Data Processing Agreement
Last updated: 20 July 2026
This agreement is under final legal review and may be updated before it is finalised.
This Data Processing Agreement ("DPA") applies where Cogent2 Limited ("Cogent²") processes personal data on behalf of a customer ("Customer") in providing the Cogent² platform and services. It forms part of, and is governed by, the Master Services Agreement between Cogent² and the Customer (the "Agreement"), and is incorporated into it by reference. Capitalised terms not defined here have the meaning given in the Agreement. This DPA and clauses 2 to 6 of the Agreement are intended to be read consistently as a single set of Article 28 processor terms; in the event of conflict, the Agreement (those clauses and their annexes) prevails.
1. Definitions
"Data Protection Laws" means all laws applicable to the processing, including the UK GDPR and the Data Protection Act 2018, the EU GDPR, the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles, and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA). "Controller", "Processor", "Personal Data", "Processing", "Personal Data Breach", "Data Subject" and "Sub-processor" have the meanings given in the applicable Data Protection Laws.
2. Roles and instructions
For the Personal Data processed under the services, the Customer is the Controller and Cogent² is the Processor. Cogent² will process Personal Data only on the Customer's documented instructions (including as to international transfers), unless required to do otherwise by a law that applies to it, in which case it will inform the Customer first unless the law prohibits this on important grounds of public interest. The Agreement and the Order Form are the Customer's complete documented instructions. Cogent² will inform the Customer without undue delay if, in its opinion, an instruction infringes Data Protection Laws.
3. Confidentiality
Cogent² will ensure that persons authorised to process the Personal Data are subject to appropriate confidentiality obligations.
4. Security
Cogent² will implement and maintain the technical and organisational measures in Annex B, appropriate to the risk under Article 32 UK GDPR and the equivalent obligations under the other Data Protection Laws.
5. Sub-processors
The Customer gives Cogent² general written authorisation to engage the Sub-processors listed in Annex C. Cogent² has entered into, and will maintain, written contracts with each Sub-processor imposing data-protection obligations that meet Article 28, including the Annex B security measures and an obligation to notify Cogent² of a Personal Data Breach without undue delay. Cogent² remains fully liable to the Customer for each Sub-processor's data-protection obligations, as required by Article 28(4) UK GDPR (the monetary amount recoverable is subject to the liability cap in the Agreement). Cogent² will give at least 30 days' notice of any intended addition or replacement of a Sub-processor; the Customer may object on reasonable data-protection grounds, and if the objection cannot be resolved may terminate the affected service as its sole remedy.
6. Assisting the Customer with data-subject rights
Taking into account the nature of the processing, Cogent² will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights. If Cogent² receives such a request directly, it will not respond substantively except on the Customer's documented instruction, and will forward it to the Customer without undue delay.
7. Personal Data Breach
Cogent² will notify the Customer of a Personal Data Breach affecting the Customer's Personal Data without undue delay and, where feasible, no later than 72 hours after Cogent² becomes aware of it. The notification will describe, as it becomes known, the nature of the breach, the likely consequences, the measures taken or proposed, and a contact point, and may be provided in phases. Cogent² will assist the Customer with the Customer's own breach-notification obligations to supervisory authorities and Data Subjects. A notification is not an acknowledgement of fault or liability.
8. Impact assessments
Taking into account the information available to it, Cogent² will assist the Customer with data protection impact assessments and prior consultation with a supervisory authority where required by the Data Protection Laws.
9. International transfers
Cogent² hosts its application, database and EDI file storage in the EU region. Where Cogent² makes a transfer of Personal Data outside the UK or EEA, it will ensure an appropriate safeguard is in place, being an adequacy basis where available (including the EU-US Data Privacy Framework and its UK Extension for a certified Sub-processor), or otherwise the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum, together with any supplementary measures identified by a transfer risk assessment. Cogent² is established in the United Kingdom, so the UK GDPR applies to its processing regardless of where Data Subjects are located; where the Customer or its Data Subjects are in the EEA the EU GDPR applies, and where in Australia the Australian Privacy Act applies. Where the EU GDPR applies and the United Kingdom ceases to benefit from an EU adequacy decision, Cogent² will, on request, enter into the EU Standard Contractual Clauses as data importer for the Customer-to-Cogent² transfer.
10. Deletion and return
On termination of the relevant service, Cogent² will, at the Customer's choice, delete or return the Personal Data processed under that service and delete existing copies within 30 days, unless retention is required by law, and will certify deletion in writing on request. EDI files are retained on a rolling 30-day basis and then deleted automatically; on termination of the EDI service all of the Customer's EDI files are deleted within 30 days.
