PREAMBLE
This Data Processing Agreement ("DPA") is entered into between CENOBE SA, Karneadou 25-29, Athens, Greece, VAT EL801188366 ("CENOBE" or the "Processor") and the entity that has accepted the Terms and Conditions for the Use of Morpheus ("the Client" or the "Controller"), as identified in the Client's account registration.
This DPA forms an integral part of the Terms and Conditions for the Use of Morpheus ("Main Agreement") and is incorporated therein by reference. In the event of any conflict between the terms of this DPA and the Main Agreement, the terms of this DPA shall prevail with respect to the processing of personal data.
Acceptance and execution of this DPA takes place in two steps:
Step 1 — Online acceptance: By completing the registration process and checking the dedicated acceptance box — which expressly refers to this DPA — the Client confirms that it has read and understood the terms of this DPA and agrees to be bound by them as of the date of registration ("Effective Date"). This step enables immediate access to the Platform.
Step 2 — Electronic signature: Upon activation of access to the Platform, CENOBE will send the Client an email containing this DPA for electronic signature. The Client undertakes to return the signed DPA within five (5) Business Days of receipt. Both parties acknowledge that the DPA executed by electronic signature constitutes a binding written agreement within the meaning of Article 28(9) GDPR. Until the electronically signed DPA is returned, the Client's online acceptance under Step 1 shall constitute the binding agreement between the parties for the purposes of Article 28 GDPR.
CENOBE shall maintain a record of each Client's acceptance, including the date, method and version of the DPA accepted, for the duration of the Main Agreement and for a minimum period of five (5) years following termination.
Any material amendments to this DPA shall be communicated to the Client by email with at least thirty (30) days' notice. Continued use of the Platform following the expiry of the notice period shall constitute acceptance of the amended DPA. Where an amendment materially affects the Client's rights or obligations, a new electronic signature shall be requested.
Having regard to the following:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data ("GDPR") and any applicable national data protection legislation.
- The Terms and Conditions for the Use of Morpheus between the parties (the "Main Agreement"), pursuant to which CENOBE provides the Client with a cybersecurity platform incorporating breach and attack simulation, attack surface management, security analytics and continuous automated red teaming services.
- That in the course of providing the services under the Main Agreement, CENOBE may process personal data on behalf of the Client, acting as a processor within the meaning of Article 28 GDPR.
- That this DPA constitutes an integral schedule to the Main Agreement and governs all processing of the Client's personal data by CENOBE.
The parties agree as follows:
ARTICLE 1 — DEFINITIONS
"GDPR"
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, as amended or replaced from time to time.
"Data Protection Law"
Any applicable law or regulation relating to the processing and protection of personal data, including the GDPR and any applicable national implementing legislation.
"Data"
The personal data processed by CENOBE on behalf of the Controller in the course of providing the Morpheus services, as further specified in Schedule 1.
"Processing"
Any operation or set of operations performed on personal data, whether or not by automated means, within the meaning of Article 4(2) GDPR.
"Data Subjects"
The natural persons whose personal data are subject to processing under this DPA.
"Controller"
The Client, who determines the purposes and means of the processing of the Data, within the meaning of Article 4(7) GDPR.
"Processor"
CENOBE, which processes Data on behalf of the Controller and on its instructions, solely for the purposes set out in this DPA, within the meaning of Article 4(8) GDPR.
"Personal Data Breach"
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data, within the meaning of Article 4(12) GDPR.
"Supervisory Authority"
The Hellenic Data Protection Authority (HDPA) or any other competent supervisory authority within the meaning of Article 4(21) GDPR.
"Main Agreement"
The Terms and Conditions for the Use of Morpheus between the parties, pursuant to which the Platform is provided.
"Sub-processor"
Any third-party processor engaged by CENOBE to carry out processing activities in respect of the Data pursuant to Article 9 of this DPA.
"Business Day"
Any day other than a Saturday, Sunday or public holiday in Greece.
Capitalized terms used but not defined herein shall have the meaning ascribed to them in Article 4 GDPR.
ARTICLE 2 — SUBJECT MATTER AND PURPOSE OF PROCESSING
2.1. CENOBE processes Data solely for the purpose of providing the Morpheus services, namely: breach and attack simulation, attack surface management, security analytics and continuous automated red teaming, in accordance with the instructions of the Controller.
2.2. CENOBE does not process Data for its own purposes beyond those set out in this DPA. Should CENOBE consider that an instruction from the Controller infringes applicable Data Protection Law, it shall immediately notify the Controller in writing.
2.3. A detailed description of the processing activities is set out in Schedule 1.
ARTICLE 3 — GENERAL OBLIGATIONS OF THE PROCESSOR
3.1. CENOBE processes Data solely on documented instructions from the Controller, including as set out in this DPA and the Main Agreement, unless required to do so by Union or Member State law.
3.2. CENOBE ensures that persons authorized to process the Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.3. CENOBE implements all measures required pursuant to Article 32 GDPR (see Article 5 hereof).
3.4. CENOBE complies with the obligations set out in Articles 4 through 12 of this DPA.
3.5. CENOBE makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR.
ARTICLE 4 — CONFIDENTIALITY
4.1. CENOBE ensures that any person acting under its authority has access to the Data processes such Data solely on instructions from the Controller, unless required to do so by Union or Member State law.
4.2. The Data shall not be disclosed to third parties without the prior written consent of the Controller, unless required by law.
ARTICLE 5 — SECURITY OF PROCESSING
5.1. Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, CENOBE shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR.
5.2. Such measures are detailed in Schedule 2.
5.3. CENOBE shall maintain or provide evidence of compliance with such measures upon the Controller's request. In this regard, CENOBE's ISO 27001 certification constitutes acceptable evidence of the implementation of appropriate technical and organizational measures.
ARTICLE 6 — DATA SUBJECT RIGHTS
6.1. CENOBE shall assist the Controller, by appropriate technical and organizational measures insofar as possible, in fulfilling the Controller's obligation to respond to requests for exercising Data Subjects' rights under the GDPR (access, rectification, erasure, portability, objection, restriction of processing).
6.2. CENOBE shall notify the Controller immediately and in any event within two (2) Business Days upon receipt of a request from a Data Subject.
6.3. CENOBE shall not respond directly to Data Subject requests without prior instruction from the Controller, unless required by law.
ARTICLE 7 — ASSISTANCE WITH CONTROLLER'S OBLIGATIONS
7.1. Taking into account the nature of the processing and the information available to it, CENOBE shall assist the Controller in ensuring compliance with obligations pursuant to Articles 32 to 36 GDPR (security, notification of personal data breach, data protection impact assessment, prior consultation).
ARTICLE 8 — PERSONAL DATA BREACH NOTIFICATION
8.1. CENOBE shall maintain appropriate policies and procedures for the prevention and detection of Personal Data Breaches.
8.2. CENOBE shall notify the Controller of any Personal Data Breach without undue delay and in any event within 24 hours of becoming aware of it, providing at minimum:
- A description of the nature of the breach and the date on which CENOBE became aware of it.
- The categories and approximate number of Data Subjects and personal data records concerned.
- The likely consequences of the breach.
- The measures taken or proposed to address the breach.
- The contact details of the responsible point of contact.
8.3. CENOBE shall provide all information requested by the Controller and shall cooperate in any notification to the Supervisory Authority or to the affected Data Subjects.
8.4. CENOBE shall not make any public disclosure in connection with a Personal Data Breach without the prior written consent of the Controller.
8.5. The obligations set out in this Article apply to the extent that the Personal Data Breach has been demonstrably caused by CENOBE's own acts, omissions or failure to comply with its obligations under this DPA. CENOBE shall bear no costs or liability in respect of incidents attributable to the Controller, to third parties, or to circumstances beyond CENOBE's reasonable control.
ARTICLE 9 — SUB-PROCESSORS
9.1. The Controller hereby grants CENOBE general authorization to engage Sub-processors for the processing of Data, subject to the conditions set out in this Article.
9.2. CENOBE shall inform the Controller of any intended changes to the list of Sub-processors, providing at least fourteen (14) calendar days' notice to allow the Controller to raise reasonable objections. If the Controller does not raise an objection within that period, the change shall be deemed approved.
9.3. CENOBE shall enter into a written agreement with each Sub-processor imposing data protection obligations equivalent to those set out in this DPA.
