ETOS GateKeeperETOS GateKeeper

Legal

Data Processing Agreement

The controller–processor terms on which Sunday Machine Ltd processes customer personal data through ETOS GateKeeper.

Version 1.0 — 16 September 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between Sunday Machine Ltd, a company registered in England and Wales under company number 11935976, whose registered office is at 10A The Rock, Bury, BL9 0NT, United Kingdom (“ETOS”, “Processor”, “we”, “us”); and the customer identified in the applicable order form, subscription, pilot agreement, statement of work or other agreement for ETOS GateKeeper services (“Customer” or “Controller”). Together, the “Parties”.

1. Purpose and scope

1.1 This DPA applies where ETOS processes Personal Data on behalf of the Customer in connection with the provision of ETOS GateKeeper.

1.2 This DPA supplements the agreement under which the Customer obtains access to or uses ETOS GateKeeper (“Agreement”).

1.3 In relation to Personal Data processed by ETOS on behalf of the Customer: (a) the Customer is the Controller; and (b) Sunday Machine Ltd is the Processor, unless the Parties expressly agree otherwise in writing.

1.4 This DPA does not apply to processing for which Sunday Machine Ltd acts independently as Controller, including appropriate business administration, contractual, billing, security and compliance processing. Such processing is governed by the ETOS GateKeeper Privacy Policy and applicable Data Protection Law.

2. Definitions

Data Protection Law means applicable UK laws governing the processing of Personal Data, including the UK GDPR and Data Protection Act 2018, as amended or replaced from time to time.

Personal Data, Controller, Processor, Data Subject, Processing, Personal Data Breach and Supervisory Authority have the meanings given to them under applicable Data Protection Law.

Customer Data means Personal Data processed by ETOS on behalf of the Customer through ETOS GateKeeper.

Subprocessor means a third party appointed by ETOS to process Customer Data on behalf of the Customer.

3. Processing instructions

3.1 ETOS shall process Customer Data only: (a) on the Customer's documented instructions; (b) as necessary to provide, secure, support and maintain the ETOS GateKeeper services in accordance with the Agreement; or (c) where required by applicable law.

3.2 The Agreement, this DPA, the Customer's configuration and use of the service, and other documented instructions accepted by ETOS constitute the Customer's documented instructions.

3.3 Where ETOS is required by law to process Customer Data other than on the Customer's instructions, ETOS shall inform the Customer of that legal requirement before processing unless prohibited by law.

3.4 ETOS shall inform the Customer if, in its reasonable opinion, an instruction infringes applicable Data Protection Law.

4. Details of processing

The subject matter, nature, purpose and duration of processing, together with the relevant categories of Personal Data and Data Subjects, are described in Schedule 1.

5. Customer responsibilities

5.1 The Customer is responsible for: (a) ensuring that it has a lawful basis for the collection and processing of Customer Data; (b) providing all notices and obtaining any consents required by Data Protection Law; (c) ensuring its instructions to ETOS comply with Data Protection Law; (d) determining whether ETOS GateKeeper is appropriate for the Customer's intended processing and risk profile; and (e) avoiding the submission of Personal Data that is unnecessary for the relevant assurance purpose.

5.2 The Customer remains responsible for determining the purposes and essential means of its processing of Customer Data.

6. Confidentiality

6.1 ETOS shall ensure that persons authorised to process Customer Data: (a) process it only as necessary to perform their duties; and (b) are subject to appropriate contractual or statutory obligations of confidentiality.

7. Security

7.1 Taking into account the state of the art, implementation costs, nature, scope, context and purposes of processing, and the risks to individuals, ETOS shall maintain appropriate technical and organisational measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

7.2 Those measures shall be proportionate to the risks presented by the processing.

7.3 ETOS may update its technical and organisational measures from time to time, provided that such changes do not materially reduce the overall protection afforded to Customer Data.

7.4 Nothing in this DPA represents that ETOS holds a security certification or independent audit attestation unless expressly identified as such in current ETOS documentation.

8. Personal Data Breaches

8.1 ETOS shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data.

8.2 Where reasonably available, notification shall include information necessary to assist the Customer in meeting its obligations under applicable Data Protection Law, including: (a) the nature of the breach; (b) categories of affected Personal Data and Data Subjects; (c) likely consequences; (d) measures taken or proposed to address or mitigate the breach; and (e) an appropriate contact for further information.

8.3 Where complete information is not immediately available, ETOS may provide information in phases as it becomes available.

