Data Processing
Agreement.
Where Pintop processes personal data on behalf of a client, the applicable Data Processing Agreement forms part of the contractual arrangement and defines the obligations applying to that processing relationship.
The agreement behind the processing relationship.
A Data Processing Agreement establishes the terms under which Pintop processes personal data for a client organisation through an applicable product, service or implementation.
The final agreement is connected to the commercial contract and may include schedules that reflect the specific product, data categories, hosting arrangement, integrations and services involved.
This page provides an overview and a route for requesting the current agreement. It is not itself the executed DPA.
Clear roles for a
defined relationship.
The agreement records how responsibilities are divided where a client determines the purpose of processing and Pintop processes information on the client’s behalf.
Data controller
The client determines the purpose and principal means of the processing and provides Pintop with documented instructions connected to the service.
Data processor
Pintop processes the relevant personal data for the client in connection with the contracted product, implementation or support service.
What the agreement
covers.
The applicable DPA defines the core obligations and safeguards surrounding the processing relationship.
Roles and instructions
The roles of each party, the authorised processing instructions and the limits applying to Pintop’s use of client personal data.
Processing details
The subject matter, duration, nature and purpose of the processing, together with the categories of personal data and affected individuals.
Confidentiality and access
Confidentiality requirements, authorised personnel, access controls and responsibilities for managing accounts and privileges.
Security measures
Technical and organisational safeguards connected to the product, service, hosting model and relevant processing risks.
Incident and assistance obligations
Security incident notification, cooperation, data subject request support and assistance with applicable compliance obligations.
Sub-processors and transfers
The conditions for appointing service providers and the safeguards applying where personal data is processed across borders.
Audit and information rights
The information, cooperation and review arrangements available for demonstrating compliance with the agreement.
Return, deletion and termination
The arrangements applying when the processing ends, including data return, deletion, retention and any continuing legal obligations.
Schedules reflect the
actual service.
Product and deployment details may be recorded in schedules connected to the principal agreement.
Processing description
Data categories, affected individuals, processing activities, service purpose and expected duration.
Security measures
Relevant technical and organisational controls connected to the contracted service and deployment.
Sub-processors
Service providers involved in processing and the applicable notification or authorisation arrangements.
Hosting arrangement
Infrastructure ownership, processing locations, environments and responsibilities relevant to the implementation.
Connected services
Integrations, payment services, identity providers, APIs and other systems involved in the processing flow.
Retention and exit
Service-specific retention, export, return, deletion and termination arrangements.
Important
clarifications.
The DPA is connected to a specific client relationship and should be read together with the relevant commercial documents.
This page is not the agreement
The legally operative terms are contained in the DPA incorporated into or signed alongside the relevant commercial contract.
The scope may differ by product
Processing activities, hosting, integrations, data categories and security responsibilities may differ across CoreWave CBA, MeVerify, CoreWave 360 and custom software engagements.
Authorised representatives
Requests for contractual documents should come from an authorised representative of the relevant client or prospective client organisation.
Request the current DPA for your engagement.
Share the organisation, Pintop product or service, deployment context and stage of the commercial discussion. The request will be routed to the appropriate account, legal or data-protection contact.
Identify the organisation
Provide the client or prospective client organisation and your role.
Identify the service
State the Pintop product, implementation or service involved.
Add the processing context
Include relevant hosting, integration or procurement information where known.
Receive the applicable document
Pintop will route the request and provide the appropriate current documentation.
Related privacy and
security information.
These pages provide additional context about Pintop’s privacy and security arrangements.
