AqNova Marketplace Policies & Disclosures
Global Legal Footer Framework
Comprehensive Compliance & Platform Governance Reference
GDPR Article 28 Compliant — Global Cross-Jurisdiction Edition
Including Standard Contractual Clauses (SCCs) Annex for International Transfers
Effective Date: April 7, 2026 | Version 1.0 | Arivon Holding Corporation
| WARNING — IMPORTANT LEGAL NOTICE THIS DATA PROCESSING AGREEMENT IS A LEGALLY BINDING CONTRACT. IT IS ENTERED INTO BETWEEN ARIVON HOLDING CORPORATION (OPERATING AS AQNOVA MARKETPLACE) AND THE VENDOR, PARTNER, OR PROCESSOR IDENTIFIED IN THE EXECUTION BLOCK AT SECTION 6.15. BY ACCESSING THE PLATFORM AS A VENDOR OR PARTNER, OR BY EXECUTING THIS DPA, THE COUNTERPARTY AGREES TO BE BOUND BY ALL TERMS OF THIS AGREEMENT IN FULL. IF YOU ARE ACTING ON BEHALF OF AN ENTITY, YOU REPRESENT THAT YOU HAVE FULL AUTHORITY TO BIND IT. |
|---|
This Data Processing Agreement ("DPA," "Agreement") is entered into between Arivon Holding Corporation, operating the AqNova Marketplace ("AqNova," "Controller," "we," "us") and the Vendor, Partner, or Data Processor identified in the Execution Block at Section 6.15 ("Processor," "Partner," "you"). This DPA forms part of and is incorporated into the Platform Terms & Conditions, the Vendor Agreement, or any applicable master services agreement between the parties (collectively, the "Principal Agreement").
This DPA applies wherever AqNova shares, makes accessible, or instructs the processing of Personal Data with or by a Vendor or Partner in connection with their participation on or integration with the Platform. It establishes the legal, technical, and organizational requirements for all such processing, consistent with applicable global data protection law.
| DPA Structure at a Glance Section 6.1 — Definitions & Interpretation Section 6.2 — Scope & Roles of the Parties Section 6.3 — Processor Obligations (GDPR Art. 28 Core Requirements) Section 6.4 — Sub-Processing Section 6.5 — Data Subject Rights Assistance Section 6.6 — Security of Processing Section 6.7 — Personal Data Breach Notification Section 6.8 — Data Protection Impact Assessments (DPIAs) Section 6.9 — Return & Deletion of Personal Data Section 6.10 — Audit Rights & Compliance Verification Section 6.11 — International Data Transfer Framework Section 6.12 — Jurisdiction-Specific Data Protection Addenda Section 6.13 — Liability, Indemnification & Governing Law Section 6.14 — Term & Termination Section 6.15 — Execution Block & Authorized Signatures Annex I — Description of Processing Activities Annex II — Technical & Organizational Security Measures (TOMs) Annex III — Approved Sub-Processors Annex IV — Standard Contractual Clauses (SCCs) for International Transfers |
|---|
Unless otherwise defined herein, capitalized terms have the meanings given in the Principal Agreement. The following definitions apply throughout this DPA:
"Applicable Data Protection Law": All laws, regulations, directives, and binding guidance governing the processing of Personal Data applicable to a party or processing activity, including without limitation the GDPR, UK GDPR, CCPA/CPRA, LGPD, POPIA, PDPA, APPI, DPDPA, NDPR, PIPEDA, and all equivalent national frameworks in every jurisdiction where AqNova operates.
"Controller": The natural or legal person that determines the purposes and means of the processing of Personal Data. In the standard AqNova marketplace relationship, AqNova is the Controller of Buyer and Platform Visitor Personal Data.
"Data Subject": An identified or identifiable natural person to whom Personal Data relates.
"GDPR": Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
"UK GDPR": The GDPR as retained in United Kingdom law by virtue of the European Union (Withdrawal) Act 2018, as supplemented by the Data Protection Act 2018.
"Personal Data": Any information relating to an identified or identifiable natural person, as defined under Applicable Data Protection Law. For the purposes of this DPA, Personal Data includes all data categories described in Annex I.
"Processing": Any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction.
"Processor": A natural or legal person that processes Personal Data on behalf of the Controller. In the standard AqNova relationship, the Vendor or Partner executing this DPA is the Processor.
"Sub-Processor": Any Processor engaged by the Processor to carry out specific processing activities on behalf of the Controller.
"Personal Data Breach": A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
"Restricted Transfer": A transfer of Personal Data from the EEA, UK, or any jurisdiction with data export restrictions to a country not recognized as providing adequate data protection.
"SCCs": The Standard Contractual Clauses adopted by the European Commission under Implementing Decision 2021/914/EU, or any successor instrument, supplemented as needed by the UK IDTA or Addendum for UK transfers.
"Special Categories of Personal Data": Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for unique identification, health data, or data concerning sex life or sexual orientation.
"Technical and Organizational Measures" or "TOMs": The security measures implemented by the Processor to protect Personal Data, as described in Annex II of this DPA.
In this DPA: (a) references to processing include both automated and non-automated means; (b) references to a law include amendments and successor legislation; (c) the singular includes the plural and vice versa; (d) any obligation to notify or inform requires written communication; and (e) this DPA must be read in conjunction with Applicable Data Protection Law, which prevails in the event of any inconsistency.
This DPA applies to all processing of Personal Data by the Processor: (a) received from AqNova in connection with the Principal Agreement; (b) collected directly from AqNova's users, buyers, or visitors in the course of performing services under the Principal Agreement; or (c) accessed through the AqNova Platform API, data feeds, or reporting systems. It does not apply to the Processor's independent processing of Personal Data for its own separate business purposes outside the scope of the Principal Agreement.
| Processing Scenario | Role Determination & Applicable Framework |
|---|---|
| Vendor processes AqNova-sourced Buyer Personal Data to fulfill marketplace orders (name, shipping address, contact details) | AqNova = Controller. Vendor = Processor. This DPA applies in full. GDPR Art. 28 governs the relationship. |
| Vendor independently collects and processes Buyer data on its own platform outside AqNova for CRM or marketing purposes | Vendor = Independent Controller. This DPA does not apply. Vendor must comply with Applicable Data Protection Law independently. |
| AqNova and Vendor jointly determine purposes and means of processing (e.g., co-branded loyalty or rewards program) | AqNova and Vendor = Joint Controllers under GDPR Art. 26. A separate Joint Controller Agreement (JCA) is required. |
| Third-party technology partner processes data solely as a technical service provider acting on AqNova's documented instructions | AqNova = Controller. Partner = Processor. This DPA applies in full. |
| Vendor as controller provides Buyer data to AqNova for dispute resolution or fraud prevention purposes | Vendor = Controller. AqNova = Processor or independent Controller depending on purpose. Separate processing terms apply. |
The subject matter, nature, duration, and purpose of the processing, as well as the type of Personal Data and categories of Data Subjects, are described in detail in Annex I to this DPA. The parties agree that Annex I shall be updated whenever there is a material change to the processing activities. No new categories of Personal Data shall be processed without prior written agreement and an updated Annex I.
The Processor agrees, for the entire duration of this DPA and the Principal Agreement, to comply with each of the following obligations:
Process Personal Data only on AqNova's documented instructions, as set out in this DPA, the Principal Agreement, and any supplemental written instructions provided by AqNova from time to time. The Processor shall not process Personal Data for any purpose other than to perform its obligations under the Principal Agreement or as required by Applicable Data Protection Law. If required by law to process beyond AqNova's instructions, the Processor shall inform AqNova before processing (unless prohibited by law on grounds of public interest).
If the Processor believes that any instruction from AqNova infringes Applicable Data Protection Law, it shall immediately notify AqNova in writing, setting out the basis for that belief, and shall await further written instruction before proceeding. This does not relieve the Processor of its own independent compliance obligations.
Ensure that all personnel authorized to process Personal Data under this DPA are bound by appropriate confidentiality obligations (whether contractual or statutory) and have received adequate data protection training relevant to their role. The Processor shall ensure that access to Personal Data is strictly limited to those personnel who need access for the purposes of the Principal Agreement (minimum necessary access principle).
Implement and maintain the technical and organizational security measures described in Annex II, taking into account: (a) the state of the art in data security technology; (b) the costs of implementation; (c) the nature, scope, context, and purposes of the processing; and (d) the risks to the rights and freedoms of Data Subjects. The TOMs in Annex II represent the minimum required standard. Any reduction in the level of protection requires AqNova's prior written approval.
Not engage any Sub-Processor without AqNova's prior specific or general written authorization, as further described in Section 6.4.
Assist AqNova, by appropriate technical and organizational measures, in fulfilling AqNova's obligations to respond to Data Subject rights requests under Applicable Data Protection Law, as further described in Section 6.5.
Assist AqNova in ensuring compliance with obligations under Applicable Data Protection Law with respect to: (a) security of processing (GDPR Art. 32); (b) Personal Data Breach notification to supervisory authorities and Data Subjects (GDPR Arts. 33-34); (c) Data Protection Impact Assessments (GDPR Art. 35); and (d) prior consultation with supervisory authorities (GDPR Art. 36). Costs are allocated based on which party caused the compliance obligation.
At AqNova's election upon termination or expiry of the Principal Agreement: (a) securely return all Personal Data (including all copies and backups) in a structured, commonly used, machine-readable format within 30 calendar days; or (b) securely and irreversibly delete all Personal Data and confirm deletion in writing (a "Deletion Certificate") within 30 calendar days. Further details are in Section 6.9.
Make available to AqNova all information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits and inspections conducted by AqNova or a mandated independent auditor, as further described in Section 6.10.
Not sell, rent, lease, share, or otherwise commercially exploit Personal Data received from AqNova to any third party for such third party's own purposes, regardless of whether monetary consideration is exchanged. This prohibition is in addition to any restrictions imposed by Applicable Data Protection Law, including the CCPA/CPRA prohibition on selling or sharing Personal Data without a valid opt-out mechanism.
Before engaging a new Sub-Processor or replacing an existing one, the Processor must:
Provide AqNova with at least 30 days' prior written Sub-Processor Notice identifying the Sub-Processor's name, country of establishment, processing activities to be sub-contracted, and data protection safeguards in place.
AqNova has 14 days from receipt to object in writing on reasonable data protection grounds. If AqNova does not object within 14 days, the engagement is deemed approved.
If AqNova objects, the parties shall negotiate in good faith for up to 30 days to resolve the objection. If unresolved, either party may terminate the relevant processing activities on 30 days' written notice without penalty.
Where the new Sub-Processor involves a Restricted Transfer, the Processor must also comply with Section 6.11 before commencing any processing.
Before engaging any Sub-Processor (including those in Annex III), the Processor must enter into a written sub-processing agreement imposing, at minimum, the same data protection obligations as this DPA. The agreement must address: security measures; Data Subject rights assistance; Personal Data Breach notification to the Processor within 24 hours of discovery; return or deletion of Personal Data upon termination; and a prohibition on the Sub-Processor engaging further sub-processors without the Processor's prior written consent.
The Processor remains fully liable to AqNova for the performance of any Sub-Processor's obligations under this DPA, to the extent the Sub-Processor fails to fulfill those obligations. Engagement of a Sub-Processor does not relieve the Processor of any of its responsibilities under this DPA or Applicable Data Protection Law.
The Processor shall assist AqNova in responding to Data Subject rights requests across all applicable jurisdictions. The following table identifies the key rights and their legal bases:
| Data Subject Right | Applicable Jurisdictions & Legal Basis |
|---|---|
| Right of Access / Right to Know | GDPR Art. 15; UK GDPR Art. 15; CCPA/CPRA s.1798.100; LGPD Art. 18; POPIA s.23; PDPA Reg. 5(1); PIPEDA Principle 9; DPDPA s.11 |
| Right to Rectification / Correction | GDPR Art. 16; UK GDPR Art. 16; CCPA/CPRA s.1798.106; LGPD Art. 18(III); POPIA s.24; DPDPA s.12 |
| Right to Erasure / Deletion | GDPR Art. 17; UK GDPR Art. 17; CCPA/CPRA s.1798.105; LGPD Art. 18(VI); POPIA s.24; DPDPA s.13 |
| Right to Restriction of Processing | GDPR Art. 18; UK GDPR Art. 18; LGPD Art. 18(IV); PDPA Regulation 4 |
| Right to Data Portability | GDPR Art. 20; UK GDPR Art. 20; LGPD Art. 18(V); CCPA/CPRA s.1798.100(d) |
| Right to Object | GDPR Art. 21; UK GDPR Art. 21; LGPD Art. 18(II) |
| Right to Opt-Out of Sale or Sharing | CCPA/CPRA ss.1798.120, 1798.121; Colorado CPA s.6-1-1306; Texas TDPSA; Virginia CDPA |
| Right Not to Be Subject to Automated Decision-Making | GDPR Art. 22; UK GDPR Art. 22; LGPD Art. 20; DPDPA s.16 |
| Right to Withdraw Consent | GDPR Art. 7(3); UK GDPR; LGPD Art. 8(5); POPIA s.11(1)(a); PDPA s.16 |
| Right to Lodge a Complaint with Supervisory Authority | GDPR Art. 77; UK GDPR Art. 77; LGPD Art. 55-A; PIPA Art. 73 (Korea); POPIA s.74 |
Upon receiving notification from AqNova of a Data Subject request, or upon directly receiving such a request in connection with processing under this DPA, the Processor shall:
Immediately (and no later than 2 Business Days) forward to AqNova at privacy@aqnova.co any Data Subject request received directly by the Processor relating to Personal Data processed on AqNova's behalf.
