Data Processing Agreement
Last updated: July 2026
This Data Processing Agreement ("DPA") sets out the principles under which Aitrion processes personal data on behalf of its customers when providing its products and services. It forms part of, and supplements, any agreement between Aitrion and its customers where personal data is processed.
Purpose
Aitrion is committed to protecting personal data and processing it in accordance with applicable data protection legislation.
This DPA outlines the responsibilities of both Aitrion (the Processor) and the Customer (the Controller) regarding the processing of personal data.
Scope
This DPA applies whenever Aitrion processes personal data on behalf of a customer while delivering software, implementation services, support or related professional services.
Roles and Responsibilities
Customer (Controller)
The Customer is responsible for:
- Determining the purpose and lawful basis for processing personal data.
- Ensuring that appropriate notices and permissions have been obtained where required.
- Providing only the personal data necessary for the agreed services.
Aitrion (Processor)
Aitrion agrees to:
- Process personal data only on documented instructions from the Customer.
- Maintain appropriate technical and organisational security measures.
- Ensure authorised personnel are subject to confidentiality obligations.
- Assist the Customer in meeting applicable data protection obligations where reasonably required.
- Notify the Customer without undue delay if a personal data breach affecting Customer data is identified.
Security Measures
Aitrion implements reasonable administrative, technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Security measures may include:
- Access controls
- Authentication and authorisation
- Encryption where appropriate
- Secure hosting environments
- Audit logging
- Regular security reviews
Confidentiality
Any personnel with access to Customer data are required to maintain appropriate confidentiality obligations and access data only where necessary to perform their duties.
Sub-processors
Aitrion may engage trusted third-party service providers to assist in delivering its services.
Where sub-processors are used, Aitrion will take reasonable steps to ensure they provide appropriate safeguards for personal data and remain subject to suitable contractual obligations.
International Data Transfers
Where personal data is transferred outside the applicable jurisdiction, Aitrion will implement appropriate safeguards in accordance with applicable data protection legislation.
Where possible, customer data may be hosted within the United Kingdom or another agreed location.
Data Subject Rights
Where reasonably requested, Aitrion will assist the Customer in responding to requests relating to:
- Access
- Rectification
- Erasure
- Restriction of processing
- Data portability
- Objection to processing
Personal Data Breaches
If Aitrion becomes aware of a personal data breach affecting Customer data, it will notify the Customer without undue delay and provide reasonable information to assist with any required response.
Data Retention and Deletion
Upon termination of the services, and subject to applicable legal or contractual obligations, Aitrion will return or securely delete Customer personal data as agreed between the parties.
Audit and Compliance
Upon reasonable request, Aitrion may provide information demonstrating its compliance with applicable data protection obligations, subject to appropriate confidentiality and security requirements.
Changes
This DPA may be updated periodically to reflect changes in legislation, regulatory guidance or Aitrion's services. The latest version will be made available through the Aitrion website or provided upon request.
Contact
If you have any questions regarding this Data Processing Agreement or Aitrion's data protection practices, please contact us using the details provided on the Aitrion website.
