Legal · Data Protection
Data Processing Agreement
PIEDAP Enterprise Innovation Ecosystem
Last Updated: 28 September 2026
Purpose of this DPA
This Data Processing Agreement ("DPA") forms part of the agreement between an enterprise customer and Pion Global Private Limited for use of PIEDAP and its platforms. It governs processing of Customer Personal Data by Pion Global as a processor / Data Processor on behalf of the Customer as controller / Data Fiduciary, where that relationship applies.
| Party / Item | Details |
|---|---|
| Processor / Service Provider | Pion Global Private Limited ('Pion Global') |
| Ecosystem | PIEDAP Enterprise Innovation Ecosystem |
| Platforms | GRCNest, NexGenQE, DPConsent, PIEStrat, EvalTiq and Talenaise |
| Customer | The entity identified in the applicable MSA, subscription agreement, order form, statement of work or other binding agreement |
| Effective Date | The effective date of the Agreement, or the date this DPA is accepted or executed, whichever applies |
| DPA Scope | Customer Personal Data processed by Pion Global on behalf of Customer in connection with the Services |
1.Scope and Relationship to the Agreement
This DPA is incorporated into and forms part of the master services agreement, subscription agreement, order form, statement of work, online terms or other written agreement governing Customer use of the Services (the "Agreement").
It applies only to the extent Pion Global processes Customer Personal Data on behalf of Customer. Pion Global may separately act as an independent controller / Data Fiduciary for limited business contact, account administration, billing, security, legal compliance, marketing or similar data as described in the applicable PIEDAP Privacy Policy.
If there is a conflict regarding processing of Customer Personal Data, the following order applies: applicable mandatory law and incorporated transfer clauses, this DPA, the Agreement, and then general documentation. Commercial terms such as fees and general liability remain governed by the Agreement except where this DPA or mandatory law expressly requires otherwise.
2.Definitions
| Term | Meaning |
|---|---|
| Applicable Data Protection Law | Any law applicable to the relevant processing of Customer Personal Data, including where applicable the EU GDPR, UK GDPR, India Digital Personal Data Protection Act and rules in force, Swiss data protection law, California privacy law and other applicable privacy or data protection laws. |
| Customer Personal Data | Personal data, personal information or digital personal data contained in Customer Data that Pion Global processes on Customer's behalf under the Services. |
| Customer Data | Data, content, records, files, configurations, prompts, submissions and other information provided to, generated in, or made available through the Services by or for Customer, excluding Pion Global's independent business records and de-identified service telemetry. |
| Data Subject / Data Principal | An identified or identifiable individual to whom Customer Personal Data relates. |
| Data Breach | A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. |
| Processor / Data Processor | A party that processes personal data on behalf of a controller / Data Fiduciary. |
| Subprocessor | A third party engaged by Pion Global to process Customer Personal Data in connection with the Services. |
| Services | The PIEDAP Enterprise Innovation Ecosystem, its six platforms, shared ecosystem capabilities, APIs, integrations and contracted support or professional services. |
3.Roles of the Parties
- Customer determines the purposes and essential means of processing Customer Personal Data and acts as controller, Data Fiduciary, business or equivalent responsible party under Applicable Data Protection Law, except where the parties expressly agree otherwise.
- Pion Global acts as processor, Data Processor, service provider or contractor when processing Customer Personal Data on documented Customer instructions. If Pion Global determines purposes and means outside those instructions for its own independent processing, it will act as controller / Data Fiduciary for that separate processing and the PIEDAP Privacy Policy will apply.
- Customer is responsible for ensuring it has a valid legal basis, authority and required notices or consents for Customer Personal Data submitted to the Services, including employee, customer, supplier, assessment, consent-management and other personal data.
4.Processing Instructions
Pion Global will process Customer Personal Data only on Customer's documented instructions, including the Agreement, this DPA, Customer configurations, API calls, authorized administrator actions, support requests and other written instructions, unless applicable law requires otherwise.
- If Pion Global believes an instruction infringes Applicable Data Protection Law, it may notify Customer and suspend the affected processing until the parties resolve the issue, unless prohibited by law.
- Where law requires Pion Global to process Customer Personal Data beyond Customer instructions, Pion Global will inform Customer before processing unless legally prohibited from doing so.
