Data Processing Agreement
Last updated: July 22, 2025
This Data Processing Agreement ("DPA" or "Agreement") is entered into between Cogniquest Technologies Private Limited ("Cogniquest", "We", "Us", or "Our") and the Customer ("You" or "Customer") who has agreed to Cogniquest's Terms of Service available at https://www.cogniquest.ai/terms-of-service (the "Terms") or any other written or electronic agreement governing Customer's access to and use of Cogniquest's intelligent document processing and text analytics platform and related services (collectively, the "Services"). This DPA forms part of and is incorporated into the Terms.
Customer enters into this DPA on behalf of itself and any Affiliates authorised to use the Services under the Terms. For purposes of this DPA only, and except where otherwise indicated, references to "Customer" include Customer and such Affiliates.
The Parties hereby agree that the terms and conditions set out below shall govern Cogniquest's processing of Customer Personal Data in connection with the Services.
1. Definitions
In this DPA, the following terms shall have the meanings set out below:
- "Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with a Party, where "control" means the possession, directly or indirectly, of the power to direct or cause the direction of the management and policies of an entity, whether through ownership of voting securities, by contract or otherwise.
- "Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.
- "Customer Personal Data" means any Personal Data provided by or made available by Customer (or collected by Cogniquest on Customer's behalf) which is Processed by Cogniquest solely to perform the Services under the Terms.
- "Data Protection Laws" means all applicable laws and regulations relating to the processing, privacy, and use of Personal Data, including without limitation: (i) the General Data Protection Regulation (EU) 2016/679 ("EU GDPR"); (ii) the UK GDPR as defined in section 3(10) of the Data Protection Act 2018 ("UK GDPR"); (iii) India's Information Technology Act, 2000 and rules made thereunder; (iv) India's Digital Personal Data Protection Act, 2023 ("DPDPA") and applicable rules; and (v) any other applicable national, state, or local law relating to data protection or privacy, each as amended or replaced from time to time.
- "Data Subject" means the identified or identifiable natural person to whom Customer Personal Data relates.
- "EU Area" means the European Union, the European Economic Area, the United Kingdom, and Switzerland.
- "Personal Data" has the meaning given to it under applicable Data Protection Laws and generally means any information relating to an identified or identifiable natural person.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data transmitted, stored, or otherwise processed by Cogniquest.
- "Processor" means a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.
- "Restricted Transfer" means a transfer of Customer Personal Data from a country in the EU Area to a country that has not received an adequacy decision from the relevant supervisory authority (a "Third Country").
- "Standard Contractual Clauses" or "SCCs" means (i) the standard contractual clauses for the transfer of Personal Data to third countries approved by the European Commission Decision of 4 June 2021 ("EU SCCs"); (ii) the International Data Transfer Addendum ("UK Addendum") issued by the UK Information Commissioner's Office under section 119A of the Data Protection Act 2018; or (iii) any successor or equivalent clauses adopted by a competent supervisory authority.
- "Security Incident" means any confirmed breach of Cogniquest's security that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data. Security Incidents do not include unsuccessful attempts that do not compromise the security of Customer Personal Data, such as unsuccessful login attempts, pings, port scans, or denial-of-service attacks.
- "Services" means Cogniquest's intelligent document processing and text analytics platform and any related professional or support services supplied to Customer under the Terms.
- "Sub-processor" means any Processor engaged by Cogniquest to process Customer Personal Data on Cogniquest's behalf in connection with the Services.
- "Supervisory Authority" means the competent public authority responsible for supervising the application of applicable Data Protection Laws in a given jurisdiction.
Capitalised terms not otherwise defined in this DPA shall have the meanings ascribed to them in the Terms.
2. Scope and Application
- This DPA applies to Cogniquest's Processing of Customer Personal Data in connection with the Services to the extent such Processing is subject to Data Protection Laws.
