PEAK 15 Data Processing Addendum

Last Updated: 17th February 2026 


This Data Processing Addendum, including its Annexes (this “DPA”) forms an integral part of the Master Services Agreement (the “Agreement”) between Customer and PEAK 15 Systems, Inc. (“Provider”) and applies to the extent that Provider processes Customer Personal Data in the course of its performance under the Agreement. Provider shall have the right to update this DPA from time to time as needed to comply with Data Protection Laws.


1.        Definitions. Capitalized terms not otherwise defined in this DPA have the meaning given in the Agreement.


1.1      “Controller”, “Data Subject”, “Personal Data”, “Process/Processing”, “Processor”, “Sell”, “Service Provider”, “Share”, “Subprocessor”, and “Supervisory Authority” (and equivalent terms) have the meanings given to such terms in Data Protection Laws.


1.2      “Customer Personal Data” means any Personal Data that is provided to Provider by or on behalf of Customer to Provider for Processing on behalf of Customer or any Personal Data that Provider or any of its Subprocessors creates, collects, hosts, transmits or otherwise Processes on behalf of Customer.


1.3      “Data Protection Laws” means any and all privacy and data protection laws of Australia, Canada, the European Union, the European Economic Area and their member states, Switzerland, the United Kingdom, the United States of America, and any applicable data protection or privacy laws of any other country.


1.4      “Data Subject Request” means a request from a Data Subject to exercise any right under Data Protection Laws.


1.5      “FADP” means the Swiss Federal Data Protection Act of 19 June 1992 and its Ordinance, as may be amended, superseded, or replaced.


1.6      “GDPR” means EU General Data Protection Regulation, Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data, and repealing Directive 95/46/EC.


1.7      “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.


1.8      “Restricted Transfer” means a transfer of European Personal Data from Customer to Provider, to a jurisdiction outside of Europe which is not deemed to have “adequate safeguards” as set forth under GDPR, Art. 45(1); the UK GDPR; or the FADP.


1.9       “Services” means the services and other activities or deliverables to be supplied to or carried out by or on behalf of Provider for Customer pursuant to the Agreement.


1.10     “Standard Contractual Clauses” means standard contractual clauses annexed to the European Commission’s Decision (EU) 2021/914 of 4 June 2021 currently found at https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc/standard-contractual-clauses-international-transfers_en, as may be updated, amended, replaced, or superseded from time to time, set out in Annex I, amended as indicated in that Annex.


1.11     “UK GDPR” means the GDPR as transposed into United Kingdom national law by operation of section 3 of the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019.


1.12     “UK IDTA” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the UK Information Commissioner under Section 119A(1) Data Protection Act 2018, as may be updated, amended, replaced or superseded from time to time by the UK Government.


2.        Relationship of the Parties. The parties acknowledge that for the purpose of Data Protection Law, Customer is the Controller and Provider is the Processor.


3.        Instructions Regarding Processing of Customer Personal Data. Provider will ensure that it and each of its Subprocessors will: (a) comply with all Data Protection Laws when Processing Customer Personal Data; and (b) Process Customer Personal Data pursuant only to Customer’s written instructions unless Processing by Provider is required by Data Protection Laws. Without limiting the generality of the foregoing, Provider will not sell any Customer Personal Data to any third party. Customer’s instructions to Provider shall comply with Data Protection Laws. Customer shall have sole responsibility for the accuracy, quality, and legality of Customer Personal Data and the means by which Customer acquired Customer Personal Data. Annex I to this DPA sets out certain information regarding Provider’s Processing of Customer Personal Data as required by Data Protection Laws. Customer may make reasonable amendments to Annex I by written notice to Provider if Customer considers them necessary to meet those requirements. Nothing in Annex I (including as amended pursuant to the immediately preceding sentence) confers any right or imposes any obligation on any party to this DPA. Customer acknowledges that the Provider is under no duty to investigate the completeness, accuracy, or sufficiency of any specific Customer instructions related to processing or Customer Personal Data other than as required under Data Protection Laws.


4.        Customer Obligations. Customer represents, warrants and covenants that it has all necessary and legally required consents, permissions and rights to share or otherwise make available to Provider, Customer Personal Data. Customer further represents, warrants and covenants that it shall not input, upload or otherwise use the Services to process any special categories of Personal Data (as such term is defined in Data Protection Laws). In the event Customer breaches this provision, Customer, not Provider, shall be solely responsible for any and all damages and liabilities arising out of such breach. Customer’s instructions to Provider shall comply with Data Protection Laws. Customer shall have sole responsibility for the accuracy, quality, and legality of Customer Personal Data and the means by which Customer acquired Customer Personal Data. 