Provide AqNova with all information and records necessary to respond within applicable legal deadlines: 30 days under GDPR; 45 days under CCPA/CPRA; 15 business days under LGPD; and as required under other applicable frameworks.
Apply or lift any restriction, deletion, correction, or portability requirement to the relevant Personal Data as directed in writing by AqNova.
Not independently respond to a Data Subject request relating to Personal Data processed on AqNova's behalf without AqNova's prior written authorization, except where Applicable Data Protection Law mandates an independent response.
The Processor shall implement and maintain appropriate TOMs to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, damage, alteration, or unauthorized disclosure. TOMs must be appropriate to: (a) the nature and sensitivity of the Personal Data; (b) the state of the art in data security technology at the time of processing; (c) the costs of implementation relative to the risks presented; and (d) the likelihood and severity of potential harm to Data Subjects in the event of a security incident. The minimum required TOMs are set out in Annex II.
Without limiting Section 6.6.1, the Processor's TOMs must include at minimum:
Encryption of Personal Data in transit using TLS 1.2 minimum (TLS 1.3 recommended) and at rest using AES-256 or equivalent standard encryption.
Pseudonymization of Personal Data where technically feasible and proportionate to the processing purpose.
Access controls implementing the principle of least privilege: role-based access management (RBAC); multi-factor authentication (MFA) for all accounts with access to Personal Data; and quarterly access review with immediate revocation upon role change or departure.
Audit logging of all access to and operations performed on Personal Data, with logs retained for a minimum of 12 months.
Regular security testing, including automated vulnerability scanning of production systems and annual external penetration testing by a qualified independent security firm.
Documented business continuity and disaster recovery plans, tested annually, with defined Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).
Secure disposal of Personal Data and media containing Personal Data in accordance with recognized standards (NIST SP 800-88 or equivalent).
Supply chain security controls ensuring that hardware and software components used in processing Personal Data meet appropriate security standards.
Upon becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA, the Processor shall notify AqNova without undue delay and in any event within 24 hours of becoming aware of the breach. This 24-hour obligation applies regardless of the severity or apparent impact of the breach. Early notification is required to support AqNova's compliance with its own statutory notification deadlines — including the 72-hour deadline under GDPR Article 33 — which begin running from the time the Controller becomes aware.
The Processor's breach notification must be submitted simultaneously to security@aqnova.co and legal@aqnova.com and must include, to the extent known at the time:
A description of the nature of the breach, including the categories and approximate number of Data Subjects affected and the categories and approximate number of Personal Data records involved.
The name and contact details of the Processor's Data Protection Officer (if applicable) or designated security incident contact.
A description of the likely consequences of the breach and its estimated impact on affected Data Subjects.
A description of measures taken or proposed to address the breach and to mitigate its possible adverse effects.
The date and time the Processor became aware of the breach, and the estimated date and time of the breach itself, if known.
The source of the breach (internal system failure, third-party Sub-Processor, external cyberattack, etc.) to the extent determinable at the time of notification.
Information not available at the time of initial notification must be provided in supplemental reports without undue delay. A comprehensive incident report must be submitted to AqNova within 72 hours of the initial notification.
Following discovery of a breach, the Processor shall: (a) take immediate steps to contain the breach and prevent further unauthorized access or disclosure; (b) cooperate fully with AqNova's investigation and any investigation by a supervisory authority; (c) preserve all evidence relating to the breach; (d) not make any public statement, press release, or regulatory notification regarding the breach without AqNova's prior written consent (except where required by Applicable Data Protection Law, in which case the Processor must notify AqNova before making such disclosure to the extent legally permissible); and (e) provide AqNova with a final incident report within 14 calendar days of the breach being contained.
The Processor shall provide AqNova with all reasonable assistance in conducting Data Protection Impact Assessments (DPIAs) and, where required, prior consultation with the relevant supervisory authority, in respect of processing activities that are likely to result in a high risk to the rights and freedoms of natural persons, as required by GDPR Article 35 and equivalent provisions in applicable national data protection laws.
Processing activities under this DPA that are likely to require a DPIA include, without limitation:
Systematic and extensive profiling of Data Subjects producing legal or similarly significant effects on individuals.
Large-scale processing of Special Categories of Personal Data or personal data relating to criminal convictions and offences.
Systematic monitoring of publicly accessible areas on a large scale (e.g., CCTV or equivalent digital surveillance).
Processing involving innovative technologies or new types of processing where the risks are not yet fully assessed.
Cross-border Restricted Transfers of Personal Data to non-adequate third countries at scale.
Processing that involves matching or combining Personal Data sets from different sources in a manner that produces novel insights or assessments.
The Processor shall contribute to DPIAs by providing within 10 Business Days of AqNova's written request: (a) full and accurate descriptions of all processing activities carried out under this DPA, including all data flows; (b) assessments of the risks associated with the processing from the Processor's perspective, including risks arising from its sub-processing arrangements; (c) details of the TOMs implemented or proposed to mitigate identified risks; and (d) any other information reasonably requested by AqNova to complete the DPIA.
Upon the termination or expiry of the Principal Agreement, or upon AqNova's written request at any time, the Processor shall — at AqNova's election — either: (a) securely return all Personal Data (including all copies, backup copies, and derivatives) to AqNova in a structured, commonly used, and machine-readable format (e.g., CSV or JSON) within 30 calendar days; or (b) securely and irreversibly delete all Personal Data and confirm deletion in writing by means of a Deletion Certificate within 30 calendar days.
The Processor may retain Personal Data beyond the termination date only to the extent and for the duration required by Applicable Data Protection Law or applicable mandatory legal obligations (e.g., tax record retention, anti-money laundering record requirements). In such cases, the Processor must: (a) notify AqNova in writing of the specific legal basis and expected duration of continued retention before or promptly after the termination date; (b) restrict all processing of the retained data to the minimum necessary to fulfil the applicable legal obligation; and (c) delete the retained data as soon as the legal retention obligation expires, providing a Deletion Certificate within 30 days of deletion.
A valid Deletion Certificate must include: the date of deletion; confirmation that all copies (including all backups) have been deleted; the method of deletion used (e.g., cryptographic erasure, secure overwrite, physical destruction); a list of the categories of Personal Data deleted; and the name, title, and authorized signature of the Processor representative who oversaw and certifies the deletion.
AqNova has the right to verify the Processor's compliance with this DPA by conducting audits and inspections, either directly or through a qualified independent auditor bound by appropriate confidentiality obligations. AqNova will provide the Processor with at least 30 days' advance written notice before commencing an audit, except in the case of a suspected or confirmed Personal Data Breach or an active regulatory investigation, where shorter notice may apply.
