AqNova Marketplace Policies & Disclosures
Global Legal Footer Framework
Comprehensive Compliance & Platform Governance Reference
GDPR Article 28 | UK GDPR | CCPA/CPRA Service Provider | LGPD | PDPA | POPIA | NDPR | Global Data Processing Requirements — Standard Form for Vendors & Business Partners
Effective Date: April 7, 2026 | Version 1.0 | Arivon Holding Corporation
| Regulatory Frameworks — Data Processing Agreement EU GDPR: Regulation (EU) 2016/679 — Article 28 (processor obligations); Article 28(3) (required contract terms); Article 28(4) (sub-processors); Article 28(9) (contract in writing); Article 29 (processing under authority); Article 32 (security of processing); Article 33 (breach notification — 72h); Article 35 (DPIA); Article 36 (prior consultation); Article 82 (liability); Chapter V (international transfers); 2021 SCCs (Commission Decision 2021/914/EU) UK GDPR: Data Protection Act 2018; UK GDPR Article 28; ICO IDTA (international transfers); ICO guidance on controllers and processors California: CCPA (Cal. Civ. Code § 1798.100 et seq.) — service provider agreement requirements; § 1798.140(ag) definition of service provider; CPRA (Prop. 24) — contractor agreement requirements; prohibition on selling/sharing/retaining data outside service scope Brazil: LGPD (Lei 13,709/2018) — Art. 37 (joint controller/operator agreements); Art. 46 (security measures by operators); Art. 48 (incident notification to ANPD and data subjects) South Africa: POPIA — s. 19 (security safeguards by operators); s. 20–21 (operator processing prohibition without authority); s. 22 (notification of security compromises) Nigeria: NDPR — Art. 2.10 (data processor contractual obligations); NDPR Art. 4 (security safeguards) India: DPDPA 2023 — Data Processor obligations (s. 8); contracts with Data Processors (s. 8(2)); sub-processor requirements Singapore: PDPA — binding instructions and obligations on data intermediaries Australia: Privacy Act 1988 / APPs — APP 8 (cross-border disclosure); contractual protections for overseas disclosure Canada: PIPEDA Schedule 1 Clause 4.1.3 — accountability for third-party processors; comparable protection required China: PIPL (2021) — Art. 21 (joint controllers); Art. 22 (data processors); Art. 59 (processor security obligations) Japan: APPI — Article 24 (oversight of delegated processors); Art. 25 (recordkeeping of sub-processors) South Korea: PIPA — Art. 26 (processing trustee contractual requirements) Security: ISO/IEC 27001:2022 | ISO/IEC 27002:2022 | SOC 2 Type II NIST SP 800-53 | PCI DSS v4.0 (where applicable) |
|---|
| DPA Availability & How to Request AqNova's Standard DPA AqNova's Data Processing Agreement (DPA) is available to: — Vendors who process personal data of AqNova's Buyers or other users in connection with orders fulfilled through the Platform — Business partners, logistics providers, payment processors, and technology suppliers who process personal data on behalf of or in connection with AqNova's operations — Any party that processes personal data to which AqNova is controller or joint controller HOW TO REQUEST THE STANDARD DPA: Email: legal@aqnova.com [Subject: DPA Request — [Company Name]] Portal: [aqnova.co/partners/dpa] WHEN A DPA IS REQUIRED: A DPA is required under GDPR Article 28(3) whenever a controller uses a processor that processes personal data on the controller's behalf. AqNova requires a DPA with all service providers and business partners who process personal data of AqNova's users. NOTE ON THIS DOCUMENT: This Section 7.7 describes the framework, structure, and legal basis for AqNova's DPA. The operative DPA — the binding legal agreement to be signed — is provided as a separate document upon request. This Section constitutes the platform-level governance documentation for AqNova's DPA program. |
|---|
AqNova's Data Processing Agreement establishes the legal framework for any situation in which a third party processes personal data on behalf of Arivon Holding Corporation (as controller), or in which Arivon Holding Corporation processes personal data on behalf of a business customer (as processor). It reflects the requirements of GDPR Article 28, UK GDPR Article 28, CCPA/CPRA service provider agreement obligations, LGPD operator agreement requirements, and equivalent data processing contract requirements across all operating jurisdictions.
