AuditBadger AuditBadger

Legal

Data Processing Agreement

Current Humadroid Data Processing Agreement template and reviewed data processor references.

Version 1.0
Effective June 23, 2026

Data Processing Agreement

Version: 1.0

This Data Processing Agreement ("DPA") forms part of, and is subject to, the AuditBadger Terms of Use governing the provision of the AuditBadger platform and related services (the "Agreement") between the parties identified below. It governs the Processing of Personal Data by the Processor on behalf of the Controller. By accepting the Agreement, the Customer and AuditBadger are bound by this DPA, which is incorporated into the Agreement by reference; a signature on this DPA is not required for it to take effect.


1. The Parties

Controller ("Customer")

Legal entity name Customer legal name
Registered address Customer legal address
Authorised signatory Authorized signer
Title Signer title
Contact email Signer email

Processor ("AuditBadger")

Legal entity name Prograils Sp. z o.o.
Registered address Sczanieckiej 9a/9, 60-215 Poznań, Poland
Data protection contact privacy@prograils.com

Effective Date: June 23, 2026


2. Definitions

Terms not defined here have the meaning given in the Agreement or in the EU General Data Protection Regulation 2016/679 ("GDPR").

  • "Applicable Data Protection Law" means the GDPR and any national laws implementing or supplementing it that apply to the Processing under this DPA, and — where relevant under Section 6.4 — the UK GDPR and the Swiss FADP.
  • "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Supervisory Authority", and "Personal Data Breach" have the meanings given in the GDPR.
  • "Customer Personal Data" means Personal Data that the Processor Processes on behalf of the Controller under the Agreement, as described in Annex 1.
  • "Sub-processor" means any third party engaged by the Processor to Process Customer Personal Data.
  • "Standard Contractual Clauses" ("SCCs") means the clauses adopted by the European Commission in Decision (EU) 2021/914 for the transfer of Personal Data to third countries.
  • "UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the UK Data Protection Act 2018.

3. Roles and Scope

3.1 For Customer Personal Data, the Customer is the Controller and AuditBadger is the Processor. The Customer may itself be acting as a processor for a third-party controller; in that case the Customer warrants it has the authority to engage AuditBadger on those terms.

3.2 AuditBadger Processes Customer Personal Data only to provide the AuditBadger platform and the services described in the Agreement, and as further described in Annex 1.

3.3 This DPA does not apply to Personal Data for which AuditBadger acts as a controller (for example, AuditBadger's own account-administration, billing, and security-log data), which is governed by AuditBadger's privacy notice.


4. Processor Obligations

AuditBadger shall:

4.1 Process only on documented instructions. Process Customer Personal Data only on the Controller's documented instructions, including with regard to international transfers, unless required to act otherwise by EU or Member State law (in which case AuditBadger will inform the Controller of that legal requirement before Processing, unless the law prohibits this).

4.2 Notify unlawful instructions. Inform the Controller promptly if, in AuditBadger's opinion, an instruction infringes Applicable Data Protection Law.

4.3 Confidentiality. Ensure that persons authorised to Process Customer Personal Data are bound by an appropriate duty of confidentiality.

4.4 Security. Implement and maintain the technical and organisational measures set out in Annex 2, appropriate to the risk.

4.5 Sub-processing. Engage Sub-processors only in accordance with Section 5.

4.6 Assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller's obligation to respond to Data Subject requests under Chapter III of the GDPR (Articles 12–23).

4.7 Assist with compliance. Assist the Controller in ensuring compliance with its obligations under Articles 32–36 of the GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of Processing and the information available to AuditBadger.

4.8 Deletion or return. At the Controller's choice, delete or return all Customer Personal Data after the end of the provision of services, and delete existing copies unless EU or Member State law requires storage (see Section 11).

4.9 Demonstrate compliance. Make available to the Controller the information necessary to demonstrate compliance with Article 28 of the GDPR, and allow for and contribute to audits in accordance with Section 8.


5. Sub-processors

5.1 The Controller provides general written authorisation for AuditBadger to engage Sub-processors to Process Customer Personal Data, subject to this Section.

5.2 A current list of Sub-processors is maintained at:

https://auth.auditbadger.com/legal/data-processors

5.3 AuditBadger imposes on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, in particular regarding security and the requirements of Article 28(3) of the GDPR. AuditBadger remains fully liable to the Controller for the performance of each Sub-processor's obligations.

5.4 AuditBadger will give the Controller prior notice of any intended addition or replacement of a Sub-processor, allowing the Controller a reasonable period to object on reasonable data-protection grounds. Notice is given by updating the list at the URL above and/or by notification to the Controller's contact email. If the Controller objects and the parties cannot resolve the objection, the Controller may terminate the affected services.

