DATA PROCESSING AGREEMENT

Data Processing Terms – English

Version: 2.3
Version date: 10 August 2026

DATA PROCESSING AGREEMENT

These data processing terms (the “DPA”) form part of and are incorporated by reference into the agreement under which Imprima, or the relevant Imprima Affiliate, provides the Services to the Client (the “Service Agreement”).

The relevant Imprima contracting entity is referred to as the “Service Provider”. The customer identified in the Service Agreement is referred to as the “Client”. For the processing described in this DPA, the Client acts as controller and the Service Provider acts as processor, except where Data Protection Law provides otherwise for a particular processing activity.

By entering into the Service Agreement, or by continuing to provide or receive the Services where this DPA has been incorporated by reference, the parties agree to be bound by this DPA.

If there is a conflict between this DPA and the Service Agreement concerning the protection or processing of Client Personal Data, this DPA prevails to the extent of that conflict. Any mandatory terms of an applicable transfer mechanism prevail where they expressly require a different result.

  1. DEFINITIONS

    Capitalised terms not defined in this DPA have the meaning given to them in the Service Agreement.

    Affiliate” means an entity that directly or indirectly controls, is controlled by, or is under common control with a party.

    Business Day” means Monday to Friday, excluding public holidays in England.

    Approved Transfer Mechanism” means an adequacy decision or regulation, the then-current standard contractual clauses approved by the European Commission, the UK International Data Transfer Agreement or UK Addendum where applicable, binding corporate rules, or another lawful transfer mechanism recognised under Data Protection Law.

    Client Affiliate” means an Affiliate of the Client that is authorised to use the Services under the Service Agreement and for whose benefit Client Personal Data is processed.

    Client Personal Data” means personal data processed by or on behalf of the Service Provider as processor in connection with the Services. This includes: (a) End User account and access information, such as names, business email addresses, usernames, authentication and role information, permissions, audit records and support information; and (b) any personal data contained in documents, files, messages, metadata or other information uploaded to, stored in, generated through, or otherwise processed within the Services by or on behalf of the Client, a Client Affiliate or an authorised End User. For the avoidance of doubt, Client Personal Data does not include personal data processed by the Service Provider in its capacity as an independent controller for its own lawful business purposes or to comply with legal obligations, including business contact, customer relationship management, contractual, billing, accounting, tax, compliance and legal records, even where such information relates to the Client or its personnel.

    Data Protection Law” means all privacy and data protection laws applicable to the processing of Client Personal Data under the Service Agreement, including, where applicable, Regulation (EU) 2016/679 (the “EU GDPR”), the UK GDPR, the UK Data Protection Act 2018 as amended (including by the Data (Use and Access) Act 2025), applicable ePrivacy rules, and any amendment, replacement, successor or other applicable data protection or privacy legislation.

    End User” means an individual authorised by or on behalf of the Client to access or use the Services.

    Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Client Personal Data transmitted, stored or otherwise processed.

    Restricted Transfer” means a transfer of Client Personal Data to a country or recipient that requires an Approved Transfer Mechanism under Data Protection Law.

    Service Incident” means a suspected defect, security issue, outage, material degradation or other operational issue reported in relation to the Services.

    Services” means the cloud-based virtual data room and related services described in the Service Agreement, including any enabled support, security, search, redaction, document-processing and AI-assisted functionality.