9.4. CENOBE shall remain fully liable to the Controller for the performance of a Sub-processor's obligations to the same extent as if CENOBE were performing the services directly.
9.5. Approved Sub-processors as of the date of signature are listed in Schedule 3.
ARTICLE 10 — INTERNATIONAL TRANSFERS
10.1. CENOBE shall not transfer Data outside the EU/EEA without the prior written consent of the Controller.
10.2. Where CENOBE intends to transfer Data outside the EU/EEA, it shall notify the Controller in writing and shall ensure that appropriate safeguards are in place in accordance with Articles 44 to 49 GDPR.
ARTICLE 11 — AUDITS AND INFORMATION
11.1. CENOBE shall make available to the Controller all information necessary to demonstrate compliance with its obligations under this DPA, upon written request with at least ten (10) Business Days' notice.
11.2. The Controller, or an auditor authorized by the Controller, shall be entitled to conduct compliance audits — upon written notice of at least ten (10) Business Days — no more than once per calendar year. Audits shall be conducted in a manner that does not unreasonably disrupt CENOBE's operations.
11.3. CENOBE shall promptly remediate, at its own cost, any security issue identified during an audit that is attributable to a breach of this DPA.
ARTICLE 12 — LIABILITY FOR BREACH OF DPA
12.1. In the event that CENOBE breaches its obligations under this DPA, and in particular where such breach causes a Supervisory Authority to levy a fine on the Controller or its Affiliate, or gives rise to obligations to pay damages to a Data Subject, CENOBE shall indemnify the Controller for such fines, material or immaterial damages and other expenses, only to the extent that the breach has been demonstrably caused by CENOBE's own acts, omissions or failure to comply with its obligations under this DPA. In any event, CENOBE's aggregate liability under this Article shall not exceed 1.500 euros.
12.2. This shall include damages related to unauthorized transfers of personal data, including disclosure of a Data Subject's personal data in response to an order from a state body or law enforcement authority outside the EU/EEA, in a manner that violated applicable Data Protection Law. The liability cap set out in Article 12.1 shall apply to any claims arising under this Article 12.2.
ARTICLE 13 — RETURN AND DELETION OF DATA
13.1. At the Controller's choice, CENOBE shall return or securely delete all Data upon termination of the processing services and shall delete all existing copies, unless Union or Member State law requires storage of the personal data.
13.2. Retention and deletion specifics are set out in Schedule 1.
ARTICLE 14 — TERM
This DPA shall enter into force on the date of signature and shall remain in effect for the duration of the Main Agreement, without prejudice to obligations that survive by their nature (confidentiality, security, deletion) for a minimum period of five (5) years following termination.
ARTICLE 15 — GENERAL PROVISIONS
15.1. This DPA constitutes an integral schedule to the Main Agreement. In the event of any conflict between the terms of this DPA and the Main Agreement, the terms of this DPA shall prevail.
15.2. Any amendments to this DPA shall be made in writing.
15.3. This DPA shall be governed by Greek law. The competent courts shall be those of Athens, Greece.
In witness whereof, the parties have executed this DPA in two (2) originals.
SCHEDULE 1
DESCRIPTION OF PROCESSING ACTIVITIES
1. Nature and Purposes of Processing
The Morpheus Platform provides cybersecurity services through automated and continuous testing of the Client's systems, networks and assets. The agent performs automated scanning and simulated attack operations strictly within the scope defined by the Rules of Engagement agreed under the Main Agreement.
Personal data is not intentionally collected or targeted as part of the services. Any processing of personal data that occurs is incidental and arises solely as a consequence of the services being performed on live systems that may contain personal data.
2. Categories of Personal Data
The categories of personal data that may be incidentally accessed during the provision of the services cannot be predetermined, as they depend entirely on the data landscape of the Client's systems and environment at the time of testing.
The Client, as Controller, is responsible for being aware of the categories of personal data present in the systems to be tested, including whether special categories of data within the meaning of Article 9 GDPR are present. CENOBE shall apply the Responsible Disclosure Procedure set out in Section 6 of this Schedule regardless of the category of personal data encountered.
3. Categories of Data Subjects
The categories of Data Subjects cannot be predetermined and depend on the data landscape of the Client's systems. They may include, without limitation, the Client's employees, contractors, customers, patients or other individuals whose personal data resides in the systems subject to testing.
