This Data Processing Agreement ("DPA" or "Agreement") forms an integral part of, and is governed by, the services agreement entered into between the Customer ("Controller") and Giro Risk Management, S. de R.L. de C.V. ("GRM" or "Processor"), together referred to as "the Parties".
This DPA governs the processing of personal data that GRM carries out on behalf of and under the instructions of the Controller, in connection with the P-ERM 4.0 platform and other contracted services. In the event of a conflict between the main agreement and this DPA regarding the protection of personal data, this DPA shall prevail.
This Agreement is entered into in accordance with the Mexican Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) and its Regulations and —where applicable to data subjects located in the European Economic Area— with Article 28 of the General Data Protection Regulation (GDPR).
1. Definitions and roles
The terms "personal data", "data subject", "processing", "controller", "processor", "transfer" and "personal data breach" shall have the meaning given to them by the LFPDPPP and, where applicable, the GDPR.
- Controller: the Customer, who determines the purposes and means of the processing.
- Processor: GRM, who processes personal data solely on behalf of the Controller.
- Sub-processor: a third party engaged by GRM to perform part of the services involving the processing of data.
2. Subject matter, nature and purpose of processing
GRM shall process personal data solely to provide the contracted services (operation of the P-ERM 4.0 platform, hosting, technical support, maintenance and associated risk-management features). The details of the processing —categories of data, of data subjects, purpose and duration— are set out in Annex I.
GRM shall not process personal data for its own purposes or for purposes other than those instructed by the Controller.
3. Duration
This DPA shall remain in force for as long as GRM processes personal data on behalf of the Controller and, in any event, for the duration of the main agreement. Confidentiality and data return or deletion obligations shall survive its termination.
4. Processor obligations
GRM, as Processor, undertakes to:
- Process personal data only on the documented instructions of the Controller, including with regard to international transfers.
- Ensure that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Not transfer or disclose the data to third parties except on the Controller's instructions or by legal obligation; in the latter case, GRM shall inform the Controller before processing, unless legally prohibited.
- Assist the Controller, through appropriate technical and organisational measures, in complying with its obligations to respond to data subjects and to ensure the security of processing.
- Make available to the Controller the information necessary to demonstrate compliance with the obligations set out herein.
5. Security measures
GRM shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex II. Such measures shall be reviewed and updated periodically.
6. Sub-processors
The Controller grants GRM general authorisation to engage the sub-processors listed in Annex III. GRM shall impose on each sub-processor, by contract, data protection obligations equivalent to those in this DPA.
GRM shall inform the Controller of any addition or replacement of sub-processors with reasonable prior notice, giving it the opportunity to object on justified data-protection grounds. GRM shall remain liable to the Controller for its sub-processors' compliance.
7. International transfers
Where providing the service involves processing data outside the country of origin of the Controller or the data subject, GRM shall ensure that such transfers are carried out with adequate safeguards.
For data subject to the GDPR, transfers outside the European Economic Area shall rely on the Standard Contractual Clauses (SCC) approved by the European Commission or another valid transfer mechanism, incorporated by reference into this DPA.
8. Data subject rights
Taking into account the nature of the processing, GRM shall assist the Controller, insofar as possible, in responding to requests to exercise rights of Access, Rectification, Cancellation and Objection (ARCO under Mexican law) —or access, rectification, erasure, restriction, portability and objection under the GDPR—.
If GRM receives a request directly from a data subject, it shall forward it to the Controller without responding on its own account, unless expressly authorised.
9. Personal data breach notification
GRM shall notify the Controller without undue delay, and no later than 72 hours after becoming aware, of any personal data breach affecting the data processed on behalf of the Controller.
The notification shall include, to the extent available, the nature of the breach, the categories and approximate number of affected data subjects, the likely consequences, and the measures taken or proposed to mitigate it.
10. Audits
GRM shall make available to the Controller the information necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, by the Controller or an auditor mandated by it, with reasonable prior notice and subject to confidentiality obligations.
11. Return and deletion of data
Upon termination of the services, and at the Controller's choice, GRM shall return or delete all personal data processed on its behalf, as well as existing copies, unless retention is required by an applicable legal obligation.
12. Liability and governing law
Each Party shall be liable for the damage it causes by breaching its obligations, on the terms and within the liability limits set out in the main agreement. This DPA is governed by the laws of the United Mexican States, and the Parties submit to the competent courts of Cuernavaca, Morelos, México, unless a mandatory data-protection rule provides otherwise.
Annexes
Annex I — Details of processing
| Subject matter | Provision of the P-ERM 4.0 platform services and associated services. |
|---|---|
| Nature and purpose | Hosting, processing, support and management of the Controller's risk information. |
| Categories of data subjects | Platform users: personnel designated by the Controller to operate P-ERM 4.0. |
| Categories of data | Name, email address and job title of users. |
| Special-category data | None. The processing does not include special categories of personal data. |
| Confidential information (non-personal) | Data on the Controller's vital assets, vulnerabilities, controls and risk-management methodology, treated as confidential information under clauses 4 and 5 and Annex II. |
| Duration of processing | For the duration of the main agreement, plus applicable legal retention periods. |
Annex II — Technical and organisational measures
GRM applies, as a minimum, the following security measures (to be tailored to P-ERM's actual infrastructure):
- Encryption of data in transit (TLS) and at rest.
- Role-based access control and least-privilege principle.
- User authentication and access logging.
- Regular backups and disaster-recovery procedures.
- Logical segregation of information between customers.
- Internal security, confidentiality and incident-management policies.
- Periodic vulnerability assessment and monitoring.
Annex III — Authorised sub-processors
List of sub-processors with access to personal data (to be completed with P-ERM's actual providers):
| Hostinger International Ltd. | Application hosting and infrastructure — United States (Boston) |
|---|---|
| Supabase, Inc. | Database and user authentication — United States (East US, Northern Virginia) |
| Resend (Plus Five Five, Inc.) | Sending of transactional emails and notifications — United States |
Questions about this DPA?
To request signature of the DPA, exercise rights or resolve data-protection queries, contact our privacy officer Carmela Ramos Moguel, Dirección — Departamento de Privacidad de GRM at info@girorm.mx. Address: Prol. Reforma 17, Fracc. Jardines de Reforma, C.P. 62269, Cuernavaca, Morelos, México. Tax ID (RFC): GRM131016H42.
Model document for information purposes. The binding contractual version is the one signed by both Parties. Subject to legal review.