    Subprocessor” means a third party appointed by or on behalf of the Service Provider to process Client Personal Data in connection with the Services.
    The terms “controller”, “processor”, “data subject”, “personal data”, “processing”, “supervisory authority”, “special categories of personal data” and “criminal offence data” have the meanings given to them under Data Protection Law.
  2. SCOPE, APPOINTMENT AND CLIENT AFFILIATES
    1. The Client appoints the Service Provider to process Client Personal Data on behalf of the Client in accordance with this DPA, the Service Agreement and the Client’s documented instructions.
    2. Where the Client enters into the Service Agreement for the benefit of one or more Client Affiliates, the Client confirms that it is authorised to provide instructions and exercise the rights of those Client Affiliates in relation to the Services. Unless otherwise agreed in writing, the Client remains the primary point of contact for all instructions and communications under this DPA.
    3. The Service Provider shall process Client Personal Data only to host, store, organise, index, secure, transmit, display and otherwise operate, maintain and support the Services in accordance with the Client’s documented lawful instructions, or as required by applicable law.
    4. The processing details required by Data Protection Law are set out in Schedule 1. The Client determines the business purposes for which the Services are used, the personal data and documents uploaded to a data room, the End Users who may access them and the permissions applied. The Service Provider does not select or determine the substantive content uploaded by the Client and is not responsible for deciding whether that content is necessary or lawful for the Client’s purposes.
    5. For the avoidance of doubt, the hosting, storage, indexing, transmission, access control, support and other technical operations performed on Client Personal Data constitute processing carried out by the Service Provider as processor. Those technical operations do not give the Service Provider control over the Client’s reasons for uploading or using Client Personal Data.
  3. DURATION
    1. This DPA begins on the earlier of the date on which it is executed, incorporated into the Service Agreement or otherwise becomes binding between the parties, and continues until the Service Provider has ceased processing Client Personal Data following termination or expiry of the Service Agreement.

    2. Any provision that by its nature is intended to survive termination, including confidentiality, deletion, audit, liability and international-transfer obligations, survives for as long as necessary to give it effect.

  4. DOCUMENTED INSTRUCTIONS AND LAWFUL PROCESSING
    1. The Service Agreement, this DPA, the Client’s configuration and use of the Services, and any additional written instructions agreed by the parties constitute the Client’s documented instructions.

    2. The Service Provider shall inform the Client if, in its reasonable opinion, an instruction infringes Data Protection Law. Where reasonably necessary to avoid unlawful processing, the Service Provider may suspend the affected processing until the parties agree a lawful instruction.

    3. If the Service Provider is required by applicable law to process Client Personal Data other than on the Client’s instructions, it shall inform the Client of that legal requirement before processing unless the law prohibits notification on important grounds of public interest.

    4. The Service Provider may create and use aggregated or irreversibly anonymised information relating to the operation, security and performance of the Services, provided that the information does not constitute personal data and cannot reasonably be used to identify the Client, a Client Affiliate, an End User or a data subject.

    5. Where the Client enables AI-assisted functionality, the Client instructs the Service Provider to process Client Personal Data as reasonably necessary to provide, secure, maintain, test and improve that functionality in accordance with the applicable feature description, access controls and this DPA. The Service Provider may use aggregated or irreversibly anonymised information derived from the Services to develop, test and train proprietary models used solely to provide or improve Imprima services, provided that the information no longer constitutes personal data and cannot reasonably identify the Client, a Client Affiliate, an End User or a data subject. Where a specific AI feature may use Client Content or Client Personal Data for proprietary model improvement or training beyond aggregated or irreversibly anonymised information, the Service Provider shall describe that limited use in the applicable feature terms, service notice or configuration before it begins and shall provide the Client with a reasonable opportunity to object, opt out or disable the relevant use. To the extent permitted by Data Protection Law and the Client is authorised to give the instruction, continued enabled use of the feature after that notice and opportunity shall constitute the Client’s documented instruction for the limited processing described. Such processing shall be subject to appropriate access, confidentiality, security, data-minimisation and retention controls. The Service Provider shall not provide Client Personal Data to a third party for training a public, shared or generally available model, or make client-specific training data available to other clients, unless separately agreed in writing.

  5. CLIENT RESPONSIBILITIES
    1. The Client shall comply with Data Protection Law in relation to Client Personal Data and shall ensure that it has all necessary rights, notices, lawful bases, consents and authorisations to provide Client Personal Data to the Service Provider and instruct the processing described in this DPA.

    2. The Client is responsible for configuring the Services appropriately, controlling End User access, maintaining accurate access permissions, protecting authentication credentials and promptly removing access that is no longer required.

    3. The Client shall not instruct the Service Provider to process Client Personal Data in a manner that violates Data Protection Law and shall provide reasonable cooperation and information required for the Service Provider to perform its obligations under this DPA.