| Section 7.7 — Structure 7.7.1 Legal Basis — Why a DPA Is Required 7.7.2 Scope — Who Needs a DPA with AqNova 7.7.3 Core DPA Terms — GDPR Article 28(3) Requirements 7.7.4 Sub-Processing Obligations 7.7.5 Security of Processing — Technical & Organisational Measures 7.7.6 Personal Data Breach Notification 7.7.7 Data Subject Rights Assistance 7.7.8 Audit & Inspection Rights 7.7.9 Data Return, Deletion & Retention 7.7.10 International Data Transfers — SCCs & IDTA 7.7.11 CCPA/CPRA Service Provider Obligations 7.7.12 Global Jurisdiction-Specific DPA Provisions 7.7.13 Liability & Indemnification 7.7.14 DPA Term & Termination 7.7.15 Annex A — Details of Processing 7.7.16 Annex B — Technical & Organisational Security Measures 7.7.17 Contact Information — Data Processing Agreement |
|---|
GDPR Article 28(3) requires that processing by a processor shall be governed by a contract or other legal act in writing. The contract must set out the subject-matter, duration, nature and purpose of the processing, the type of personal data and categories of data subjects, and the obligations and rights of the controller. The seven mandatory obligations of the contract are set out in GDPR Article 28(3)(a)–(h).
GDPR Article 28(9) confirms that the contract referred to in Article 28(3) must be in writing, including in electronic form. AqNova's DPA is provided in electronic form via AqNova's legal portal and may be executed electronically.
Processing personal data without a GDPR Article 28-compliant DPA is itself a GDPR violation. Under GDPR Article 83(4), violations of Article 28 obligations are subject to administrative fines of up to EUR 10,000,000 or 2% of total worldwide annual turnover of the preceding financial year, whichever is higher. Supervisory authorities have enforced Article 28 non-compliance across the EU.
AqNova's data processing role depends on the specific activity:
AqNova as controller: in the vast majority of its activities, AqNova determines the purposes and means of processing personal data of its users (Buyers and Vendors). AqNova is the controller for processing Buyer and Vendor account data; transaction data; behavioral analytics; fraud detection; and Platform operations.
AqNova as processor: where AqNova processes personal data on behalf of a business customer (e.g., where a large retailer or brand uses AqNova's Platform to process orders for their own customers), AqNova may act as a processor for that business customer's personal data.
Joint controllership: in some contexts — for example, where AqNova and a Vendor jointly determine the purposes of processing for a co-marketing activity — AqNova and the Vendor may be joint controllers, requiring a joint controller arrangement under GDPR Article 26.
AqNova requires a DPA with all of the following categories of parties:
| Party Type | DPA Role & Requirement |
|---|---|
| Technology suppliers / SaaS vendors with access to AqNova user data | Processor (AqNova is controller). Applies to: email service providers; analytics platforms; CRM systems; customer support platforms; fraud detection providers; cloud infrastructure providers. DPA required before any personal data is shared or accessible. Standard AqNova Processor DPA applies. |
| Payment processors and payment technology providers | Processor (AqNova is controller) for payment data processed on AqNova's behalf; or independent controller for payment data processed for their own purposes (e.g., fraud detection, AML). Separate DPA scopes required per role. PCI DSS v4.0 and applicable AML regulatory requirements included in DPA. |
| Logistics partners (carriers, warehouse operators, last-mile delivery) | Processor (AqNova is controller) for shipment and address data shared with logistics providers to enable delivery. DPA required where personal data (name, address, contact) is shared. |
| Vendors on AqNova Marketplace who process order/Buyer data | Independent controllers (for their own records) or processors (for data processed on AqNova's behalf). Vendor Agreement contains processor obligations. Where Vendors act as independent controllers for their own CRM/marketing purposes, they are controllers and must comply with applicable data protection law directly. |
| AqNova acting as processor for enterprise business customers | AqNova is processor; business customer is controller. Enterprise customer DPA provided. GDPR Art. 28 obligations apply to AqNova as processor. |
| Marketing agencies and advertising technology partners | Processor or joint controller depending on data flows. DPA or joint controller arrangement as appropriate. CPRA contractor/service provider provisions apply for California data. |
| Professional services (legal, accounting, consulting) | Processor (for data shared for service delivery). DPA required where personal data of AqNova's users is shared. |
GDPR Article 28(3)(a)–(h) mandates that the DPA contract includes the following obligations on the processor. AqNova's standard DPA includes all eight required provisions:
28(3)(a) The processor shall process personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which the processor is subject; in such a case, the processor shall inform the controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
AqNova's DPA implementation: the processor undertakes to process personal data only pursuant to AqNova's documented instructions as set out in the DPA and any supplementary instruction schedules. Where applicable law requires processing contrary to AqNova's instructions, the processor must notify AqNova before processing (unless prohibited by law). The processor confirms it has no reason to believe that applicable law prevents it from fulfilling this instruction obligation.