5.Details of Processing
The subject matter, duration, nature, purpose, data types and categories of individuals are described in Schedule 1. Customer may further configure the Services, and such lawful configuration and use form part of Customer's documented instructions.
6.Confidentiality and Personnel
- Pion Global will limit access to Customer Personal Data to personnel and contractors who require access to perform the Services or meet legal obligations.
- Authorized personnel will be subject to confidentiality obligations or equivalent statutory duties.
- Pion Global will provide appropriate privacy and security awareness to personnel with relevant access.
- Customer remains responsible for provisioning and de-provisioning its own users and for maintaining appropriate permissions within Customer-controlled accounts.
7.Security Measures
Pion Global will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access, taking into account the state of the art, implementation costs, the nature and context of processing, and the risks to individuals.
The baseline controls are described in Schedule 2. Security measures may evolve as technology, threats and Services change, provided the overall level of protection is not materially reduced during the applicable subscription term.
8.Data Breach Management
Pion Global will notify Customer without undue delay after becoming aware of a confirmed Data Breach affecting Customer Personal Data for which Pion Global is acting as processor, unless notification is prohibited by law.
- Notice will include, to the extent known and reasonably available, the nature of the incident, affected data or individuals, likely consequences, mitigation steps and an appropriate incident contact.
- Pion Global will take reasonable steps to contain, investigate and remediate the incident and will provide reasonable cooperation needed for Customer to meet applicable notification obligations.
- Notification of an incident does not constitute an admission of fault or liability.
Customer is responsible for determining whether notification to regulators, Data Subjects / Data Principals, customers or other parties is legally required, except where Pion Global has an independent legal notification obligation.
9.Data Subject and Data Principal Rights
Taking into account the nature of the processing, Pion Global will provide reasonable assistance through available product functionality and support channels to help Customer respond to requests to exercise applicable privacy rights, including access, correction, deletion, restriction, objection, portability, consent withdrawal or grievance rights where applicable.
If Pion Global receives a request directly concerning Customer Personal Data, it will not respond substantively on Customer's behalf unless authorized or legally required. Where reasonably possible, Pion Global will refer the requester to Customer or notify Customer of the request.
10.Assistance With Compliance Obligations
Taking into account the nature of processing and information available to Pion Global, Pion Global will provide reasonable assistance with Customer obligations relating to security, Data Breach assessment, data protection impact assessments, prior consultation with regulators, records of processing and other processor-assistance obligations required by Applicable Data Protection Law.
If assistance requires substantial work outside normal Service functionality or support, the parties may agree reasonable professional-services fees unless the need results from Pion Global's material breach of this DPA.
11.Subprocessors
Customer provides general written authorization for Pion Global to engage Subprocessors necessary to provide the Services, subject to this section.
- Pion Global will maintain a current Subprocessor List or equivalent Trust Center disclosure identifying material Subprocessors that process Customer Personal Data.
- Pion Global will impose written data protection obligations on each Subprocessor that provide a level of protection appropriate to the processing and materially consistent with applicable processor obligations under this DPA.
- Pion Global remains responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Law and the Agreement.
- Pion Global will provide reasonable advance notice of a material new Subprocessor where required by law or agreed contractually. Customer may raise a reasonable, documented data protection objection within the stated notice period. The parties will work in good faith on a commercially reasonable resolution.
Customer-specific third parties enabled, selected or instructed directly by Customer, including customer-managed connectors or external applications, are not Pion Global Subprocessors merely because the Services interoperate with them.
12.International Data Transfers
Pion Global will ensure that international transfers of Customer Personal Data are made in accordance with Applicable Data Protection Law. Depending on the relevant jurisdictions, this may include adequacy decisions, statutory transfer mechanisms, Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, recognized certifications, or other lawful safeguards.
12.1 EEA Standard Contractual Clauses
Where Customer Personal Data subject to the EU GDPR is transferred to Pion Global or a Subprocessor in a third country and no other valid transfer mechanism applies, the European Commission Standard Contractual Clauses adopted under Decision (EU) 2021/914 are incorporated by reference. Module 2 (Controller to Processor) or Module 3 (Processor to Processor) applies according to the parties' roles. The information in Schedules 1 to 3 of this DPA will populate the corresponding SCC annex information to the extent applicable.
