Data Processing Agreement
The Article 28 terms on which we process personal data on behalf of our customers. It takes effect when a workspace is opened, so it binds us whether or not anyone signs it. If your procurement needs an executed copy, ask and we will send one.
Last updated 22 September 2026
1. The parties
The processor is LAZO Group, a company registered in France, of 3 rue Lamartine, 91320 Wissous, France, trading as Relynt. Throughout this agreement "we", "us" and "Relynt" mean that company.
The controller is the organisation that holds the workspace: the entity named on the subscription, or, where no subscription has been taken, the entity whose staff opened it. Throughout this agreement "you" means that organisation.
Questions, notices and requests under this agreement go to support@relynt.io. Notices to you go to the email addresses of the administrators of your workspace.
2. This agreement and how it is entered into
This data processing agreement is the agreement required by Article 28(3) of Regulation (EU) 2016/679 (the GDPR) between Relynt, as processor, and the customer organisation whose workspace holds the data, as controller.
It takes effect automatically when a workspace is opened and applies for as long as we process personal data on your behalf. You do not need to sign anything for it to bind us. If your procurement process requires an executed copy on your own paper, or a copy with your entity details filled in, write to support@relynt.io and we will return a signed one.
It forms part of our terms of service. Where it conflicts with those terms on anything concerning personal data, this agreement prevails.
Where the UK GDPR applies to your processing, references to the GDPR are read as references to the UK GDPR and references to a supervisory authority include the Information Commissioner.
3. Roles of the parties
You are the controller of the personal data inside your workspace. You decide what goes into it, why, who may see it and how long it stays. That includes the contact details of your own staff, and the contact details of people at your ICT providers whom you invite to answer an assessment.
We are your processor for that data. We process it only to provide the platform to you.
We are a separate and independent controller for a small set of data that is ours rather than yours: the account and billing records of the organisation that contracts with us, the enquiries people send through our website, and our own security and service logs. Our privacy notice covers that data, and this agreement does not apply to it.
Neither party is a joint controller with the other. We do not determine the purposes of the processing described in this agreement.
4. Subject matter, duration, nature and purpose
The subject matter is the operation of an ICT third-party risk management platform for financial entities subject to Regulation (EU) 2022/2554.
The nature of the processing is storage, organisation, retrieval, structuring, display, export and erasure of records you create, together with transmission to the sub-processors listed below.
The purpose is to provide the platform and its features to you, to keep it secure and available, and to give you support when you ask for it. We do not process your workspace content for any purpose of our own.
The duration is the term of your subscription, followed by the deletion period described in section 12.
5. Categories of data subjects and personal data
The platform is built around records about organisations rather than people, so most of what it holds is not personal data at all. The personal data it does hold falls into these categories.
| Data subjects | Personal data |
|---|---|
| Your staff who use the platform | Name, work email address, job title, role in the workspace, authentication data including a password hash and two-factor enrolment, last sign-in time, and the entries they generate in the audit trail. |
| Contacts at your ICT providers | Name, work email address, job title, and the answers and documents they submit in response to an assessment or an evidence request. |
| People named inside content you upload | Whatever appears in contracts, audit reports, certificates, assessment responses and other documents you choose to store. Typically signatories, security contacts and report authors. You control what is uploaded. |
| People named in free-text fields | Whatever you record in a risk description, a finding, a note or a board report narrative. |
6. Special categories of data
The platform is not designed for, and should not be used to store, special categories of personal data under Article 9, or data relating to criminal convictions and offences under Article 10.
Nothing in the product asks for such data and no feature depends on it. If you put it into a free-text field or an uploaded document anyway, we will process it under this agreement, but you remain responsible for having a lawful basis and an Article 9 condition for doing so, and for judging whether the measures described here are appropriate to it.
7. Our instructions
We process personal data only on your documented instructions, including for international transfers, unless the law of the Union or a member state requires otherwise. Where such a law applies we tell you before processing, unless that law forbids us from telling you on important grounds of public interest.
Your instructions are: this agreement, our terms of service, the documented behaviour of the product as you configure and use it, and any further written instruction you give us through support.
We will tell you if, in our opinion, an instruction infringes the GDPR or another data protection provision. We may suspend the affected processing until the instruction is withdrawn or amended.
Some features send content outside our own systems, and those features are yours to switch on. Model-assisted contract review sends the text of the document being reviewed to Anthropic at the moment of review. It is off unless an administrator enables it, and enabling it is your instruction to us to make that transfer.
