Insuja
Request demo ↗Request access →

Data processing addendum

Processing instructions matched to the platform boundaries.

EFFECTIVE / 28 JUL 2026

This baseline DPA applies only when an order form or service agreement incorporates it and the provider processes personal data for a customer.

Legal & trust

Legal centerPrivacyTerms of useAcceptable useCookies & local storageSubprocessorsData processing addendumInvestment disclaimer

Questions or rights requests: hi@insuja.com

Contract status

This DPA is not a standalone offer. It becomes binding only when incorporated into an executed order form or service agreement between the customer and the INSUJA provider named there.

1. Roles and definitions

“Customer Personal Data” means personal data processed by the provider on the customer's behalf through the service. The customer is the controller or processor that gives lawful instructions. The provider is the processor or subprocessor. “Data Protection Law” means the law applicable to that processing, including the GDPR where it applies. Terms such as controller, processor, data subject, processing, and personal data have the meanings given by Data Protection Law.

2. Instructions and purpose

The provider will process Customer Personal Data only to provide, secure, support, and delete or return the service as documented in the agreement, customer configuration, authorized user actions, and other written instructions. The provider will inform the customer if it believes an instruction violates Data Protection Law, unless law prohibits notice. The provider will not sell Customer Personal Data, use it for cross-context behavioral advertising, or train a generalized AI model on it without separate written authorization.

3. Customer obligations

The customer will provide lawful instructions; give required notices; obtain necessary rights and lawful bases; limit data to what is necessary; configure users, releases, retention, and integrations; and avoid prohibited or specially regulated data unless the agreement expressly authorizes it. The customer is responsible for responding to data subjects and regulators as controller.

4. Confidentiality and access

The provider will restrict Customer Personal Data to personnel who need access to perform the agreement and who are bound by confidentiality. Access is subject to authentication, least privilege, workspace and party boundaries, and logging appropriate to the service.

5. Security measures

Taking account of the state of the art, implementation cost, scope, context, purpose, and risk, the provider will maintain appropriate technical and organizational measures. The current design includes:

  • encryption in transit and encrypted storage or envelopes for protected data;
  • separate public, buyer-private, seller-private, and controlled shared boundaries;
  • deny-by-default authorization and scoped, short-lived, or opaque sessions;
  • seller-controlled, immutable version-pinned releases;
  • audit evidence, security-event classification, rate limiting, and abuse controls;
  • backup, restoration, retention, legal-hold, and verified deletion controls;
  • change review, dependency checks, testing, incident response, and access lifecycle procedures.

Customer-specific measures, regions, availability commitments, and certifications apply only when stated in the agreement. A design or readiness document is not a certification.

6. Subprocessors

The customer authorizes the providers listed on the Subprocessors page. The provider remains responsible for each subprocessor's data-protection obligations to the extent required by law and contract. Change notice and objection rights follow the agreement. An objection must be based on reasonable data-protection grounds; the parties will work in good faith on a reasonable alternative.

7. Restricted transfers

If Customer Personal Data is transferred to a country without an applicable adequacy decision, the parties will use a lawful transfer mechanism. Where appropriate, the then-current European Commission standard contractual clauses are incorporated by reference with the module matching the parties' roles, the DPA annex information completing the appendices, and the competent supervisory authority and governing law selected under those clauses. The provider will make information about relevant supplementary measures available on reasonable request.

8. Assistance

Taking account of the nature of processing and information available, the provider will reasonably assist the customer with data-subject requests, security obligations, breach assessment and notification, data-protection impact assessments, and regulator consultations. The provider may charge reasonable fees for assistance beyond standard service obligations unless the need results from its breach.

9. Personal data incidents

The provider will notify the customer without undue delay after confirming a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. Notice will include available information reasonably needed for the customer's duties and will be updated as facts develop. Notice is not an admission of fault. The customer is responsible for notifications required from it as controller.

10. Return and deletion

On termination or a lawful instruction, the provider will return or delete Customer Personal Data as provided by the service and agreement, unless law requires retention. Deletion remains subject to active legal holds, approved retention, backup expiry, security evidence, and verification controls. Data retained by law remains protected and is not used for another purpose.

11. Information and audits

The provider will make information reasonably necessary to demonstrate compliance available through current documentation, questionnaires, independent reports where available, and reasonable follow-up. If that is insufficient and law requires an audit, the customer may conduct one no more than annually with reasonable notice, during business hours, without access to another customer's data or provider secrets, and subject to confidentiality and security. Additional audits may follow a confirmed material incident or regulator request.

12. Processing details

Subject and duration
Providing the contracted INSUJA service for the agreement term plus approved return, deletion, backup, and legal-retention periods.
Nature and purpose
Hosting, organizing, securing, retrieving, sharing under explicit permissions, supporting, exporting, retaining, and deleting customer workspace data.
Data subjects
Customer users, personnel, advisers, counterparties, sellers, buyers, target-company contacts, and individuals identified in customer-submitted material.
Data types
Business contact and identity data, account and permission data, deal and portfolio records, documents, communications, activity and audit evidence, and support data.
Sensitive data
Not intended unless expressly authorized in the agreement and protected by customer-approved additional measures.
Frequency
Continuous or as initiated by authorized users during the service term.

13. Conflict and liability

This DPA prevails over the agreement only for conflicting data-processing terms. The agreement's liability limits apply to this DPA unless Data Protection Law prohibits them. Changes must be in writing, except updates required to keep referenced legal transfer terms valid.

INSUJA
InsujaPrivate-company investment infrastructure.
© 2026 INSUJA
Investment infrastructureInvestment lifecyclePortfolio operationsRequest accessRequest a demoBuyer platformSeller VDRServicesAccess processDocumentationSecurityFAQPrivacyTermsAcceptable useCookiesSubprocessorsData processingInvestment disclaimerLegal center