- This DPA is supplemental to, and forms part of, the Terms. In the event of any inconsistency between this DPA and the Terms, the following order of precedence shall apply: (a) applicable Standard Contractual Clauses; (b) this DPA; (c) the Terms.
- This DPA shall remain in force for the duration of the Terms and shall terminate automatically upon expiry or termination of the Terms, subject to any obligations that survive termination.
3. Roles of the Parties
- The Parties acknowledge and agree that with regard to the Processing of Customer Personal Data: Customer acts as the Controller (or Business, as applicable), and Cogniquest acts as the Processor (or Service Provider, as applicable), as further described in Annex 1 to this DPA.
- Cogniquest shall Process Customer Personal Data only on Customer's documented instructions, including as set out in this DPA and the Terms. Cogniquest shall immediately inform Customer if, in Cogniquest's opinion, any instruction from Customer infringes applicable Data Protection Laws.
- Customer is solely responsible for: (a) ensuring that its instructions to Cogniquest are lawful; (b) the lawfulness of any collection or transfer of Customer Personal Data to Cogniquest; (c) complying with applicable Data Protection Laws in respect of its role as Controller; and (d) notifying relevant Supervisory Authorities and Data Subjects of any Security Incident as required by applicable Data Protection Laws.
4. Description and Purpose of Processing
- The subject matter, duration, nature, purpose, type of Personal Data, and categories of Data Subjects in relation to Cogniquest's Processing of Customer Personal Data are set out in Annex 1 to this DPA.
- The purpose of Processing under this DPA is the provision of the Services to Customer pursuant to the Terms. Cogniquest shall not Process Customer Personal Data for any other purpose unless required by applicable law.
5. Cogniquest's Processing Obligations
Cogniquest shall comply with all applicable Data Protection Laws in the Processing of Customer Personal Data and shall in particular:
- Lawful Processing. Process Customer Personal Data only on the documented instructions of Customer (including as set out in this DPA and the Terms) and solely for the purpose of providing the Services, unless otherwise required by applicable law. Where applicable law requires Cogniquest to Process Customer Personal Data for another purpose, Cogniquest shall inform Customer before such Processing (unless prohibited by law).
- Confidentiality. Ensure that all personnel authorised to Process Customer Personal Data are subject to binding confidentiality obligations (whether by contract or applicable professional obligations), and that access to Customer Personal Data is restricted to personnel who need such access to perform the Services.
- Security Measures. Implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, having regard to the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing as well as the risks to the rights and freedoms of natural persons. Such measures shall include as a minimum:
- Encryption of Customer Personal Data at rest and in transit;
- Pseudonymisation of Customer Personal Data where practicable;
- Ongoing measures to ensure the confidentiality, integrity, availability, and resilience of Cogniquest's processing systems and services;
- The ability to restore availability and access to Customer Personal Data in a timely manner in the event of a physical or technical incident; and
- Processes for regularly testing, assessing, and evaluating the effectiveness of technical and organisational security measures.
- Sub-processors. Not engage any Sub-processor to Process Customer Personal Data without Customer's prior general or specific written authorisation. Customer hereby grants general authorisation for Cogniquest to engage the Sub-processors listed in Annex 2 to this DPA. Cogniquest shall:
- Notify Customer at least thirty (30) days in advance of any intended addition to or replacement of Sub-processors listed in Annex 2;
- Impose data protection obligations on each Sub-processor that are materially equivalent to those set out in this DPA; and
- Remain liable to Customer for any failure by a Sub-processor to fulfil its data protection obligations.
- Data Subject Rights. Taking into account the nature of Processing, provide Customer with reasonable technical and organisational assistance to enable Customer to fulfil its obligations to respond to Data Subject requests to exercise rights under applicable Data Protection Laws (including rights of access, rectification, erasure, restriction, portability, and objection). Customer shall bear Cogniquest's reasonable costs of providing such assistance.