We do not use your workspace content to train machine learning models, our own or anyone else's, and our agreement with Anthropic prevents them from doing so with content we send.
8. Confidentiality
Everyone we authorise to process personal data on your behalf is bound by an enforceable duty of confidentiality that survives the end of their engagement, whether they are an employee or a contractor.
Access is limited to the people who need it to run the service. Staff access to a customer workspace is possible only through an administrative account that is protected by two-factor authentication, and every use of it is written to an audit trail that you can request.
9. Security of processing
We implement appropriate technical and organisational measures under Article 32. The measures in force are published in full on our security page and are summarised here. We may change a measure, but not in a way that materially reduces the protection given to your data.
- Encryption of personal data in transit over TLS and at rest in the database and document storage.
- Tenant isolation enforced at the database itself through row level security, so a query carrying one workspace's identity cannot read another's, in addition to the checks in the application.
- Role-based access control inside each workspace, with a workspace-level setting that makes two-factor authentication mandatory for every member.
- Two-factor authentication using time-based one-time passwords, with single-use recovery codes, and mandatory two-factor for every member of our own staff who can reach customer data.
- An append-only audit trail of reads and writes to customer records, exportable by an administrator.
- Documented restore testing of backups, so recovery is a rehearsed procedure rather than an assumption.
- Separate development and production environments, with no customer data in development.
- Penetration testing of the platform, delegated to an external specialist firm, with findings tracked to closure.
- Application error reporting configured to exclude request bodies, cookies, headers and session recordings, with secret values scrubbed before transmission.
10. Sub-processors
You give us general written authorisation to engage sub-processors. The current list, with what each one does, which data reaches it and where it runs, is published at /security/sub-processors and forms part of this agreement.
Before we add or replace a sub-processor we publish the change on that page and notify workspace administrators by email at least thirty days before it takes effect.
You may object to a change on reasonable data protection grounds within those thirty days by writing to support@relynt.io. We will work with you to find a solution. If we cannot, you may terminate the affected subscription and we will refund the unused part of any prepaid term. Objecting costs you nothing.
We impose on every sub-processor, by written contract, data protection obligations no less protective than those in this agreement, and we remain fully liable to you for their performance.
11. International transfers
The platform runs in the European Union. The database, authentication and document storage are in Frankfurt, the application servers are in Frankfurt, and error reporting stays in the European Union. In ordinary use your workspace content does not leave the EU.
Two sub-processors are in the United States. Transactional email goes through Resend, which receives a recipient address and the contents of that message, never workspace records. Model-assisted contract review, if you enable it, sends document text to Anthropic.
Those transfers are made under the European Commission's standard contractual clauses of 4 June 2021, module three, controller to processor to processor, together with supplementary measures including encryption in transit and minimisation of what is sent. We will provide the executed clauses and our transfer impact assessment on request.
If you do not wish any personal data to leave the European Union, leave model-assisted review switched off, which is its default state. Email cannot be disabled, because it carries sign-in and invitation messages the service cannot function without.
12. Assisting you with data subject rights
Most requests you receive can be answered without us. An administrator can search, correct, export and delete records directly in the product, and can export the entire workspace as a single file. That is deliberate: it is faster for you and it means fewer people touch the data.
Where a request cannot be satisfied through the product, we assist you by appropriate technical and organisational measures, taking into account the nature of the processing. We answer such a request within ten business days and sooner where your own statutory deadline requires it. We do not charge for this.
If a data subject contacts us directly about data in your workspace, we do not respond to the substance. We tell them to contact you, and we tell you promptly that they approached us.
13. Assisting you with security, breaches and assessments
Taking into account the nature of the processing and the information available to us, we assist you in meeting your obligations under Articles 32 to 36: security of processing, breach notification to a supervisory authority and to data subjects, data protection impact assessments, and prior consultation.
For a data protection impact assessment we provide the description of our processing, our security measures, our sub-processor list and our transfer mechanisms. We do not complete the assessment for you, because the risk being assessed is the risk of your processing, which only you can weigh.
14. Personal data breach
We notify you without undue delay, and in any event within twenty-four hours, after confirming a personal data breach affecting personal data we process for you. Notification goes by email to the administrators of the affected workspace.
The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the time window affected, the likely consequences, the measures we have taken or propose to take, and a named contact. Where we cannot provide all of it at once we provide it in phases, without further undue delay.
We give you what a financial entity needs for its own incident classification and reporting under Regulation (EU) 2022/2554. We do not classify or report on your behalf, and we do not notify a supervisory authority or a data subject on your behalf, because those are the controller's decisions.
Our full severity model and response process is published at /security/incident-response.
15. Deletion and return
At any time during the subscription an administrator can export the whole workspace as a single file, and can delete the workspace permanently. Export continues to work while a workspace is read-only for non-payment, so a billing dispute never becomes a hostage situation.
At the end of the relationship you choose whether we return or delete the personal data. If you tell us nothing, we delete the workspace and its contents thirty days after the subscription ends. Backups containing it age out within a further thirty-five days.
Where a trial ends and no subscription follows, we warn the administrators by email before deleting anything, and the workspace is deleted only after that warning has had time to be acted on.
We retain personal data after that point only where Union or member state law requires it, for example billing records kept for ten years under accounting law. Anything so retained is kept only for that purpose and remains subject to the security measures in this agreement.
Our audit trail of what happened in a workspace is retained for the life of that workspace. You may configure a shorter period, but not shorter than twelve months, because a shorter one would defeat the evidential purpose the regulation expects it to serve.
16. Information and audit
We make available to you the information necessary to demonstrate compliance with Article 28, and we allow for and contribute to audits, including inspections, conducted by you or by an auditor you mandate.
In the first instance we answer with documentation: our security page, our sub-processor list, our incident response process, our penetration test summary, our restore testing records, and a completed security questionnaire on your own template. For most requests this is enough, and it is the fastest route for both of us.
Where documentation does not answer your question, you may audit us directly. We ask for thirty days' written notice, that an audit takes place during business hours, that it does not unreasonably disrupt the service, that anyone attending is bound by confidentiality, and that audits happen no more than once in any twelve-month period unless a supervisory authority requires otherwise or we have notified you of a breach. You bear your own costs and we bear ours.
Nothing in this section limits a right of access, inspection or audit that you, your auditor, or your competent authority holds under Regulation (EU) 2022/2554 or other mandatory law. Where that law gives a broader right than this section, that right applies.
An audit never extends to the data of another customer, and we will refuse a request that would expose it.
17. Relationship to DORA Article 30
We are an ICT third-party service provider to financial entities, so your contract with us has to carry the provisions that Article 30 of Regulation (EU) 2022/2554 requires. We have written them into our terms of service and this agreement rather than making you negotiate them in, and we are glad to walk through the mapping with your procurement team.
That includes a clear description of the service and its locations, the requirement that we give notice before materially changing where or how the service is provided, our security and availability commitments, our incident notification obligations, our assistance at no additional cost when an ICT incident concerns you, our obligation to cooperate with your competent authorities, termination rights, and the exit support described below.
On exit, we support an orderly transfer: your data is exportable in a documented, machine-readable format at any time without our involvement, and we will keep your workspace available for a reasonable transition period on request so that migration is not a cliff edge.
Where you classify us as supporting a critical or important function, tell us. Some Article 30(3) provisions depend on that classification, and we would rather record it in writing than have either of us assume.
18. Liability
Each party is liable for its own breach of this agreement. The limitations and exclusions of liability in our terms of service apply to this agreement as well, except where the GDPR or other mandatory law does not permit them, in which case that law governs.
Nothing in this agreement limits a data subject's rights or the liability either party has directly to a data subject under Article 82.
19. Changes to this agreement
We may update this agreement where the law changes, where our processing changes, or where a supervisory authority or a court gives guidance that requires it. For a change that materially affects your rights we notify workspace administrators by email at least thirty days before it takes effect.
Changes to the sub-processor list follow section 8 instead, which gives you a right to object.
The date at the top of this page is the date it last changed. Earlier versions are available on request.
20. Contact
Questions about this agreement, a request for an executed copy on your own paper, a copy of the standard contractual clauses, a completed security questionnaire, or anything else concerning how we handle personal data: support@relynt.io.
Requests about data in a customer workspace should go to the customer organisation that controls it, not to us. If you are not sure who that is, write to us and we will tell you.
This agreement supplements our terms of service and should be read with the privacy notice, the security page and the sub-processor list. Where it conflicts with the terms of service on anything concerning personal data, this agreement prevails.