    4. The Client determines what information is uploaded to the Services, including whether it contains special categories of personal data or criminal offence data. The Client shall upload and permit processing of such information only where lawful, necessary and appropriate for the Client’s purposes. The Service Provider does not determine the nature or content of documents uploaded by the Client and is not required to review Client Content to identify personal data or special categories of personal data.

  6. CONFIDENTIALITY AND PERSONNEL
    1. The Service Provider shall ensure that persons authorised to process Client Personal Data are subject to an enforceable duty of confidentiality and receive appropriate data protection and information security awareness training.

    2. The Service Provider shall restrict access to Client Personal Data to personnel and authorised contractors who require access for the performance, security or support of the Services, and shall apply role-based and least-privilege access controls.

    3. The Service Provider remains responsible for the compliance of its personnel with the obligations applicable to them under this DPA.

  7. SECURITY OF PROCESSING
    1. Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the risks to the rights and freedoms of natural persons, the Service Provider shall implement and maintain appropriate technical and organisational measures designed to protect Client Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

    2. The security measures currently applicable to the Services are described in Schedule 2. The Service Provider may update those measures from time to time, provided that the overall level of protection is not materially reduced during the Term.

    3. The Service Provider shall maintain an information security management system aligned with its ISO/IEC 27001 certification and shall periodically test, assess and evaluate the effectiveness of relevant security measures.

    4. The Client acknowledges that security is a shared responsibility and shall use the security functionality made available within the Services, including appropriate authentication and access-control options.

  8. SERVICE SUPPORT AND INCIDENT RESPONSE
    1. The Client shall report a Service Incident through a support or contact channel designated by the Service Provider and shall provide information reasonably required to identify the affected Service, room, account or function and understand the reported impact.

    2. The Service Provider shall determine the applicable priority based on the verified impact, scope, availability of a reasonable workaround, potential risk and information available. A priority selected or requested by the Client is not binding and may be revised following technical assessment.

    3. Subject to the remaining provisions of this clause, the Service Provider shall use commercially reasonable efforts to provide an initial response within the target periods shown below. The targets are measured in Business Days and do not imply continuous or round-the-clock staffing.

    4. Priority Classification Target initial response
      P1 – Critical A complete outage of the Services, a confirmed material security incident, or most users being unable to perform an essential platform function where no reasonable workaround is available. Within one (1) Business Day
      P2 – High A material partial outage, failure of a core function affecting multiple rooms or a substantial number of users, or severe widespread performance degradation. Within two (2) Business Days
      P3 – Medium A material issue affecting one room or a limited group of users, or impaired functionality where a reasonable workaround remains available. Within three (3) Business Days
      P4 – Low A minor, cosmetic or isolated issue that does not materially prevent normal use of the Services or produce materially incorrect results. Within five (5) Business Days
    5. The applicable target period begins when the Service Provider has received sufficient information to identify and assess the reported Service Incident. A report received on a day that is not a Business Day is treated as received on the next Business Day for the purpose of calculating the target period.

    6. “Initial response” means acknowledgement of the report and commencement of appropriate validation or technical triage. It does not mean that the Service Incident has been resolved, that a workaround has been provided, or that a software correction will be released within the target period.

    7. The applicable target period may be suspended while the Service Provider awaits information, evidence, access, confirmation, approval or action from the Client or a third party, or where investigation is affected by circumstances outside the Service Provider’s reasonable control.

    8. These are operational response targets rather than guaranteed resolution periods. Unless expressly agreed otherwise in the Service Agreement, failure to meet a target does not automatically constitute a material breach and does not give rise to service credits, penalties, refunds or liquidated damages. Requests for enhancements, new features, custom reports, branding, configuration work, training or other tasks outside ordinary incident support may be handled separately and may be subject to additional scope, charges or delivery estimates.

  9. DATA SUBJECT RIGHTS REQUESTS
    1. Taking into account the nature of the processing, the Service Provider shall provide reasonable assistance to the Client through appropriate technical and organisational measures, insofar as possible, for the fulfilment of the Client’s obligations to respond to requests by data subjects exercising rights under Data Protection Law.