8.4 Notification of a Personal Data Breach does not constitute an admission of fault or liability.

9. Data Subject rights

9.1 Taking into account the nature of the processing, ETOS shall provide reasonable assistance to enable the Customer to respond to requests by Data Subjects exercising their rights under applicable Data Protection Law.

9.2 If ETOS receives a Data Subject request relating to Customer Data for which the Customer is Controller, ETOS shall, where legally permitted, direct the request to the Customer or notify the Customer and shall not independently respond except on the Customer's documented instructions or as required by law.

10. Assistance with compliance

Taking into account the nature of processing and information available to ETOS, ETOS shall provide reasonable assistance to the Customer with its applicable obligations relating to: (a) security of processing; (b) Personal Data Breach assessment and notification; (c) data protection impact assessments; and (d) prior consultation with a Supervisory Authority where required.

11. Subprocessors

11.1 The Customer provides general written authorisation for ETOS to engage Subprocessors necessary to provide ETOS GateKeeper.

11.2 ETOS shall maintain information identifying its material Subprocessors and their processing purposes and make that information available to Customers through its published documentation or another reasonable mechanism.

11.3 ETOS shall impose data-protection obligations on each Subprocessor that provide an equivalent level of protection for Customer Data, as required by applicable Data Protection Law.

11.4 ETOS remains responsible to the Customer for the performance of its Subprocessors' applicable data-protection obligations to the extent required by Data Protection Law.

11.5 ETOS shall provide reasonable notice of material new or replacement Subprocessors where required by Data Protection Law, giving the Customer a reasonable opportunity to raise a legitimate data-protection objection.

11.6 If the Parties cannot reasonably resolve such an objection, either Party may exercise any applicable termination rights under the Agreement in respect of the affected service.

12. International transfers

12.1 ETOS shall not make a restricted transfer of Customer Data contrary to applicable Data Protection Law.

12.2 Where a restricted international transfer requires an appropriate safeguard, the Parties shall implement an applicable lawful transfer mechanism before that transfer, which may include: (a) the UK International Data Transfer Agreement (“IDTA”); (b) the UK International Data Transfer Addendum to the European Commission Standard Contractual Clauses; or (c) another lawful mechanism recognised under applicable Data Protection Law.

12.3 Where required, the Parties shall cooperate in completing any applicable transfer risk assessment and implementing supplementary measures reasonably necessary for the transfer.

13. Return and deletion

13.1 Customer Data shall be retained only for as long as necessary to provide the services, satisfy the Customer's documented instructions, or comply with applicable legal obligations.

13.2 On termination or expiry of the relevant service, ETOS shall, at the Customer's choice and subject to applicable law: (a) return Customer Data in a reasonably available format; or (b) delete Customer Data, and shall delete remaining copies unless applicable law requires continued storage.

13.3 Where immediate deletion from backup systems is not technically practicable, Customer Data may remain in protected backups until overwritten or deleted in accordance with the applicable backup-retention cycle, during which time it shall remain protected and shall not be processed for other purposes except as required for recovery or by law.

14. Audit and compliance information

14.1 ETOS shall make available to the Customer information reasonably necessary to demonstrate compliance with its obligations under Article 28 of the UK GDPR.

14.2 Subject to appropriate confidentiality, security and operational safeguards, ETOS shall allow for and contribute to reasonable audits or inspections by the Customer or an independent auditor appointed by the Customer where necessary to demonstrate compliance with this DPA.

14.3 Where appropriate, the Parties should first seek to satisfy an audit request through available documentation, questionnaires, security information and other relevant evidence before requiring an on-site inspection.

14.4 Audits shall, unless required following a material incident or by a Supervisory Authority: (a) be conducted on reasonable prior notice; (b) occur during normal business hours; (c) avoid unreasonable disruption to ETOS or other customers; (d) not expose another customer's confidential information or Personal Data; and (e) be subject to reasonable confidentiality and security requirements.

15. Regulatory cooperation

ETOS shall cooperate reasonably with the Customer where information concerning processing under this DPA is lawfully required by the Information Commissioner's Office or another competent Supervisory Authority.

16. Records and evidence

ETOS shall maintain records relating to its processing activities as required by applicable Data Protection Law and shall provide information reasonably necessary to demonstrate compliance with this DPA.

17. Liability

The liability of each Party arising from this DPA is subject to the liability provisions of the Agreement except to the extent that such limitation is prohibited by applicable Data Protection Law.

Nothing in this DPA excludes or limits any liability that cannot lawfully be excluded or limited.

18. Order of precedence

If there is a conflict concerning the protection or processing of Personal Data between (a) this DPA and (b) the Agreement, this DPA prevails to the extent of that conflict.

Where an applicable mandatory international transfer mechanism conflicts with this DPA, the mandatory transfer provisions prevail in relation to the relevant transfer.

19. Changes in law

The Parties shall cooperate in good faith to amend this DPA where reasonably necessary to maintain compliance with changes to applicable Data Protection Law.

20. Governing law

This DPA is governed by the laws of England and Wales.

The courts of England and Wales shall have exclusive jurisdiction, subject to any mandatory rights or jurisdiction arising under applicable Data Protection Law.

Schedule 1 — Details of Processing

1. Subject matter

Provision of ETOS GateKeeper decision-assurance, evidence, governance, authority, audit and related platform services to the Customer.

2. Nature and purpose

  • provide and operate ETOS GateKeeper;
  • receive and process Customer-submitted assurance requests and supporting evidence;
  • perform configured assurance and governance workflows;
  • maintain decision, evidence, authority and audit records;
  • administer Customer accounts and authorised users;
  • provide security, support and service administration; and
  • meet documented Customer instructions associated with the service.

3. Duration

For the duration of the Customer's use of ETOS GateKeeper and any subsequent retention period required by documented Customer instructions, the Agreement or applicable law.

4. Categories of Data Subjects

Depending on the Customer's use of ETOS GateKeeper:

  • Customer employees;
  • officers and authorised decision-makers;
  • contractors;
  • reviewers;
  • platform users;
  • agents or representatives;
  • individuals identified in Customer-submitted evidence; and
  • other individuals whose Personal Data the Customer chooses to include in an assurance workflow.

5. Categories of Personal Data

Depending on Customer use:

  • names;
  • business contact information;
  • job title, role and organisation;
  • account and user identifiers;
  • authentication and access metadata;
  • decision and review identifiers;
  • audit and activity records;
  • evidence metadata;
  • correspondence and support information;
  • authority, reviewer and approval information; and
  • other Personal Data intentionally submitted by the Customer within evidence or assurance material.

6. Special-category and highly sensitive data

ETOS GateKeeper is not intended to require special-category Personal Data as part of ordinary service operation.

The Customer should not submit special-category Personal Data, criminal-offence data or other highly sensitive Personal Data unless its use is necessary, lawful, appropriate for the agreed service, and expressly supported by the applicable engagement and safeguards.

7. Processing frequency

Processing may occur continuously or as initiated by the Customer, its authorised users or authorised systems during the term of the service.

Schedule 2 — Technical and Organisational Measures

ETOS shall maintain measures appropriate to the risks associated with the service. These may include, as applicable:

  • authentication and access controls;
  • role-based or tenant-based authorisation;
  • separation of customer data;
  • encryption in transit;
  • appropriate encryption or provider-managed protection at rest;
  • secrets and credential management;
  • logging and audit trails;
  • controlled administrative access;
  • integrity and evidence-protection controls;
  • vulnerability management;
  • backup and recovery measures;
  • incident-management procedures;
  • change and release controls;
  • access review and least-privilege practices; and
  • testing and monitoring appropriate to the service.

The precise technical implementation may evolve over time provided the overall level of protection is not materially reduced. Nothing in this Schedule states that ETOS holds a security certification or independent audit attestation.

Schedule 3 — Subprocessors

The following material Subprocessors are used to provide ETOS GateKeeper. This list is maintained by ETOS from current production provider information and is updated when a material Subprocessor changes.

Lovable

Application hosting, database, file storage, transactional email delivery and AI model access used by the assistant and assurance features.

SumUp

Card payment processing for amounts charged in GBP.

Paystack

Card payment processing for amounts charged in Nigerian Naira.

Microsoft

Where a Customer uses the Microsoft integration, authenticated relay of assurance requests to the Customer's own Microsoft tenant, and marketplace activation records where access is obtained through Microsoft Marketplace.

Categories of data, processing locations and any applicable international-transfer safeguard for a specific engagement are confirmed in writing before onboarding. No provider, region or transfer safeguard is represented here unless supported by current evidence.

Contact

Sunday Machine Ltd

Company No. 11935976

10A The Rock, Bury, BL9 0NT, United Kingdom

VAT registration number GB 365 1366 93

Data protection: privacy@etosgatekeeper.com

Security reports: security@etosgatekeeper.com with the subject line SECURITY