Data protection and contractual processing

Data Processing
Agreement.

Where Pintop processes personal data on behalf of a client, the applicable Data Processing Agreement forms part of the contractual arrangement and defines the obligations applying to that processing relationship.

Client organisation
Pintop Technologies
Controller
Processor

The agreement behind the processing relationship.

A Data Processing Agreement establishes the terms under which Pintop processes personal data for a client organisation through an applicable product, service or implementation.

The final agreement is connected to the commercial contract and may include schedules that reflect the specific product, data categories, hosting arrangement, integrations and services involved.

This page provides an overview and a route for requesting the current agreement. It is not itself the executed DPA.

Clear roles for a
defined relationship.

The agreement records how responsibilities are divided where a client determines the purpose of processing and Pintop processes information on the client’s behalf.

Client organisation

Data controller

The client determines the purpose and principal means of the processing and provides Pintop with documented instructions connected to the service.

Processing instructions
Pintop Technologies

Data processor

Pintop processes the relevant personal data for the client in connection with the contracted product, implementation or support service.

What the agreement
covers.

The applicable DPA defines the core obligations and safeguards surrounding the processing relationship.

01

Roles and instructions

The roles of each party, the authorised processing instructions and the limits applying to Pintop’s use of client personal data.

02

Processing details

The subject matter, duration, nature and purpose of the processing, together with the categories of personal data and affected individuals.

03

Confidentiality and access

Confidentiality requirements, authorised personnel, access controls and responsibilities for managing accounts and privileges.

04

Security measures

Technical and organisational safeguards connected to the product, service, hosting model and relevant processing risks.

05

Incident and assistance obligations

Security incident notification, cooperation, data subject request support and assistance with applicable compliance obligations.

06

Sub-processors and transfers

The conditions for appointing service providers and the safeguards applying where personal data is processed across borders.

07

Audit and information rights

The information, cooperation and review arrangements available for demonstrating compliance with the agreement.

08

Return, deletion and termination

The arrangements applying when the processing ends, including data return, deletion, retention and any continuing legal obligations.

Schedules reflect the
actual service.

Product and deployment details may be recorded in schedules connected to the principal agreement.

Processing description

Data categories, affected individuals, processing activities, service purpose and expected duration.

Security measures

Relevant technical and organisational controls connected to the contracted service and deployment.

Sub-processors

Service providers involved in processing and the applicable notification or authorisation arrangements.

Hosting arrangement

Infrastructure ownership, processing locations, environments and responsibilities relevant to the implementation.

Connected services

Integrations, payment services, identity providers, APIs and other systems involved in the processing flow.

Retention and exit

Service-specific retention, export, return, deletion and termination arrangements.

Important
clarifications.

The DPA is connected to a specific client relationship and should be read together with the relevant commercial documents.

This page is not the agreement

The legally operative terms are contained in the DPA incorporated into or signed alongside the relevant commercial contract.

The scope may differ by product

Processing activities, hosting, integrations, data categories and security responsibilities may differ across CoreWave CBA, MeVerify, CoreWave 360 and custom software engagements.

Authorised representatives

Requests for contractual documents should come from an authorised representative of the relevant client or prospective client organisation.

Request the agreement

Request the current DPA for your engagement.

Share the organisation, Pintop product or service, deployment context and stage of the commercial discussion. The request will be routed to the appropriate account, legal or data-protection contact.

01

Identify the organisation

Provide the client or prospective client organisation and your role.

02

Identify the service

State the Pintop product, implementation or service involved.

03

Add the processing context

Include relevant hosting, integration or procurement information where known.

04

Receive the applicable document

Pintop will route the request and provide the appropriate current documentation.