12.2 United Kingdom and Switzerland
For restricted transfers subject to UK law, the applicable UK transfer addendum or other valid UK transfer mechanism will supplement the EU SCCs where appropriate. For Swiss-restricted transfers, the SCCs will be interpreted and adapted as required by applicable Swiss data protection law.
12.3 Transfer Assessments
Pion Global will provide reasonable information available to it to support legally required transfer assessments and will implement supplementary safeguards where appropriate to the risk and required by law.
13.Government and Law-Enforcement Requests
If Pion Global receives a legally binding request from a public authority for Customer Personal Data, Pion Global will, where legally permitted, notify Customer before disclosure, review the request for legal validity, seek to limit disclosure to what is legally required, and challenge requests that Pion Global reasonably considers unlawful where an effective legal basis exists to do so.
14.Artificial Intelligence and Automated Processing
PIEDAP may provide AI-assisted functionality across the ecosystem, including copilots, analytics, recommendations, summarization, planning, assessment, testing, compliance and workflow automation. Where Customer Personal Data is processed through such features, it remains subject to this DPA.
- Customer controls whether and how authorized users submit Customer Personal Data to AI-enabled features, subject to Service configuration and the Agreement.
- Pion Global will not use Customer Personal Data to train shared or general-purpose AI models for unrelated customers unless Customer expressly authorizes that use through a contract, product setting or other documented instruction.
- If a third-party AI provider processes Customer Personal Data on Pion Global's behalf, that provider will be treated as a Subprocessor where required.
- AI outputs may be probabilistic and should be reviewed appropriately. Customer remains responsible for decisions made using AI outputs, particularly legal, compliance, employment, audit, risk or other high-impact decisions.
- Pion Global may use de-identified or aggregated telemetry that does not identify Customer or individuals to improve service reliability, security and general product performance, subject to the Agreement and applicable law.
15.Platform-Specific Processing Considerations
| Platform | Processing Considerations |
|---|---|
| GRCNest | May process governance, risk, compliance, control, audit, policy, evidence, incident, third-party and related user/account data. Customer determines frameworks, scope, evidence and authorized users. |
| NexGenQE | May process software quality, testing, defect, release, engineering, repository/integration metadata and user/account data. Customer determines connected systems and test data supplied to the platform. |
| DPConsent | May process consent records, privacy preferences, Data Principal interactions, notices, request records and related identifiers. Customer ordinarily determines the legal basis and purposes of consent/privacy operations and remains the Data Fiduciary/controller unless separately agreed. |
| PIEStrat | May process project, portfolio, program, task, resource, risk, dependency, document, collaboration and related user data. |
| EvalTiq | May process assessment responses, evidence, scores, maturity/gap results, survey responses and evaluator/respondent data configured by Customer. |
| Talenaise | May process employee or workforce competency, skills, performance, 360-degree feedback and evaluator data. Customer is responsible for lawful workplace use, notices, access controls and employment decisions. |
16.Special Categories, Sensitive Data and Regulated Data
Customer will not submit special-category, sensitive, highly regulated or legally restricted data unless the relevant Service is designed and contractually approved for that data and Customer has satisfied applicable legal requirements. Where such processing is agreed, the parties may document additional safeguards, instructions or sector-specific terms.
Unless separately agreed in writing, the Services are not intended to create an independent obligation for Pion Global to comply with a sector-specific regulated-data regime solely because Customer uploads data associated with that regime.
17.California and Similar U.S. Privacy Requirements
Where Pion Global processes personal information as a service provider or contractor under the California Consumer Privacy Act, as amended, or a materially similar state law, Pion Global will process that information only for the limited and specified business purposes described in the Agreement and Customer instructions; will not sell or share the personal information as those terms are defined by applicable law; and will not retain, use or disclose it outside the direct business relationship except as permitted by law.
Pion Global will not combine Customer Personal Data with personal information received from another person or collected from Pion Global's own interactions with an individual except where permitted by applicable law and necessary to provide the Services.
18.Audit and Demonstration of Compliance
Pion Global will make available information reasonably necessary to demonstrate compliance with this DPA and applicable processor obligations. Pion Global may satisfy routine diligence through security questionnaires, policies, independent audit reports, certifications, penetration-test summaries, Trust Center materials or similar documentation where available.
If such materials are insufficient for a reasonable, documented compliance need, Customer may request an audit no more than once in any 12-month period, except following a material Data Breach, regulatory requirement or reasonable evidence of material non-compliance. Audits will be subject to reasonable notice, confidentiality, security and non-disruption requirements and will not require disclosure of information that would compromise other customers, Pion Global security, privileged information or third-party confidentiality.