5.        Provider Personnel.  Provider will take reasonable steps to inform its employee, agent, or Provider contractor and any Subprocessor (“Personnel”) who may have access to Customer Personal Data of the confidential nature of Customer Personal Data, provide appropriate training to such Personnel on their responsibilities, limit access to those Personnel performing the Services in accordance with the Agreement, ensure the reliability of such Personnel, and ensure that all such Personnel are subject to obligations of confidentiality.


6.        Security.  Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk of varying likelihood and severity to the rights and freedoms of natural persons, including from a Personal Data Breach, Provider will implement appropriate technical and organizational measures designed to ensure a level of security for Customer Personal Data appropriate to that risk.


7.        Subprocessing. Customer hereby confirms its general written authorization for Provider’s use of Subprocessors listed at https://peak15systems.com/sub-processors-page/ provided that Provider and the relevant Subprocessor has entered into a written contract including terms which offer at least the same, if not more stringent level of protection for Customer Personal Data as those in this DPA. Customer may object to Provider’s use of a new Subprocessor by notifying Provider promptly in writing within ten (10) business days after receipt of Provider’s notice of engaging such Subprocessor (email notice or notice via website shall suffice). Provider shall remain fully liable to Customer for any breach of this DPA that arises out of or results from any act or omission of relevant Subprocessor.


8.        Data Subject Rights. Taking into account the nature of the Processing, Provider will provide timely assistance to Customer in connection with the fulfilment of Customer’s obligations to respond to Data Subject Requests and to respond to any correspondence or complaint received from a Data Subject, Supervisory Authority or other third party. Provider will promptly notify Customer if Provider or any of its Subprocessors receives a request from a Data Subject under any Data Protection Law regarding Customer Personal Data so Customer can meet its reporting obligations within the designated time period. Provider will not directly respond to a Data Subject Request except pursuant to Customer’s written instruction, unless legally compelled to do so.


9.        Personal Data Breaches. Provider will promptly notify Customer upon Provider or any Subprocessor becoming aware of a Personal Data Breach (and in any event, within 72 hours of becoming aware of such incident). Provider will provide Customer with information relating to the Personal Data Breach as reasonably requested by Customer to investigate such Personal Data Breach and assess its obligations under Data Protection Laws. Provider will use reasonable endeavours to assist Customer in mitigating, to the extent possible, the adverse effects of a Personal Data Breach.


10.        Data Protection Impact Assessment and Prior Consultation. Upon reasonable notice and subject to reasonable compensation, Provider will reasonably assist Customer with any data protection impact assessments. Provider will also timely assist Customer in consulting with Supervisory Authorities. Any assistance to Customer with regard to data protection impact assessments or prior consultations with Supervisory Authorities shall be solely at Customer’s expense.


11.        Deletion or Return of Customer Personal Data. Following expiration or termination of this DPA, or earlier at request of Customer, Provider will, and require its subprocessors to return or delete all Customer Personal Data, except Provider may retain Customer Personal Data if required by law or pursuant to Customer’s internal document retention policies. Nothing in this DPA shall prohibit Provider from maintaining, using or disclosing any data derived from Customer Personal Data, provided that in any such data shall be aggregated or otherwise Processed to remove all personally identifiable attributes from such Customer Personal Data.


12.      Audit Rights. Upon Customer’s written request, and subject to the confidentiality obligations set forth in the Agreement, Provider will make available to Customer, or Customer’s independent, third-party auditor, information as may be reasonably requested by Customer from time to time regarding Provider’s compliance with the obligations set forth in this DPA, and will allow for up to one audit per year, at Customer’s expense, conducted by Customer (provided that Customer will provide reasonable notice of its intent to audit, conduct the audit during normal business hours, and take reasonable measure to prevent unnecessary business disruptions to Provider’s operations), or a third-party auditor, by completing a data protection questionnaire of reasonable length, no more than once a year, at Customer’s expense. To the extent Customer is able to demonstrate that Provider’s questionnaire responses do not provide sufficient information to demonstrate compliance with this DPA, Provider shall provide access to relevant, knowledgeable Personnel. Except when required by a Regulatory Authority, the audit described in Clause 8.9 of the Standard Contractual Clauses shall be carried out in accordance with this Section 10.


13.      Restricted Transfers. With respect to any Restricted Transfer of Customer Personal Data, subject to the GDPR, UK GDPR, or FADP, as the case may be, the Restricted Transfer shall be carried out in accordance with, and will be subject to, the applicable terms identified in this Section 11.