    2. If the Service Provider receives a request from a data subject relating to Client Personal Data, it shall notify the Client without undue delay. The Service Provider may acknowledge receipt and direct the data subject to the Client, but shall not respond substantively except on the Client’s documented instructions or where required by applicable law.

    3. The Client remains responsible for determining the validity, scope and legal response to a request, including verification of the data subject’s identity and authority. The Service Provider may request confirmation or additional information before retrieving, disclosing, correcting, restricting or deleting Client Personal Data.

    4. The Service Provider shall handle assistance relating to data subject requests through a controlled process designed to prevent unauthorised disclosure. Relevant requests and actions shall be appropriately recorded, access shall be restricted, and information provided by the Service Provider shall be transmitted using a reasonably secure method.

    5. Where reasonably necessary, information retrieved for a request may be reviewed to identify third-party personal data, confidential information, legal restrictions or other material that should not be disclosed without further instruction or lawful authority. The Client remains responsible for deciding whether and how such information is disclosed to the data subject.

  10. COMPLIANCE ASSISTANCE
    1. Taking into account the nature of processing and the information available to it, the Service Provider shall provide reasonable assistance to the Client in relation to the Client’s obligations concerning security of processing, Personal Data Breach notifications, data protection impact assessments and prior consultation with a supervisory authority.

    2. Where legally permitted, the Service Provider shall notify the Client without undue delay of a binding regulatory, law-enforcement or governmental request specifically relating to Client Personal Data. The Service Provider shall disclose only the information legally required and shall take reasonable steps to preserve the confidentiality of Client Personal Data.

    3. Standard assistance that can reasonably be provided through existing documentation, certifications, product functionality and ordinary support is included in the Services. Bespoke, repetitive or materially burdensome assistance may be charged at reasonable rates where the parties agree the scope and expected cost in advance, except where urgent action is required by law or arises from a material failure by the Service Provider to comply with this DPA.

  11. SUBPROCESSORS
    1. The Client grants the Service Provider general written authorisation to appoint Subprocessors for processing Client Personal Data in connection with the Services.

    2. The Service Provider shall maintain a current list of relevant Subprocessors and shall make that list available through its published documentation or on request.

    3. Where practicable, the Service Provider shall provide reasonable advance notice of an intended addition or replacement of a Subprocessor. A shorter notice period, or notice after the change, may apply where an urgent change is reasonably required for security, legal, regulatory or service-continuity reasons.

    4. The Client may object within a reasonable period after notice, solely on reasonable and documented data protection grounds. The parties shall work in good faith to address the objection, including by considering a commercially reasonable alternative where available. If no reasonable resolution is available, either party may terminate the affected Services in accordance with the Service Agreement.

    5. Before a Subprocessor processes Client Personal Data, the Service Provider shall carry out proportionate due diligence and enter into a binding written agreement imposing data protection obligations that provide at least an equivalent level of protection for Client Personal Data as the relevant obligations in this DPA.

    6. The Service Provider remains responsible to the Client for the performance of its Subprocessors’ data protection obligations to the extent required by Data Protection Law.

  12. PERSONAL DATA BREACHES
    1. The Service Provider shall notify the Client without undue delay after becoming aware of a Personal Data Breach affecting Client Personal Data.

    2. The absence of complete information shall not delay an initial notification where sufficient information is available to identify that a Personal Data Breach has occurred. Information may be provided in phases as it becomes available.

    3. To the extent known at the relevant time, the notification shall describe the nature of the Personal Data Breach, the categories of affected data subjects and records where available, the likely consequences, the measures taken or proposed to contain and mitigate the incident, and relevant contact details and information reasonably available to assist the Client in meeting its legal obligations.

    4. The Service Provider shall investigate the Personal Data Breach, take reasonable steps to contain and mitigate its effects, preserve relevant evidence where appropriate, cooperate with the Client and provide material updates as further relevant information becomes available.

    5. Where reasonably practicable and appropriate to the nature of the incident, the Service Provider shall provide a written incident summary after the incident has been contained or closed. The summary may be updated if further relevant information becomes available.