4. Legal Basis
The legal basis for the processing of personal data incidentally accessed during the provision of the services is Article 6(1)(b) GDPR - processing necessary for the performance of the contract between the parties, namely the Main Agreement pursuant to which CENOBE provides the Morpheus services.
By accepting this DPA, the Client acknowledges and confirms that it has assessed the data landscape of the systems to be tested and that it is aware of the categories of personal data - including any special categories within the meaning of Article 9 GDPR - that may reside therein. The Client's acceptance of this DPA constitutes its explicit instruction to CENOBE to proceed with the services notwithstanding the possible incidental access to such data, and constitutes the Client's express consent within the meaning of Article 9(2)(a) GDPR to the extent that special categories of personal data may be incidentally accessed in the course of the services.
The Client undertakes to notify CENOBE in writing prior to commencement of testing if the systems to be tested contain special categories of personal data within the meaning of Article 9 GDPR, so that enhanced safeguards may be agreed between the parties. Failure to notify shall not affect the validity of the Client's consent under this clause but shall be taken into account in the assessment of liability in the event of a Personal Data Breach attributable in whole or in part to the nature of the data present in the Client's systems.
5. Responsible Disclosure Procedure
Where personal data is incidentally accessed in the course of testing operations, CENOBE applies the following procedure regardless of the category of data encountered:
- Access limitation: Access is restricted to what is strictly necessary to evidence the existence of the vulnerability. CENOBE does not extract, copy or store personal data beyond this minimum.
- Encrypted handling: Any data temporarily retained in the course of testing is handled in encrypted form with access restricted to authorized personnel only.
- Anonymization and pseudonymization: Where technically feasible, personal data encountered during testing is anonymized or pseudonymized before being referenced in reports or other documentation.
- Report content: Findings reports reference personal data only to the extent strictly necessary to demonstrate the vulnerability. Personal data fields are redacted where possible without compromising the intelligibility of the finding.
- Immediate notification: Where personal data is encountered during testing, the Controller is notified without undue delay, irrespective of whether the encounter constitutes a Personal Data Breach.
- Deletion: All personal data incidentally accessed or retained in the course of testing is securely deleted within ten (10) days of delivery of the final report to the Controller, with a Destruction Certificate provided to the Controller upon completion.
Where the Client has notified CENOBE of the presence of special categories of data prior to testing, enhanced measures as agreed between the parties shall apply, which may include immediate deletion upon encounter without retention for evidentiary purposes.
6. Retention Periods
Retention is governed by the nature of the contact with personal data:
| Type | Retention Period | Method |
|---|---|---|
| Personal data incidentally accessed during testing | Deleted within 10 days of delivery of final report | Secure deletion - Destruction Certificate issued to Controller |
| Logs of testing operations (if containing personal data) | Deleted within 10 days of delivery of final report | Secure deletion - Destruction Certificate issued to Controller |
| Findings reports - Controller's copy | At Controller's discretion | N/A - governed by Controller's own retention policy |
| Findings reports - CENOBE's copy | Retained in fully anonymized form only | Non-anonymized elements deleted within 10 days of report delivery |
Where enhanced measures have been agreed for special categories of data, shorter retention periods or immediate deletion upon encounter shall apply as agreed prior to commencement of testing.
7. Processing Location
The Data is processed within the EU/EEA.
Any transfer of Data outside the EU/EEA requires the prior written consent of the Controller and shall be subject to appropriate safeguards in accordance with Articles 44 to 49 GDPR.