Audits may include: review of the Processor's Records of Processing Activities (ROPA) required by GDPR Article 30; inspection of the TOMs documented in Annex II; review of sub-processing agreements and Annex III compliance; review of Personal Data Breach logs and incident response documentation; testing of security controls (by separate prior written agreement); and review of data retention and deletion practices.
In lieu of or in addition to a direct on-site audit, AqNova may accept a current and valid third-party security certification as evidence of compliance with specific security requirements, including: ISO/IEC 27001 certificate; SOC 2 Type II report; CSA STAR certification; or equivalent recognized security audit. Submission of a valid certification does not preclude AqNova from conducting a focused audit on matters not covered by the certification.
The costs of audits conducted under this Section 6.10 shall be borne by AqNova, except that where an audit reveals material non-compliance with this DPA, the Processor shall bear the costs of the audit and all reasonable remediation costs. Audits shall be conducted during normal business hours in a manner that minimizes disruption to the Processor's operations.
The Processor shall not make any Restricted Transfer unless one of the following lawful transfer mechanisms is in place and fully documented prior to any transfer commencing: (a) an adequacy decision issued by the European Commission or the UK Secretary of State in respect of the destination country; (b) appropriate safeguards in the form of SCCs as adopted under Commission Decision 2021/914/EU (Module 2 or Module 3 as applicable), supplemented where necessary by the UK IDTA or Addendum; (c) Binding Corporate Rules approved by a competent supervisory authority; or (d) an applicable derogation under GDPR Article 49 (e.g., explicit Data Subject consent; necessity for contract performance; substantial public interest).
Where SCCs are required as the transfer mechanism, the parties incorporate the SCCs set out in Annex IV of this DPA. The applicable module is:
Module 2 (Controller to Processor): Applies where AqNova (as Controller) transfers EEA-originating Personal Data to the Processor for processing in a non-adequate third country. AqNova is the data exporter and the Processor is the data importer.
Module 3 (Processor to Processor): Applies where the Processor onward-transfers Personal Data to a Sub-Processor in a non-adequate third country. The Processor is the data exporter and the Sub-Processor is the data importer.
The SCCs in Annex IV are incorporated in their entirety and take precedence over this DPA to the extent of any conflict on the subject of cross-border data transfers. The parties shall execute the SCCs (or confirm their application in writing) for each specific Restricted Transfer.
Before relying on SCCs for any Restricted Transfer, the parties must conduct and document a Transfer Impact Assessment (TIA) evaluating: (a) the legal framework and law enforcement access powers in the destination country, taking into account relevant supervisory authority and EDPB guidance; (b) the practical relevance of any government access risk given the purpose and nature of the processing; and (c) whether supplementary measures (contractual, technical, or organizational) are necessary and sufficient to bring the level of protection to EEA/UK standards. TIA documentation must be retained for a minimum of 3 years from the date of the relevant transfer.
For transfers of Personal Data subject to UK GDPR from the UK to a non-adequate third country, the parties shall execute the UK International Data Transfer Addendum (IDTA) issued by the UK Information Commissioner's Office (version B1.0 or any successor version), incorporated as a supplement to Annex IV for all UK-originating transfers. In the event of any conflict between the UK IDTA and the EU SCCs, the UK IDTA prevails for UK transfers only.
| Originating Jurisdiction | Transfer Mechanism & Requirements |
|---|---|
| European Economic Area (EEA) | Adequacy decision (Commission Decision 2021/914) or SCCs Module 2/3 (Annex IV) plus TIA. Prior written approval from AqNova's Data Protection Officer required. |
| United Kingdom | UK Adequacy Regulations or UK IDTA / Addendum to EU SCCs. All transfers to non-adequate countries require TIA and ICO-approved transfer mechanism. |
| California, USA (CCPA/CPRA) | No cross-border restriction per se, but data sharing agreements, opt-out rights (sale/sharing), and purpose limitation apply. CPRA requires disclosure of cross-border transfers. |
| Canada (PIPEDA / Quebec Law 25) | Contractual protections equivalent to PIPEDA accountability principle required. Quebec Law 25 requires a Privacy Impact Assessment (PIA) before cross-border transfers of Quebec residents' personal information. |
| Brazil (LGPD Arts. 33-36) | Transfer permitted where: destination provides adequate protection; SCCs or BCRs in place; specific consent obtained; necessary for contract performance; or ANPD authorization obtained. |
| Nigeria (NDPR / NDA 2023) | NDPC authorization required, or destination provides adequate protection. Contractual safeguards required for all third-country transfers. |
| South Africa (POPIA Section 72) | Adequate protection at destination; or data subject consent; or contract necessity; or public interest; or adequate contractual safeguards in place and documented. |
| Kenya (DPA 2019, Section 49) | Adequate protection at destination, or equivalent contractual or organizational safeguards in place. |
| India (DPDPA 2023) | Central Government to notify permitted/restricted jurisdictions. Standard contractual and organizational safeguards apply pending Government notification. |
| Australia (Privacy Act 1988 / APPs) | APP 8: cross-border disclosure to non-comparable jurisdiction requires contractual protections ensuring recipient implements equivalent safeguards. Sending entity remains accountable. |
| Singapore (PDPA Section 26) | Contractual protections equivalent to PDPA obligations, or PDPC-approved Binding Corporate Rules, or adequacy recognized by PDPC. |
| South Korea (PIPA) | Data Subject consent or compliance with PIPA transfer provisions. Notification to PIPC for certain categories of cross-border transfer. |
| Japan (APPI, Amended 2022) | Data Subject consent, or confirmation that recipient implements equivalent protection measures. PPC-whitelisted countries permit transfer without additional steps. |
| Colombia (Law 1581 of 2012) | SIC authorization or adequacy recognized by SIC. Data Subject consent or BCRs may substitute for adequacy determination. |
| Chile & Argentina | National data protection authority approval or adequacy determination. Contractual safeguards are strongly recommended for all transfers. |
The following addenda apply to processing activities subject to the specified jurisdiction's data protection law, in addition to and not in lieu of the general provisions of this DPA. Where a conflict exists between a jurisdiction-specific addendum and the general DPA provisions, the addendum prevails for the relevant jurisdiction to the extent of the inconsistency.
A.1 Lawful Basis for Processing
The Processor acknowledges that AqNova's lawful bases for processing Personal Data under GDPR Article 6 include: contract performance (Art. 6(1)(b)); compliance with a legal obligation (Art. 6(1)(c)); and legitimate interests of AqNova or third parties (Art. 6(1)(f)) where not overridden by Data Subject rights. For Special Categories of Personal Data, AqNova relies on explicit consent (Art. 9(2)(a)) or other applicable grounds. The Processor shall not process Personal Data in a manner inconsistent with the documented lawful basis applicable to the relevant processing activity.