- Security Incident Notification. Notify Customer without undue delay (and, where feasible, within forty-eight (48) hours) after becoming aware of a Security Incident involving Customer Personal Data, providing at a minimum: (i) a description of the nature of the Security Incident; (ii) the categories and approximate number of Data Subjects affected; (iii) the categories and approximate volume of Customer Personal Data records affected; (iv) the likely consequences of the Security Incident; and (v) the measures taken or proposed to address the Security Incident. Cogniquest's notification of a Security Incident shall not constitute an admission of fault or liability.
- Assistance with Compliance. Provide reasonable assistance to Customer with its obligations under applicable Data Protection Laws, including Data Protection Impact Assessments (DPIAs) and prior consultations with Supervisory Authorities under Articles 35 and 36 of the EU GDPR (or equivalent provisions), taking into account the nature of Processing and the information available to Cogniquest. Customer shall bear Cogniquest's reasonable costs of providing such assistance.
- Legally Binding Requests. To the extent legally permissible, promptly notify Customer upon receipt of any legally binding request from a public authority for disclosure of Customer Personal Data, and not disclose Customer Personal Data in response to such a request without first informing Customer, unless prohibited by applicable law. Cogniquest shall maintain a record of all legally binding disclosure requests.
- Return or Deletion. Upon termination or expiry of the Terms, and at Customer's election, either securely return or delete all Customer Personal Data (including all copies) within sixty (60) days, unless applicable law requires Cogniquest to retain some or all of the Customer Personal Data. Any retained Customer Personal Data shall remain subject to the confidentiality obligations of the Terms.
- Records of Processing. Maintain accurate and up-to-date records of all categories of Processing activities carried out on behalf of Customer as required by applicable Data Protection Laws.
- Audit Rights. Make available to Customer, upon reasonable written notice, all information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits or inspections conducted by Customer or a mutually agreed independent third-party auditor, provided that: (i) Customer gives Cogniquest at least thirty (30) days' prior written notice; (ii) audits are conducted during normal business hours and in a manner that minimises disruption to Cogniquest's operations; and (iii) Customer bears all reasonable costs incurred by Cogniquest in connection with the audit. Unless required by a Supervisory Authority or necessitated by a Security Incident, audits shall not occur more than once per calendar year. In the first instance, Cogniquest will provide responses to reasonable cybersecurity and compliance questionnaires and only where Customer cannot establish compliance from such responses shall an on-site audit be requested.
6. Customer's Obligations
- Customer shall comply with all applicable Data Protection Laws in connection with its use of the Services and the Processing of Customer Personal Data, including ensuring that it has a lawful basis for providing Customer Personal Data to Cogniquest and for instructing Cogniquest to Process Customer Personal Data.
- Customer shall not provide Cogniquest with Special Categories of Personal Data (as defined under the EU GDPR, including data concerning health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, sex life or sexual orientation) unless expressly agreed in writing between the Parties.
- Customer agrees to provide instructions to Cogniquest only in accordance with applicable Data Protection Laws.
7. International Data Transfers
- General. The Parties agree that where the transfer of Customer Personal Data from Customer (as data exporter) to Cogniquest (as data importer) constitutes a Restricted Transfer and EU Area Law applies, such transfer shall be subject to the appropriate Standard Contractual Clauses, which are deemed incorporated into and form part of this DPA as follows:
- EU GDPR Transfers: The EU SCCs (Module Two: Controller to Processor) shall apply, with the following configuration: (i) the optional docking clause in Clause 7 shall apply; (ii) Option 2 in Clause 9 shall apply, with thirty (30) days' notice for Sub-processor changes; (iii) the optional language in Clause 11 shall not apply; (iv) Clause 17 shall be governed by Irish law; (v) disputes shall be resolved before the courts of the Republic of Ireland; and (vi) Annexes I and II of the EU SCCs shall be deemed completed with the information in Annex 1 of this DPA.
