info@cetonix.com +91 (966) 512-1196 Mon–Fri, 09:30–18:00 IST
HomeData Transfer Addendum

Data Transfer Addendum

Cetonix processes engagement data in India. These are the terms that govern personal data reaching us from the EEA, the UK, Switzerland, Canada and the United States.

This Addendum supplements our Data Processing Agreement and applies wherever personal data is transferred to Cetonix from a jurisdiction that restricts international transfers. It is published in full so your privacy counsel can assess us before any credentials change hands.

Version 1.0 · Effective 1 October 2025.

1. Where your data goes

Cetonix is established in Pune, Maharashtra, India. Engagement data is processed and stored in India on infrastructure Cetonix controls. We say this plainly rather than burying it, because it is material to your assessment and you will find it out anyway.

India is not the subject of an adequacy decision by the European Commission or the UK Government. Transfers therefore rely on the mechanisms below.

2. EEA transfers — Standard Contractual Clauses

For personal data originating in the European Economic Area, the parties enter into the European Commission’s Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two: controller to processor, which are incorporated by reference with the following selections:

  • Clause 7 (docking): applicable.
  • Clause 9 (sub-processors): Option 2, general written authorisation, with a minimum 30 days’ notice. As set out in our sub-processor list, no sub-processor currently accesses engagement data.
  • Clause 11 (redress): the optional independent dispute resolution language is not adopted.
  • Clause 17 (governing law): the law of Ireland.
  • Clause 18 (forum): the courts of Ireland.
  • Annex I, II and III: populated by the details in our DPA sections 2, 5 and 7 respectively.

3. UK transfers

For personal data subject to the UK GDPR, the parties enter into the International Data Transfer Addendum to the EU SCCs (version B1.0, issued by the ICO), with Tables 1 to 4 populated by reference to this Addendum and the DPA. Neither party may terminate under Section 19 of the IDTA other than as provided in the DPA.

4. Swiss transfers

For personal data subject to the Swiss Federal Act on Data Protection, the SCCs apply with the amendments recognised by the Swiss Federal Data Protection and Information Commissioner: references to the GDPR are read as references to the FADP, the competent authority is the FDPIC, and the Clauses also protect the data of legal entities until the FADP is amended to remove that protection.

5. Canadian transfers

For personal information subject to PIPEDA or a substantially similar provincial law, Cetonix acts as a service provider processing on the transferring organisation’s behalf. The organisation remains accountable for the information; Cetonix provides a comparable level of protection through the contractual and technical measures in the DPA and this Addendum.

6. United States

Where the Controller is subject to US state privacy law, Cetonix acts as a service provider or processor under the terms in DPA section 12. Cetonix does not sell or share personal information and does not combine it with data from other sources.

7. Transfer impact assessment

We provide a completed transfer impact assessment on request, covering:

  • The categories of data transferred and the purpose of the transfer.
  • Indian legal provisions relevant to government access to data held by private entities, including the Information Technology Act 2000 and the Digital Personal Data Protection Act 2023, and the procedural conditions attaching to any such access.
  • Whether Cetonix has ever received a government access request relating to client data. To date, we have received none.
  • The supplementary measures in section 8 and our assessment of their effectiveness.

8. Supplementary measures

  • Encryption of engagement data at rest and in transit, with keys held solely by Cetonix and never by a hosting provider.
  • Minimisation at source. In a penetration test we do not receive a dataset. Personal data is encountered incidentally and, where a finding exposes records, they are counted and classified rather than copied. This is the strongest supplementary measure available in our line of work: the data largely never leaves your systems.
  • Short retention. Evidence and credentials are destroyed at the end of the retest window, or earlier on written request, with written confirmation.
  • Access control on a least-privilege basis, restricted to the assigned engagement team, logged and reviewed.
  • No onward transfer. No sub-processor, no AI service, no third party receives engagement data.
  • Transparency commitment. Cetonix will notify the Controller of any legally binding request for disclosure of personal data unless prohibited from doing so, will challenge requests that appear unlawful or overbroad, and will disclose only the minimum lawfully required.

9. Data localisation

Where your contract, regulator or internal policy requires that engagement data remain in a specific jurisdiction, raise it at scoping. Depending on the engagement we may be able to work entirely inside infrastructure you provide and control, so that no engagement data leaves your environment at any point. We confirm in writing what is achievable before contracting, not after.

10. Precedence

Where this Addendum conflicts with the DPA or the master services agreement on international transfers, this Addendum prevails. Where the SCCs or the UK IDTA conflict with either, the SCCs or IDTA prevail. Where the Controller’s own transfer terms are executed, those prevail over this Addendum.

Please have this reviewed by your own counsel before signature. It is a template drafted for common engagement types, not legal advice. Request a signable copy via our contact form or privacy@cetonix.com.