    6. Notification or investigation of a Personal Data Breach shall not be construed as an admission of fault or liability.

    7. Except where disclosure is required by applicable law, a court, a competent supervisory or regulatory authority, applicable stock-exchange rules or another binding legal obligation, the Client shall not issue any press release, public filing, public statement, public report or other external communication that identifies the Service Provider or attributes a Personal Data Breach to the Service Provider without the Service Provider’s prior written approval, such approval not to be unreasonably withheld or delayed. Where a disclosure is legally required and the Client is legally permitted to do so, the Client shall notify and consult with the Service Provider in advance and shall limit the disclosure to what is reasonably required.

  13. DATA LOCATION AND INTERNATIONAL TRANSFERS
    1. The Service Provider shall host Client Personal Data within the European Economic Area. The standard hosting arrangement uses Microsoft Azure in the Netherlands as the primary location and Ireland for disaster-recovery purposes.

    2. The Service Provider shall not make a Restricted Transfer without the Client’s authorisation and implementation of an Approved Transfer Mechanism, together with any supplementary measures reasonably required under Data Protection Law.

    3. Where an Approved Transfer Mechanism is required, the parties shall cooperate in good faith to complete the relevant documentation and any assessment required by Data Protection Law. The appropriate European Commission Standard Contractual Clauses, UK International Data Transfer Agreement, UK Addendum or replacement mechanism may be incorporated or executed as applicable.

    4. The Service Provider shall ensure that any authorised Subprocessor making a Restricted Transfer is subject to an appropriate Approved Transfer Mechanism.

    5. If an applicable transfer mechanism is amended, replaced or ceases to provide a lawful basis for a Restricted Transfer, the parties shall cooperate to implement a lawful alternative. The Service Provider may suspend the affected transfer or processing where reasonably necessary to comply with Data Protection Law.

  14. RETURN AND DELETION OF CLIENT PERSONAL DATA
    1. During the Term, the Client may export Client Personal Data using functionality made available within the Services, subject to the Service Agreement and applicable access rights.

    2. At the Client’s choice, following termination or expiry of the Services, the Service Provider shall return or delete Client Personal Data, unless retention is required or permitted under this clause or applicable law. The return and deletion obligations in this clause apply only to Client Personal Data processed by the Service Provider in its capacity as processor and do not require deletion of personal data processed independently by the Service Provider as controller for its own lawful business purposes or legal obligations, including business contact, customer relationship management, contractual, billing, accounting, tax, compliance and legal records. The Client is responsible for completing any required export before deletion is carried out.

    3. Subject to completion of any required export and no valid reason for temporary preservation applying, the Service Provider will ordinarily aim to complete deletion of Client Personal Data from active production systems within approximately thirty (30) days following termination, expiry or receipt of an authorised deletion instruction. This is an operational target only and is not a guaranteed or fixed deletion deadline.

    4. The Service Provider may defer, suspend or perform deletion in stages where reasonably necessary and legally permitted, including:
      (a) where the Client requests, authorises or agrees that Client Personal Data should be preserved;
      (b) to comply with applicable law, a court order, regulatory requirement, legal hold or other lawful preservation obligation;
      (c) to investigate, contain or remediate a security incident, suspected misuse, fraud, abuse or technical issue;
      (d) for the establishment, exercise or defence of legal claims;
      (e) to complete an agreed export, migration, reconciliation, restoration or controlled deletion-verification process;
      (f) where deletion depends on information, confirmation, access or instructions from the Client or another authorised party; or
      (g) because of reasonable technical, operational, business-continuity, backup or disaster-recovery requirements.

    5. Client Personal Data temporarily retained under clause 14.4 shall remain protected in accordance with this DPA, access shall be restricted, and the data shall not be processed except for the purpose justifying retention. The Service Provider shall complete deletion when the relevant reason for retention no longer applies, subject to its normal technical and operational processes.

    6. Copies held solely within backup or disaster-recovery systems may remain until overwritten or deleted through the Service Provider’s normal retention cycle. Such copies shall remain protected, shall not be used for ordinary business purposes and shall only be restored where reasonably required for business continuity or disaster recovery. Where a backup is restored, the applicable deletion instruction shall continue to apply.

    7. The Service Provider may retain information that has been irreversibly anonymised so that it no longer constitutes personal data, provided that the Service Provider does not attempt to re-identify it.

    8. Upon reasonable written request, the Service Provider shall confirm completion of deletion carried out under this clause. Non-standard return, export, restoration, migration or bespoke deletion assistance may be subject to reasonable charges agreed with the Client.

  15. INFORMATION, AUDIT AND INSPECTION
    1. The Service Provider shall make available information reasonably necessary to demonstrate compliance with this DPA. The parties shall first seek to satisfy audit requirements through current certifications, independent audit reports or summaries, security documentation, completed questionnaires and other relevant evidence.

    2. Where the information provided is insufficient to demonstrate compliance, the Client may conduct an audit itself or through an independent auditor that is not a competitor of the Service Provider, subject to reasonable confidentiality, security and operational requirements.

    3. Routine audits shall be conducted on reasonable written notice, during normal business operations, no more frequently than reasonably necessary and in a manner that avoids unreasonable disruption. These restrictions do not apply where an audit is required by a competent supervisory authority, follows a confirmed Personal Data Breach affecting Client Personal Data, or is reasonably necessary due to credible evidence of material non-compliance.

    4. An audit shall be limited to processing of Client Personal Data, shall not provide access to another client’s data or confidential information, and may be satisfied in whole or in part through an independent third-party assessment, remote review or other reasonable evidence.

    5. Each party shall bear its own costs of an ordinary documentary review. The Client shall reimburse reasonable additional costs incurred by the Service Provider for a bespoke, on-site or materially burdensome audit, unless the audit identifies a material breach of this DPA by the Service Provider.

  16. RECORDS AND REGULATORY COOPERATION
    1. The Service Provider shall maintain records of processing activities to the extent required of a processor under Data Protection Law.

    2. The Service Provider shall cooperate with competent supervisory authorities in the performance of their lawful tasks concerning processing of Client Personal Data.

  17. CHANGES TO THE SERVICES OR THIS DPA
    1. The Service Provider may update this DPA where reasonably necessary to reflect changes in Data Protection Law, regulatory guidance, the Services, security measures or processing arrangements, provided that an update does not materially reduce the protection of Client Personal Data or the Client’s mandatory rights under Data Protection Law.

    2. The Service Provider shall provide reasonable notice of a material change to this DPA. If a change materially and adversely affects the Client’s data protection rights, the parties shall discuss the concern in good faith.

  18. LIABILITY AND COSTS
    1. Each party’s liability arising from or in connection with this DPA is subject to the exclusions and limitations of liability in the Service Agreement, except to the extent that liability cannot lawfully be limited or excluded.

    2. Nothing in this DPA limits the rights of data subjects or the powers of a competent supervisory authority under Data Protection Law.

    3. Where the Client requests an instruction, restriction, Subprocessor objection, transfer limitation, deletion, return or other measure that makes continued provision of all or part of the Services unlawful, technically impracticable or materially different from the agreed Services, the parties shall first seek a lawful and commercially reasonable alternative. If none is reasonably available, the Service Provider may suspend or terminate the affected Services in accordance with the Service Agreement and without liability for the consequences of complying with the Client’s request or Data Protection Law.

    4. Fees, expenses and payment obligations arising under the Service Agreement remain payable in accordance with its terms. Any assistance expressly stated in this DPA to be chargeable shall be invoiced on a reasonable basis.

  19. NOTICES
    1. Formal notices under this DPA shall be in English, in writing and sent to the primary contractual, legal, privacy or security contact designated by the receiving party. Email is sufficient where receipt can be reasonably evidenced.

    2. Operational communications, including Personal Data Breach notifications, may be sent through the Client’s designated account, security or incident contacts and may be supplemented by telephone or another agreed communication channel.