Customer will bear reasonable audit costs unless the audit identifies Pion Global's material breach of this DPA, in which case responsibility for reasonable costs will be addressed under the Agreement and applicable law.
19.Data Return, Deletion and Portability at Termination
During the subscription term, Customer may use available export functionality or request reasonable assistance to retrieve Customer Data, subject to the Agreement and technical capabilities.
Following termination or expiry, Pion Global will, at Customer's choice and subject to applicable law, delete or return Customer Personal Data within the period specified in the Agreement or, if none is specified, within a commercially reasonable period. Copies retained in backups may remain until normal backup rotation, provided they remain protected and are not restored except for disaster recovery, legal obligation or security purposes.
Pion Global may retain limited records where required by law, to establish or defend legal claims, or for legitimate security and financial-record purposes, provided such retained data remains protected and is not used for unrelated purposes.
20.Customer Responsibilities
- Provide lawful, documented instructions and ensure Customer use of the Services complies with Applicable Data Protection Law.
- Provide required notices and obtain consents or other lawful bases where necessary.
- Configure access controls, roles, retention, integrations and privacy settings appropriately for Customer's use case.
- Avoid uploading unnecessary personal data and apply data minimization, especially to free-text fields, AI prompts, test data and attachments.
- Respond to Data Subjects / Data Principals and regulators as the responsible controller / Data Fiduciary, with Pion Global assistance as required by this DPA.
- Assess the legality and appropriateness of employment, profiling, monitoring, automated decision-making, consent-management and other high-impact uses configured by Customer.
21.Liability
Each party remains responsible for its own obligations under Applicable Data Protection Law. Except to the extent prohibited by mandatory law or applicable Standard Contractual Clauses, liability arising from this DPA is subject to the exclusions, limitations and allocation of liability in the Agreement.
22.Term and Survival
This DPA remains in effect for as long as Pion Global processes Customer Personal Data on behalf of Customer. Provisions that by their nature should survive, including confidentiality, deletion, audit, international transfer, liability and security obligations for retained data, will survive termination for the relevant period.
23.Changes to this DPA
Pion Global may update this DPA to reflect changes in law, regulatory guidance, Services or security practices. Changes that materially reduce Customer data protection rights during a committed subscription term will not apply retroactively unless required by law or agreed by the parties. Where the DPA is separately signed, amendments will follow the amendment mechanism in the Agreement.
24.Notices and Contact
| Item | Details |
|---|---|
| Processor | Pion Global Private Limited |
| Ecosystem | PIEDAP Enterprise Innovation Ecosystem |
| Privacy / DPA Contact | [email protected] |
| Website | https://www.piedap.io |
| Business Address | 48, 4th B Main, Classic Paradise Layout, Begur Road, Bengaluru, Karnataka, India |
| Customer Notices | As specified in the Agreement or Order Form |
Schedules
Schedule 1 — Processing Details
A. Subject Matter and Duration
Processing of Customer Personal Data necessary to provide, secure, support, maintain and improve the contracted PIEDAP Services for the duration of the Agreement, including any agreed post-termination retention or transition period.
B. Nature and Purpose of Processing
- Hosting, storage, retrieval, organization, structuring and display of Customer Data.
- Workflow execution, analytics, reporting, dashboards, notifications and collaboration.
- AI-assisted analysis, recommendations, summarization, testing, assessment, planning, compliance and automation configured by Customer.
- Authentication, authorization, security monitoring, audit logging, troubleshooting, support and service administration.
- Integration with Customer-authorized external systems, APIs and partner applications.
C. Categories of Data Subjects / Data Principals
- Customer employees, contractors, consultants, administrators and platform users.
- Customer customers, prospects, suppliers, vendors, partners and other business contacts where Customer chooses to process such data.
- Data Principals whose consent, preference or privacy-request information is managed through DPConsent.
- Assessment respondents, evaluators, auditees, survey participants and evidence owners in EvalTiq or GRCNest.
- Employees, managers, peers, direct reports and other evaluators in Talenaise.
- Developers, testers and engineering users in NexGenQE; project/program participants in PIEStrat.
D. Types of Personal Data
- Identity and contact data: name, business email, username, organization, role and contact details.
