Cetonix processes engagement data in India. These are the terms that govern personal data reaching us from the EEA, the UK, Switzerland, Canada and the United States.
This Addendum supplements our Data Processing Agreement and applies wherever personal data is transferred to Cetonix from a jurisdiction that restricts international transfers. It is published in full so your privacy counsel can assess us before any credentials change hands.
Version 1.0 · Effective 1 October 2025.
Cetonix is established in Pune, Maharashtra, India. Engagement data is processed and stored in India on infrastructure Cetonix controls. We say this plainly rather than burying it, because it is material to your assessment and you will find it out anyway.
India is not the subject of an adequacy decision by the European Commission or the UK Government. Transfers therefore rely on the mechanisms below.
For personal data originating in the European Economic Area, the parties enter into the European Commission’s Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two: controller to processor, which are incorporated by reference with the following selections:
For personal data subject to the UK GDPR, the parties enter into the International Data Transfer Addendum to the EU SCCs (version B1.0, issued by the ICO), with Tables 1 to 4 populated by reference to this Addendum and the DPA. Neither party may terminate under Section 19 of the IDTA other than as provided in the DPA.
For personal data subject to the Swiss Federal Act on Data Protection, the SCCs apply with the amendments recognised by the Swiss Federal Data Protection and Information Commissioner: references to the GDPR are read as references to the FADP, the competent authority is the FDPIC, and the Clauses also protect the data of legal entities until the FADP is amended to remove that protection.
For personal information subject to PIPEDA or a substantially similar provincial law, Cetonix acts as a service provider processing on the transferring organisation’s behalf. The organisation remains accountable for the information; Cetonix provides a comparable level of protection through the contractual and technical measures in the DPA and this Addendum.
Where the Controller is subject to US state privacy law, Cetonix acts as a service provider or processor under the terms in DPA section 12. Cetonix does not sell or share personal information and does not combine it with data from other sources.
We provide a completed transfer impact assessment on request, covering:
Where your contract, regulator or internal policy requires that engagement data remain in a specific jurisdiction, raise it at scoping. Depending on the engagement we may be able to work entirely inside infrastructure you provide and control, so that no engagement data leaves your environment at any point. We confirm in writing what is achievable before contracting, not after.
Where this Addendum conflicts with the DPA or the master services agreement on international transfers, this Addendum prevails. Where the SCCs or the UK IDTA conflict with either, the SCCs or IDTA prevail. Where the Controller’s own transfer terms are executed, those prevail over this Addendum.
Please have this reviewed by your own counsel before signature. It is a template drafted for common engagement types, not legal advice. Request a signable copy via our contact form or privacy@cetonix.com.