A.2 Records of Processing Activities (GDPR Art. 30)
The Processor shall maintain a current Record of Processing Activities (ROPA) for all processing carried out under this DPA, containing all information required by GDPR Article 30(2), including: the Processor's name and contact details and those of its DPO; categories of processing carried out on behalf of AqNova as Controller; details of cross-border transfers and applicable transfer mechanisms; a general description of TOMs; and retention periods for each data category. The ROPA must be made available to AqNova and to supervisory authorities on request.
A.3 Data Protection Officer (DPO)
Where the Processor is required to appoint a Data Protection Officer under GDPR Article 37, it shall: appoint a suitably qualified and independent DPO; register the DPO with the relevant national supervisory authority; and provide AqNova with the DPO's name and contact details. Any change in DPO must be notified to AqNova within 5 Business Days.
A.4 EU & UK Representatives
If established outside the EEA or UK and processing Personal Data of EEA or UK Data Subjects under GDPR or UK GDPR territorial scope, the Processor must designate an EU Representative pursuant to GDPR Article 27 and/or a UK Representative pursuant to UK GDPR Article 27 (unless an exemption applies). The Processor shall provide AqNova with the Representatives' contact details and registration information upon request.
B.1 Service Provider and Contractor Designation
For purposes of the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), Cal. Civ. Code Section 1798.100 et seq., the Processor is designated as a 'Service Provider' (where receiving Personal Information from AqNova for a Business Purpose) or 'Contractor' (where accessing Personal Information under a written contract). The Processor certifies that it: (a) is prohibited from selling or sharing Personal Information received from AqNova; (b) shall not retain, use, or disclose Personal Information for any purpose other than the Business Purpose specified in the Principal Agreement; (c) shall not combine Personal Information received from AqNova with Personal Information from other sources except as permitted by CPRA; and (d) grants AqNova the right to take reasonable and appropriate steps to verify compliance with this certification.
B.2 Sensitive Personal Information
The Processor shall not process 'Sensitive Personal Information' as defined by CPRA Section 1798.140(ae) collected from California consumers beyond what is strictly necessary to perform the services under the Principal Agreement, and shall not use such information to infer characteristics about California consumers. Sensitive Personal Information includes Social Security numbers, financial account credentials, precise geolocation, racial or ethnic origin, religious beliefs, union membership, communications content, genetic and biometric data, health information, and sex life or sexual orientation data.
B.3 Multi-State Privacy Law Compliance
The Processor shall comply with all applicable US state privacy laws as they apply to processing activities under this DPA, including the Virginia Consumer Data Protection Act (CDPA); Colorado Privacy Act (CPA); Connecticut Data Privacy Act (CTDPA); Texas Data Privacy and Security Act (TDPSA); and Florida Digital Bill of Rights (FDBR), as enacted and in force from time to time.
C.1 Accountability & Onward Transfer
AqNova remains accountable under PIPEDA Principle 1 (Accountability) for all Personal Information transferred to the Processor. The Processor shall implement security safeguards equivalent to those required by PIPEDA and shall immediately notify AqNova of any privacy breach that creates a real risk of significant harm to any individual, to enable AqNova to comply with its breach reporting obligations to the Office of the Privacy Commissioner of Canada (OPC).
C.2 Quebec Law 25 (Act to Modernize Legislative Provisions as Regards the Protection of Personal Information)
For Personal Information of Quebec residents processed under this DPA, the Processor shall comply with Quebec Law 25 (chapter P-39.1), including: conducting a Privacy Impact Assessment (PIA) before any cross-border communication of Quebec residents' personal information; entering into a written agreement with AqNova confirming that the destination provides equivalent protection; and ensuring all profiling or automated decision-making activities comply with the consent and transparency requirements of Law 25. The PIA documentation must be retained and made available to AqNova upon request.
For processing subject to the LGPD (Law 13,709/2018), the Processor (acting as 'Operador' under LGPD terminology) shall: (a) process Personal Data only in accordance with AqNova's (the 'Controlador's') documented instructions; (b) implement security measures required by LGPD Article 46 to protect Personal Data from unauthorized access, destruction, loss, alteration, communication, or any form of improper or unlawful processing; (c) report any security incidents to AqNova within 24 hours of becoming aware; (d) provide full cooperation in fulfilling Data Subject rights under LGPD Article 18; and (e) comply with all obligations applicable to Operadores under the LGPD and ANPD regulations and guidelines. For cross-border transfers of Brazilian residents' Personal Data, the mechanisms in Section 6.11 and LGPD Articles 33-36 apply.
E.1 Nigeria — NDPR 2019 & Nigeria Data Protection Act 2023
The Processor shall comply with the Nigeria Data Protection Act 2023 and the NDPR 2019 for all processing of Nigerian residents' Personal Data. Requirements include: registration with the Nigeria Data Protection Commission (NDPC) where required; conducting an annual Data Protection Audit if processing the Personal Data of more than 10,000 data subjects per year; appointing a Data Protection Compliance Organisation (DPCO) or a Data Protection Officer; and complying with all NDPC guidelines on lawful processing, data subject rights, data localization requirements, and cross-border transfers.
E.2 South Africa — POPIA (Protection of Personal Information Act 4 of 2013)
The Processor (acting as 'Operator' under POPIA) shall: process Personal Information only with AqNova's (the 'Responsible Party's') knowledge and authorization; implement appropriate, reasonable technical and organizational measures to prevent loss, damage, unauthorized destruction of, or unlawful access to Personal Information (POPIA Section 19); immediately notify AqNova upon becoming aware of any suspected compromise of Personal Information (POPIA Section 22); and comply with all conditions for lawful processing under POPIA Chapter 3. All cross-border transfers of Personal Information must comply with POPIA Section 72.
E.3 Kenya (Data Protection Act 2019) & Ghana (Data Protection Act 2012, Act 843)
For processing of Personal Data of Kenyan or Ghanaian residents, the Processor shall comply with the Kenya Data Protection Act 2019 (including registration with the Office of the Data Protection Commissioner where required) and the Ghana Data Protection Act 2012, Act 843 (including registration with the Data Protection Commission of Ghana where required). The Processor shall implement safeguards consistent with both Acts and provide AqNova with written confirmation of its registration status upon request.
F.1 Australia — Privacy Act 1988 (Australian Privacy Principles)
The Processor shall comply with the Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs). APP 11 requires the Processor to take reasonable steps to protect Personal Information from misuse, interference, loss, and unauthorized access, modification, or disclosure. APP 8 requires contractual protections for cross-border disclosures ensuring the recipient implements protections broadly equivalent to the APPs. The Notifiable Data Breaches (NDB) scheme requires notification to both OAIC and affected individuals for eligible data breaches.
