Standard DPA
Cognia's standard Data Processing Addendum is modeled on the European Commission's Standard Contractual Clauses (Module 2 — Controller to Processor) and incorporates the UK International Data Transfer Addendum where applicable. It documents:
- The scope, nature, and purpose of processing under your subscription.
- Categories of data subjects and personal data processed.
- Technical and organizational measures (TOMs) — encryption, access control, monitoring, incident response.
- Subprocessor flow-down obligations and our notification commitments.
- International transfer mechanisms (SCCs, UK IDTA, Swiss addendum).
- Data subject rights assistance and breach notification SLAs.
Download
The standard DPA is pre-signed by Cognia. Counter-sign and email the executed copy back to legal@cogniahq.tech and we will return it for your records.
Download standard DPA (PDF)Custom DPA
Enterprise customers with specific legal or regulatory requirements (HIPAA BAA, sector-specific addenda, jurisdiction riders) can request a custom DPA. Contact legal@cogniahq.tech with the relevant context and we will route to our outside counsel.