TEMPLATE — NOT LEGAL ADVICE. This Data Processing Agreement is a starting-point template generated to help ComplyWise and its customers accelerate launch. It is not legal advice and does not create a lawyer-client relationship. It contains placeholders in square brackets (e.g., [Governing law: e.g., State of Delaware, USA]) that must be completed, and terms that must be reviewed, adapted, and approved by qualified legal counsel and each party's data-protection function before it is signed, published, or relied upon. Regulatory requirements, sub-processor lists, transfer mechanisms, and security controls change over time; confirm each against the live production environment and current law before use.
Data Processing Agreement
This Data Processing Agreement (the "DPA") forms part of, and is subject to, the agreement for the provision of the ComplyWise compliance-training platform between the parties (the "Principal Agreement"). It is entered into between:
- ComplyWise, Inc., a company with registered address at [registered address] ("ComplyWise", the "Processor"); and
- the customer identified in the Principal Agreement and in Annex I (the "Customer", the "Controller").
ComplyWise and the Customer are each a "party" and together the "parties". This DPA reflects the parties' agreement on the processing of Personal Data in connection with the ComplyWise multi-tenant Software-as-a-Service compliance learning management system used to manage role-based training assignments, SCORM courses, quizzes, 21 CFR Part 11 electronic signatures, a tamper-evident audit trail, and completion certificates (the "Service").
1. Definitions and interpretation
1.1 "Data Protection Law" means all laws and regulations applicable to the processing of Personal Data under this DPA, including Regulation (EU) 2016/679 (the "GDPR"), the GDPR as retained in United Kingdom law (the "UK GDPR") together with the UK Data Protection Act 2018, and, where applicable, the Swiss Federal Act on Data Protection.
1.2 The terms "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "processing", "special categories of personal data", and "supervisory authority" have the meanings given in the GDPR.
1.3 "Sub-processor" means any third party engaged by ComplyWise (or by another sub-processor of ComplyWise) to process Personal Data on behalf of the Customer under this DPA.
1.4 "SCCs" means the standard contractual clauses for the transfer of personal data to third countries set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, together with the UK International Data Transfer Addendum and any applicable Swiss amendments, as further described in Section 12.
1.5 In the event of any conflict between this DPA and the Principal Agreement in relation to the processing of Personal Data, this DPA prevails. In the event of any conflict between this DPA and the SCCs, the SCCs prevail.
2. Subject-matter, duration, nature and purpose of processing
2.1 Roles. The Customer is the Controller and ComplyWise is the Processor in respect of the Personal Data processed to provide the Service. Where ComplyWise processes limited Personal Data as an independent controller for its own legitimate business purposes (for example, account administration, billing, security, fraud prevention, and product improvement using aggregated or de-identified data), it does so in accordance with its privacy notice and applicable Data Protection Law, and such processing is outside the scope of this DPA.
2.2 Subject-matter. The subject-matter of the processing is the delivery, operation, support, and security of the Service on behalf of the Customer.
2.3 Duration. ComplyWise will process Personal Data for the term of the Principal Agreement and for the additional period contemplated by Section 10 (deletion and return), unless a longer retention period is required by applicable law.
2.4 Nature and purpose. The nature and purpose of the processing are to host and operate a compliance-training learning management system, including: creating and administering tenant accounts and user records; assigning and tracking role-based training; delivering SCORM courses and quizzes; capturing completion status, scores, and 21 CFR Part 11 electronic signatures; generating completion certificates; maintaining a tamper-evident, hash-chained audit trail; and providing security, monitoring, backup, and support.
2.5 The categories of Data Subjects and Personal Data, and further details of the processing, are set out in Annex I.
3. Processing only on documented instructions
3.1 ComplyWise will process Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by European Union or Member State law to which ComplyWise is subject; in such a case, ComplyWise will inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
3.2 The Principal Agreement, this DPA (including its Annexes), and the Customer's authorised use and configuration of the Service constitute the Customer's complete and documented instructions. Additional or different instructions must be agreed in writing and may be subject to adjustments to fees or scope.
3.3 ComplyWise will immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Law. ComplyWise is not obliged to carry out a legal assessment of the Customer's instructions and this Section 3.3 is without prejudice to the parties' respective obligations under Data Protection Law.
