Data Processing Addendum (DPA)
This Data Processing Addendum (DPA) supplements the Master Purchase and Services Agreement between the Company and CSPMX. It establishes the responsibilities of each party regarding the processing of Personal Data in accordance with applicable privacy laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). Where there is any conflict between this Addendum and the Service Agreement, the terms of this Addendum will prevail.
1. Purpose and Scope
- This Addendum applies to the processing of Personal Data under the GDPR and CCPA and describes the categories of personal data, data subjects, and processing purposes.
- The Addendum incorporates the EU Standard Contractual Clauses for the transfer of Personal Data from the European Economic Area (EEA) to countries that do not provide an adequate level of data protection.
- CSPMX will process Personal Data only on documented instructions from the Company and only to the extent necessary to provide the agreed Products and Services.
2. Definitions
- Personal Data – Information relating to an identified or identifiable individual as defined under the GDPR, and 'Personal Information' as defined under the CCPA.
- Subprocessor – Any third party engaged by CSPMX to process Personal Data on behalf of the Company.
- EU Standard Contractual Clauses – The standard contractual clauses approved by the European Commission for international transfers of Personal Data.
3. Data Processing Responsibilities
- The Company remains the Data Controller and determines the purposes and means of processing Personal Data.
- CSPMX acts as the Data Processor and processes Personal Data only in accordance with documented instructions from the Company.
- Both parties will implement appropriate technical and organisational measures to safeguard Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
4. Subprocessors
- CSPMX may engage approved subprocessors to support the delivery of its services.
- Current approved subprocessors include Amazon Web Services (AWS) and Google.
- The Company will be notified of any new or replacement subprocessors and may raise reasonable objections within 30 days.
5. International Data Transfers
- Transfers of Personal Data originating from the European Economic Area will be governed by the EU Standard Contractual Clauses.
- CSPMX will not transfer Personal Data to jurisdictions without adequate data protection safeguards unless authorised by the Company and permitted by applicable law.
6. Security Measures
- Role-based access controls
- Encryption of data in transit and at rest
- Pseudonymisation where appropriate
- Regular security audits and risk assessments
- Incident detection and response procedures
- Measures to maintain confidentiality, integrity, availability, and resilience of systems
7. Incident Management
- CSPMX will notify the Company without undue delay following the discovery of any Personal Data breach affecting Company data.
- Notifications will include the nature of the incident, categories of affected data, likely consequences, and the remediation measures being taken.
8. Return or Deletion of Data
Upon termination or expiry of the Service Agreement, CSPMX will, at the Company's direction, securely return or permanently delete all Personal Data unless retention is required by applicable law.
9. Assistance to the Company
CSPMX will provide reasonable assistance to help the Company meet its obligations under applicable privacy laws, including responding to Data Subject requests, supporting Data Protection Impact Assessments (DPIAs), and cooperating with regulatory authorities where required.
10. Contact
For questions regarding this Data Processing Addendum or CSPMX's data protection practices, please contact our privacy team using the contact information provided on our website.

