Skip to main content

Data Processing Addendum

This Data Processing Addendum (“DPA”) supplements, and is incorporated into, the Master Subscription Agreement (“Agreement”) between Kuberno Solutions Inc. (“KubernoGRC”) and the Customer identified in the applicable Order (“Customer”), and applies to KubernoGRC’s Processing of Personal Information on behalf of Customer in connection with the Services. In the event of a conflict between this DPA and the Agreement with respect to the Processing of Personal Information, this DPA controls.

This DPA incorporates by reference: Schedule 1 (Processing Activities Description). Additional exhibits will be added as required by applicable law.

1. Definitions

Capitalized terms used in this DPA have the following meanings (terms not defined herein have the meanings given in the Agreement):

“Controller” means the entity that determines the purposes and means of Processing Personal Information.

“Data Protection Laws” means all applicable US federal and state privacy and data protection laws and regulations governing the processing of Personal Information, including without limitation: the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA); the Virginia Consumer Data Protection Act (CDPA); the Colorado Privacy Act (CPA); the Connecticut Data Privacy Act (CTDPA); the Texas Data Privacy and Security Act (TDPSA); the Oregon Consumer Privacy Act (OCPA); and any successor or similar state laws enacted after the Effective Date of this DPA.

“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an identified or identifiable natural person, as defined under applicable Data Protection Laws.

“Processing” (and “Process”) means any operation or set of operations performed on Personal Information, including but not limited to collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission, dissemination, or erasure.

“Processor” means the entity that Processes Personal Information on behalf of the Controller.

“Service Provider” means as defined under the CCPA/CPRA, a business that Processes Personal Information on behalf of another business pursuant to a written contract, for a business purpose.

“Subprocessor” means a third party engaged by KubernoGRC to Process Personal Information on KubernoGRC’s behalf in connection with providing the Services.

“Personal Data Breach” means any confirmed unauthorized or unlawful access to, acquisition of, or disclosure of Personal Information Processed by KubernoGRC under this DPA that compromises the security, confidentiality, or integrity of such Personal Information.

2. Roles and Instructions

2.1 Roles. As between the Parties: (a) Customer is the Controller of Personal Information submitted to the Services; and (b) KubernoGRC is the Processor (and, for California-resident Personal Information, the Service Provider) of such Personal Information, acting on behalf of and at the direction of Customer. KubernoGRC Processes Personal Information solely to provide the Services and as otherwise permitted under this DPA and the Agreement.

2.2 Customer Instructions. KubernoGRC will Process Personal Information only on documented instructions from Customer, including as set forth in the Agreement, this DPA, applicable Orders, and Customer’s configuration of the Services. If KubernoGRC is required by applicable law to Process Personal Information in a manner inconsistent with Customer’s instructions, KubernoGRC will notify Customer before such Processing (unless prohibited by law). KubernoGRC will promptly inform Customer if, in KubernoGRC’s reasonable judgment, an instruction violates applicable Data Protection Laws.

2.3 No Sale or Sharing. KubernoGRC will not: (a) sell or share Personal Information (as “sell” and “share” are defined under CCPA/CPRA) to or with any third party; (b) retain, use, or disclose Personal Information for any purpose other than the specific business purpose of providing the Services as set forth in this DPA and the Agreement; (c) retain, use, or disclose Personal Information outside of the direct business relationship with Customer; or (d) combine Personal Information received from Customer with Personal Information obtained from any other source, except as permitted under applicable Data Protection Laws.

2.4 Notification of Inability to Comply. KubernoGRC will notify Customer promptly if KubernoGRC determines it can no longer meet its obligations as a Service Provider or Processor under applicable Data Protection Laws.

3. Confidentiality

KubernoGRC will ensure that persons authorized to Process Personal Information are subject to appropriate confidentiality obligations — whether by contract, employment agreement, or professional duty — with respect to such Personal Information.

4. Security Measures

4.1 Technical and Organizational Measures. KubernoGRC will implement and maintain appropriate technical and organizational security measures designed to protect Personal Information against unauthorized or unlawful Processing, and against accidental loss, destruction, damage, alteration, or disclosure. These measures take into account: (a) the state of the art and cost of implementation; (b) the nature, scope, context, and purposes of Processing; and (c) the risks to the rights and freedoms of natural persons. A summary of KubernoGRC’s current security controls is set forth in the Security Exhibit to the Agreement.