4. Confidentiality
4.1 ComplyWise will ensure that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4.2 ComplyWise will limit access to Personal Data to personnel who need access to perform ComplyWise's obligations under the Principal Agreement, and will ensure such personnel receive appropriate data-protection and security training.
5. Security of processing (Article 32)
5.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to the rights and freedoms of natural persons, ComplyWise will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The measures in force as at the effective date are described in Annex II.
5.2 ComplyWise may update or modify the measures in Annex II from time to time, provided that such updates do not materially reduce the overall level of security of the Service.
5.3 The Customer is responsible for the secure use of the Service within its control, including configuring role-based access, enforcing multi-factor authentication and password policy where offered, managing its administrators and users, and promptly deactivating credentials for users who no longer require access.
6. Sub-processors
6.1 General authorisation. The Customer grants ComplyWise general authorisation to engage Sub-processors to process Personal Data, subject to this Section 6. The Sub-processors authorised as at the effective date are listed in Annex III.
6.2 Flow-down. Where ComplyWise engages a Sub-processor, it will do so by way of a written contract that imposes data-protection obligations that are substantially the same as, and no less protective than, those set out in this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures. ComplyWise remains fully liable to the Customer for the performance of each Sub-processor's obligations.
6.3 Change notice and objection. ComplyWise will give the Customer prior written notice (which may be given by email or through the Service or ComplyWise's sub-processor page) of any intended addition or replacement of a Sub-processor, giving the Customer a reasonable opportunity — at least [30] days before the new Sub-processor begins processing Personal Data — to object on reasonable data-protection grounds. If the Customer objects, the parties will work in good faith to resolve the objection. If no resolution is reached, the Customer may, as its sole and exclusive remedy, terminate the affected part of the Service in accordance with the Principal Agreement.
7. Assistance with Data Subject requests
7.1 Taking into account the nature of the processing, ComplyWise will assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in the fulfilment of the Customer's obligation to respond to requests to exercise Data Subject rights under Chapter III of the GDPR (including rights of access, rectification, erasure, restriction, data portability, and objection).
7.2 ComplyWise will provide self-service functionality within the Service enabling the Customer to access, correct, export, and delete Personal Data. Where a Data Subject request cannot be fulfilled through such functionality, ComplyWise will provide reasonable additional assistance at the Customer's request.
7.3 If ComplyWise receives a request directly from a Data Subject relating to Personal Data processed under this DPA, ComplyWise will, unless legally prohibited, promptly inform the Customer and will not respond to the request itself except on the Customer's documented instructions or as required by applicable law.
8. Assistance with Articles 32 to 36
8.1 Taking into account the nature of processing and the information available to ComplyWise, ComplyWise will assist the Customer in ensuring compliance with the Customer's obligations under Articles 32 to 36 of the GDPR, namely security of processing, notification of Personal Data Breaches to the supervisory authority and to Data Subjects, data protection impact assessments, and prior consultation with the supervisory authority.
8.2 Such assistance may include making available the security information in Annex II, this DPA, and other documentation reasonably necessary for the Customer to carry out a data protection impact assessment and, where required, prior consultation.
9. Personal Data Breach notification
9.1 ComplyWise will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA.
9.2 The notification will, to the extent known and insofar as reasonably possible, describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Where the information cannot be provided at the same time, it may be provided in phases without undue further delay.
9.3 ComplyWise's notification of, or response to, a Personal Data Breach will not be construed as an acknowledgement by ComplyWise of any fault or liability. The Customer remains responsible for its own notification obligations to supervisory authorities and Data Subjects.
10. Deletion and return on termination
10.1 At the choice of the Customer, ComplyWise will delete or return all Personal Data to the Customer after the end of the provision of the Service, and delete existing copies, unless European Union or Member State law requires storage of the Personal Data.
10.2 The Customer may export its Personal Data (including training records, electronic-signature manifests, audit-trail entries, and certificates) using the Service's export functionality during the term and for a period of [30] days after termination or expiry (the "retrieval period"). After the retrieval period, ComplyWise will delete Personal Data within [90] days, subject to Section 10.3.
10.3 ComplyWise may retain Personal Data to the extent, and for the period, required by applicable law (including records that must be preserved to support the integrity of a 21 CFR Part 11 / EU Annex 11 audit trail), and Personal Data residing in routine encrypted backups will be deleted in accordance with ComplyWise's backup rotation schedule. During any such extended retention, the obligations of this DPA continue to apply and the Personal Data will remain subject to the security measures in Annex II and will only be processed as necessary for the retention purpose.
