Scope
This DPA applies whenever Natton processes personal data on behalf of customer in connection with the services. For the purposes of GDPR, UK GDPR and DPDP, customer is the controller and Natton is the processor.
Processing details
Nature + purpose: as described in the order form. Categories of data subjects + personal data: as instructed by customer. Duration: for the term of the master agreement.
Natton's obligations
We process personal data only on documented instructions, ensure confidentiality of personnel, implement technical + organisational measures (Annex A), assist with data subject rights, breach notification, and DPIAs.
Sub-processors
Customer authorises Natton to engage sub-processors listed in our security portal, with prior notice + right to object before any new sub-processor is added.
International transfers
Where personal data is transferred outside the customer's home jurisdiction, we use SCCs (EU + UK), DPDP-compliant mechanisms or equivalent. For sovereign engagements, data stays in-country.
Security measures (Annex A)
Encryption at rest + in transit, least-privilege access, MFA, secure SDLC, network segmentation, vulnerability scanning, 24×7 SOC monitoring, ISO 27001 + SOC 2 controls, annual penetration testing.
Audit
Customer may request audit reports (SOC 2, ISO 27001) under NDA once per year, or schedule an audit at customer's expense with reasonable notice.
Breach notification
We notify customer within 48 hours of becoming aware of a personal data breach, with details of nature, scope, likely consequences + remediation steps.
Return + deletion
On termination, Natton returns or deletes all personal data within 30 days, except where retention is required by law.
Contact
Privacy: privacy@natton.ai. Security incidents: security@natton.ai.