13.1      With respect to any Customer Personal Data transfer subject to the GDPR, the transfer shall be carried out in accordance with, and will be subject to, the Standard Contractual Clauses. For purposes of these Standard Contractual Clauses: Customer is the “data exporter” and Provider is the “data importer”. The importer and exporter have agreed on the following:


  1. Module Two (Controller to Processor) shall apply where Customer is a Controller of Customer Personal Data and Provider is Processing Customer Personal Data as a Processor.
  2. Clause 7 of the Standard Contractual Clauses (Docking Clause) does not apply.
  3. Clause 9(a) Option 2 (General written authorization) is selected, and the time period to be specified is determed in Section 5 of this DPA.
  4. The option in clause 11(a) of the Standard Contractual Clauses (Independent dispute resolution body) does not apply.
  5. With regard to clause 17 of the Standard Contractual Clauses (Governing law), the Parties agree that option one shall apply. The parties agree that the governing law shall be the law of the Republic of Ireland.
  6. In clause 18 of the Standard Contractual Clauses (Choice of forum and jurisdiction), the Parties submit themselves to the jurisdiction of the courts of the Republic of Ireland.
  7. Annex I of the DPA contains the specifications regarding the parties, the description of transfer, and the competent supervisory authority.
  8. Annex II of the Addendum contains the technical and organizational measures.
  9.   https://peak15systems.com/sub-processors-page/ contains Provider’s Sub-processor list. The Sub-processor’s contact person’s name, position and contact details will be provided by Provider upon request.


13.2     With respect to any Customer Personal Data transfer subject to the UK GDPR, the parties hereby enter into the UK IDTA (with Customer as data exporter and Provider as data importer), which is incorporated by reference into this DPA and which shall come into effect upon the commencement of such transfer. Any conflict between the terms of the Standard Contractual Clauses and the UK IDTA will be resolved in accordance with Section 10 and Section 11 of the UK IDTA. The parties make the following selections for the purpose of the UK IDTA:


Part 1: Tables


Table 1

  1. The Start Date is the Effective Date of the Agreement.
  2. The Exporter is Customer and the Importer is Provider.
  3. The Exporter’s details are found in Annex I.A. The Importer’s details are found in the Annex I.A.
  4. The Exporter’s Key Contact can be found in Annex I.A. The Importer’s Key Contact information can be found in Annex I.A. 

Table 2: The Parties choose the Standard Contractual Clauses as set out in Section 11.1, including the following Annex II Information and with only the following modules, clauses, or optional provisions of the Standard Contractual Clauses brought into effect for the purposes of this IDTA:

  1. Clause 7 – See Annex I.D, Clause 7.
  2. Clause 9 – See Annex I.D, Clause 9.
  3. Clause 11 – See Annex I.D, Clause 11.

Table 3

  1. Annex I.A: See Annex I.A.
  2. Annex I.B: See Annex I.B.
  3. Annex II: See Annex II.

Table 4

  1. The Importer may end this IDTA.


Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.


13.3       With respect to any Customer Personal Data transfer subject to the FADP, the transfer shall be carried out in accordance with, and will be subject to, the Standard Contractual Clauses set out in Section 11.1, which will form contractual terms between the parties for that particular transfer of Customer Personal Data with Customer as data exporter and Provider as data importer. The parties make the same elections as outlined in Annex I for Customer Personal Data, with the following additional modifications:


  1.          References to the GDPR shall be interpreted as references to the FADP or by any subsequent act, including the relevant amendments and implementing ordinances (whereby “the competent supervisory” and “competent courts” shall mean the “Swiss Federal Data Protection and Information Commissioner” and the “relevant courts in Swizterland”).
  2.          “personal data”, “special categories of data/sensitive data”, “personality profiles”, “profiling” “profiling with high risk”, “process/processing”, “controller”, “processor”, “data subject” and “supervisory authority/authority” shall have the meaning assigned to them by the Swiss Federal Act on Data Protection of June 19, 1992 (“FADP”) or by any subsequent act, including the relevant amendments and implementing ordinances (whereby “the competent supervisory” and “competent courts” shall mean the “Swiss Federal Data Protection and Information Commissioner” and the “relevant courts in Swizterland”).
  3.        The data importer acknowledges and agrees that the personal data transferred to data importer by data exporter may include personal data of legal persons and personality profiles of natural persons. The data importer shall process personal data of legal persons in the same manner as other personal data and personality profiles in the same manner as special categories of data (the special protection of data from legal persons and from personality profiles will be abolished upon entering into force of the revised Swiss Federal Data Protection Act of September 25, 2020 (“R-FADP”))
  4.        References to “Member State,” “EU,” and “Union law” shall be interpreted as references to Swiss law.