10.4 On the Customer's written request, ComplyWise will certify in writing that it has complied with this Section 10.
11. Audits and information
11.1 ComplyWise will make available to the Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.
11.2 To satisfy the requirements of Section 11.1, ComplyWise may make available its then-current security documentation, third-party audit reports, certifications, and responses to reasonable written security questionnaires.
11.3 Where the information made available under Section 11.2 is insufficient, the Customer may, on reasonable prior written notice of at least [30] days and no more than once per twelve-month period (unless required following a Personal Data Breach or by a supervisory authority), conduct an audit during normal business hours. Audits must be conducted in a manner that minimises disruption, must respect the confidentiality and security of ComplyWise's other customers and its multi-tenant environment, must not include access to other customers' data or to any penetration testing of production systems without ComplyWise's prior written consent, and the auditor must enter into a confidentiality undertaking acceptable to ComplyWise. Each party bears its own costs, save that the Customer bears ComplyWise's reasonable costs where the audit reveals no material non-compliance.
12. International transfers
12.1 The Service is hosted on Vercel, with the database and object storage provided by Supabase; ComplyWise is established in the United States. Application hosting runs in Vercel’s iad1 region (Washington, D.C., USA); the Supabase project — database and object storage — is in us-east-1 (N. Virginia, USA). Vercel’s global edge network serves static assets from locations worldwide, but the application functions that process personal data execute in iad1. Accordingly, the provision of the Service may involve the transfer of Personal Data to, and processing in, the United States and other countries in which ComplyWise or its Sub-processors operate.
12.2 Where the processing of Personal Data subject to the GDPR or UK GDPR involves a transfer to a country that is not the subject of an adequacy decision, the parties agree that such transfer is governed by the SCCs, which are hereby incorporated into this DPA by reference and completed as follows:
- Module. Module Two (Controller to Processor) applies where the Customer is a controller and ComplyWise is a processor. Module Three (Processor to Processor) applies in respect of onward transfers to Sub-processors.
- Docking clause (Clause 7). The optional docking clause applies.
- General authorisation (Clause 9(a), Option 2). The general Sub-processor authorisation in Section 6 applies, with the time period specified in Section 6.3.
- Redress and governing law/forum (Clauses 11, 17, 18). The optional redress clause does not apply; the governing law and forum are those of an EU Member State that allows for third-party beneficiary rights, namely [EU Member State: e.g., Ireland].
- Annexes. Annex I to this DPA populates Annexes I.A and I.B of the SCCs; the competent supervisory authority (Annex I.C) is identified in Annex I; Annex II to this DPA populates Annex II of the SCCs; and Annex III to this DPA populates the list of Sub-processors.
12.3 United Kingdom. For transfers subject to the UK GDPR, the SCCs apply as varied and supplemented by the UK International Data Transfer Addendum issued by the Information Commissioner under section 119A of the Data Protection Act 2018, which is incorporated by reference and completed using the corresponding information in this DPA and its Annexes.
12.4 Switzerland. For transfers subject to the Swiss Federal Act on Data Protection, the SCCs apply with the amendments necessary to give effect to Swiss law (including references to the Swiss Federal Data Protection and Information Commissioner and to Swiss law), as published by the Swiss authority.
12.5 Where and to the extent ComplyWise participates in an approved transfer framework recognised as providing an adequate level of protection (for example, the EU-U.S. Data Privacy Framework and its UK and Swiss extensions), the parties may rely on such framework as an alternative transfer mechanism for transfers to the United States.
12.6 If the transfer mechanism relied upon is invalidated, superseded, or ceases to provide a valid basis for transfer, the parties will work together in good faith to implement an alternative lawful transfer mechanism without undue delay.
13. Liability
13.1 Each party's liability arising out of or in connection with this DPA and the SCCs, whether in contract, tort (including negligence), or otherwise, is subject to the aggregate limitations of liability and exclusions agreed in the Principal Agreement, and any reference in those limitations to the liability of a party will mean the aggregate liability of that party under the Principal Agreement and this DPA together.
13.2 Nothing in this DPA limits or excludes either party's liability where it cannot be limited or excluded under applicable law, including liability of a Data Subject's right to compensation under Article 82 of the GDPR, or the rights of Data Subjects under the SCCs.
