About This Agreement: This Data Processing Agreement ("DPA") supplements the S2T Consulting Terms of Service and governs the processing of personal data by S2T Consulting LLC ("Processor") on behalf of customers ("Controller"). This DPA incorporates the Standard Contractual Clauses as approved by the European Commission Decision 2021/914.

1. Definitions

In this DPA, the following terms have the meanings set forth below. Terms not defined herein shall have the meanings assigned in the GDPR, CCPA, or applicable data protection law.

1.1 "Controller"

The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. In this DPA, Controller refers to the Customer.

1.2 "Processor"

The natural or legal person, public authority, agency, or other body which processes personal data on behalf of the Controller. In this DPA, Processor refers to S2T Consulting LLC.

1.3 "Personal Data"

Any information relating to an identified or identifiable natural person ("Data Subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity.

1.4 "Processing"

Any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.

1.5 "Data Subject"

An identified or identifiable natural person whose personal data is processed.

1.6 "Subprocessor"

Any processor engaged by S2T Consulting to process personal data on behalf of the Controller.

1.7 "Personal Data Breach"

A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.

1.8 "Standard Contractual Clauses" or "SCCs"

The standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission pursuant to Decision 2021/914.

2. Scope of Processing

2.1 Subject Matter and Duration

This DPA applies when S2T Consulting processes personal data on behalf of Controller in the course of providing services under the applicable service agreement. The duration of processing corresponds to the term of the underlying service agreement.

2.2 Nature and Purpose of Processing

The nature and purpose of processing are determined by the services engaged, which may include:

2.3 Categories of Data Subjects

Data subjects may include:

2.4 Types of Personal Data

Personal data processed may include:

2.5 Data Locality Architecture

Important: S2T's platform operates on a "methodology-as-a-service" model with data locality. This means:

  • Customer data typically remains in the Customer's environment
  • S2T provides assessment frameworks and AI orchestration logic
  • S2T does not typically access or store customer operational data
  • When personal data is processed, it is limited to service delivery requirements

3. Controller Responsibilities

As the Controller, Customer is responsible for:

4. Processor Obligations

As the Processor, S2T Consulting agrees to:

4.1 Lawful Processing

4.2 Confidentiality

4.3 Security

4.4 Assistance

4.5 Data Retention

4.6 Demonstration of Compliance

5. Data Subject Rights

S2T will assist Controller in responding to requests from data subjects to exercise their rights under applicable data protection laws. These rights may include:

5.1 GDPR Rights (EU/EEA Data Subjects)

5.2 CCPA Rights (California Residents)

5.3 Response Timeframes

S2T will respond to Controller's requests for assistance with data subject requests within:

6. Security Measures

S2T implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

6.1 Encryption

6.2 Access Controls

6.3 Infrastructure Security

6.4 Monitoring and Logging

6.5 Personnel Security

6.6 Business Continuity

7. Subprocessor Requirements

7.1 Authorization

Controller authorizes S2T to engage subprocessors for the processing of personal data. The current list of subprocessors is maintained at /legal/subprocessors.html.

7.2 Subprocessor Obligations

S2T will:

7.3 New Subprocessors

S2T will:

8. Data Breach Notification

72-Hour Notification Commitment: S2T will notify Controller of any personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of the breach.

8.1 Notification Content

Breach notifications will include, to the extent known:

8.2 Cooperation

S2T will:

9. International Data Transfers

9.1 Primary Processing Location

S2T primarily processes data within the United States, specifically in the AWS us-east-1 (Virginia) region.

9.2 Transfer Mechanisms

For transfers of personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to the United States or other third countries, S2T relies on:

9.3 Transfer Impact Assessment

S2T has conducted a transfer impact assessment and determined that U.S. law does not prevent S2T from fulfilling its obligations under the SCCs. S2T will:

10. Standard Contractual Clauses Reference

10.1 Incorporation

The Standard Contractual Clauses for the transfer of personal data to third countries (Module Two: Controller to Processor) as adopted by European Commission Decision 2021/914 are hereby incorporated by reference.

10.2 Clause Specifications

10.3 UK and Swiss Transfers

For transfers from the UK or Switzerland:

10.4 Execution

Upon request, S2T will execute the Standard Contractual Clauses with Controller as a standalone document.

11. Audit Rights

11.1 Information Access

S2T will make available to Controller information necessary to demonstrate compliance with this DPA, including:

11.2 Audit Procedures

Upon reasonable request and subject to confidentiality obligations:

11.3 Audit Costs

11.4 Third-Party Certifications

S2T may satisfy audit requests by providing:

12. Duration and Termination

12.1 Term

This DPA remains in effect for the duration of S2T's processing of personal data on behalf of Controller.

12.2 Effect of Termination

Upon termination of the service agreement:

12.3 Retention Exceptions

S2T may retain personal data after termination:

Any retained data will continue to be protected in accordance with this DPA.

13. Liability

13.1 Allocation

Each party's liability under this DPA is subject to the limitations of liability in the underlying service agreement.

13.2 Indemnification

Each party will indemnify the other for losses arising from the indemnifying party's breach of this DPA or applicable data protection law.

13.3 Regulatory Fines

To the extent permitted by law, each party will be responsible for fines or penalties imposed on it by regulatory authorities for its own violations of data protection law.

14. Contact Information

For questions about this DPA, data protection matters, or to exercise data subject rights:

S2T Consulting LLC

Data Protection Contact

Email: privacy@s2tconsulting.com

Website: www.s2tconsulting.com

Related Documents: