This Data Processing Agreement (“DPA”) governs the processing of personal data by Prymera Consulting Private Limited (“Processor”, “we”) on behalf of a customer (“Controller”, “you”) in connection with the ARGOS service. It is incorporated into and forms part of the agreement between the parties (the “Agreement”). Terms in the GDPR / UK GDPR have the same meaning here.
1. Roles and scope
For personal data you submit to the service, you are the Controller and we are the Processor. We process personal data only on your documented instructions — including those given through your configuration and use of the service — unless required by law, in which case we’ll tell you (unless legally prohibited). Where a screened individual’s data is processed (for example in PEP/sanctions or adverse-media screening), you remain the Controller for that data.
2. Our obligations
- Purpose limitation: process personal data only to provide and support the service, and per your instructions.
- Confidentiality: ensure people authorised to process the data are bound by confidentiality.
- Security: implement appropriate technical and organisational measures (see Annex B), backed by our ISO/IEC 27001:2022 certification.
- Assistance: assist you, taking into account the nature of processing, with data-subject requests and with your obligations on security, breach notification, and DPIAs.
- Breach notification: notify you without undue delay after becoming aware of a personal-data breach, with the information you need to meet your Article 33/34 duties.
- Deletion/return: on termination, delete or return personal data as described in our SLA (30-day export window, deletion from active systems within 90 days), unless retention is legally required.
- Records & audits: make available the information needed to demonstrate compliance and allow for audits, including via up-to-date documentation and certifications (Annex B).
3. Your obligations
You warrant that you have a lawful basis for the personal data you process through the service, that your instructions are lawful, and that you have provided any notices and obtained any consents required for us to process the data as Processor.
4. Sub-processors
You provide general authorisation for us to engage the sub-processors listed on our Sub-processors page. We impose data-protection obligations on each sub-processor no less protective than this DPA, and we remain responsible for their performance. We will give at least 30 days’ notice of any intended addition or replacement of a sub-processor (by updating that page and, on request, by email), during which you may reasonably object on data-protection grounds.
5. International transfers
Some processing takes place outside the EEA/UK (see Annex A and the Sub-processors page). Where we transfer personal data of EEA/UK individuals to a country without an adequacy decision, the transfer is made under the European Commission’s Standard Contractual Clauses (SCCs) — Module Two (Controller-to-Processor) and, where relevant, Module Three (Processor-to-Processor) — together with the UK International Data Transfer Addendum for UK data. By entering into this DPA, the parties are deemed to have entered into the applicable SCCs, which are incorporated by reference and completed by the details in the Annexes.
6. Liability & term
This DPA is effective for as long as we process personal data on your behalf, and liability is subject to the limitations in the Agreement. If any conflict arises between this DPA and the Agreement on data protection, this DPA prevails.
Annex A — Details of processing
| Subject matter | Provision of the ARGOS AML compliance service. |
|---|---|
| Duration | The term of the Agreement, plus the deletion period in the SLA. |
| Nature & purpose | Hosting, storage, retrieval, screening (PEP/sanctions/adverse-media), LLM-assisted analysis, and audit logging, to deliver compliance tooling. |
| Categories of data subjects | Your authorised users; individuals who are the subject of your screening/compliance cases. |
| Categories of personal data | User account data (name, work email, hashed credentials); case and screening data you submit (names, identifiers, and details relevant to AML checks); query text and uploaded documents. |
| Special-category data | Not required by the service. You should avoid submitting special-category data except where necessary for a screening decision; you remain responsible for any you submit. |
| Sub-processors & locations | As listed on the Sub-processors page (India, EU, and US). |
Annex B — Technical & organisational measures
- Certified information-security management system (ISO/IEC 27001:2022, Cert. KDACI202601011).
- Encryption in transit (TLS 1.2+, HSTS) and at rest (AES-256).
- Invite-only, role-based access; PBKDF2-SHA256 password hashing; short-lived tokens with rotation and revocation.
- Per-tenant isolation of all cases, watchlists, audit rows and sessions.
- Tamper-evident, SHA-256 hash-chained audit trail, verifiable on demand; self-service export is on our roadmap — today, ask connect@remitso.com for an extract.
- Per-IP and per-route rate limiting; prompt-injection scanning; hardened security headers and CSP.
- Model queries sent direct to the provider(s) under each provider's own data-processing terms; queries are answered by a primary provider with an automatic fallback to a secondary provider if the primary is unavailable (see Sub-processors); no customer data is used to train models.
- A documented, customer-facing backup cadence and retention SLA is on our roadmap — ask connect@remitso.com for our current recovery posture.
To sign this DPA or request our SCC package and TOM detail, contact connect@remitso.com.