13.3 As between the parties, and without prejudice to the rights of Data Subjects or supervisory authorities, liability for administrative fines, claims, or damages arising from a party's own breach of its obligations under Data Protection Law will be allocated according to each party's responsibility for the harm caused, taking into account the roles of Controller and Processor.
14. General
14.1 Term. This DPA takes effect on the effective date of the Principal Agreement (or, if later, the date it is last signed) and continues for as long as ComplyWise processes Personal Data on behalf of the Customer.
14.2 Governing law and jurisdiction. Except where Data Protection Law or the SCCs require otherwise, this DPA is governed by, and construed in accordance with, the laws of [Governing law: e.g., State of Delaware, USA], and the courts identified in the Principal Agreement have exclusive jurisdiction.
14.3 Severance and survival. If any provision of this DPA is held invalid or unenforceable, the remainder continues in effect. Provisions that by their nature should survive termination will survive.
14.4 Data protection contact. Data-protection queries relating to this DPA may be directed to ComplyWise at [DPO / privacy contact email].
Annex I — Description of processing
A. List of parties
Data exporter (Controller): the Customer identified in the Principal Agreement.
- Name and address: [Customer legal name] / [Customer registered address].
- Contact person, position and details: [Customer data-protection contact — name, title, email].
- Activities relevant to the data transferred: use of the ComplyWise Service to administer and record compliance training for its workforce.
- Role: Controller.
Data importer (Processor): ComplyWise, Inc.
- Name and address: ComplyWise, Inc., [registered address].
- Contact person, position and details: [DPO / privacy contact email].
- Activities relevant to the data transferred: provision, operation, support, and security of the ComplyWise compliance-training platform.
- Role: Processor.
B. Description of processing
Categories of Data Subjects. The Customer's personnel and other individuals whose training the Customer administers through the Service, including:
- the Customer's employees, trainees, and workers assigned to compliance training;
- the Customer's administrators, authors, managers, and learners who hold Service accounts;
- contractors, temporary staff, or other authorised users the Customer chooses to enrol.
Categories of Personal Data.
- Account data: organisation name and subscription plan.
- User identity and profile data: full name, work email address, optional employee identifier, assigned role (tenant admin / author / manager / learner), and authentication data (hashed password, TOTP multi-factor secret and backup codes, and SSO identifiers where SAML/SCIM is used).
- Training records: course and quiz assignments, completion status, scores, 21 CFR Part 11 electronic-signature records (signer identity, meaning of signature, and timestamp), and completion certificates.
- Audit and security logs: IP address, user-agent, timestamps, and event metadata recorded in the tamper-evident, hash-chained audit trail.
Special categories of Personal Data. The Service is not designed or intended to process special categories of personal data (Article 9) or criminal-conviction data (Article 10). The Customer must not upload such data except free-text content it chooses to enter; if it does, the Customer is responsible for ensuring a lawful basis and any additional safeguards.
Frequency of processing. Continuous, for the duration of the Principal Agreement.
Nature and purpose of processing. As described in Section 2 of this DPA — hosting and operating a compliance-training learning management system, including assignment and tracking of training, delivery of SCORM courses and quizzes, capture of scores and electronic signatures, generation of certificates, maintenance of an audit trail, and provision of security, backup, monitoring, and support.
Retention period. For the term of the Principal Agreement plus the periods described in Section 10, and thereafter only as required by applicable law (for example, to preserve regulated training and audit-trail records).
Transfers to Sub-processors. Subject-matter, nature, and duration of processing by Sub-processors are as set out in Annex III.
C. Competent supervisory authority
The competent supervisory authority is the authority of the EU Member State in which the Customer, or its EU representative, is established, or otherwise as determined under Clause 13 of the SCCs: [Competent supervisory authority — e.g., the Irish Data Protection Commission]. For UK transfers, the competent authority is the UK Information Commissioner's Office; for Swiss transfers, the Swiss Federal Data Protection and Information Commissioner.
Annex II — Technical and organisational security measures
The following measures are implemented and maintained by ComplyWise as at the effective date. They may be updated in accordance with Section 5.2. This Annex also completes Annex II of the SCCs.
1. Tenant isolation and access control
- Hard multi-tenant isolation enforced at the database layer using PostgreSQL row-level security (RLS), with the application connecting through a dedicated non-superuser role that cannot bypass RLS policies.