5.5 Customer-connected third-party services. Where the Customer chooses to connect a third-party service to the AuditBadger platform (for example Google Workspace, Microsoft 365, AWS, Google Cloud Platform, Linear, Shortcut, Vercel, or similar integrations), the provider of that service is not a Sub-processor under this DPA. The Customer acts as controller of the data it directs to and from those services and is responsible for its own agreements with those providers. Where AuditBadger ingests and stores data from such a connected service on its own infrastructure (for example, a list of user accounts retained as compliance evidence), that stored data is Customer Personal Data and is Processed under this DPA and secured by the Sub-processors named in the list referenced in Section 5.2.


6. International Transfers

6.1 AuditBadger will not transfer Customer Personal Data outside the European Economic Area ("EEA") unless it has taken measures necessary to ensure the transfer is compliant with Applicable Data Protection Law.

6.2 Certain Sub-processors are established outside the EEA, including in the United States (for example, payment processing, content-delivery/DNS, and AI service providers as identified in the Sub-processor list). For such transfers, AuditBadger relies on one or more of the following:

(a) a European Commission adequacy decision applicable to the recipient (including, where applicable and valid, the recipient's self-certification under the EU-U.S. Data Privacy Framework); or

(b) the Standard Contractual Clauses (SCCs), incorporated into this DPA by reference and completed as set out in Annex 3 (Module Two: controller-to-processor, or Module Three: processor-to-processor, as applicable), together with any supplementary measures required following a transfer impact assessment.

6.3 Where the SCCs apply and there is a conflict between them and this DPA, the SCCs prevail in respect of the relevant transfer.

6.4 United Kingdom and Switzerland. Where the Customer is subject to the UK GDPR (the retained EU GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland) or to the Swiss Federal Act on Data Protection ("FADP"), the following apply to transfers of Customer Personal Data to which those laws apply:

(a) for transfers subject to UK GDPR, the UK Addendum is incorporated into this DPA and completed as set out in Annex 3, and references in the SCCs to the GDPR are read as references to the UK GDPR;

(b) for transfers subject to the FADP, the SCCs apply with the adaptations described in Annex 3 (including that the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority and that the term "Member State" does not prevent Swiss data subjects from exercising their rights in their place of habitual residence);

(c) all other terms of this DPA apply equally to such transfers, and the protections of this DPA are extended to the relevant data subjects accordingly.


7. Personal Data Breach

7.1 AuditBadger will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

7.2 The notification will, to the extent known, describe the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address it. Where the information cannot all be provided at once, it may be provided in phases without undue further delay.

7.3 AuditBadger will reasonably assist the Controller in meeting the Controller's own breach-notification obligations to Supervisory Authorities and Data Subjects.


8. Audit

8.1 AuditBadger will make available to the Controller the information reasonably necessary to demonstrate compliance with Article 28 of the GDPR.

8.2 The Controller may satisfy its audit rights primarily through AuditBadger's available compliance reports, certifications, and security documentation. AuditBadger currently maintains a SOC 2 Type I and SOC 2 Type II report and is pursuing ISO/IEC 27001 certification; current reports are made available to the Controller on request under confidentiality.

8.3 Where those materials are not sufficient, the Controller (or a mutually agreed independent auditor bound by confidentiality) may conduct an audit on reasonable prior written notice, no more than once per twelve-month period except where required by a Supervisory Authority or following a Personal Data Breach. Audits are conducted during business hours, with minimal disruption, and at the Controller's cost.


9. Special Categories of Personal Data

9.1 The AuditBadger platform is not intended to Process special categories of Personal Data (Article 9 GDPR) or data relating to criminal convictions and offences (Article 10 GDPR).

9.2 The Controller shall not upload, sync, or otherwise submit such data to the platform unless separately agreed in writing with AuditBadger. The Controller is responsible for ensuring that evidence and other content it provides is limited to the minimum Personal Data necessary for its compliance purposes.


10. Liability

The liability of each party under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement.


11. Term, Deletion and Return

11.1 This DPA takes effect on the Effective Date and continues for as long as AuditBadger Processes Customer Personal Data under the Agreement.

11.2 On termination or expiry of the services, AuditBadger will, at the Controller's choice, delete or return all Customer Personal Data and delete existing copies, within a reasonable period, unless EU or Member State law requires continued storage. Backups are deleted in the ordinary course of AuditBadger's backup-rotation cycle.


12. General

12.1 In the event of a conflict between this DPA and the Agreement on data protection matters, this DPA prevails.

12.2 This DPA is governed by the laws of Poland, without prejudice to any mandatory provisions of Applicable Data Protection Law. The courts referred to in the Agreement have jurisdiction.

12.3 If any provision is found invalid, the remainder of the DPA remains in effect.


13. Acceptance and Optional Signature

This DPA is incorporated into the Agreement by reference and takes effect when the Customer accepts the Agreement. No signature is required for it to be binding on either party.

The Customer may, at its option, sign below to retain a counter-signed record. Doing so does not change the effective date or the binding nature of this DPA.

Customer — Customer legal name

Name: Authorized signer Title: Signer title Date: June 23, 2026 Signature: _______________________________

For and on behalf of the Processor, Prograils Sp. z o.o. — accepted and made available through the AuditBadger platform; no manual signature required.


Annex 1 — Description of Processing

Subject matter Provision of the AuditBadger compliance-management platform and related services.
Duration The term of the Agreement, plus any deletion/return period under Section 11.
Nature and purpose Hosting, storing, displaying, and organising Customer Personal Data to enable the Customer to manage and evidence its compliance with information-security and regulatory frameworks.
Categories of Data Subjects The Customer's personnel and authorised platform users; individuals whose data appears in systems the Customer connects to the platform (e.g., user accounts in connected services).
Categories of Personal Data Names; email addresses; job roles/titles; account and login identifiers; authentication metadata; and Personal Data contained in evidence the Customer uploads or syncs.
Special categories None (see Section 9).
Frequency Continuous, for the duration of the services.

Annex 2 — Technical and Organisational Measures

AuditBadger maintains the following measures, appropriate to the risk (Article 32 GDPR):

  • Access control — role-based access, unique credentials, and least-privilege principles for systems Processing Customer Personal Data.
  • Authentication — enforced strong authentication for administrative access to production systems.
  • Encryption — encryption of Customer Personal Data in transit (TLS) and at rest.
  • Network security — segregation of production environments, firewalling, and restricted ingress.
  • Logging and monitoring — security event logging and monitoring of production systems.
  • Backups — regular backups with defined retention and rotation.
  • Change management — version control, code review, and continuous-integration checks prior to deployment.
  • Vulnerability management — patching and remediation of identified vulnerabilities.
  • Personnel — confidentiality obligations and security-awareness measures for staff.
  • Sub-processor management — contractual data-protection obligations imposed on all Sub-processors.
  • Resilience — measures to restore availability and access to Customer Personal Data in a timely manner after an incident.

These measures are reviewed periodically and may be updated provided the overall level of security is not reduced.


Annex 3 — Standard Contractual Clauses: Elections and Completion

This Annex records the elections that complete the Standard Contractual Clauses ("SCCs") incorporated by reference under Section 6, and the equivalent completion of the UK Addendum and Swiss adaptations under Section 6.4.

  1. Module in operation. Where AuditBadger acts as processor for the Customer as controller, Module Two (controller-to-processor) applies. Where the Customer is itself a processor acting for a third-party controller, Module Three (processor-to-processor) applies. The relevant Sub-processor transfers operate as onward transfers under the same Module.

  2. Clause 7 — Docking clause. The optional docking clause applies.

  3. Clause 9 — Use of sub-processors. Option 2 (general written authorisation) applies. The time period for prior notice of Sub-processor changes is as stated in Section 5.4 of this DPA.

  4. Clause 11 — Redress. The optional independent dispute-resolution body language does not apply.

  5. Clause 17 — Governing law. The SCCs are governed by the law of Poland.

  6. Clause 18 — Choice of forum and jurisdiction. Disputes arising from the SCCs are resolved before the courts of Poland, consistent with Section 12.2.

  7. Annexes to the SCCs.

    • Annex I.A (List of Parties): the Controller and Processor identified in Section 1 of this DPA, in their roles of data exporter and data importer respectively.
    • Annex I.B (Description of Transfer): as set out in Annex 1 of this DPA.
    • Annex I.C (Competent Supervisory Authority): the Polish President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), or, where the Customer is established in another EEA state and that state's authority is competent, that authority.
    • Annex II (Technical and Organisational Measures): as set out in Annex 2 of this DPA.
    • Annex III (List of Sub-processors): the list maintained at the URL in Section 5.2.
  8. UK Addendum completion. For UK transfers: Tables 1, 2 and 3 of the UK Addendum are populated by Sections 1 and 6, and Annexes 1, 2 and 3 of this DPA. In Table 4, neither party may end the Addendum when the Approved Addendum changes, save as required by law.

  9. Precedence. Where there is a conflict, the order of precedence is: (1) the SCCs / UK Addendum; (2) this Annex 3; (3) the remainder of this DPA.