Cognivio

Data processing agreement

Version of 18 September 2026. Forms part of the terms of service whenever Cognivio processes personal data on a customer’s behalf. A signed copy is available on request.

1. Parties and definitions

This agreement is between the customer named in the order (“Controller”) and Cognivio (“Processor”). “Personal data”, “processing”, “data subject”, “supervisory authority” and “personal data breach” have the meanings given in the GDPR (Regulation (EU) 2016/679) and, where applicable, the UK GDPR.

2. When this agreement applies

Cognivio appliances run in the Controller’s facility, and in normal use Cognivio has no access to the data they process. This agreement applies when Cognivio processes personal data on the Controller’s behalf in the course of providing services, in particular:

  • support, when the Controller sends logs, configuration files or support bundles;
  • on-site and remote work, when the Controller grants access to its systems for installation, commissioning, troubleshooting or upgrades;
  • any hosted or managed service agreed in an order.

3. Details of processing

Subject matterInstallation, support and maintenance of Cognivio appliances operated by the Controller
DurationThe term of the contract and the time needed to close each support case
Nature and purposeReading, analysing and storing diagnostic material to resolve issues; accessing systems at the Controller’s direction
Types of dataIP addresses, host names, system user names, names and email addresses in alert and notification settings, and any personal data incidentally contained in logs
Data subjectsEmployees and contractors of the Controller; occasionally other persons whose data appears in logs

4. Processor obligations

Cognivio shall:

  1. process personal data only on the Controller’s documented instructions, including with regard to transfers to a third country, unless required to do so by law, in which case it will inform the Controller before processing unless the law prohibits it;
  2. inform the Controller immediately if, in its opinion, an instruction infringes data protection law;
  3. ensure that persons authorised to process the data are bound by confidentiality;
  4. implement the technical and organisational measures in section 7;
  5. respect the conditions in section 5 for engaging sub-processors;
  6. assist the Controller, by appropriate technical and organisational measures, in responding to requests from data subjects;
  7. assist the Controller in ensuring compliance with GDPR articles 32 to 36, taking into account the nature of processing and the information available to it;
  8. at the Controller’s choice, delete or return all personal data after the end of the services, and delete existing copies unless the law requires storage;
  9. make available all information necessary to demonstrate compliance with GDPR article 28 and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by it, on reasonable notice and no more than once a year unless a supervisory authority requires otherwise or a breach has occurred.

5. Sub-processors

The Controller gives general authorisation for Cognivio to engage sub-processors for email and document hosting, issue tracking and remote access tooling. The current list is available on request. Cognivio will inform the Controller of any intended addition or replacement at least 30 days in advance; the Controller may object on reasonable data protection grounds, in which case the parties will seek a solution and, failing that, the Controller may terminate the affected services. Cognivio imposes on each sub-processor, by contract, the same obligations as in this agreement and remains fully liable to the Controller for their performance.

6. International transfers

Cognivio will not transfer personal data outside the European Economic Area or the United Kingdom without an adequacy decision, the standard contractual clauses adopted by the European Commission (with the UK addendum where applicable) or another lawful transfer mechanism.

7. Security measures

  • Access to customer material is limited to the engineers working on the case, protected by individual accounts with multi-factor authentication.
  • Support material is stored encrypted at rest and transmitted only over encrypted connections.
  • Remote access to Controller systems takes place only through the means and for the duration the Controller provides, and is logged.
  • Support material is deleted within 30 days after a case is closed.
  • Personnel are trained in data protection and bound by confidentiality.
  • Security incidents are handled under a documented procedure with named responsibilities.

8. Personal data breach

Cognivio notifies the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the Controller’s data. The notification describes the nature of the breach, the likely consequences, the measures taken or proposed, and a contact point, and is supplemented as further information becomes available.

9. Data subject requests

If Cognivio receives a request from a data subject concerning the Controller’s data, it forwards the request to the Controller within 3 business days and does not respond itself except to direct the data subject to the Controller, unless instructed otherwise.

10. Liability, term and precedence

The liability provisions of the terms of service apply to this agreement. This agreement lasts as long as Cognivio processes personal data on the Controller’s behalf. In case of conflict between this agreement and the terms of service or an order, this agreement prevails on matters of data protection.

11. Signature

This agreement is accepted by the parties through the order. Customers who need a signed copy, a completed sub-processor list or the standard contractual clauses attached can request them at office@cognivio.net with “DPA” in the subject.