- UK GDPR Transfers: The EU SCCs shall apply as modified by the UK International Data Transfer Addendum (UK Addendum). In the event of a conflict between the EU SCCs and the UK Addendum, the UK Addendum shall prevail. Tables 1–3 of the UK Addendum shall be completed with the information in Annex 1 of this DPA, and Table 4 shall be deemed completed by selecting both "Importer" and "Exporter".
- Swiss Transfers: The EU SCCs shall apply as adapted for Switzerland, with references to "EU/EEA" and "Member State" being interpreted as references to Switzerland, and references to the competent supervisory authority being interpreted as the Swiss Federal Data Protection and Information Commissioner (FDPIC).
- Supplementary Measures. Where the applicable Standard Contractual Clauses or other transfer mechanism alone is insufficient to ensure an adequate level of protection, Cogniquest shall promptly implement supplementary technical and organisational measures to ensure Customer Personal Data is protected to the standard required under applicable Data Protection Laws.
- AI and Automated Processing. Where Cogniquest processes Customer Personal Data using artificial intelligence or machine learning technologies, such processing shall be conducted solely to the extent necessary to provide the Services, in accordance with Customer's instructions, and in compliance with applicable Data Protection Laws.
- Disclosure to Public Authorities. If Cogniquest receives a request from a public authority to access Customer Personal Data, Cogniquest shall (to the extent legally permitted): (a) challenge the request if reasonable grounds exist; (b) notify Customer promptly; and (c) disclose only the minimum amount of Customer Personal Data strictly required by the authority, maintaining a record of such disclosure.
8. Warranties
- Each Party warrants that it and its personnel and Sub-processors (as applicable) shall comply with their respective obligations under applicable Data Protection Laws for the duration of this DPA.
- Cogniquest warrants that it shall process Customer Personal Data in a manner consistent with the principles of privacy by design and default, as required by applicable Data Protection Laws.
9. Indemnification
- To the extent permissible by applicable law, Customer shall indemnify and hold harmless Cogniquest and its Affiliates, officers, directors, and employees from and against any third party claims, losses, damages, fines, and costs (including reasonable legal fees) arising from any breach by Customer of this DPA or its obligations under applicable Data Protection Laws.
- To the extent permissible by applicable law, Cogniquest shall indemnify and hold harmless Customer from and against any third party claims, losses, damages, fines, and costs (including reasonable legal fees) arising from any breach by Cogniquest of this DPA or its obligations under applicable Data Protection Laws in connection with the Processing of Customer Personal Data.
10. Miscellaneous
- Severability. If any provision of this DPA is found by a court or competent authority to be unlawful or unenforceable, it shall be deemed modified to the minimum extent necessary to make it enforceable, and such finding shall not invalidate or render unenforceable any other provision of this DPA.
- Governing Law. This DPA shall be governed by the laws of India, unless otherwise required by applicable Data Protection Laws. The Parties consent to the exclusive jurisdiction of the courts located in Bengaluru, Karnataka, India for any dispute arising under this DPA, except where the applicable Standard Contractual Clauses specify a different governing law or forum.
- No Temporary Files. Cogniquest does not generate temporary files containing Customer Personal Data outside of transient processing memory required to deliver the Services.
- Compliance Standards. Cogniquest shall comply with applicable statutory and regulatory requirements and shall maintain certifications and controls appropriate to the nature of its Services, including industry-standard information security practices consistent with ISO 27001 or equivalent frameworks.
- Entire Agreement. This DPA, together with the Terms and any applicable Standard Contractual Clauses, constitutes the entire agreement between the Parties with respect to the subject matter hereof and supersedes all prior agreements, representations, and understandings relating to such subject matter.
11. Data Protection Officer (DPO) Contact
In the event a Data Subject wishes to exercise its rights under applicable Data Protection Laws, or if Customer has any questions, concerns, or complaints relating to the Processing of Customer Personal Data under this DPA, please contact Cogniquest's Data Protection Officer:
- Name: Thejaswi S
- Email: thejaswi.s@cogniquest.ai
- Address: Cogniquest Technologies Private Limited, 2nd Floor, Garuda BHive Workspace, BTM, Bengaluru (India) 560068
Annex 1 — Description of Processing Activities
This Annex sets out certain details of Cogniquest's Processing of Customer Personal Data in connection with the Services.