28(3)(b) The processor shall ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
AqNova's DPA implementation: the processor undertakes that all personnel authorized to process AqNova's personal data are subject to appropriate confidentiality obligations (contractual or statutory) and have received data protection training relevant to their processing activities. Access to personal data is limited to personnel who need it for the purposes of providing the contracted services.
28(3)(c) The processor shall take all measures required pursuant to Article 32 (security of processing).
AqNova's DPA implementation: the processor implements and maintains appropriate technical and organizational security measures as specified in Annex B to the DPA (Section 7.7.16). Article 32 requires that security measures take into account: (a) the state of the art; (b) the costs of implementation; (c) the nature, scope, context, and purposes of processing; and (d) the risk of varying likelihood and severity of harm to individuals. AqNova's minimum required security measures are specified in Annex B.
28(3)(d) The processor shall respect the conditions referred to in paragraphs 2 and 4 for engaging another processor.
AqNova's DPA implementation: see Section 7.7.4 below.
28(3)(e) The processor shall, taking into account the nature of the processing, assist the controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III of the GDPR.
AqNova's DPA implementation: the processor undertakes to assist AqNova in fulfilling its obligations to data subjects under GDPR Chapter III, including: rights of access; rectification; erasure; restriction of processing; data portability; and objection. The processor notifies AqNova of any data subject request received directly and does not respond independently unless specifically authorized by AqNova. See Section 7.7.7.
28(3)(f) The processor shall assist the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36, taking into account the nature of processing and the information available to the processor.
AqNova's DPA implementation: the processor undertakes to provide AqNova with all information reasonably necessary to assess the processor's security of processing and to assist AqNova in: conducting DPIAs (GDPR Article 35); prior consultation with supervisory authorities where a high residual risk is identified (GDPR Article 36); personal data breach response (GDPR Articles 33–34). See Sections 7.7.6 and 7.7.8.
28(3)(g) The processor shall, at the choice of the controller, delete or return all the personal data to the controller after the end of the provision of services relating to processing, and delete existing copies unless Union or Member State law requires storage of the personal data.
AqNova's DPA implementation: see Section 7.7.9.
28(3)(h) The processor shall make available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.
AqNova's DPA implementation: see Section 7.7.8.
GDPR Article 28(2) requires that the processor not engage another processor without prior specific or general written authorization of the controller. AqNova's DPA provides for both specific and general authorization models:
The processor must impose the same data protection obligations as set out in the DPA on any sub-processor it engages, by way of a written contract (GDPR Article 28(4)).
The processor remains fully liable to AqNova for the performance of the sub-processor's obligations under GDPR Article 28(4) — the engagement of a sub-processor does not relieve the processor of its responsibilities.
The processor must ensure that sub-processors implement appropriate technical and organizational security measures (GDPR Article 32) at least equivalent to those required of the processor under Annex B of the DPA.
GDPR Article 32 requires that both the controller and processor implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. AqNova's minimum required security measures (specified in Annex B — Section 7.7.16) include:
Pseudonymisation and encryption: personal data must be pseudonymised and/or encrypted at rest and in transit where technically feasible and appropriate to the risk. Encryption minimum standard: AES-256 at rest; TLS 1.2+ in transit.
Confidentiality, integrity, availability, and resilience: ongoing ability to ensure confidentiality, integrity, availability, and resilience of processing systems and services.
Backup and recovery: ability to restore availability and access to personal data in a timely manner in the event of a physical or technical incident.
Testing and evaluation: process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures.
Access control: logical access controls restricting access to personal data to authorized personnel only; role-based access controls; principle of least privilege; multi-factor authentication for systems containing AqNova personal data.
Incident response: documented incident response plan covering detection, escalation, investigation, containment, and notification procedures.
Staff training: regular data protection training for all personnel with access to AqNova personal data.
Physical security: physical security measures for facilities where AqNova personal data is processed, appropriate to the risk.
Where processors hold security certifications, these provide additional evidence of their security posture. AqNova gives preference to processors holding:
ISO/IEC 27001:2022 Information Security Management System certification.
SOC 2 Type II report covering the AqNova processing scope.
PCI DSS v4.0 Attestation of Compliance (for processors handling payment card data).
NIST Cybersecurity Framework alignment (particularly for US-based processors).
GDPR Article 33(2) requires processors to notify the controller without undue delay after becoming aware of a personal data breach. AqNova's DPA contains the following breach notification requirements:
| Personal Data Breach Notification Requirements NOTIFICATION TIMELINE: The processor must notify AqNova of any personal data breach involving AqNova's personal data within 24 HOURS of the processor becoming aware of the breach. Note: GDPR Art. 33(2) requires notification 'without undue delay'. AqNova's DPA sets a stricter 24-hour standard to enable AqNova to meet its own 72-hour supervisory authority notification obligation under GDPR Art. 33(1). NOTIFICATION CHANNEL: Email: legal@aqnova.com [Subject: DATA BREACH NOTIFICATION — URGENT] AND: privacy@aqnova.co [Subject: DATA BREACH NOTIFICATION — URGENT] MINIMUM CONTENT OF BREACH NOTIFICATION: (a) Nature of the breach (unauthorized access; accidental disclosure; ransomware; insider threat; etc.) (b) Categories and approximate number of data subjects affected (c) Categories and approximate number of personal data records affected (d) Name and contact details of the processor's data protection contact (e) Likely consequences of the breach (f) Measures taken or proposed to address the breach (g) Measures taken or proposed to mitigate the effects of the breach PHASED NOTIFICATION PERMITTED: Initial notification may be provided without all required information where not all information is yet available — provided it is made within 24 hours and further information is provided as it becomes available, without undue delay. PROCESSOR'S COOPERATION OBLIGATIONS: — Promptly investigate and contain the breach — Preserve evidence relating to the breach — Cooperate fully with AqNova's investigation and response — Take all necessary steps to mitigate further risk to data subjects — Provide ongoing updates as the investigation progresses — Not notify affected data subjects or supervisory authorities without AqNova's prior written consent (unless required to do so by law) |
|---|
The processor must assist AqNova in fulfilling its data subject rights obligations under GDPR Chapter III (Articles 15–22). The following procedures apply:
Forwarding data subject requests: the processor must forward to AqNova any data subject request received directly (including requests for access, rectification, erasure, restriction, portability, or objection) within 5 Business Days of receipt. The processor must not respond independently to data subject requests unless specifically authorized by AqNova in writing.
Technical assistance: the processor must provide AqNova with technical assistance — including tools, access, or exports — necessary to enable AqNova to respond to data subject requests within applicable legal deadlines (EU/UK GDPR: 1 month; CCPA/CPRA: 45 days; LGPD: 15 days; etc.).
Deletion/erasure assistance: the processor must be technically capable of deleting specific data subjects' personal data upon AqNova's instruction, without affecting other data. The processor must confirm completion of deletion within 10 Business Days of receiving the instruction.
Data portability: the processor must be technically capable of providing personal data in a structured, commonly used, machine-readable format (such as JSON or CSV) for data portability requests under GDPR Article 20.
GDPR Article 28(3)(h) requires the processor to allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller. AqNova's DPA includes the following audit rights:
Information provision: the processor must promptly provide AqNova with all information necessary to demonstrate compliance with the DPA and GDPR Article 28, upon request.
Audit right (announced): AqNova has the right to conduct, or commission a third-party auditor to conduct, an audit of the processor's data processing activities and security measures relevant to AqNova's personal data, upon 30 Business Days' written notice.
