\✅ GDPR / CCPA / ISO 27001 Compliant

1. Scope & Applicability

\u25BC

This Data Processing Agreement ("DPA") applies to all data processing activities conducted by Aevum Zenth Conglomerate and its subsidiaries on behalf of data controllers. It governs the collection, storage, processing, and transmission of personal data across all 400+ subsidiaries and regional operations.

Coverage

  • European Economic Area (GDPR), UK (UK GDPR), California (CCPA/CPRA), and other applicable jurisdictions
  • All cloud-hosted, on-premise, and hybrid infrastructure managed by Aevum Zenth
  • Cross-divisional data flows (e.g., Health Sciences to Capital Group analytics pipelines)

2. Controller & Processor Roles

\u25BC

Aevum Zenth may act as a data processor, controller, or joint controller depending on the contractual relationship and data context.

Processor Obligations

When acting as a processor, Aevum Zenth:

  • Processes personal data only on documented instructions from the controller
  • Maintains detailed Records of Processing Activities (ROPA)
  • Cooperates with supervisory authorities upon controller request
  • Does not engage secondary processors without prior written authorization

3. Data Protection Principles

\u25BC

All processing activities are governed by the following core principles:

  • Lawfulness & Transparency: Clear legal basis documented; privacy notices updated per jurisdiction
  • Purpose Limitation: Data collected for specified, explicit, and legitimate purposes only
  • Data Minimization: Only necessary data is retained; automated purging after retention periods expire
  • Accuracy: Regular validation cycles; mechanisms for subjects to request corrections
  • Storage Limitation: Tiered retention schedules aligned with regulatory and business requirements
  • Integrity & Confidentiality: Role-based access controls, encryption, and least-privilege architecture

4. Technical & Organizational Measures

\u25BC

Aevum Zenth maintains an enterprise-grade security posture aligned with ISO 27001, SOC 2 Type II, and NIST CSF.

Technical Controls

  • AES-256 encryption at rest; TLS 1.3+ in transit
  • Zero-trust network architecture with microsegmentation
  • Automated DLP (Data Loss Prevention) and anomaly detection
  • Hardware security modules (HSM) for key management

Organizational Controls

  • Quarterly security awareness training for all personnel
  • Strict background checks and NDAs for staff with data access
  • Segregation of duties and multi-factor authentication (MFA) enforcement

5. Sub-processor Management

\u25BC

Aevum Zenth engages third-party subprocessors for specialized infrastructure and SaaS services. All subprocessors are bound by data processing terms at least as protective as this DPA.

Current Subprocessors

  • Cloud Infrastructure: AWS, Azure, GCP (regions configurable)
  • Identity & Access: Okta, CyberArk
  • Analytics & Telemetry: Snowflake, Datadog
  • Communications: Twilio, Microsoft 365

Controllers will receive 30 days' written notice of material changes. Full subprocessor register is available upon request or at aevumzenth.com/subprocessors.

6. Data Subject Rights

\u25BC

Aevum Zenth facilitates the timely fulfillment of data subject rights requests (DSRs). When acting as processor, we:

  • Notify controllers of DSRs within 24 hours
  • Assist with verification, data mapping, and secure export
  • Implement automated data discovery for accurate response
  • Document all actions taken for audit trails

Direct requests should be routed to the controller. Aevum Zenth does not independently respond to subject requests unless explicitly authorized.

7. Security Incident Response

\u25BC

In the event of a personal data breach, Aevum Zenth commits to:

  • Immediate containment and forensic isolation
  • Notification to the controller within 24 hours of confirmation
  • Provision of impact assessment, affected data categories, and remediation steps
  • Cooperation with regulatory reporting obligations

Our Security Operations Center (SOC) operates 24/7 across three geographic regions to ensure rapid detection and response.

8. International Data Transfers

\u25BC

Cross-border data transfers are conducted in compliance with EU SCCs, UK IDTA, and relevant adequacy decisions. Aevum Zenth implements:

  • Standard Contractual Clauses (2021 version) for EEA/UK to third countries
  • Transfer Impact Assessments (TIA) for non-adequate jurisdictions
  • Data localization options for regulated sectors (healthcare, finance, government)
  • Supplementary measures: pseudonymization, strict access logging, and contractual safeguards

9. Audit & Compliance

\u25BC

Aevum Zenth accepts reasonable audit rights for controllers, subject to confidentiality obligations and 15 days' advance notice. Audits may be conducted by the controller or an independent third party.

Available Documentation

  • ISO 27001 & SOC 2 Type II Reports
  • Penetration Testing Summaries (redacted)
  • Business Continuity & Disaster Recovery Plans
  • Data Flow Maps & Architecture Diagrams

Requests for audit materials or certifications should be submitted to privacy@aevumzenth.com.

10. Term, Termination & Data Return

\u25BC

This DPA remains in effect for the duration of the underlying service agreement. Upon termination:

  • All personal data will be securely returned or permanently deleted per controller instruction
  • Certificates of destruction/deletion will be issued within 14 days
  • Archival or backup copies will be isolated and destroyed within 30 days of the next scheduled overwrite cycle
  • Legal retention obligations (e.g., financial, healthcare) will be honored under strict access controls

Request a Signed DPA

For controllers, legal teams, and compliance officers requiring a executed agreement, security pack, or custom addendum.