11. Audit and information
Cogent² will make available information reasonably necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits, subject to reasonable notice, frequency limits and confidentiality, which it may satisfy with a recognised third-party certification or report where that reasonably addresses the request.
12. United States (CCPA/CPRA)
Where the Customer or its processing is subject to the CCPA or CPRA, Cogent² acts as a "service provider" (or "contractor"), processes the personal information only for the business purpose of providing the services, and will not sell or share it or retain, use or disclose it outside the direct business relationship or as otherwise prohibited by the CCPA. Cogent² will provide the same level of privacy protection as the CCPA requires of the Customer, will not combine the personal information with data from other sources except as the CCPA permits, will assist the Customer with verifiable consumer requests, and will notify the Customer if it determines it can no longer meet its obligations.
13. Australia
For a cross-border disclosure under Australian Privacy Principle 8, Cogent² will take reasonable steps, including binding contractual commitments, to ensure overseas recipients handle personal information consistently with the Australian Privacy Principles. The Customer remains accountable under APP 8.1.
14. Prohibited Data
The Customer will not submit to the services any health or medical information, government-issued identifiers, financial-account or payment-card data subject to the PCI DSS, biometric data, special-category data, or any unlawful data or data it has no right to submit. Cogent²'s redaction pipeline is designed to strip PII-shaped fields but is not a guarantee, and the Customer remains responsible for keeping such data out of the services, in particular out of EDI files, which are stored whole.
15. Liability
The parties' liability under this DPA is subject to the limitations and exclusions in the Agreement.
Annex A: Details of processing
Subject matter and duration: processing of Personal Data to provide the services for the term of the Agreement, plus the retention periods below.
Nature and purpose: the Cogent² iPaaS orchestrates, maps and transfers data between the Customer's connected systems and supports monitoring, diagnosis and AI-assisted support of those integrations; the EDI service receives, validates, cleans, translates and delivers EDI and flat files between the Customer's trading partners and its systems; Professional Services may incidentally access Personal Data during consulting, configuration and training.
Types of Personal Data: names, business and delivery contact details, email and postal addresses, telephone numbers, order and transaction data, and any Personal Data incidentally contained in files or payloads, excluding Prohibited Data.
Categories of Data Subjects: the Customer's end customers, the Customer's suppliers and trading-partner contacts, and the Customer's personnel who use the services.
Retention: operational metadata for the term; EDI files for 30 days rolling; deletion or return on termination as above.
Annex B: Technical and organisational measures
- Data minimisation and payload firewall (iPaaS). Raw Customer payload data is not persisted: a redaction pipeline removes credential-shaped and PII-shaped fields before storage; schema observation captures data types only, never values; content sent to the AI Sub-processor is redacted on the same basis; and payloads are truncated before any write. EDI files are stored whole and protected by the measures below plus 30-day deletion.
- Encryption. Data is transmitted over TLS. Data at rest is protected by managed encryption, and sensitive credentials including per-account integration keys are encrypted at rest using authenticated encryption with managed key rotation.
- Access control. Role-based access control with least-privilege roles, tenant isolation and enforced account scoping so one account cannot access another's data; administrative access is restricted and, where enabled, protected by multi-factor authentication.
- Hosting. Application and database hosting in the EU region; EDI object storage in the AWS EU region.
- Logging and monitoring. Operational logging and monitoring, with alerting on integration failures and suspect data.
- Resilience. Back-ups of platform data and documented recovery processes, with target recovery point and recovery time objectives available on request.
- Sub-processor controls. Contractual data-protection terms with all Sub-processors.
- Testing. Security and cross-account access testing as part of the development lifecycle.
Annex C: Approved Sub-processors
As at the date of this DPA the approved Sub-processors are Railway Corp. (EU region), Supabase, Inc. (EU region), Amazon Web Services (EU region), Patchworks Media Ltd (United Kingdom), Anthropic, PBC (United States) and Resend, Inc. (United States). Our Sub-processors page shows the current list with each one's purpose and location. Cogent² will change the approved Sub-processors only in accordance with the 30 days' notice-and-objection process in section 5, and not by unilateral amendment of that page.
Voyage AI, Inc. (United States) is a built but currently inactive Sub-processor for text embeddings. It will not process Personal Data until the transfer safeguards in section 9 are confirmed, and its activation will be treated as a change under section 5.