  20. GENERAL
    1. This DPA and the Service Agreement constitute the agreement between the parties concerning processing of Client Personal Data in connection with the Services and supersede prior data processing terms relating to the same subject matter.

    2. If any provision of this DPA is invalid or unenforceable, the remaining provisions remain in effect. The parties shall replace the invalid or unenforceable provision with a valid provision that most closely reflects its intended purpose and the requirements of Data Protection Law.

    3. Neither party may assign this DPA separately from the Service Agreement. Any permitted assignment of the Service Agreement includes this DPA.

    4. A failure or delay in exercising a right under this DPA does not waive that right.

  21. GOVERNING LAW AND JURISDICTION
    1. This DPA is governed by the law specified in the Service Agreement. If the Service Agreement does not specify governing law, this DPA is governed by the laws of the Netherlands.

    2. The courts specified in the Service Agreement shall have jurisdiction. If the Service Agreement does not specify jurisdiction, the parties submit to the exclusive jurisdiction of the courts of Amsterdam, the Netherlands, without prejudice to either party’s right to seek urgent injunctive or protective relief in another competent court.

SCHEDULE 1 – DETAILS OF PROCESSING

Item Description
Subject matter Provision, operation, hosting, security, support and maintenance of the cloud-based Imprima virtual data room Services.
Duration For the Term of the Service Agreement and the period during which Client Personal Data is returned, preserved or deleted in accordance with this DPA.
Nature and purpose Receiving, recording, organising, structuring, storing, hosting, indexing, searching, retrieving, consulting, displaying, transmitting and sharing Client Personal Data under Client-controlled permissions; operating End User accounts and access controls; generating user-requested outputs; supporting, securing, backing up, restoring for disaster recovery and deleting Client Personal Data in order to provide the Services. The Client, not the Service Provider, determines the business purpose and substantive content of the information uploaded to each data room.
Categories of data subjects End Users; Client and Client Affiliate personnel; directors and officers; advisers; shareholders, investors and lenders; customers and suppliers; transaction counterparties; job applicants and employees; and other individuals whose personal data is contained in documents or information uploaded by or on behalf of the Client.
Types of personal data End User account and access data, including names, business email addresses, usernames, authentication details, roles, permissions, support information, IP and device information, and audit or usage records; document metadata; and any personal data contained in documents, files, messages or other information that the Client or its End Users choose to upload, including professional, employment, transaction, corporate, commercial, financial and shareholder information.
Special categories and criminal offence data The Services do not require these categories as a standard input, but the Client may upload documents containing such data at its discretion. The Client is responsible for ensuring that any such processing is lawful, necessary and appropriate.
Frequency Continuous or as initiated by the Client and End Users during the Term.
Controller rights and obligations As set out in the Service Agreement, this DPA and Data Protection Law, including determining the purposes and essential means of processing; deciding what information is uploaded and who may access it; providing lawful documented instructions; managing End User access and permissions; responding to data subjects; and complying with transparency, lawful-basis, data-minimisation and retention requirements.

SCHEDULE 2 – TECHNICAL AND ORGANISATIONAL MEASURES

The Service Provider maintains the following measures as applicable to the Services. Specific implementation details may change as technologies, risks and legal requirements evolve, provided that the overall level of protection is not materially reduced.

  1. Information security governance
    • An information security management system aligned with ISO/IEC 27001 and maintained certification.
    • Documented security policies, assigned responsibilities, risk assessment, internal audit, management review and continual-improvement processes.
    • Security awareness and confidentiality obligations for personnel.

  2. Hosting and data location
    • Microsoft Azure hosting within the European Economic Area, with the Netherlands as the primary region and Ireland used for disaster-recovery purposes.
    • Cloud and infrastructure services selected and managed through supplier due diligence and contractual security requirements.
    • Physical and environmental controls for cloud data centres provided by Microsoft Azure, supplemented by the Service Provider’s organisational controls.

  3. Encryption and key management
    • Encryption in transit using TLS 1.2 or higher.
    • Encryption at rest using Azure platform encryption, including AES-256 where applicable.
    • Managed key protection using Azure key-management capabilities, with customer-managed key or BYOK options where separately agreed and technically supported.
    • Encryption of authorised portable storage where its use is permitted.

