Operational draft: This self-service DPA requires counsel and operational review before reliance. Scryon's entity identity and address, security schedule, subprocessors, data locations, EU and UK exporter/importer details, and transfer mechanism must be validated. Email privacy@scryon.io to request an executed copy.
This Data Processing Addendum ("DPA") forms part of the agreement between the customer identified in an order or account ("Customer") and Scryon ("Scryon") governing the Service ("Agreement"). It applies when Scryon processes Customer Personal Data on Customer's behalf.
1. Application and definitions
This section defines key terms and when this DPA applies.
"Applicable Data Protection Law" means privacy and data-protection laws applicable to the processing, including where applicable the GDPR, UK GDPR, and US state privacy laws. "Customer Personal Data" means personal data contained in Customer Data that Scryon processes as a processor or service provider. "GDPR" means Regulation (EU) 2016/679. "Security Incident" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
Terms such as controller, processor, data subject, personal data, process, sell, share, and supervisory authority have the meanings in Applicable Data Protection Law. If there is a conflict, this DPA controls for processing of Customer Personal Data.
2. Roles, instructions, and processing
This section explains roles, instructions, and permitted processing.
Customer is the controller or processor that appoints Scryon. Scryon is Customer's processor, subprocessor, service provider, or contractor as applicable. Each party will comply with its obligations under Applicable Data Protection Law.
Scryon will process Customer Personal Data only to provide, secure, support, and improve the Service; on Customer's documented instructions in the Agreement, orders, configuration, support requests, and use of the Service; or as required by law. If law requires other processing, Scryon will notify Customer before processing unless prohibited. Scryon will inform Customer if, in its opinion, an instruction violates Applicable Data Protection Law.
Customer instructs Scryon to import, host, organize, match, deduplicate, classify, enrich, score, summarize, analyze, and export Customer Personal Data, including through authorized AI and machine-learning models. Customer is responsible for the lawfulness, accuracy, transparency, and scope of its instructions and for responding as controller to data subjects and regulators.
Scryon will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations. Scryon will not sell Customer Personal Data, share it for cross-context behavioral advertising, retain, use, or disclose it outside the business purposes specified in the Agreement, or combine it with personal data received from other persons except as permitted by Applicable Data Protection Law and necessary to provide the Service.
3. Security and incidents
This section covers security measures and incident notice.
Scryon will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data, considering the state of the art, implementation cost, nature and scope of processing, and risk to individuals. Measures will address, as appropriate, access control, authentication, encryption in transit and at rest, logging, vulnerability and patch management, backups and recovery, personnel confidentiality, vendor oversight, and incident response. The exact controls and certifications require operational confirmation and may be documented in an executed security schedule.
Scryon will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data and provide available information reasonably needed for Customer's legal obligations, including the nature of the incident, affected data, likely consequences, and mitigation. Notice is not an admission of fault. Scryon will take reasonable steps to contain, investigate, and remediate the incident.
4. Data-subject rights and compliance assistance
This section covers help with data-subject requests and compliance.
Taking into account the nature of processing and information available, Scryon will reasonably assist Customer with:
- responding to requests for access, correction, deletion, restriction, portability, objection, opt-out, and other applicable rights;
- security, breach notification, data-protection impact assessments, and prior consultation with supervisory authorities; and
- information reasonably necessary to demonstrate compliance with Article 28 of the GDPR and comparable laws.
If Scryon receives a request concerning Customer Personal Data, it may direct the requester to Customer and will not respond substantively except on Customer's instruction or as required by law. Customer is responsible for requests and costs arising from its instructions, subject to any limits in the Agreement.
5. Subprocessors
This section explains how subprocessors are used and disclosed.
Customer gives Scryon general authorization to use subprocessors to provide the Service, including hosting, infrastructure, security, communications, support, CRM integration, payment, analytics, and AI-model providers. Scryon will impose data-protection obligations appropriate to the processing and remains responsible for each subprocessor's performance to the extent required by law.
The current operational list is at Subprocessors and Data Sources. That page separates processors from independent data sources. Scryon will provide reasonable advance notice of a new subprocessor that will materially process Customer Personal Data, such as by updating the list or email where an executed DPA provides a subscription mechanism.
Customer may object on reasonable data-protection grounds by emailing privacy@scryon.io within 15 days of notice. The parties will work in good faith on a commercially reasonable alternative. If none is available, either party may terminate only the affected Service, and Scryon will refund prepaid fees for the terminated period where applicable.