SCHEDULE 2
TECHNICAL AND ORGANISATIONAL SECURITY MEASURES
Implemented pursuant to Article 32 GDPR and in accordance with ISO/IEC 27001
1. Governance and Certification
| Measure | Details |
|---|---|
| ISMS Certification | CENOBE holds ISO/IEC 27001 certification |
| Data Protection Officer | — contact: dpo@cenobe.com |
| Information Security Policy | Maintained, approved by management and reviewed at least annually |
| Risk Assessment | Formal risk assessment conducted at least annually and upon any material change to processing activities or infrastructure |
| Supplier Management | Third-party suppliers and sub-processors assessed for security compliance prior to engagement and periodically thereafter |
2. Resource and Asset Management
| Measure | Details |
|---|---|
| IT Asset Register | CENOBE maintains a register of IT resources used for the processing of personal data. The register is reviewed and updated on a regular basis. |
| Roles and Access | Roles having access to specific resources are defined and documented. |
| Software Agent Inventory | The software agent deployed within the Client's environment is registered as an IT asset. Its version, deployment location and authorized access scope are documented and kept up to date. |
3. Access Control and Authentication
| Measure | Details |
|---|---|
| Access Control Policy | Specific access rights allocated to each role based on the need-to-know principle. Segregation of access control roles clearly defined and documented. |
| Role-Based Access Control | Access rights assigned based on job role and reviewed regularly and upon role change or termination |
| Multi-Factor Authentication | Required for all access to systems processing personal data |
| Privileged Access Management | Privileged accounts subject to enhanced controls and logging |
| Password Policy | Passwords comply with CENOBE's password policy, which enforces minimum complexity, length and rotation requirements. Passwords stored in hashed form. |
| Remote Access | All remote access performed via secure encrypted channels, limited to authorized personnel and authorized devices |
4. Change Management
| Measure | Details |
|---|---|
| Change Register | All changes to IT systems used for the processing of personal data are registered and monitored by a designated responsible person. |
| Environment Separation | Software development is performed in an environment separate from the production environment used for the processing of personal data. |
| Agent Updates | Updates to the software agent deployed within the Client's environment are subject to the change management procedure. The Client is notified in advance of significant changes. |
5. Encryption and Pseudonymization
| Measure | Details |
|---|---|
| Data at Rest | CENOBE applies industry-standard encryption for all storage systems containing personal data |
| Data in Transit | All data transmission, including communication between the software agent and the Platform, is encrypted using industry-standard cryptographic protocols. No data is transmitted in plaintext. |
| Pseudonymization | Pseudonymization techniques applied where feasible to avoid direct linking to data subjects without additional information. Applied in particular to personal data incidentally accessed during testing operations. |
| Key Management | Encryption keys managed and rotated regularly in accordance with CENOBE's key management policy |
| Endpoint Encryption | Encryption applied to devices used to process personal data |
| Report Encryption | Findings reports delivered to the Client in encrypted format |
6. Logging and Monitoring
| Measure | Details |
|---|---|
| Log Activation | Log files activated for each system and application used for the processing of personal data, covering all access types. Logs are timestamped. |
| Log Integrity | Log files protected against tampering and unauthorized access. System clocks are synchronized to a single reference time source. |
| Administrator Logging | Actions of system administrators and operators, including changes to user rights, are logged. |
| Log Retention | Logs retained for a period sufficient to support security monitoring, incident investigation and compliance obligations |
| Security Monitoring | Systems processing personal data are subject to continuous monitoring for anomalous or suspicious activity, with alerting mechanisms in place. |
| Agent Activity Logging | All activities performed by the software agent within the Client's environment are logged and made available to the Client via the Platform. |
7. Server, Database and Endpoint Security
| Measure | Details |
|---|---|
| Server Configuration | Database and application servers configured with minimum necessary privileges. Personal data processing limited to what is required for the services. |
| Endpoint Security | Anti-malware protection maintained and updated. Security configurations enforced. Critical security updates applied regularly. Session time-outs enforced upon inactivity. |
| Workstation Controls | Users cannot deactivate or bypass security settings or install unauthorized software. |
| Mobile and Portable Devices | Mobile and portable devices allowed to access systems processing personal data are pre-registered, pre-authorized and subject to equivalent access control procedures. |
8. Network and Communication Security
| Measure | Details |
|---|---|
| Encrypted Communication | All internet-based access to systems processing personal data is encrypted via industry-standard cryptographic protocols. |
| Firewalls | Network traffic to and from systems processing personal data is monitored and controlled through firewalls. |