In the event Customer transfers Customer Personal Data that relates to data subjects in Switzerland to Provider, the terms in this subsection shall modify the corresponding references in this DPA. For clarity and avoidance of doubt, the terms in this subsection will amend this DPA to the extent necessary for compliance with the FADP. The terms in this Section 11.3 shall only apply to Customer Personal Data subject to the FADP.


14.      U.S. Specific Terms.


           14.1      The parties agree that the “business purpose(s)”, as “business purpose” is defined under CCPA, of Synop’s Processing of Client Data are in Annex I. Client is providing Client Personal Data to Synop only for the limited and specified purposes listed in Annex I. The Parties agree that the transfer of any Client Personal Data in accordance with this Addendum does not constitute a sale or sharing.


            14.2      Provider will not: (a) Sell or Share Customer Personal Data; (b) retain, use, or disclose Customer Personal Data: (i) for any purpose other than those listed in Annex I, unless permitted by Data Protection Laws, (ii) for a commercial or any other purpose other than for the specific purpose of providing, managing, or supporting the Services, or as otherwise permitted by Data Protection Laws, or (iii) outside of the direct business relationship between Provider and Customer, unless expressly permitted by Data Protection Laws; or (c) combine Customer Personal Data that Provider receives from or on behalf of Customer with Personal Data that Provider receives from or on behalf of another person, or collects from its own interaction with an individual, unless permitted by Data Protection Laws.  Provider will notify Customer after its determination that it can no longer meet its obligations under Data Protection Laws.


15.      General Terms.


15.1     Nothing in this Addendum reduces Provider’s or any Subprocessor’s obligations under the Agreement in relation to the protection of Personal Data or permits Provider or any Subcontractor to Process (or permit the Processing of) Customer Personal Data in a manner which is prohibited by the Agreement. In the event of any conflict or inconsistency between this Addendum and the Standard Contractual Clauses, the Standard Contractual Clauses will prevail. In the event of inconsistencies between the provisions of this DPA and any other agreements between the parties, including the Agreement, the provisions of this DPA will prevail.


15.2      If any variation is required to this DPA as a result of a change in Data Protection Laws, including any variation which is required to the Standard Contractual Clauses, then either party may provide written notice to the other party of that change in law. The parties will discuss and negotiate in good faith any necessary variations to this DPA, including the Standard Contractual Clauses, to address such changes.


15.3     Any claims brought under this DPA shall be subject to the terms and conditions of the Agreement, including the exclusions and limitations of liability set forth in the Agreement.


ANNEX I


A. LIST OF PARTIES


Data Exporter: See Order Form
Address: See Order Form
Contact person’s name, position, and contact details: See Order Form
Role: Controller

Data Importer: See Order Form
Address: See Order Form
Contact person’s name, position, and contact details: See Order Form
Role: Processor

Activities relevant to the data transferred under these Clauses: The activities specified in Annex I.B. below. 


B. DESCRIPTION OF TRANSFER


Data subjects
The Personal Data transferred concern the following categories of data subjects:

  • Natural persons who are Customer’s
  • Employees
  • Agents 
  • Advisors 
  • Clients 
  • Client’s Employees, Agents, Advisors, Contractors, Clients 
  • Vendors 
  • Vendor’s Employees, Agents, Advisors, Contractors, Clients 


Categories of data
The Personal Data transferred concern the following categories of data:

  • Identification data: civil/marital status, first and last name, date and place of birth, nationality, gender 
  • Contact details: Address (previous and new), telephone number (home, office, and mobile), email address, fax number, emergency contact information 
  • Employment details: Job title 
  • National identifiers: Passport number, government identification number 
  • Financial data: Bank details such as bank name and address
  • IT-related data: User ID and password   
  • Personal data: Health conditions, Dietary restrictions or preferences, Travel interests, Travel history 


Special categories of data (if appropriate)
The Personal Data transferred concern the following special categories of data: N/A


Frequency of transfer
Provider will transfer Customer Personal Data on an ongoing or regular basis.


Subject matter, nature, and purpose of the Processing operations
Provider will Process Customer Personal Data for the purpose of providing the Services, and for such other purposes as may be described in the Agreement or instructions of Customer., except here Provider retains Customer Personal Data to comply with applicable laws or to establish, exercise, or defend its legal rights, in accordance with its data retention policies. 


Duration of Processing
Provider will Process Customer Personal Data only for as long as Services are provided under the Agreement.


