(L) · LEGAL

Data Processing Addendum (Template)

Last updated · 28 August 2026

A data processing addendum for engagements in which RAVENTRYX processes personal data on a client’s behalf. This template becomes effective only when incorporated into or executed as part of an applicable client agreement or Statement of Work.

Status of this template

Until it is incorporated into or executed as part of a client agreement or Statement of Work, this Addendum imposes no obligation on either party. It is published so that it can be read before an engagement begins.

It is also not a policy governing this website. Personal data that RAVENTRYX handles as a controller of its own, including anything you submit through this site, is covered by the Privacy Notice instead.

Parties & roles

This Addendum forms part of the agreement between the client ("Controller") and RAVENTRYX LLC ("Processor") and applies where RAVENTRYX processes personal data on the Controller’s behalf.

Subject-matter & duration

Processing lasts for the term of the underlying engagement and any agreed wind-down period, for the subject-matter described in the relevant SOW.

Nature & purpose

RAVENTRYX processes personal data only to perform the engagement and on the Controller’s documented instructions.

Categories of data & data subjects

The categories of personal data and data subjects are specified per engagement in an annex to the SOW.

Processor obligations (GDPR Art. 28)

RAVENTRYX maintains confidentiality, appropriate security, records of processing, and assists the Controller with data-subject requests and regulatory obligations, as required by Article 28.

Sub-processors

RAVENTRYX engages sub-processors only under written terms no less protective than this Addendum and notifies the Controller of intended changes.

International transfers

Any transfer of personal data outside its origin jurisdiction relies on an approved transfer mechanism, such as Standard Contractual Clauses.

Security measures

Technical and organizational measures are set out in a security annex and kept appropriate to the risk.

Audit & assistance

RAVENTRYX makes available information necessary to demonstrate compliance and allows for audits as required by Article 28(3)(h).

Return or deletion

On termination, RAVENTRYX returns or deletes personal data at the Controller’s choice, save where retention is legally required.

← Back to home