AssetWRX Data Processing Agreement

Last updated: 19 July 2026 Effective: 19 July 2026 Version: 1.0.0

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you or your organisation (“Customer”, the “Controller”) and Cogniforma Ltd, operator of AssetWRX (“Cogniforma”, the “Processor”). It governs Cogniforma’s processing of personal data contained in Customer Content on the Customer’s behalf. It is drafted to satisfy Article 28 of the EU GDPR and the UK GDPR. In the event of conflict with the Terms of Service, this DPA controls for the processing it covers.

1. Roles

For personal data in Customer Content, the Customer is the controller (or a processor acting on behalf of a third-party controller) and Cogniforma is the processor. Cogniforma processes Customer Content only on the Customer’s documented instructions, which comprise the Terms of Service, this DPA, and the Customer’s use of the Service’s features. For account, billing and diagnostic data, Cogniforma is an independent controller as described in the Privacy Policy.

2. Subject-matter, duration, nature and purpose

  • Subject-matter and duration: processing for the term of the Customer’s agreement and until deletion in accordance with the Data Deletion Policy.
  • Nature and purpose: hosting, storage, transmission, indexing, backup, sharing, report and summary generation, and optional AI processing, in each case to provide the Service.
  • Types of personal data: identifiers and contact details, asset and inspection records, photographs and media, location data, and any other personal data the Customer chooses to submit.
  • Categories of data subject: the Customer’s personnel, contractors, contacts, requesters, and the subjects of inspections.

3. Processor obligations

Cogniforma will:

  1. process Customer Content only on the Customer’s documented instructions, including as to international transfers, unless required otherwise by law (in which case it will inform the Customer unless legally prohibited);
  2. ensure persons authorised to process Customer Content are bound by confidentiality;
  3. implement appropriate technical and organisational measures under Article 32 (see section 7 and Privacy Policy section 12);
  4. respect the conditions in section 4 for engaging sub-processors;
  5. taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to data-subject requests;
  6. assist the Customer in ensuring compliance with Articles 32–36 (security, breach notification, and data protection impact assessments), taking into account the information available to it;
  7. at the Customer’s choice, delete or return Customer Content at the end of the provision of the Service, as described in the Data Deletion Policy; and
  8. make available information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, as described in section 8.

4. Sub-processors

The Customer provides general authorisation for Cogniforma to engage the sub-processors listed at assetwrx.com/legal/subprocessors. Cogniforma imposes data-protection obligations on each sub-processor no less protective than those in this DPA and remains liable for their performance. Cogniforma will give notice of any intended addition or replacement of a sub-processor via the sub-processors page, and the Customer may object on reasonable data-protection grounds within 30 days.

5. Data-subject requests

Where Cogniforma receives a request from a data subject relating to Customer Content, it will not respond directly (except to confirm the request should be directed to the Customer) and will promptly forward it to the Customer and provide reasonable assistance in responding.

6. Personal data breach

Cogniforma will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Content, and will provide information reasonably required for the Customer to meet its own notification obligations under Articles 33 and 34.

7. Security

Cogniforma maintains the technical and organisational measures described in section 12 of the Privacy Policy, including encryption in transit and at rest, access controls and row-level security, audit logging, and least-privilege access.

8. Audit

Cogniforma will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA. Where the Customer reasonably requires further audit, the parties will agree scope and timing in advance; audits are limited to once per twelve months absent a regulator requirement or a suspected breach, conducted on reasonable notice and without disrupting the Service.

9. International transfers

Cogniforma processes Customer Content in the regions described in the sub-processors list. Where processing occurs outside the UK or EEA, the transfer mechanisms in section 7 of the Privacy Policy apply, and the Standard Contractual Clauses (2021/914) together with the UK International Data Transfer Addendum are incorporated by reference where required.

10. Return and deletion

On termination, Cogniforma will delete or, at the Customer’s election, return Customer Content in accordance with the Data Deletion Policy, subject to the retention of records required by law.

11. Liability

The liability of each party under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.

Contact

privacy@assetwrx.com | Cogniforma Ltd, 17 Quaves Road, Slough, SL3 7NX, UK