- Account and access data: user IDs, role/permission data, authentication metadata and session/security logs.
- Business and operational data: projects, tasks, controls, risks, audits, evidence, defects, tests, assessments, consent records and workflow data where linked to individuals.
- Workforce data: competency, skills, performance, 360-degree feedback, evaluation and development information where Customer uses Talenaise.
- Technical data: IP address, device/browser information, API identifiers, integration logs and audit trails.
- AI interaction data: prompts, submitted context, generated outputs and associated metadata to the extent they contain personal data.
- Any other personal data Customer lawfully chooses to submit within the contracted Service configuration.
E. Special Categories / Sensitive Data
Not required by default. Such data may be processed only where Customer lawfully chooses to submit it and the applicable Service, Agreement and security controls support that use. Customer is responsible for identifying sensitive data and applying required legal safeguards.
F. Processing Frequency
Continuous or event-driven during Customer use of the Services, depending on Customer activity, integrations, workflows and configured automation.
Schedule 2 — Technical and Organizational Measures
| Control Domain | Baseline Measures |
|---|---|
| Governance & Security Management | Documented security responsibilities, risk-based security governance, policies and periodic review appropriate to the Services. |
| Identity & Access Management | Role-based or least-privilege access, authentication controls, privileged-access restriction, periodic access review and de-provisioning processes. |
| Encryption & Transmission Security | Encryption or secure protocols for data in transit and appropriate encryption or equivalent protective controls for stored data, based on service architecture and risk. |
| Tenant & Environment Segregation | Logical segregation of customer environments and authorization controls designed to prevent unauthorized cross-tenant access. |
| Secure Development | Secure development practices, code review, dependency management, change control, testing and release controls appropriate to the software development lifecycle. |
| Vulnerability Management | Vulnerability identification, prioritization, remediation processes, security testing and responsible vulnerability reporting mechanisms. |
| Logging & Monitoring | Security, administrative and audit logging appropriate to the Service; monitoring and alerting designed to detect suspicious or unauthorized activity. |
| Incident Response | Incident identification, containment, investigation, remediation, communication and post-incident improvement procedures. |
| Availability & Resilience | Backup, recovery, continuity and resilience measures appropriate to contracted deployment and service architecture. |
| Personnel Security | Confidentiality commitments, access based on role and security/privacy awareness for relevant personnel. |
| Vendor & Subprocessor Risk | Due diligence and contractual controls for material service providers that process Customer Personal Data. |
| Data Lifecycle | Controls supporting retention, deletion, backup management and secure disposal appropriate to the Agreement and service capabilities. |
| AI & Automation Controls | Access controls, logging, data-handling restrictions and human oversight expectations for AI-enabled or agentic functions where applicable. |
Schedule 3 — Subprocessor and Transfer Information
Pion Global will maintain the current Subprocessor List through a designated Trust Center, legal page, customer portal or equivalent disclosure. The list should identify, at a minimum, the Subprocessor name, processing purpose and relevant processing location or region where appropriate.
For a Customer requiring a signed annex, the then-current Subprocessor List may be attached to or incorporated into this Schedule by reference. If a specific subprocessor notice period or objection procedure is negotiated in an Order Form or MSA, that negotiated term will control.
Schedule 4 — International Transfer Terms
| Scenario | Transfer Mechanism / Treatment |
|---|---|
| EEA controller to Pion Global processor outside EEA | EU SCCs, Module 2, unless another valid mechanism applies. |
| EEA processor to Pion Global subprocessor outside EEA | EU SCCs, Module 3, unless another valid mechanism applies. |
| UK restricted transfer | Applicable UK International Data Transfer Addendum / Agreement or other valid UK mechanism. |
| Swiss restricted transfer | EU SCCs with Swiss-law adaptations where required, or another valid Swiss transfer mechanism. |
| India or other jurisdictions | Transfers handled in accordance with applicable statutory restrictions, government notifications and lawful transfer mechanisms in force. |
Schedule 5 — Signature / Acceptance
This DPA may be accepted by signature, electronic acceptance, incorporation by reference into an Agreement or other legally valid method permitted by the Agreement.
CUSTOMER
Name / Entity:
Authorized Signatory:
Date:
PION GLOBAL PRIVATE LIMITED
Name:
Authorized Signatory:
Date: