Data Processing Addendum (DPA)
This DPA applies where ZAYNO PTE. LTD. processes personal data on behalf of a business Customer (Controller) as a Processor under GDPR, UK GDPR and equivalent regimes. It supplements our Terms of Service.
1. Parties and roles
For personal data that Customer submits to ProMongoDB — for example, employee learner accounts on team or cohort orders — Customer is the Controller and ZAYNO PTE. LTD. is the Processor. For visitors of the public website and individual buyers, ZAYNO PTE. LTD. is the Controller (see the Privacy Policy).
2. Subject matter, duration and nature
Subject matter: providing self-paced courses and instructor-led cohorts, related account management, invoicing and support.
Duration: for the term of the underlying order, plus retention periods required by law.
Nature and purpose: hosting, transmitting and storing personal data strictly to deliver the ordered services.
3. Categories of data and data subjects
- Data subjects: Customer's authorised learners, admins and billing contacts.
- Categories: identification and contact data, authentication credentials (hashed), learning progress, cohort participation, invoicing metadata.
- No special categories of data are intentionally processed. Customer agrees not to submit special-category or high-risk data.
4. Processor obligations
- Process personal data only on documented instructions from Customer, including transfers.
- Ensure persons authorised to process personal data are bound by confidentiality.
- Implement appropriate technical and organisational measures (see Annex II).
- Assist Customer with data-subject requests and with DPIAs where reasonably needed.
- Notify Customer without undue delay after becoming aware of a personal data breach.
- Delete or return personal data at the end of the services, subject to legal retention.
5. Subprocessors
Customer authorises the following subprocessors:
- Application hosting and edge delivery — EU/US regions.
- Managed database and backups — EU region.
- Transactional email delivery — EU/US.
- Payment processing and invoicing — EU/US, PCI-DSS certified.
- Error monitoring and product analytics — EU region where available.
- Customer support helpdesk — EU/US.
We give Customer at least 30 days' notice before adding or replacing a subprocessor, and Customer may object on reasonable data-protection grounds.
6. International transfers
Where personal data is transferred outside the EEA, UK or Switzerland to a country without an adequacy decision, the parties incorporate the European Commission's Standard Contractual Clauses (Module Two: Controller-to-Processor) and the UK IDTA / Swiss addendum by reference, with the docking clause left open for further parties.
7. Audit rights
We make available all information necessary to demonstrate compliance and allow for audits, including inspections, by Customer or a mandated auditor, no more than once per year, with 30 days' notice, subject to reasonable confidentiality and security controls. Where available, third-party audit reports satisfy this obligation.
Annex I — Processing details
See sections 2 and 3 above.
Annex II — Technical and organisational measures
- TLS 1.2+ for data in transit; AES-256 for data at rest.
- Role-based access control with least privilege; SSO and MFA for internal admin.
- Encrypted backups with tested restore procedures.
- Centralised audit logging with retention.
- Secure SDLC, dependency scanning, code review, environment segregation.
- Documented incident response plan with defined severity levels.
- Vendor risk review and DPA in place with each subprocessor.
Signing this DPA
This DPA is incorporated into the Terms of Service and takes effect upon acceptance of the Terms. Business customers requiring a countersigned version should email legal@promongodb.pro.