A. List of Parties
Data Exporter (Controller)
- Name: Customer (as defined in the Terms)
- Address: As set forth in the relevant Order Form or Registration
- Contact person: As set forth in the relevant Order Form or Registration
- Activities relevant to transferred data: Recipient of the Services provided by Cogniquest in accordance with the Terms
- Role: Controller / Business
Data Importer (Processor)
- Name: Cogniquest Technologies Private Limited
- Address: 2nd Floor, Garuda BHive Workspace, BTM, Bengaluru (India) 560068
- Contact person: Thejaswi S, thejaswi.s@cogniquest.ai
- Activities relevant to transferred data: Provision of the Services to Customer in accordance with the Terms
- Role: Processor / Service Provider
B. Competent Supervisory Authority
As determined by the application of applicable Data Protection Laws. For transfers subject to the EU SCCs, the competent supervisory authority shall be determined in accordance with Clause 13 of the EU SCCs.
C. Processing Details
| Categories of Data Subjects | Customer's authorised users of the Services; employees, contractors, and agents of Customer whose data appears in documents submitted for processing |
| Categories of Personal Data Transferred | Processed automatically by the Services:
Processed where and to the extent provided by Customer in submitted documents:
|
| Sensitive Personal Data | None intended. Customer shall not submit Special Categories of Personal Data unless separately agreed in writing. |
| Frequency of Transfer | Continuous, as Customer submits documents for processing |
| Nature of Processing | Collection, storage, extraction, structuring, analysis, and retrieval of data from documents using proprietary AI and large language models; query processing; output generation; and deletion upon instruction or expiry |
| Purpose of Processing | Provision of intelligent document processing and text analytics Services to Customer, including financial spreading, accounts payable automation, corporate customer onboarding (KYB), claims underwriting support, and related use cases |
| Retention Period | For the duration of the Terms, and thereafter for up to sixty (60) days unless Customer requests earlier deletion or applicable law requires a longer retention period |
D. Technical and Organisational Security Measures
Cogniquest maintains the following categories of technical and organisational security measures to protect Customer Personal Data:
- Access Control: Role-based access control, multi-factor authentication for system access, and least-privilege principles.
- Encryption: Encryption of Customer Personal Data at rest (AES-256 or equivalent) and in transit (TLS 1.2 or higher).
- Pseudonymisation: Where practicable, Personal Data is pseudonymised to reduce risk in the event of unauthorised access.
- Network Security: Firewalls, intrusion detection/prevention systems, and regular vulnerability assessments.
- Business Continuity: Regular data backups, disaster recovery procedures, and tested restoration processes.
- Incident Response: Documented Security Incident response plan including detection, containment, eradication, and notification procedures.
- Personnel Training: Regular privacy and security awareness training for all personnel with access to Customer Personal Data.
- Vendor Management: Due diligence and contractual requirements for all Sub-processors handling Customer Personal Data.
Annex 2 — Approved Sub-processors
The following Sub-processors are authorised by Customer under this DPA. Cogniquest will notify Customer of any changes to this list in accordance with Section 5(d) of this DPA.
| Sub-processor | Location | Processing Activity |
|---|---|---|
| Amazon Web Services (AWS) | India / Global (as configured) | Cloud infrastructure, compute, and storage |
| Microsoft Azure / OpenAI | Global | AI and language model processing (where applicable) |
| Google Cloud Platform | Global | Cloud services and AI/ML infrastructure (where applicable) |
| Cloudflare | Global | Content delivery, DDoS protection, and network security |
| Resend / SendGrid | Global | Transactional email delivery (account and notification emails) |
The current list of Sub-processors may be updated from time to time in accordance with this DPA. Customers may request the most up-to-date list by contacting thejaswi.s@cogniquest.ai.