Audit right (unannounced): in the event of a reasonable, documented concern about a data breach or significant non-compliance, AqNova reserves the right to conduct an unannounced audit.
Third-party audit reports as substitute: processors may satisfy audit requests by providing AqNova with current, in-scope third-party audit reports (ISO/IEC 27001 certificate + audit summary; SOC 2 Type II report; penetration test summary from accredited provider) in lieu of a direct audit, provided the reports are sufficiently current (not older than 12 months) and cover the scope of AqNova's processing.
Cost of audit: AqNova bears the cost of its own audits unless the audit reveals a material breach of the DPA, in which case the processor bears the reasonable costs of the audit.
Confidentiality: AqNova treats all audit information as confidential and uses it solely for the purpose of assessing the processor's compliance with the DPA.
GDPR Article 28(3)(g) requires the processor, at the controller's choice, to delete or return all personal data upon termination of the services, and to delete existing copies unless law requires storage. AqNova's DPA provisions:
Upon termination of services: within 30 calendar days of expiration or termination of the DPA (or the underlying service agreement), the processor must either: (a) return all AqNova personal data to AqNova in a structured, machine-readable format; OR (b) certifiably delete all AqNova personal data from its systems and those of its sub-processors, as AqNova directs.
Deletion certification: upon deletion, the processor must provide AqNova with a written certificate of deletion, specifying the data categories deleted, deletion methodology, and date of deletion.
Legal retention exceptions: where applicable law requires the processor to retain AqNova personal data beyond the service termination period, the processor must: inform AqNova of the legal retention obligation; retain only the minimum data required; protect it with at least the same security measures as during the service period; and delete it as soon as the legal retention period expires.
Backup copies: the processor must ensure that AqNova personal data in backup copies is deleted in accordance with the agreed timeline, which may differ from primary system deletion due to backup rotation schedules. The processor must confirm the expected timeline for backup deletion.
Retention during DPA: during the service period, the processor must retain personal data only as long as necessary for the purposes of providing the contracted services, or as instructed by AqNova.
Where the processor processes AqNova's personal data outside the European Economic Area (EEA) or the United Kingdom, the DPA incorporates international transfer mechanisms to ensure that the transfer is lawful under GDPR Chapter V and UK GDPR respectively.
AqNova's standard DPA incorporates the EU Standard Contractual Clauses adopted by Commission Implementing Decision 2021/914/EU of June 4, 2021, as Annex C to the DPA. The applicable module(s) are completed based on the processing relationship:
Module 1 (Controller-to-Controller): where the processor is an independent controller receiving AqNova personal data.
Module 2 (Controller-to-Processor): where the processor processes AqNova personal data on AqNova's behalf.
Module 3 (Processor-to-Processor): where AqNova as processor sub-processes to another processor.
Module 4 (Processor-to-Controller): where AqNova as processor sends data back to the controller.
Transfer Impact Assessment: consistent with EDPB Recommendations 01/2020 and the CJEU Schrems II judgment (C-311/18), where SCCs are the transfer mechanism, AqNova and its processors must conduct a Transfer Impact Assessment (TIA) to assess whether the law and practice of the receiving country provides an equivalent level of protection to EU data protection standards. Where the TIA identifies a gap, supplementary measures must be implemented.
For transfers of UK personal data, AqNova's DPA incorporates the UK Information Commissioner's International Data Transfer Agreement (IDTA — issued March 2022). The IDTA is the UK equivalent of EU SCCs and is required for transfers of UK personal data to countries not covered by a UK adequacy regulation.
The Addendum to the EU SCCs (issued by the ICO) may also be used where a single document is needed to cover both EU and UK data transfers consistently.
Where AqNova is a business under the California Consumer Privacy Act (CCPA, Cal. Civ. Code § 1798.100 et seq.) and CPRA (Proposition 24, effective January 1, 2023), and a third party processes personal information on AqNova's behalf, the CCPA/CPRA requires that the parties enter into a written contract establishing a 'service provider' relationship. The absence of such a contract means the disclosure may constitute a 'sale' of personal information.
| CCPA/CPRA Service Provider Contract Requirements AqNova's DPA includes the following CCPA/CPRA-required provisions: 1. PURPOSE LIMITATION: The service provider may use AqNova's personal information only for the specific business purpose(s) set out in the DPA and for no other commercial purpose. 2. NO SALE OR SHARING: The service provider must not sell or share AqNova's personal information (within the meaning of Cal. Civ. Code § 1798.140(ad) and (ag)). 3. NO RETENTION BEYOND SERVICE SCOPE: The service provider must not retain, use, or disclose AqNova's personal information outside the direct business relationship with AqNova. 4. COMBINATION PROHIBITION: The service provider must not combine AqNova's personal information with personal information received from other sources, except as permitted by CCPA/CPRA. 5. CERTIFICATION: The service provider certifies that it understands and will comply with these CCPA/CPRA service provider restrictions. 6. SUB-SERVICE PROVIDERS: The service provider may engage sub-service providers only where the sub-service provider is bound by a written contract with the same restrictions. 7. CONSUMER RIGHTS ASSISTANCE: The service provider must assist AqNova in responding to consumer requests under CCPA/CPRA within the required statutory timeframes. CPRA CONTRACTOR REQUIREMENTS (§ 1798.140(j)): Where a third party receives AqNova's personal information for the purpose of processing for a business purpose, and the third party is a 'contractor' (not a service provider), a written contract must prohibit the contractor from selling, sharing, or using the personal information for purposes other than the contracted purpose. |
|---|
AqNova's DPA includes jurisdiction-specific addendums for each major market. These addendums supplement the GDPR-based core DPA with requirements specific to each jurisdiction:
| Jurisdiction / Addendum | Key Provisions Required |
|---|---|
| Brazil — LGPD Addendum | LGPD Art. 37 (agreements between controllers and operators): processor obligations as 'operator' (operador); Art. 46 security obligations; Art. 48 incident notification to ANPD within 72 hours and to data subjects within a reasonable period; Art. 7 legal bases for processing; ANPD as competent supervisory authority. |
| South Africa — POPIA Addendum | POPIA ss. 19–22: security safeguards (s. 19); processing only with controller's knowledge/authorization (s. 20); notification of security compromise to Information Regulator and data subjects (s. 22); operator processing prohibition without controller authority; Information Regulator as competent supervisory authority. |
| Nigeria — NDPR Addendum | NDPR Art. 2.10: data processor contractual obligations including confidentiality; security; sub-processor restrictions; NITDA notification of data breaches; applicable processing purposes per NDPR consent requirements. |
| India — DPDPA Addendum | DPDPA 2023 s. 8: Data Processor obligations; contracts with Data Processors (s. 8(2)); sub-processor requirements; security obligations consistent with DPDPA; alignment with Significant Data Fiduciary requirements where applicable. |
| Australia — Privacy Act Addendum | APP 8 cross-border disclosure obligations: equivalent protection required; Australian Privacy Principles compliance by processor; OAIC as competent authority; notifiable data breach scheme (NDB) — notification to OAIC and individuals within 30 days where eligible data breach occurs. |
| Canada — PIPEDA Addendum | PIPEDA Clause 4.1.3: accountability for third-party processing; comparable protection required; processor must provide comparable level of protection to PIPEDA requirements. Notification obligations under PIPEDA s. 10.1 for material security breaches. |
| Singapore — PDPA Addendum | PDPA contractual protection for personal data disclosed to data intermediaries; binding instructions for processing; security measures; notification of data breaches to PDPC and data subjects under the Mandatory Data Breach Notification Obligation (effective February 2021). |
| China — PIPL Addendum | PIPL Art. 21 (entrusted processing agreements); Art. 22 (contractual requirements for processors); Art. 59 (processor security obligations); data breach notification to Cyberspace Administration and data subjects; no transfer of AqNova's personal information outside China without compliance with PIPL Chapter III cross-border transfer requirements. |
| South Korea — PIPA Addendum | PIPA Art. 26 (processing trustee agreement requirements): statement of processing purposes; processing period; type of personal information; security measures; sub-processor restrictions; inspection rights. Notification to PIPC for data breaches. |
| Japan — APPI Addendum | APPI Art. 24 (oversight of delegated processors); Art. 25 (recordkeeping of sub-processors — number of sub-processors, data categories, supervision methods); appropriate supervision of delegated processors; PPC as competent authority. |
GDPR Article 82 establishes liability rules for controllers and processors. AqNova's DPA includes the following liability provisions consistent with Article 82 and applicable national law:
Controller liability: AqNova, as controller, is liable to data subjects for damage caused by processing that violates the GDPR, including processing by processors acting on AqNova's instructions.