F.2 India — Digital Personal Data Protection Act 2023 (DPDPA)
The Processor shall comply with the Digital Personal Data Protection Act 2023 and rules issued by the Data Protection Board of India (DPBI). Processing must be based on consent or a legitimate use as defined by the DPDPA. The Processor shall comply with data principal rights, breach notification obligations, and cross-border transfer restrictions as determined by the Central Government's notifications under the Act. The Processor shall not retain Personal Data beyond the period necessary for the purpose for which it was collected.
F.3 Singapore — Personal Data Protection Act 2012 (PDPA)
The Processor shall comply with the PDPA and PDPC Advisory Guidelines. Obligations include: notification and purpose limitation; consent where required; data subject access and correction rights; retention limitation (Personal Data deleted when no longer necessary); and the transfer limitation obligation under PDPA Section 26. The Processor shall notify AqNova of any data breach within 3 calendar days of becoming aware of an assessable breach and shall cooperate with AqNova's compliance with mandatory data portability requirements where applicable.
F.4 Japan — Act on the Protection of Personal Information (APPI, Amended 2022)
The Processor shall comply with the APPI (Act No. 57 of 2003 as amended in 2022) and Personal Information Protection Commission (PPC) Guidelines. Cross-border transfers to non-PPC-whitelisted countries require either data subject consent or confirmation that the recipient implements equivalent protective measures documented under a written contract. The Processor shall comply with PPC mandatory reporting requirements for leakage incidents and shall maintain third-party provision records as required by APPI.
F.5 Republic of Korea — Personal Information Protection Act (PIPA)
The Processor shall comply with the PIPA (Act No. 10142 as amended) and guidelines issued by the Personal Information Protection Commission (PIPC). Sensitive personal information requires explicit consent under PIPA Article 23. The Processor shall implement the technical and managerial protective measures prescribed by the Ministry of the Interior and Safety (Standard No. 2021-2) and shall comply with all breach notification obligations under PIPA Article 34, including without delay notification to PIPC for large-scale breaches.
For processing of Personal Data of residents of Colombia, Chile, or Argentina, the Processor shall comply with the following frameworks: Ley 1581 de 2012 and Decreto 1377 de 2013 (Colombia), including registration with the Registro Nacional de Bases de Datos (RNBD) administered by the Superintendencia de Industria y Comercio (SIC) where required; Ley 19,628 (Chile) and applicable data protection reforms and cybersecurity legislation; and Ley 25,326 (Argentina) and guidelines issued by the Agencia de Acceso a la Informacion Publica (AAIP). The Processor shall implement security measures consistent with each applicable law and shall notify AqNova without delay of any data security incident affecting the Personal Data of residents of any of these jurisdictions.
Each party is liable to the other for damages caused by that party's breach of this DPA in accordance with the Principal Agreement and Applicable Data Protection Law. As between the parties in their external relationship with Data Subjects and supervisory authorities: (a) where AqNova is held liable for damage caused solely by the Processor's breach of this DPA, the Processor shall indemnify AqNova in full including all fines, penalties, Data Subject compensation, and reasonable legal costs; (b) where both parties contributed to the relevant damage, liability is apportioned in proportion to each party's respective contribution; and (c) the Processor may rely on AqNova's documented written instructions as a defence to the extent that AqNova's instructions were the sole cause of the breach.
The Processor acknowledges that breaches of GDPR and equivalent data protection law may result in regulatory fines of up to EUR 20 million or 4% of total worldwide annual turnover (whichever is higher), and that equivalent penalties may be imposed under other applicable national frameworks. The Processor shall bear full responsibility for any fine, penalty, or regulatory sanction attributable solely to the Processor's own non-compliance with this DPA or Applicable Data Protection Law.
The Processor shall indemnify, defend, and hold harmless AqNova, Arivon Holding Corporation, and their respective affiliates, officers, directors, and employees from and against all losses, liabilities, damages, fines, penalties, costs, and expenses (including reasonable legal fees) arising from or relating to: (a) the Processor's breach of this DPA; (b) unauthorized processing, disclosure, or use of Personal Data by the Processor; (c) the Processor's failure to implement adequate security measures; (d) any breach by a Sub-Processor of obligations imposed under this DPA; or (e) the Processor's violation of Applicable Data Protection Law.
This DPA is governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to its conflict-of-law rules, except that: (a) for processing subject to the GDPR or UK GDPR, the SCCs in Annex IV are governed by the governing law specified therein (EU law as interpreted by the CJEU, or English and Welsh law for UK transfers); (b) for processing subject to the LGPD, Brazilian mandatory requirements apply to the extent required by the LGPD; and (c) for processing subject to POPIA, South African mandatory requirements apply to the extent required by POPIA. Supervisory authorities retain jurisdiction as granted by Applicable Data Protection Law regardless of this governing law clause.
This DPA is effective from the date of execution by both parties, or from the effective date of the Principal Agreement if no separate DPA execution date is established, and continues in full force for the duration of the Principal Agreement unless earlier terminated.
Either party may terminate this DPA immediately upon written notice if the other party: (a) commits a material breach of this DPA that is incapable of remedy; (b) commits a material breach capable of remedy and fails to remedy it within 30 days of receiving written notice specifying the breach; or (c) becomes insolvent, enters administration, receivership, liquidation, bankruptcy, or any equivalent insolvency proceeding in any jurisdiction.
Termination of this DPA does not affect either party's accrued rights and obligations at the date of termination. The following provisions survive termination indefinitely: Section 6.7 (Breach Notification obligations for pre-termination breaches), Section 6.9 (Return & Deletion obligations), Section 6.10 (Audit rights for the period of the DPA), Section 6.12 (Jurisdiction-Specific Addenda to the extent they relate to pre-termination processing), and Section 6.13 (Liability and Indemnification).
This Annex I forms an integral part of the DPA between AqNova and the Processor. It describes the subject matter, nature, duration, and purpose of the processing activities carried out by the Processor on AqNova's behalf, together with the categories of Personal Data and Data Subjects involved.
Processing of Personal Data of Buyers, registered users, and Platform visitors of AqNova Marketplace in connection with the Vendor's fulfillment of marketplace orders, vendor-buyer communications, and related Platform services, as specified in the Principal Agreement.