6. International data transfers
This section covers international transfers of Customer Personal Data.
Customer authorizes processing in the countries where Scryon and its authorized subprocessors operate, subject to Applicable Data Protection Law. The parties must validate actual hosting and processing locations before execution.
For transfers of Customer Personal Data subject to the GDPR to a country without an adequacy decision, the parties incorporate by reference the European Commission's 2021 Standard Contractual Clauses, Decision (EU) 2021/914 ("SCCs"). Module Two applies where Customer is a controller and Scryon is a processor; Module Three applies where both are processors. Docking is optional; Clause 7 applies. Option 2 in Clause 9 applies with the notice period in Section 5. The optional language in Clause 11 does not apply. The governing law and courts in Clauses 17 and 18 will be those of an EU member state that permits third-party beneficiary rights, to be specified in an executed copy. Annexes I–III are completed by this DPA, the applicable order, the processing details below, the subprocessor list, and the validated security schedule.
For restricted transfers subject to the UK GDPR, the parties incorporate the UK International Data Transfer Addendum to the EU Commission SCCs, version B1.0 in force 21 March 2022, as revised by the UK Information Commissioner's Office. The information in the applicable SCCs and this DPA completes Tables 1–3; either party may end the Addendum as permitted by Table 4. For Switzerland, references to the GDPR and member state will be adapted to the Swiss Federal Act on Data Protection where required.
Scryon will provide reasonable information needed for transfer impact assessments and implement supplementary safeguards appropriate to risk. Exporter/importer identities, addresses, signatures, competent authority, locations, and technical measures must be completed in an executed copy.
7. Return and deletion
This section covers return or deletion of Customer Personal Data.
During the term, Customer may retrieve Customer Data through available Service functionality or a reasonable request. On termination or Customer's written instruction, Scryon will delete or return Customer Personal Data within a reasonable period unless law requires retention. Deletion from backups may occur through ordinary secure rotation. Any retained data remains protected by this DPA and will be used only for the legally required purpose. Exact export windows, backup cycles, and deletion schedules require validation.
8. Information and audits
This section explains audit and information rights.
Scryon will make available information reasonably necessary to demonstrate compliance, initially through current third-party reports, certifications, security summaries, and questionnaire responses when available. No certification is promised unless confirmed in writing.
If that information is insufficient, Customer may conduct an audit no more than once annually, and additionally after a material Security Incident or regulator request, on at least 30 days' notice. Audits must occur during business hours, avoid unreasonable disruption, protect other customers and Scryon confidential information, and use an independent auditor bound by confidentiality. Customer bears its costs, and Scryon may charge reasonable costs for disproportionate assistance. A regulator's mandatory rights are not restricted.
9. Annex I: Processing details
This section summarizes processing details for the Service.
- Subject matter and duration: Provision of B2B event-intelligence, enrichment, CRM/CSV import, organizer-data, scoring, research, and related support for the Agreement term plus the deletion period.
- Nature and purpose: Hosting, importing, organizing, matching, deduplicating, classifying, enriching, scoring, summarizing, analyzing, securing, supporting, and exporting data under Customer's instructions.
- Data subjects: Customer users, employees, contractors, prospects, customers, CRM contacts, event attendees, speakers, sponsors, exhibitors, organizers, and other professional contacts represented in Customer Data.
- Data categories: names, business contact details, employer, title, professional profiles, company attributes, event participation, CRM identifiers, account and opportunity data, communications, usage data, and customer-defined fields.
- Sensitive data: Not intended or authorized absent a written amendment. Customer must not submit sensitive data by default.
- Frequency: Continuous or as initiated by Customer during use of the Service.
- Controller rights: Customer exercises rights through Service controls and written instructions to privacy@scryon.io.
10. Execution, precedence, and contact
This section covers how the DPA is executed and how to contact us.
This posted DPA becomes binding when incorporated into an order or accepted through an authorized account flow. For a countersigned version, SCC completion, security schedule, or subprocessor notices, contact privacy@scryon.io. Scryon's complete legal entity name, address, and authorized signatory must be added before signature.
If the SCCs conflict with this DPA, the SCCs control. If this DPA conflicts with the Agreement on protection of Customer Personal Data, this DPA controls. Liability under this DPA is subject to the Agreement's lawful limitations, but no term limits rights or liability that cannot lawfully be limited.
Related documents: Terms of Service, Privacy Notice, Subprocessors and Data Sources, and Privacy Choices.