Processor liability: the processor is liable to data subjects for damage caused by processing that violates the GDPR only where the processor has not complied with its GDPR obligations or has acted outside or contrary to AqNova's lawful instructions.
Right of recourse: where AqNova (as controller) has paid compensation to a data subject for damage caused by the processor's non-compliance, AqNova has the right of recourse against the processor for that part of the compensation corresponding to the processor's responsibility.
Indemnification: the processor indemnifies AqNova against claims, damages, fines, and costs (including regulatory fines under GDPR Article 83) arising from the processor's breach of the DPA or violation of applicable data protection law, to the extent the processor is responsible for such breach or violation.
Liability cap: the processor's aggregate liability to AqNova under the DPA is limited to the greater of: (a) the total fees paid by AqNova to the processor in the 12 months preceding the event giving rise to liability; or (b) USD 100,000 — unless the liability arises from gross negligence, fraud, or willful misconduct, in which case no cap applies.
Duration: the DPA is effective from the date of execution and remains in force for as long as the processor processes personal data on behalf of AqNova.
Automatic termination: the DPA terminates automatically upon expiration or termination of the underlying service agreement between AqNova and the processor.
Termination for material breach: AqNova may terminate the DPA immediately upon written notice if the processor materially breaches the DPA and fails to cure the breach within 10 Business Days of written notice specifying the breach.
Survival: Sections 7.7.6 (breach notification obligations for any ongoing breach), 7.7.9 (data return/deletion), 7.7.13 (liability and indemnification), and jurisdiction-specific provisions survive termination of the DPA.
Annex A to AqNova's DPA contains the mandatory details of processing required by GDPR Article 28(3). This Annex is completed specifically for each DPA counterparty and covers:
| Annex A — Processing Details Template CONTROLLER (AqNova): Name: Arivon Holding Corporation (AqNova Marketplace) Address: 2571 Saturn Avenue, Unit #265, Huntington Park, CA 90255, USA Contact: privacy@aqnova.co PROCESSOR: Name: [Processor Legal Name] Address: [Processor Registered Address] Contact: [Processor DPO / Privacy Contact] SUBJECT-MATTER AND DURATION OF PROCESSING: [Description of the services being provided and the processing activities involved; duration (aligned to service agreement)] NATURE AND PURPOSE OF PROCESSING: [e.g., Hosting of AqNova's user database; email delivery services; fraud detection and risk scoring; analytics and reporting] TYPE OF PERSONAL DATA: [e.g., Name; email address; postal address; IP address; purchase history; browsing behaviour; payment card data (where applicable); account credentials (hashed); device identifiers] CATEGORIES OF DATA SUBJECTS: [e.g., Buyers registered on AqNova Marketplace; Vendors registered on AqNova Marketplace; AqNova employees and contractors (where applicable)] TRANSFERS TO THIRD COUNTRIES: [Identify all third countries to which personal data will be transferred; identify applicable transfer mechanism: EU SCCs Module [X]; UK IDTA; adequacy decision; DPF; other] AUTHORIZED SUB-PROCESSORS: [List of authorized sub-processors with name; country; processing activity; transfer mechanism if applicable] RETENTION / DELETION SCHEDULE: [Data categories; retention period during service; deletion timeline upon termination] |
|---|
Annex B specifies the minimum technical and organisational security measures that the processor must implement and maintain in connection with the processing of AqNova's personal data. These measures must meet the requirements of GDPR Article 32 and applicable national equivalent provisions:
