Data Processing Agreement

Last updated: August 26, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between the customer installing or using the Audit Otter application ("Customer") and Abrega Inc., doing business as Audit Otter ("Abrega"), and applies whenever Abrega processes personal data on Customer's behalf. A countersigned copy is available on request from privacy@auditotter.com.

1. Roles and scope

For personal data contained in Customer's compliance program data (described in Annex 1), Customer is the controller and Abrega is the processor. "Data protection law" means the law applicable to the processing, including, where relevant, the EU and UK GDPR and US state privacy laws. For data Abrega collects for its own purposes (such as the website launch list), Abrega is the controller and its Privacy Policy applies instead of this DPA.

2. Processing on instructions

Abrega processes Customer personal data only on Customer's documented instructions: the agreement between the parties, Customer's configuration of the application (including which tools Customer connects and what Customer's users ask the application to do), and this DPA. Abrega will inform Customer if, in its opinion, an instruction infringes data protection law, and may suspend the affected processing until the instruction is confirmed or changed. Abrega does not sell Customer personal data, use it for advertising, or use it to train machine-learning models.

3. Confidentiality

Abrega ensures that persons authorized to process Customer personal data are bound by confidentiality obligations, and limits access to those who need it to operate, secure, and support the service.

4. Security

Abrega implements and maintains the technical and organisational measures described in Annex 2, and will not materially reduce the overall security of the service during a subscription term.

5. Subprocessors

Customer gives general authorization for Abrega to engage subprocessors. Current subprocessors:

Abrega will give notice (by email or in-app) at least 30 days before adding or replacing a subprocessor that processes Customer personal data. If Customer reasonably objects on data-protection grounds and the parties cannot resolve the objection, Customer may terminate the affected service and export its data. Abrega imposes data-protection obligations on subprocessors that are no less protective than this DPA and remains liable for their performance.

6. Assistance

Taking into account the nature of the processing, Abrega will assist Customer, by appropriate technical and organisational measures and insofar as reasonably possible, with (a) responding to data subject requests (access, rectification, erasure, restriction, portability, objection), and (b) Customer's obligations regarding security, breach notification, data protection impact assessments, and consultations with supervisory authorities. If a data subject contacts Abrega directly about Customer's program data, Abrega will refer the request to Customer without undue delay.

7. Personal data breach

Abrega will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer personal data, and will provide information reasonably required for Customer to meet its own notification obligations, updating the notice as the investigation progresses.

8. Deletion and return

Customer can export its program data at any time through the application. On termination of the service, or on a verified deletion request from Customer's administrator, Abrega deletes Customer personal data promptly and at most within 30 days, unless law requires longer retention of specific records, in which case the data remains protected under this DPA until deleted.

9. Audits and information

Abrega will make available the information reasonably necessary to demonstrate compliance with this DPA, including summaries of security measures and, when available, third-party audit reports. Where data protection law grants Customer an audit right that these materials do not satisfy, Customer may conduct an audit at most once per year, on at least 30 days' notice, during business hours, under confidentiality, without access to other customers' data, and at Customer's cost.

10. International transfers

Customer personal data is processed in the United States on Amazon Web Services infrastructure. Where the EU or UK GDPR applies to a transfer, the parties rely on an applicable adequacy mechanism (including the EU-U.S. Data Privacy Framework where Abrega or the relevant subprocessor participates) or, failing that, the European Commission's Standard Contractual Clauses (Module Two: controller to processor) and the UK Addendum, which are incorporated into this DPA by reference, with Annexes completed by Annex 1 and Annex 2 of this DPA.

11. Liability, term, and precedence

This DPA applies for as long as Abrega processes Customer personal data. Liability under this DPA is subject to the limitations in the agreement governing Customer's use of the Audit Otter application. If this DPA conflicts with that agreement, this DPA controls for data-protection matters. If Customer has a separately negotiated DPA with Abrega, that agreement controls instead of this page.

Annex 1 · Details of processing

Annex 2 · Technical and organisational measures

Contact

Questions about this DPA, signed copies, and subprocessor notices: privacy@auditotter.com.