For the duration of the Principal Agreement and, thereafter, only as required by applicable legal retention obligations. Specific retention periods by Personal Data category are set out in AqNova's Data Retention Schedule, available from privacy@aqnova.co upon written request.
| Processing Activity | Purpose & Lawful Basis |
|---|---|
| Order processing & fulfillment | Processing of name, shipping address, contact details, and order specifics to fulfill Buyer purchases. Lawful basis: Contract performance (GDPR Art. 6(1)(b)). |
| Shipping & logistics coordination | Sharing of shipping address and contact information with carriers and logistics providers. Lawful basis: Contract performance / Legitimate interests. |
| Vendor-Buyer order communication | Facilitating order-related messaging between Buyers and Vendors through the Platform messaging system. Lawful basis: Contract performance. |
| Payment administration support | Coordination of payment authorization, refund administration, and payout management. Lawful basis: Contract performance / Legal obligation. |
| Fraud & AML screening | Screening of transaction data against sanctions lists and fraud patterns, where Vendor has access to relevant data. Lawful basis: Legal obligation / Legitimate interests. |
| Customer service & dispute resolution | Processing of order and user data to resolve disputes and Buyer Protection claims. Lawful basis: Contract performance / Legal obligation. |
| Tax & regulatory reporting | Retention of transaction records for applicable tax, VAT, and regulatory compliance periods. Lawful basis: Legal obligation. |
| Aggregated Platform analytics | Anonymized, aggregated processing for Platform performance measurement. Lawful basis: Legitimate interests. |
Identity Data: Full legal name, username, government-issued identification number (where required for KYC/AML purposes only).
Contact Data: Email address, telephone number, shipping address, billing address.
Transaction Data: Order details, product descriptions, quantities, purchase price, payment method type (last four digits of card only — full payment card data is never accessible to Vendors).
Communication Data: Messages exchanged between Buyers and Vendors through the Platform's official messaging system.
Device & Technical Data: IP address, device identifiers, and browser type, shared with Vendors only for fraud prevention purposes and only to the extent authorized by AqNova.
Compliance Data: Sanctions screening results and AML check records, applicable to qualifying Vendor accounts only.
No Special Categories of Personal Data are processed under the standard terms of this DPA. If any specific processing activity under the Principal Agreement requires the processing of Special Categories, a separate written amendment to this Annex I — including the documented lawful basis and any required Data Subject consent — is required before such processing may commence. Any unauthorized processing of Special Categories constitutes a material breach of this DPA.
Registered Buyers on the AqNova Platform who have placed or are placing orders with the relevant Vendor.
Registered Vendors and Vendor personnel, to the extent their personal data is shared with AqNova for account management, KYC, or compliance purposes.
Platform visitors, limited to technical and device data shared for fraud prevention purposes where specifically authorized by AqNova.
ANNEX II — TECHNICAL & ORGANIZATIONAL SECURITY MEASURES (TOMs)
This Annex II sets out the minimum Technical and Organizational Measures (TOMs) that the Processor must implement and maintain throughout the term of the DPA. These measures must be formally reviewed and updated at least annually, and following any material security incident, system migration, or change in processing scope.
Data in Transit: Transport Layer Security (TLS) 1.2 minimum for all Personal Data transmitted over public or third-party networks; TLS 1.3 strongly recommended.
Data at Rest: AES-256 encryption (or equivalent) for all Personal Data stored in databases, file systems, and backup media.
Key Management: Dedicated key management system (KMS); encryption keys rotated at minimum annually and upon any personnel change involving access to keys; keys stored separately from encrypted data.
Role-Based Access Control (RBAC): Access to Personal Data strictly limited to personnel whose role requires it for the purposes of the Principal Agreement.
Multi-Factor Authentication (MFA): Mandatory for all user accounts with access to systems containing Personal Data; no exceptions.
Privileged Access Management (PAM): All privileged accounts (administrator, root, super-user) subject to enhanced controls, just-in-time access where feasible, and regular review.
Access Reviews: Quarterly review and right-sizing of all access permissions; immediate revocation upon role change, transfer, or departure.
All servers and infrastructure hosting Personal Data must be located in data center facilities with ISO/IEC 27001-certified physical security controls or equivalent.
Physical access to data processing facilities controlled by biometric or card-based systems with full audit trail; CCTV monitoring; formal visitor management procedures.
Clean Desk Policy enforced for all personnel with access to Personal Data in physical or printed form.
Patch Management: Critical security patches applied within 72 hours of release; high-severity patches within 7 calendar days; standard patches within 30 days.
Vulnerability Scanning: Automated scanning of all production systems weekly; immediate remediation of critical findings.
Penetration Testing: Annual external penetration test by a qualified, independent security firm; results and remediation plans provided to AqNova upon written request.
Secure Development Lifecycle (SDLC): Security requirements integrated into software development; code review for security vulnerabilities; OWASP Top 10 compliance for all web-facing applications.
A documented and annually tested Incident Response Plan, with defined roles, escalation paths, and communication procedures.
A documented Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) with defined Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for all systems processing Personal Data under this DPA.
Daily encrypted backups of all Personal Data; backup integrity tested quarterly; offsite or cloud backup storage in a geographically separate location.
Background screening appropriate to the role and jurisdiction (consistent with applicable employment law) for all personnel with access to Personal Data.
Annual mandatory data protection training for all personnel processing Personal Data under this DPA; training records maintained and made available to AqNova upon request.
All personnel with access to Personal Data bound by enforceable confidentiality obligations, contractual or statutory, for the duration of their engagement and following termination.
Only Personal Data strictly necessary for the specified processing purpose is collected, processed, and retained. Excess data is deleted without undue delay.
Pseudonymization applied where technically feasible and proportionate to the processing risk, to reduce the potential impact of unauthorized access.
Personal Data deleted or anonymized upon expiry of the applicable retention period; automated deletion processes implemented where technically feasible.
The following Sub-Processors are approved by AqNova as of the effective date of this DPA. The Processor may engage these Sub-Processors for the described purposes without requiring separate written approval for each engagement. Any additional Sub-Processors not listed below require prior approval through the process set out in Section 6.4.2.
The Processor must ensure that a valid sub-processing agreement meeting the requirements of Section 6.4.3 is in place with each Sub-Processor listed below before any Personal Data is shared with them.
| Sub-Processor | Country | Processing Activity | Transfer Mechanism |
|---|---|---|---|
| Amazon Web Services (AWS) | USA / Global | Cloud infrastructure hosting, data storage, CDN, backup and disaster recovery services | SCCs (Module 2/3) + AWS DPA; UK IDTA for UK transfers; adequacy decision where applicable |
| Google Cloud Platform (GCP) | USA / Global | Cloud platform services, analytics infrastructure (where applicable) | SCCs (Module 2/3) + Google Cloud DPA; UK IDTA for UK transfers |
| Stripe, Inc. | USA | Payment processing, fraud screening and prevention, payout management and settlement | SCCs + Stripe Data Processing Agreement; UK IDTA for UK transfers |
| PayPal Holdings, Inc. | USA | Alternative payment processing and digital wallet services (where enabled) | SCCs + PayPal Data Processing Agreement |
| Twilio / SendGrid | USA | Transactional email delivery and SMS notification services | SCCs + Twilio/SendGrid Data Processing Agreement |
| Cloudflare, Inc. | USA | Content delivery network (CDN), DDoS protection, and web security services | SCCs + Cloudflare Data Processing Agreement |
| Zendesk, Inc. | USA | Customer support ticketing and case management (where integrated by Vendor) | SCCs + Zendesk Data Processing Agreement |
| [Additional Sub-Processor] | [Country] | [Processing Activity to be specified] | [Transfer Mechanism to be confirmed] |
AqNova maintains and publishes a current list of its own approved Sub-Processors at [aqnova.co/sub-processors]. The Processor is separately responsible for ensuring that its own Sub-Processors engaged in processing under this DPA are either listed in Annex III or have been added through the Section 6.4.2 approval process before any Personal Data is transferred to them.
ANNEX IV — STANDARD CONTRACTUAL CLAUSES (SCCs) FOR INTERNATIONAL DATA TRANSFERS
| WARNING — IMPORTANT LEGAL NOTICE THE STANDARD CONTRACTUAL CLAUSES IN THIS ANNEX IV ARE INCORPORATED BY REFERENCE FROM EUROPEAN COMMISSION IMPLEMENTING DECISION (EU) 2021/914 OF 4 JUNE 2021. IN THE EVENT OF ANY CONFLICT BETWEEN THIS ANNEX IV AND THE COMMISSION'S OFFICIAL SCC TEXT, THE OFFICIAL PUBLISHED TEXT PREVAILS. THE PARTIES MUST SELECT THE APPLICABLE MODULE AND COMPLETE ALL SCHEDULE ITEMS IN SECTION IV.B BEFORE RELYING ON THESE SCCs TO AUTHORIZE A RESTRICTED TRANSFER. PARTIES SHOULD SEEK QUALIFIED LEGAL COUNSEL BEFORE EXECUTION. |
|---|
The Standard Contractual Clauses adopted by the European Commission under Implementing Decision (EU) 2021/914 of 4 June 2021 are incorporated in their entirety into this Annex IV by reference and form a binding part of this DPA. The parties agree that the applicable Module is determined as follows:
Module 2 (Controller to Processor): Applies where AqNova, as Controller, transfers EEA-originating Personal Data to the Processor for processing in a non-adequate third country. AqNova is the 'data exporter' and the Processor is the 'data importer' under Module 2.
Module 3 (Processor to Processor): Applies where the Processor, acting as AqNova's Processor, onward-transfers Personal Data to a Sub-Processor located in a non-adequate third country. The Processor is the 'data exporter' and the Sub-Processor is the 'data importer' under Module 3.
The parties shall complete and execute the SCCs by filling in the information required in this Annex IV for each specific Restricted Transfer. Executed SCCs (or written confirmations of application) must be retained by both parties and made available to the relevant supervisory authority upon request.
| SCC Schedule — Required Completion Fields for Module 2 Transfers Clause 7 (Docking Clause): Applicable — third parties may accede with both parties' prior written consent Clause 9(a) (Sub-Processor Authorization): General Written Authorization as per Annex III of this DPA Clause 9(a) (Notice Period): 30 days advance notice per Section 6.4.2 of this DPA Clause 11 (Redress): EU ODR platform; national supervisory authority complaint mechanisms Clause 13 (Supervisory Authority): Lead supervisory authority per GDPR Art. 56 (Irish DPC for AqNova's EU establishment — to be confirmed upon EU entity registration) Clause 17 (Governing Law): Law of the Republic of Ireland (EU SCCs); English and Welsh law (UK IDTA transfers) Clause 18 (Jurisdiction): Courts of the Republic of Ireland (EU SCCs); Courts of England and Wales (UK transfers) Annex I.A — Parties: Data Exporter: Arivon Holding Corporation / AqNova Marketplace Data Importer: [Processor Full Legal Name — to be completed] Annex I.B — Description: See Annex I of this DPA (subject matter, nature, purpose, data categories, data subjects) Annex I.C — Supervisory Auth: As specified under Clause 13 above Annex II — TOMs: As per Annex II of this DPA Annex III — Sub-Processors: As per Annex III of this DPA (where Module 2 general authorization applies) |
|---|
For all transfers of Personal Data subject to UK GDPR from the United Kingdom to a non-adequate third country, the parties agree to execute the International Data Transfer Addendum to the EU Standard Contractual Clauses (IDTA, version B1.0) as issued by the UK Information Commissioner's Office, or any successor version approved by the ICO. The UK IDTA is incorporated as a binding supplement to Annex IV for all UK-originating transfers. In the event of any conflict between the UK IDTA and the EU SCCs, the UK IDTA prevails for UK transfers only. The parties confirm that Table 1 to Table 4 of the UK IDTA shall be completed consistently with the completion schedule in Section IV.B above, adapted as necessary for UK transfers.
By executing this DPA and relying on the SCCs in this Annex IV for any Restricted Transfer, the parties confirm that they have conducted, or will conduct prior to commencing the relevant transfer, a Transfer Impact Assessment (TIA) for each Restricted Transfer in accordance with Section 6.11.3 of this DPA. The TIA must address at minimum:
An assessment of the legal framework governing law enforcement, national security, and intelligence access to personal data in the destination country, taking into account the guidance published by the EDPB (Recommendations 01/2020 and subsequent updates) and, for UK transfers, ICO guidance.
A determination of whether the laws and practices of the destination country impinge on the effectiveness of the SCCs as a transfer mechanism, having regard to the specific circumstances of the transfer, the nature of the data, and any supplementary measures already in place.
An evaluation of whether supplementary measures (contractual, technical, or organizational) are necessary and, if so, whether they are sufficient to bring the level of protection to EEA or UK standards.
For US transfers: specific consideration of Section 702 of the Foreign Intelligence Surveillance Act (FISA) and Executive Order 12333, and assessment of the applicability of the EU-US Data Privacy Framework adequacy decision (Commission Decision (EU) 2023/1795) where the US importer is certified.
TIA documentation, including the assessment methodology, findings, and any supplementary measures adopted, must be retained by both parties for a minimum of 3 years from the date of the relevant Restricted Transfer. AqNova will provide Processors with a template TIA framework upon written request to dsa@aqnova.co.
Where a destination country benefits from an adequacy decision by the European Commission (or, for UK transfers, a UK adequacy regulation) that applies to the specific transfer in question, the parties may rely on that adequacy decision rather than executing SCCs for the relevant transfer. The adequacy decision must remain in force at the time of the transfer. If an adequacy decision is invalidated, suspended, or restricted by a court or regulatory authority, the parties shall promptly implement SCCs or another lawful transfer mechanism for all ongoing transfers from the affected jurisdiction.
AqNova Marketplace | Global Legal Footer Framework | Section 6: Data Processing Agreement (DPA)
Copyright 2026 Arivon Holding Corporation. All rights reserved. Effective April 7, 2026. Version 1.0.