Legal document

Data Processing Agreement

The terms under which GRM processes personal data on behalf of its customers through P-ERM 4.0 and related services.

Version: v3.3 Last updated: May 23, 2026

This Data Processing Agreement ("DPA" or "Agreement") forms an integral part of, and is governed by, the services agreement entered into between the Customer ("Controller") and Giro Risk Management, S. de R.L. de C.V. ("GRM" or "Processor"), together referred to as "the Parties".

This DPA governs the processing of personal data that GRM carries out on behalf of and under the instructions of the Controller, in connection with the P-ERM 4.0 platform and other contracted services. In the event of a conflict between the main agreement and this DPA regarding the protection of personal data, this DPA shall prevail.

This Agreement is entered into in accordance with the Mexican Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) and its Regulations and —where applicable to data subjects located in the European Economic Area— with Article 28 of the General Data Protection Regulation (GDPR).

1. Definitions and roles

The terms "personal data", "data subject", "processing", "controller", "processor", "transfer" and "personal data breach" shall have the meaning given to them by the LFPDPPP and, where applicable, the GDPR.

  • Controller: the Customer, who determines the purposes and means of the processing.
  • Processor: GRM, who processes personal data solely on behalf of the Controller.
  • Sub-processor: a third party engaged by GRM to perform part of the services involving the processing of data.

2. Subject matter, nature and purpose of processing

GRM shall process personal data solely to provide the contracted services (operation of the P-ERM 4.0 platform, hosting, technical support, maintenance and associated risk-management features). The details of the processing —categories of data, of data subjects, purpose and duration— are set out in Annex I.

GRM shall not process personal data for its own purposes or for purposes other than those instructed by the Controller.

3. Duration

This DPA shall remain in force for as long as GRM processes personal data on behalf of the Controller and, in any event, for the duration of the main agreement. Confidentiality and data return or deletion obligations shall survive its termination.

4. Processor obligations

GRM, as Processor, undertakes to:

  • Process personal data only on the documented instructions of the Controller, including with regard to international transfers.
  • Ensure that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • Not transfer or disclose the data to third parties except on the Controller's instructions or by legal obligation; in the latter case, GRM shall inform the Controller before processing, unless legally prohibited.
  • Assist the Controller, through appropriate technical and organisational measures, in complying with its obligations to respond to data subjects and to ensure the security of processing.
  • Make available to the Controller the information necessary to demonstrate compliance with the obligations set out herein.

5. Security measures

GRM shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex II. Such measures shall be reviewed and updated periodically.

6. Sub-processors

The Controller grants GRM general authorisation to engage the sub-processors listed in Annex III. GRM shall impose on each sub-processor, by contract, data protection obligations equivalent to those in this DPA.

GRM shall inform the Controller of any addition or replacement of sub-processors with reasonable prior notice, giving it the opportunity to object on justified data-protection grounds. GRM shall remain liable to the Controller for its sub-processors' compliance.

7. International transfers

Where providing the service involves processing data outside the country of origin of the Controller or the data subject, GRM shall ensure that such transfers are carried out with adequate safeguards.

For data subject to the GDPR, transfers outside the European Economic Area shall rely on the Standard Contractual Clauses (SCC) approved by the European Commission or another valid transfer mechanism, incorporated by reference into this DPA.

8. Data subject rights

Taking into account the nature of the processing, GRM shall assist the Controller, insofar as possible, in responding to requests to exercise rights of Access, Rectification, Cancellation and Objection (ARCO under Mexican law) —or access, rectification, erasure, restriction, portability and objection under the GDPR—.

If GRM receives a request directly from a data subject, it shall forward it to the Controller without responding on its own account, unless expressly authorised.

9. Personal data breach notification

GRM shall notify the Controller without undue delay, and no later than 72 hours after becoming aware, of any personal data breach affecting the data processed on behalf of the Controller.

The notification shall include, to the extent available, the nature of the breach, the categories and approximate number of affected data subjects, the likely consequences, and the measures taken or proposed to mitigate it.

10. Audits

GRM shall make available to the Controller the information necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, by the Controller or an auditor mandated by it, with reasonable prior notice and subject to confidentiality obligations.

11. Return and deletion of data

Upon termination of the services, and at the Controller's choice, GRM shall return or delete all personal data processed on its behalf, as well as existing copies, unless retention is required by an applicable legal obligation.

12. Liability and governing law

Each Party shall be liable for the damage it causes by breaching its obligations, on the terms and within the liability limits set out in the main agreement. This DPA is governed by the laws of the United Mexican States, and the Parties submit to the competent courts of Cuernavaca, Morelos, México, unless a mandatory data-protection rule provides otherwise.

Annexes

Annex I — Details of processing

Description of the processing
Subject matter Provision of the P-ERM 4.0 platform services and associated services.
Nature and purpose Hosting, processing, support and management of the Controller's risk information.
Categories of data subjects Platform users: personnel designated by the Controller to operate P-ERM 4.0.
Categories of data Name, email address and job title of users.
Special-category data None. The processing does not include special categories of personal data.
Confidential information (non-personal) Data on the Controller's vital assets, vulnerabilities, controls and risk-management methodology, treated as confidential information under clauses 4 and 5 and Annex II.
Duration of processing For the duration of the main agreement, plus applicable legal retention periods.

Annex II — Technical and organisational measures

GRM applies, as a minimum, the following security measures (to be tailored to P-ERM's actual infrastructure):

  • Encryption of data in transit (TLS) and at rest.
  • Role-based access control and least-privilege principle.
  • User authentication and access logging.
  • Regular backups and disaster-recovery procedures.
  • Logical segregation of information between customers.
  • Internal security, confidentiality and incident-management policies.
  • Periodic vulnerability assessment and monitoring.

Annex III — Authorised sub-processors

List of sub-processors with access to personal data (to be completed with P-ERM's actual providers):

Sub-processors
Hostinger International Ltd. Application hosting and infrastructure — United States (Boston)
Supabase, Inc. Database and user authentication — United States (East US, Northern Virginia)
Resend (Plus Five Five, Inc.) Sending of transactional emails and notifications — United States

Questions about this DPA?

To request signature of the DPA, exercise rights or resolve data-protection queries, contact our privacy officer Carmela Ramos Moguel, Dirección — Departamento de Privacidad de GRM at info@girorm.mx. Address: Prol. Reforma 17, Fracc. Jardines de Reforma, C.P. 62269, Cuernavaca, Morelos, México. Tax ID (RFC): GRM131016H42.

Model document for information purposes. The binding contractual version is the one signed by both Parties. Subject to legal review.

Hantavirus
Monitoreo en vivo HANTAVIRUS Tracker Global Gratis