 Verify and assess on a regular basis the effectiveness of the technical and organisational measures implemented to guarantee the security of the processing.
4.2.4 Pseudonymisation and encryption of Personal Data if applicable.
5. SUBPROCESSING
5.1 Zartis may engage the following categories of Sub-processor:
(a) Tools and service providers: third-party platforms, software, and infrastructure services used to support delivery of the Services (e.g. cloud hosting, communication tools). The current list of sub-processors is available at: https://www.zartis.com/customer-privacy-policy/subprocessors/
(b) Subcontractors: external individuals or entities contracted by Zartis to carry out specific aspects of the Services. When Client data is to be sub-processed by a subcontractor, Zartis shall notify the Client by email. For each subcontractor sub-processor, Zartis shall: (i) enter into a written agreement imposing the same data protection obligations as this DPA; and (ii) remain responsible for any acts or omissions of the subcontractor that cause Zartis to breach its obligations under this DPA.
5.2 Zartis shall inform the Client in writing of any intended changes to the list of Tools and Service sub-processors at least 14 days before the new sub-processor is engaged, including the purpose, type of data processed (if applicable), and location of processing. The Client may raise reasonable objections within that period.
5.3 Zartis shall provide prior written notice of any intended changes to the list of subcontractor sub-processors, including the name, location, and role of the proposed subcontractor. Zartis shall not engage any new subcontractor sub-processor to process Client Personal Data without first obtaining the Client’s written approval.
5.4 Zartis may use sub-processors located in the following countries: European Union member states, Bosnia and Herzegovina, Serbia, Albania, Montenegro, North Macedonia, Egypt, Turkey, South Africa, Brazil, Mexico, Chile, Colombia, Uruguay, Argentina, and Ecuador. This list may be expanded with the Client’s written approval.
6. SUPPORT TO DATA CONTROLLER IN COMPLIANCE OBLIGATIONS
6.1 Supplier shall:
6.1.1 Make available all information necessary to demonstrate compliance with the Data Processor obligations and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller. Client might be required to enter a non-disclosure agreement before any information of the Supplier is provided.
6.1.2 Provide necessary support to the Data Controller for impact assessment as appropriate.
6.1.3 Provide necessary support to the Data Controller in prior consultations to the supervisory authority.
6.1.4 Assist controller in ensuring compliance with the obligations pursuant to article 32 to 36, taking into account the nature of processing and the information available to the processor.
6.1.5 In the case of a Personal Data breach, the processor shall, without undue delay and, not later than 72 hours after having become aware of it, notify the Personal Data breach of the processed data to the Data Controller by email to (email address). This communication shall report all the relevant information for the documentation and communication of the breach. Notification shall not be necessary where the breach is unlikely to result in a risk for the rights and freedoms of the Data Subjects. If available, the following information shall be provided:
6.1.5.1 The nature of the Personal Data breach including where possible, the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned;
6.1.5.2 The name and contact details of the data protection officer or other contact point where more information can be obtained;
6.1.5.3 The likely consequences of the Personal Data breach;
6.1.5.4 The measures taken or proposed to be taken by the controller to address the Personal Data breach, including, where appropriate, measures to mitigate its possible adverse effects.
6.1.6 When the Personal Data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the Personal Data breach to the Data Subject without undue delay. This communication shall contain the information referred in clause 6.1.5.
6.1.7 Assist the Data Controller in addressing the exercise of the Data Subject rights, such as access, rectification, erasure, restriction of processing, portability, right to object automated individual decision-making, including profiling. The Data Processor shall solve, on behalf of the Data Controller, in the term set out for this purpose, any request regarding the exercise of the Data Subject rights.
7. DESTINATION OF DATA AFTER TERMINATION
7.1 On termination of this DPA the Data Processor shall, as accordingly agreed on ANNEX A to return or destroy (i) Personal Data accessed; (ii) Personal Data generated by the Data Processor by reason of the processing; (iii) Personal Data stored on physical devices or documents where the Personal Data is contained, not keeping any copy unless legally permitted or required, in which case they will not be destroyed. However, Data Processor shall be entitled to keep the data during the time that responsibilities may arise from the relation with the Data Controller. In that case Personal Data will be kept and blocked for the minimum time required, ensuring a safe and definitive destruction at the end of that term.
8. OBLIGATIONS FOR DATA CONTROLLER
8.1 Data Controller is bound to:
8.1.1 Make available data to be processed.
8.1.2 Carry out any impact assessment of the data processing activities to be conducted by the Data Processor that might be appropriate.
8.1.3 Conduct any necessary prior consultations that might be required.
8.1.4 Ensure fulfilment of the GDPR, prior and during the data processing.
8.1.5 Supervise the data processing, including inspections and audits.
9. DATA PROCESSOR LIABILITIES
9.1 Data Processor shall indemnify the Data Controller for any damages arising from the infringement of the obligations pertaining to this DPA. The Data Processor’s liability under this DPA is to be limited to five hundred thousand euros.
9.2 Neither Party will be liable to the other Party for any incidental, consequential, indirect (including, without limitation, damages for loss of profits or revenues, business interruption loss of business information, or other loss), special, exemplary or punitive damages, nor not reasonably predictable damages arising out of this DPA.
10. NOTIFICATIONS
10.1 Notifications shall be made according to the Contract.
10.2 Any notification between the Parties will be in writing and will be handed personally or by any other means that certifies receipt by the notified Party.
11. MISCELLANEOUS
11.1 This DPA governs the data processing relationship between the parties and supersedes any prior data protection agreement between them on the same subject matter. Any modification requires written agreement by both parties.
11.2 The obligations in this DPA bind the parties and their respective legal successors.
11.3 If any provision of this DPA is or becomes invalid or unenforceable, the remaining provisions shall continue in force. The parties shall replace any invalid provision with one that, as closely as possible, achieves the original intent.
ANNEX — PROCESSING DETAILS
Processing details applicable to the Agentify the C-Suite programme.
Subject matter and duration
The subject matter and duration of processing are set out in the Agreement.
Nature and purpose of processing
The following processing activities apply:
- ✅ Collection
- ✅ Recording
- ✅ Use
- ✅ Deletion
Purpose: delivery of the Agentify the C-Suite programme as defined in the Agreement, comprising: (i) scoping and use-case prioritisation; (ii) enablement and configuration of the Client’s Cowork environment; (iii) building, configuring, and refining the Custom AI Companion using materials and context provided by or on behalf of the Executive; and (iv) where the Phase IV retainer is engaged, ongoing advisory support. Processing is carried out solely on the Client’s instructions and for no other purpose.
Types of data processed
- ✅ Client employee data (including the named Executive’s contextual materials, calendar, email, and CRM data accessed during the programme)
- ✅ Client customer data of companies (company-level data accessible through the Executive’s contextual materials, CRM and other connectors during the programme)
To the extent that CRM or other connector data accessed during the programme includes contact details or other information relating to identifiable individuals at client companies (such as names, email addresses, or job titles), such data constitutes Personal Data and is processed solely to the extent necessary for delivery of the Services.
Categories of Personal Data
- ✅ Other Personal Data not included in the special categories (Art. 9 GDPR)
Data collected from children under 16
- ✅ No
Sub-processors
As set out in Clause 5 of this DPA.
Destination of Personal Data on termination
- ✅ Deletion
Personal Data is processed for the duration of the Agreement. On termination, all Personal Data is deleted in accordance with Clause 7 of this DPA and the Agreement. No Personal Data is retained by Zartis beyond termination except where required by applicable law, in which case it is stored in blocked form and destroyed at the earliest permitted opportunity.