- Role-based access control (RBAC) across four application roles — tenant admin, author, manager, and learner — restricting functionality and data access on a least-privilege basis.
- Stateless session management using signed JWTs stored in httpOnly cookies with idle-timeout expiry.
2. Authentication and secret management
- Multi-factor authentication (MFA) via time-based one-time passwords (TOTP) with recovery backup codes.
- Password protection using bcrypt hashing with configurable complexity requirements, password history, and account lockout on repeated failed attempts.
- Enterprise identity federation through SAML single sign-on and SCIM user provisioning (available on the Pro tier).
- Secret protection using envelope encryption (AES-256-GCM) under a versioned, rotatable application key held in the deployment environment and never stored in the database, for stored MFA and SSO secrets.
3. Encryption
- Encryption in transit using TLS for connections to and within the Service.
- Encryption at rest for the database and for object storage, provided by the respective platforms under their own controls. [Confirm the encryption-at-rest configuration at each provider.]
4. Integrity, audit, and electronic records
- Tamper-evident, hash-chained audit log providing a verifiable, append-only record of security- and compliance-relevant events.
- 21 CFR Part 11-compliant electronic signatures capturing signer identity, the meaning of the signature, and a trusted timestamp, consistent with EU Annex 11 expectations.
5. Availability, resilience, and infrastructure security
- Hosting on Vercel, which executes the application as managed serverless functions across its edge network, with a managed PostgreSQL database and object storage provided by Supabase. There is no separate cache or Redis tier: state that must be shared across serverless invocations, principally rate-limit counters, is held in the PostgreSQL database. Application hosting runs in Vercel’s
iad1region (Washington, D.C., USA); the Supabase project — database and object storage — is inus-east-1(N. Virginia, USA). Vercel’s global edge network serves static assets from locations worldwide, but the application functions that process personal data execute iniad1. - Managed backups of the database with encryption at rest and a defined rotation schedule.
- Per-tenant and per-user rate limiting to protect availability and mitigate abuse.
- Transactional email delivered via Resend.
6. Organisational measures
- Confidentiality obligations imposed on personnel authorised to process Personal Data, together with data-protection and security training.
- Least-privilege administrative access to production systems, limited to personnel who require it to operate and support the Service.
- Sub-processor governance through written contracts imposing data-protection obligations no less protective than those in this DPA (Section 6).
- Error monitoring via Sentry where enabled, configured to limit the capture of Personal Data.
7. Standards referenced
The Service and its controls are designed with reference to 21 CFR Part 11, EU Annex 11, ICH Q9, GAMP 5, SCORM 1.2/2004, and GDPR/UK-GDPR. References to standards describe design intent and are not, by themselves, a warranty of certification or of any particular customer's regulatory compliance.
Annex III — List of authorised Sub-processors
As at the effective date, ComplyWise engages the following Sub-processors. This list may change in accordance with Section 6.3.
- Vercel Inc. — application hosting and delivery (managed serverless functions and edge network). Processing location: United States and Vercel’s global edge locations. Nature: execution of the application and the request/function logs that hosting generates. Vercel functions execute in the
iad1region (Washington, D.C., USA); static assets are served from Vercel’s global edge network. - Supabase, Inc. — managed PostgreSQL database and object storage. Processing location: The Supabase project — database and object storage — is in
us-east-1(N. Virginia, USA). Nature: storage of all Service data. Supabase itself runs on Amazon Web Services infrastructure, so AWS is engaged as a sub-processor by Supabase rather than directly by ComplyWise. - Stripe, Inc. — payment processing and subscription billing. Processing location: United States. Nature: processing of Customer account and billing contact data; Stripe does not process learner training records.
- Resend (optional, where enabled by the operator) — transactional email delivery. Processing location: United States. Nature: delivery of Service notifications containing user name and email address.
- Sentry (optional, where enabled by the operator) — application error monitoring. Processing location: United States. Nature: capture of diagnostic and error data, configured to limit Personal Data.
Signatures
By signing the Principal Agreement, or by separately executing this DPA, each party agrees to be bound by this DPA. Each party warrants that the individual signing on its behalf is duly authorised to do so.
For ComplyWise, Inc. (Processor): Name: [___]; Title: [___]; Date: [___]; Signature: [___].
For the Customer (Controller): Name: [___]; Title: [___]; Date: [___]; Signature: [___].