  4. Identity and access management
    • Role-based access control and least-privilege principles for workforce and administrative access.
    • Multi-factor authentication for authorised workforce access and restricted administrative access.
    • Support for SAML 2.0 and Microsoft Entra ID single sign-on for Client End Users where configured.
    • Periodic access review, prompt revocation of unnecessary access and separation of duties where appropriate.

  5. Logical segregation and application controls
    • Logical separation of clients, data rooms, users and access permissions within the multi-tenant service.
    • Client-controlled room, document, group and user permissions.
    • Audit logging of relevant user and administrative activity.
    • Session and authentication controls designed to reduce unauthorised access.

  6. Endpoint, network and infrastructure security
    • Managed endpoint protection, anti-malware and security monitoring for authorised corporate devices.
    • Network security controls, filtering, restricted remote access and monitoring appropriate to the Azure-hosted service.
    • Configuration, patch and vulnerability-management processes for relevant systems and components.
    • Operational monitoring and alerting for relevant service infrastructure.

  7. Secure development and change management
    • Controlled development, testing, review and release processes.
    • Segregation of development and production responsibilities and environments where appropriate.
    • Security review of material changes and remediation tracking for identified vulnerabilities.
    • Periodic internal web-application vulnerability testing and independent external security assessment.

  8. Logging, monitoring and incident response
    • Logging and monitoring designed to support security investigation, operational support and accountability.
    • Documented incident-management, escalation, containment, investigation, communication and corrective-action processes.
    • Preservation of relevant evidence and post-incident review where appropriate.

  9. Backup, resilience and business continuity
    • Azure-managed backup and transaction-log mechanisms used for disaster recovery rather than long-term Client archiving.
    • Disaster-recovery arrangements using the Ireland region and documented business-continuity procedures.
    • Periodic testing or review of recovery and continuity arrangements.

  10. Data lifecycle and secure deletion
    • Controlled retention, preservation and deletion processes for Client Personal Data.
    • Operational processes designed ordinarily to complete deletion from active systems within the target described in clause 14, subject to permitted retention and technical or operational requirements.
    • Secure disposal or sanitisation of decommissioned storage and devices in accordance with applicable procedures.
    • Backup copies protected and overwritten in accordance with documented retention cycles.

  11. Data subject request handling
    • A controlled process for receiving, escalating, recording and assisting with data subject rights requests.
    • Identity or authority confirmation before disclosure or action where appropriate, with the Client retaining responsibility for the legal response.
    • Restricted access, secure retrieval and transmission, and review designed to avoid unauthorised disclosure of third-party or confidential information.
    • Appropriate records maintained for compliance and audit purposes.

  12. Personnel and supplier security
    • Confidentiality agreements or equivalent legal obligations for personnel with access to Client Personal Data.
    • Proportionate personnel screening where lawful and appropriate to the role.
    • Security and data-protection due diligence for relevant suppliers and Subprocessors.
    • Binding data-protection and security obligations for Subprocessors.

  13. AI-assisted functionality
    • AI-assisted functionality is subject to the same room permissions, access controls, confidentiality, encryption and logging principles applicable to the Services.
    • Aggregated or irreversibly anonymised information may be used to develop, test and train proprietary models used solely to provide or improve Imprima services, provided that the information no longer constitutes personal data and cannot reasonably identify the Client or a data subject.
    • Where a specific AI feature may use Client Content or Client Personal Data for proprietary model improvement or training beyond aggregated or irreversibly anonymised information, the limited use shall be described in the applicable feature terms, service notice or configuration before it begins. The Client shall be given a reasonable opportunity to object, opt out or disable that use. Any such processing shall remain subject to appropriate access, confidentiality, security, data-minimisation and retention controls. Client Personal Data shall not be provided to a third party for training a public, shared or generally available model, or made available as client-specific training data to other clients, unless separately agreed in writing. AI-generated outputs remain subject to authorised user review and Client-controlled access.

End of Data Processing Agreement