C. COMPETENT SUPERVISORY AUTHORITY


Where Customer is established in an EU Member State, the supervisory authority with responsibility for ensuring compliance by Customer with Regulation (EU) 2016/679 as regards the data transfer shall act as competent supervisory authority. 


Where Customer is not established in an EU Member State, but falls within the territorial scope of application of Regulation (EU) 2016/679 in accordance with its Article 3(2) and has appointed a representative pursuant to Article 27(1) of Regulation (EU) 2016/679, the supervisory authority of the Member State in which the representative within the meaning of Article 27(1) of Regulation (EU) 2016/679 is established shall act as competent supervisory authority. 

Where Customer is not established in an EU Member State, but falls within the territorial scope of application of Regulation (EU) 2016/679 in accordance with its Article 3(2) without however having to appoint a representative pursuant to Article 27(2) of Regulation (EU) 2016/679, the Irish Data Protection Commission shall act as competent supervisory authority.


ANNEX II


DESCRIPTION OF TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES


Description of the technical and organisational security measures implemented and maintained by Provider shall meet Customer’s Provider Data Protection Requirements:


The following provides more information regarding our technical and organizational security measures set forth below. 

Technical and Organizational Security Measures: 


Measures and protection of Personal Data in storage and transit: all Personal Data is encrypted in transit and at rest, and, to the extent relevant from a security standpoint, treated as if it were classified as sensitive data. Information is always transmitted over TLS with up-to-date encryption methodologies by default. 


Measures for ensuring ongoing confidentiality, integrity, and availability and resilience of processing systems and services: we enter into agreements that contain confidentiality provisions with our employees, contractors, vendors, and Sub-processors. Our Disaster Recovery policy is to prepare our business and services in the event of extended outages caused by factors beyond our control and to restore services to the widest extent possible in a minimum time frame. Our timeframes for recovery are designed to ensure we can meet our obligations to all of our customers.


Processes for regular testing, assessing and evaluating the effectiveness of technical and organizational measures to ensure the security of processing: the goal of information security is to protect the confidentiality, integrity and availability of information to the organization, employees, partners, customers and the (authorized) information systems, and to minimize the risk of damage occurring by preventing security incidents and managing security threats and vulnerabilities. Our Legal and Information Security Teams ensure that applicable regulations and standards are factored into our security frameworks. 


Measures for user identification and authorization: we follow principles of “need to know” and “least privilege”. Provisioning and deprovisioning are overseen by the Information Technology team, with Single-Sign-On and 2FA by default. Access reviews are performed on a quarterly basis for each information asset.


Measures for ensuring event logging: audit logs are centrally stored. The Incident Response Policy enforces the incident response plan and its procedures. These guidelines are being followed if any type of security or technical incident occurs. 

Measures for ensuring system configuration, including default configuration: we follow a consistent change management process for all changes to the production environment. The control process ensures that changes proposed are reviewed, authorized, tested, implemented, and released in a controlled manner; and that the status of each proposed change is monitored. Configuration baselines are followed to securely configure the systems by following best practices.

Measures for physical security: PEAK 15 has implemented and enforced a teleworking policy, which ensures employees work remotely in a secure manner. The policy enforces minimum measures around physical security, access security, connection, and communication security.


Measures for internal IT and IT security governance and management: we maintain a risk-based assessment security program, which includes administrative, organizational, technical, and physical safeguards designed to protect the Services and confidentiality, integrity, and availability of Customer Data. Our information security program is set up in a systematic and well-organized way. In addition, legal and regulatory requirements apply to ensure the confidentiality, integrity, and availability of information to the organization, employees, partners, and customers. All these are translated into our information security policies, procedures, and guidelines. We have a Governance, Risk, and Compliance Group, which is responsible for the tactical level of information security. This entails the coordination of information security activities and the translation of strategic activities to operational activities for our security and our continuous maintenance of regulatory compliance. All employees are responsible for safeguarding company assets. All our employees are screened for expertise, experience, and integrity. Employees are informed about security and data protection at the onboarding stage, as well as by way of regular team-specific training, and other company-wide all-hands presentations about the importance of data protection and security compliance.


Measures for assurance of processes and products: we undergo regular application vulnerability scans and web application penetration testing. 


Measures for ensuring accountability: we implement information security and data protection policies in accordance with applicable laws and maintain documentation of our processing activities, including recording and reporting security incidents involving Personal Data where applicable. 


Measures for ensuring data erasure: We ensure data erasure through a deletion process within our communication and infrastructure environment. This data deletion process ensures that all data that is no longer needed to fulfill a specific purpose is removed from our systems after processing.