Data Processing Addendum (DPA) — Sustalium

Tik anglų kalba: Šis puslapis prieinamas tik anglų kalba. Jei turite klausimų, susisiekite su mumis angliškai arba naudokite vertėjo įrankį.

Document Ref: DPA-POL-2026-V1.1 · Last updated: 31 August 2026 · Governing Law: The Netherlands

This Data Processing Addendum (“DPA”) forms part of the Master Services Agreement (“MSA”) between Sustalium B.V., Winkelstede 60, 2543BR, Den Haag, The Netherlands (“Processor”), and Customer, as defined in the MSA (“Controller”). This DPA governs Sustalium’s processing of Personal Data on behalf of the Customer in connection with the Services.

1. Definitions

Terms not defined in this DPA have the meaning set out in the MSA.

  • “Applicable Data Protection Law” means the GDPR (EU 2016/679), Dutch GDPR Implementation Act, and any other applicable privacy laws.
  • “Personal Data” means any information relating to an identified or identifiable natural person processed by Sustalium on behalf of the Customer.
  • “Services” means the Sustalium compliance intelligence platform and related services.
  • “Sub‑processor” means any third party engaged by Sustalium to process Personal Data.
  • “SCCs” means the EU Standard Contractual Clauses (2021/914).

2. Roles of the Parties

  • The Customer is the Data Controller.
  • Sustalium is the Data Processor.
  • Sustalium will process Personal Data only on documented instructions from the Customer.

3. Nature, Purpose, and Scope of Processing

Sustalium processes Personal Data solely for:

  • Providing access to the Sustalium platform
  • Creating, verifying, and publishing digital compliance assets
  • Managing user accounts and authentication
  • Maintaining audit trails
  • Providing customer support
  • Ensuring platform security and resilience

Sustalium is <strong>industry‑agnostic</strong> and processes only <strong>business‑context personal data</strong>.

4. Categories of Personal Data

As provided by the Customer or its users:

  • Employee names
  • Work email addresses
  • Roles and job titles
  • Supplier contact details
  • User account identifiers
  • IP addresses and device metadata
  • Compliance documents uploaded by users (may contain personal data)
  • Audit logs and timestamps

Sustalium does <strong>not</strong> process special category data.

5. Categories of Data Subjects

  • Customer employees
  • Supplier employees
  • Contractors
  • Platform users
  • Auditors (if granted access)

6. Processor Obligations

Sustalium shall:

6.1. Process only on instructions

Process Personal Data only as instructed by the Customer.

6.2. Confidentiality

Ensure personnel are bound by confidentiality obligations.

6.3. Security Measures

Implement the Technical and Organizational Measures (“TOMs”) described in Annex II, including: Mandatory MFA for administrative access, logical data isolation between customers, encrypted automated daily backups, and annual penetration testing.

6.4. Sub‑processors

Use only approved Sub‑processors listed in Annex III.

6.5. Assistance to Controller

Assist the Customer with data subject requests, security obligations, breach notifications, and DPIAs (where applicable).

6.6. Deletion or Return

Upon termination, delete or return Personal Data unless required by law to retain it.

7. Sub‑processors

Customer authorizes Sustalium to use the Sub‑processors listed in Annex III.

  • Ensure Sub‑processors are bound by equivalent data protection obligations
  • Notify Customer of any intended changes
  • Remain fully liable for Sub‑processor actions

8. International Transfers

Sustalium primarily stores data in EU GCP regions. However, certain Sub‑processors (e.g., Auth0, Microsoft SharePoint) may involve non‑EU data transfers.

  • The 2021 EU Standard Contractual Clauses (SCCs) apply and are incorporated as Annex IV.
  • Sustalium implements supplementary measures (encryption, MFA, strict access control).

9. Security Incidents

Sustalium will notify the Customer without undue delay after becoming aware of a Personal Data Breach. Notification will include:

  • Nature of the breach
  • Categories of affected data
  • Likely consequences
  • Measures taken or proposed

10. Audits

Customer may audit Sustalium’s compliance:

  • Once per year
  • With 30 days’ notice
  • Without disrupting operations
  • Via documentation review or independent auditor

11. Liability

Liability is governed by the MSA. This DPA does not expand Sustalium’s liability beyond what is defined in the MSA.

12. Governing Law

This DPA is governed by Dutch law, and disputes shall be submitted to the competent courts of Amsterdam, The Netherlands.

Annex I — Description of Processing

  • Nature: Hosting, structuring, verifying, publishing compliance assets
  • Purpose: Provide compliance intelligence services
  • Duration: Duration of the MSA
  • Data Types: As listed in Section 4
  • Data Subjects: As listed in Section 5
  • Processing Activities: Storage, retrieval, structuring, transmission, deletion

Annex II — Technical and Organizational Measures (TOMs)

See our Technical and Organisational Security Measures (TOMs) page for the full list of measures.

Annex III — Approved Sub‑processors

Sub‑processorPurposeLocationTransfer Mechanism
Google Cloud Platform (GCP) Hosting, storage, backups EU N/A (EU)
Auth0 (Okta) Authentication US SCCs
Microsoft SharePoint (Office 365) CRM storage EU/US SCCs
GCS Shield CDN/security EU N/A (EU)

See our Sub-Processor List for the full list and change policy.

Annex IV — Standard Contractual Clauses (SCCs)

The EU Commission Implementing Decision (EU) 2021/914 SCCs are incorporated by reference and apply to all transfers to non‑EU Sub‑processors.

Questions? Contact us through our contact page for any questions about this DPA.