4.2 Updates to Security Measures. KubernoGRC may update or modify its security measures from time to time, provided such updates do not materially reduce the overall level of protection afforded to Personal Information.

5. Subprocessors

5.1 Authorization. Customer authorizes KubernoGRC to engage Subprocessors to Process Personal Information in connection with providing the Services, subject to the requirements of this Section 5.

5.2 Subprocessors List. KubernoGRC maintains a current list of authorized Subprocessors. The Subprocessors List identifies each Subprocessor’s name, location, and the nature of Processing performed.

5.3 Advance Notice. KubernoGRC will provide Customer with at least ten (10) days’ prior written notice (email to Customer’s designated privacy or legal contact is sufficient) before engaging any new Subprocessor that will Process Customer Personal Information.

5.4 Customer Objection. If Customer objects to a new Subprocessor on reasonable data protection grounds, Customer must notify KubernoGRC in writing within ten (10) days of receiving notice. The Parties will work in good faith to resolve the objection. If the Parties cannot reach a resolution within thirty (30) days of Customer’s objection, Customer may terminate the affected Order upon thirty (30) days’ written notice and receive a pro-rata refund of any prepaid, unused fees.

5.5 Subprocessor Obligations. KubernoGRC will impose data protection obligations on Subprocessors that are at least as protective as those in this DPA. KubernoGRC remains liable to Customer for the performance of Subprocessors’ obligations to the extent KubernoGRC would be liable under this DPA if it performed those obligations itself.

6. Data Subject Rights Assistance

Taking into account the nature of the Processing and the information available to KubernoGRC, KubernoGRC will provide Customer with reasonable assistance, through appropriate technical and organizational measures, to enable Customer to fulfill its obligations to respond to data subject requests submitted under applicable Data Protection Laws, including but not limited to requests to access, correct, delete, restrict, or port Personal Information.

Customer acknowledges that KubernoGRC may charge a reasonable fee for assistance that requires substantial effort or resources beyond standard platform functionality.

7. Personal Data Breach Notification

7.1 Notification. KubernoGRC will notify Customer without undue delay and, in any event, no later than seventy-two (72) hours after KubernoGRC confirms that a Personal Data Breach has occurred, to the extent such breach involves Personal Information Processed by KubernoGRC under this DPA.

7.2 Notification Content. Where available at the time of notification, KubernoGRC will include in its breach notification: (a) a description of the nature of the breach, including categories and approximate number of data subjects and records affected; (b) the name and contact details of KubernoGRC’s privacy or security contact; (c) the likely consequences of the breach; and (d) measures KubernoGRC has taken or proposes to take to address the breach. Where complete information is not available at the time of initial notification, KubernoGRC will provide updates as additional information becomes available.

7.3 No Acknowledgment of Fault. Notification of a Personal Data Breach under this Section 7 does not constitute an acknowledgment of fault or liability by KubernoGRC.

7.4 Customer Obligations. Customer is solely responsible for determining whether applicable Data Protection Laws require Customer to notify any regulatory authority or affected individuals, and for making such notifications as required.

8. Security Assistance and DPIAs

Taking into account the nature of the Processing and the information reasonably available to KubernoGRC, KubernoGRC will provide Customer with reasonable assistance in: (a) confirming compliance with applicable security obligations under Data Protection Laws; (b) conducting data protection impact assessments (DPIAs) where required; and (c) prior consultation with regulatory authorities where applicable. KubernoGRC may charge a reasonable fee for such assistance.

9. Audit and Compliance

9.1 Documentation. Upon Customer’s reasonable written request (no more than once per calendar year, unless required by a regulatory authority), KubernoGRC will make available to Customer information reasonably necessary to demonstrate KubernoGRC’s compliance with this DPA, including relevant portions of KubernoGRC’s then-current available third-party audit report(s) under appropriate confidentiality obligations.

9.2 Audit Rights. Customer may, no more than once per calendar year and upon at least thirty (30) days’ prior written notice, conduct or commission an independent audit of KubernoGRC’s data processing activities relevant to this DPA, subject to reasonable confidentiality restrictions and coordination with KubernoGRC. Customer shall bear the costs of such audit; KubernoGRC may charge for reasonable staff time and resources consumed beyond document provision.

9.3 Regulatory Audits. If required by a regulatory authority or court order, the annual frequency limitation in Section 9.2 does not apply.