| Intrusion Detection | Intrusion Detection Systems deployed to detect and respond to anomalous or malicious network activity. |
| Network Segmentation | The network of the information system processing personal data is segregated from other networks. Access limited to pre-authorized devices and terminals. |
| Agent Communication | Communication between the software agent and the Morpheus Platform is encrypted and authenticated. The agent does not open inbound network ports within the Client's environment. |
9. Physical Security
| Measure | Details |
|---|---|
| Data Centre | Data processed in certified data centres with appropriate physical access controls |
| Physical Access | Access to infrastructure restricted to authorized personnel |
| Paper Documentation | Personal data in physical form secured against unauthorized access. Clean desk policy enforced. |
| Visitor Management | Visitors logged and escorted within secure areas |
10. Vulnerability and Patch Management
| Measure | Details |
|---|---|
| Vulnerability Scanning | Regular vulnerability scans of CENOBE's own infrastructure |
| Penetration Testing | Periodic penetration testing of CENOBE's own infrastructure by an independent third party |
| Patch Management | Patches applied within timeframes proportionate to severity, in accordance with CENOBE's patch management policy |
| Agent Updates | Agent updates subject to change management procedure. Client notified in advance of significant changes. |
11. Incident Response and Business Continuity
| Measure | Details |
|---|---|
| Incident Response Plan | Formal incident response plan maintained with detailed procedures, tested periodically and reviewed after significant incidents. |
| Breach Escalation | Personal Data Breaches escalated immediately to responsible personnel. Incidents recorded with details and subsequent actions. |
| Notification | Controller notified within 24 hours of a confirmed or suspected Personal Data Breach, in accordance with Article 8 of this DPA. |
| Business Continuity | Procedures in place to ensure required level of continuity and availability of systems processing personal data following an incident. |
| Recovery Objectives | Recovery time and recovery point objectives defined in CENOBE's business continuity plan |
12. Backup and Data Restore
| Measure | Details |
|---|---|
| Backup Policy | Backup and data restore procedures defined, documented and assigned to responsible roles. |
| Backup Frequency | Backups performed regularly at frequencies appropriate to the criticality of the data |
| Backup Encryption | Backups encrypted. Where third-party backup storage is used, data encrypted prior to transmission. |
| Backup Location | Stored with appropriate physical and environmental protection, in a location separate from primary infrastructure, within the EU/EEA. |
| Recovery Testing | Backup media regularly tested to ensure reliability for recovery purposes. |
13. Secure Deletion and Disposal
| Measure | Details |
|---|---|
| Deletion Standard | Secure deletion in accordance with industry-standard methods |
| Destruction Certificate | Issued to Controller within 5 Business Days of deletion of personal data |
| Hardware Disposal | Storage media securely wiped or physically destroyed prior to disposal or repurposing |
| Agent Uninstallation | Upon termination, software agent fully uninstalled and any locally cached data deleted — confirmed in writing to Controller |
14. Human Resources
| Measure | Details |
|---|---|
| Pre-Employment | Background checks conducted for personnel with access to personal data, in accordance with applicable law. Roles and responsibilities communicated during induction. |
| Confidentiality | All personnel sign confidentiality and non-disclosure agreements prior to access to personal data and agree to CENOBE's security policy. |
| Training | Regular security awareness and data protection training for all personnel involved in the processing of personal data. |
| Disciplinary Policy | Breaches of data protection and security policies subject to formal disciplinary proceedings |
15. Software Agent — Specific Controls
The following additional controls apply specifically to the software agent installed within the Client's environment:
| Measure | Details |
|---|---|
| Minimal Footprint | The agent does not store personal data locally beyond what is strictly necessary for the current operation |
| Encrypted Communication | All agent-Platform communication is encrypted. No data transmitted in plaintext. The agent does not open inbound network ports. |
| Authentication | Agent authenticated to the Platform via secure authentication mechanism |
| Scope Limitation | The agent operates strictly within the scope defined by the Client's Rules of Engagement |
| Tamper Protection | The agent includes mechanisms to detect and alert on unauthorized modification |
| Uninstallation | The agent can be fully uninstalled by the Client at any time — procedure documented in the Platform support manual |
16. Reviews and Updates
The measures set out in this Schedule are reviewed at least annually and upon any material change to CENOBE's processing activities or infrastructure. The Controller will be notified of any material changes that affect the level of protection afforded to the Data.
SCHEDULE 3
APPROVED SUB-PROCESSORS
Approved Sub-processors as of the date of publication:
| Sub-processor | Activity / Country / Safeguards |
|---|---|
| None | N/A |
CENOBE shall notify the Controller of any intended changes in accordance with Article 9.2 of this DPA.
Last updated: 5 August 2026