| Annex B — Minimum Required Technical & Organisational Measures 1. ENCRYPTION & PSEUDONYMISATION: — Data at rest: AES-256 encryption minimum for personal data — Data in transit: TLS 1.2 minimum; TLS 1.3 preferred — Pseudonymisation where technically feasible and appropriate to risk — Encryption key management: documented key management procedures 2. ACCESS CONTROL: — Role-based access controls (RBAC) for all systems containing AqNova personal data — Principle of least privilege: each user has the minimum access required — Multi-factor authentication (MFA): required for all accounts with access to AqNova personal data, especially remote access and admin accounts — Regular access reviews: quarterly review and revocation of unnecessary access — Immediate access revocation upon employee termination 3. PHYSICAL SECURITY: — Physical access controls to data processing facilities — CCTV or equivalent monitoring for server rooms / data centers — Clean desk policy for workstations with access to personal data 4. NETWORK SECURITY: — Firewall protection for all systems holding or processing AqNova personal data — Intrusion detection and/or prevention systems (IDS/IPS) — Regular vulnerability scanning and annual penetration testing — Patch management: critical security patches applied within 30 days of release 5. INCIDENT RESPONSE: — Documented incident response plan — 24-hour breach notification to AqNova (see Section 7.7.6) — Evidence preservation during incident investigation — Post-incident review and lessons learned process 6. BACKUP & RECOVERY: — Regular backups of systems holding AqNova personal data — Backup encryption consistent with primary data encryption standards — Recovery time objective (RTO) and recovery point objective (RPO) documented and tested annually 7. STAFF & AWARENESS: — Annual data protection and information security training for all personnel with access to AqNova personal data — Background checks for personnel with privileged access to AqNova data — Confidentiality obligations contractually binding on all personnel 8. THIRD-PARTY VENDOR MANAGEMENT: — Equivalent security requirements applied to all sub-processors — Annual security assessment of critical sub-processors — Due diligence on sub-processor security posture before engagement 9. AUDIT & LOGGING: — Comprehensive access and activity logging for systems holding AqNova data — Log retention: minimum 12 months — Logs reviewed for anomalous activity on a regular basis 10. CERTIFICATION & ATTESTATION: Processor should hold or pursue one or more of: — ISO/IEC 27001:2022 Information Security Management certification — SOC 2 Type II attestation (in scope for AqNova processing) — PCI DSS v4.0 Attestation of Compliance (where card data is processed) |
|---|
| AqNova — DPA Contacts REQUEST A DPA: Email: legal@aqnova.com [Subject: DPA Request — [Company Name]] Portal: [aqnova.co/partners/dpa] DATA BREACH NOTIFICATION (24-hour obligation): Email: legal@aqnova.com [Subject: DATA BREACH NOTIFICATION — URGENT] AND: privacy@aqnova.co [Subject: DATA BREACH NOTIFICATION — URGENT] DPA AMENDMENT / SUB-PROCESSOR NOTIFICATION: legal@aqnova.com [Subject: DPA — Sub-Processor Notice — [Processor Name]] DATA PROTECTION OFFICER (DPO): privacy@aqnova.co [Subject: DPO — DPA Query] INTERNATIONAL TRANSFER QUERIES (SCCs / IDTA / TIA): privacy@aqnova.co [Subject: International Transfer — DPA] AUDIT REQUESTS: legal@aqnova.com [Subject: DPA Audit Request — [Company Name]] LEGAL NOTICES: legal@aqnova.com DPA REQUEST PORTAL: [aqnova.co/partners/dpa] PRIVACY POLICY: [aqnova.co/legal/privacy] Registered Office: Arivon Holding Corporation C/O Arivon Holding Corporation, 2571 Saturn Avenue, Unit #265 Huntington Park, CA 90255, USA California File Number: B20250418195 | EIN: 41-3210066 | D-U-N-S: 142957477 GB EORI: GB511467217000 Nigeria (Sahara Eagle Ltd) — Reg: 1957145 | Tax ID: 31052811-0001 | NEPC: 0030281 |
|---|
AqNova Marketplace | Global Legal Footer Framework | Section 7.7: Data Processing Agreement (DPA)
© 2026 Arivon Holding Corporation. All rights reserved. Effective April 7, 2026. Version 1.0.
THIS DOCUMENT IS FOR PLATFORM GOVERNANCE & REGULATORY COMPLIANCE PURPOSES ONLY. THE OPERATIVE DPA IS A SEPARATE BINDING LEGAL AGREEMENT. IT DOES NOT CONSTITUTE LEGAL ADVICE.