10. Return and Deletion of Personal Information

10.1 Upon Termination. Upon termination or expiration of the Agreement, or upon Customer’s written request, KubernoGRC will, at Customer’s election: (a) return Personal Information to Customer in a portable format; or (b) securely delete or destroy Personal Information in KubernoGRC’s possession or control, unless retention is required by applicable law.

10.2 Retention Period. KubernoGRC will retain Customer’s Personal Information for up to 180 days following the effective date of termination to allow Customer to export its data. After such period, KubernoGRC will securely delete all Personal Information in identifiable form.

10.3 Confirmation of Deletion. Upon Customer’s written request, KubernoGRC will provide written confirmation of deletion within 30 days of completing the deletion process.

11. Confidentiality of Personal Information

KubernoGRC will treat all Personal Information as Confidential Information under the Agreement and will not disclose Personal Information to any third party except: (a) to Subprocessors as permitted under Section 5; (b) as required by applicable law or valid legal process (in which case KubernoGRC will, to the extent permitted by law, provide Customer with advance notice and reasonable opportunity to seek a protective order); or (c) as otherwise expressly authorized in writing by Customer.

12. US State Privacy Laws

13.1 CCPA/CPRA — Service Provider Obligations. For Personal Information of California residents Processed under this DPA, KubernoGRC acts as a “Service Provider” under the CCPA/CPRA and agrees to:

(a) Process such Personal Information only for the specific business purpose of providing the Services, as described in this DPA and the Agreement;

(b) not “sell” or “share” (as defined under CCPA/CPRA) such Personal Information with any third party;

(c) not retain, use, or disclose such Personal Information outside the direct business relationship with Customer;

(d) not combine such Personal Information with Personal Information received from or about a consumer from any other transaction or source (except as permitted under CCPA/CPRA);

(e) comply with applicable obligations under CCPA/CPRA, including providing the same level of privacy protection as required by those laws; and

(f) notify Customer if KubernoGRC determines it can no longer meet its obligations as a Service Provider under CCPA/CPRA.

Customer has the right, upon reasonable notice, to take reasonable and appropriate steps to: (i) stop and remediate unauthorized use of Personal Information; and (ii) assess KubernoGRC’s compliance with CCPA/CPRA obligations.

13.2 Other US State Privacy Laws. KubernoGRC agrees to comply with its applicable processor or service provider obligations under US state privacy laws enacted after the Effective Date of this DPA as such obligations become effective, including but not limited to: the Virginia CDPA; Colorado CPA; Connecticut CTDPA; Texas TDPSA; and Oregon OCPA.

13. Governing Law

This DPA is governed by and construed in accordance with the laws of the State of Delaware, without regard to its conflict of laws principles. Any dispute arising under this DPA will be resolved exclusively in the state or federal courts located in Wilmington, Delaware, and the Parties consent to the personal jurisdiction of such courts.

14. Conflict and Precedence

In the event of a conflict between the Agreement and this DPA with respect to the Processing of Personal Information, this DPA controls. In the event of a conflict between the body of this DPA and any Schedule or Exhibit attached hereto, the Schedule or Exhibit controls to the extent required by applicable law.

Schedule 1 — Processing Activities Description

ElementDescription
Subject matter of processingProvision of KubernoGRC’s hosted GRC platform services
Duration of processingFor the term of the Agreement, plus the post-termination retention period described in Section 10.2
Nature of processingStorage, hosting, access, analysis, display, and transmission of Customer Data submitted by Customer
Purpose of processingTo provide GRC workflow functionality to Customer and Authorized Users, as described in the Agreement
Categories of data subjectsCustomer’s employees, contractors, and any other individuals whose personal data is included in Customer Data submitted by Customer to the Services
Categories of personal dataProfessional contact information (name, email, job title, employer); compliance and audit workflow data submitted by Customer within policies, risk registers, control workpapers, and audit artifacts; authentication data (credentials managed by Customer’s SSO/MFA provider)
Special categories / sensitive dataNone expected. Customer must not submit HIPAA PHI, payment card data (PCI DSS in-scope), government-issued ID numbers, or biometric data without specific written authorization from KubernoGRC.
Sub-processorsSee Subprocessors List. AI provider(s) powering the AI Features are listed therein.
Transfer to third countriesProcessing occurs in the US. See Section 5 (Subprocessors) for transfers to subprocessors.