Annex C — Instructions and security measures | Mynder

Annex C to the data processing agreement between Mynder AS and the end customer: processing instructions, information security, assistance, deletion, locations, third countries and audits.

Annex C — Instructions and security measures

Annex C to the Data Processing Agreement — Mynder AS and end customer

C.1 Subject matter of the processing / processing instructions

The processor's processing of personal data on behalf of the controller consists of Mynder AS performing the following:

Delivering, operating, administering, securing and improving the Mynder platform (the "Service")

Creating and managing users, roles, access rights and workspaces

Storing, structuring, displaying and making available content that the controller or users enter into the Service

Processing assessments, answers, comments, documentation, maturity analyses, Trust Profile and similar content that the controller itself makes available in the Service

Performing logging, traceability, security monitoring, error correction, support, maintenance and backup

Assisting with deletion, return, export and documentation of processing in accordance with the controller's instructions

Using approved sub-processors as listed in Annex B for the processing activities described there

Mynder AS shall not process personal data for its own independent purposes, and shall not extend the processing beyond what follows from the Agreement, Annex A, Annex B and this Annex C, unless the controller provides a documented instruction or the processing is required under EEA law or national law to which Mynder AS is subject.

The controller does not instruct Mynder AS to process special categories of personal data under GDPR Article 9 or data on criminal convictions and offences under GDPR Article 10, beyond what follows from the limitations and exceptions in Annex A.3, or what is specifically agreed in writing. The instruction nevertheless covers such descriptions of such data as are necessary for the controller to document incidents, events, risk assessments and its record of processing, within the minimisation obligation in Annex A.3. Data under GDPR Article 9 or 10 must not be entered into the AI functionality.

If such data is nevertheless entered by the controller or users in free-text fields, document uploads, chat or similar functions, the data is processed solely as a result of the controller's use of the Service and within the controller's documented instructions. Mynder AS shall process such data with the same level of security as other content in the Service, cf. Annex C.2, regardless of whether it was entered contrary to the limitations in Annex A.3.

C.2 Information security

The level of security shall reflect the nature, scope, purpose and context of the processing, as well as the risk to the rights and freedoms of natural persons. The processing concerns a digital platform for organisations' work on security, privacy, compliance, supplier management and maturity assessments. The platform may contain business-critical documentation, assessments, security-related information, contact details, user activity and other information that the controller enters itself.

A level of security shall therefore be established that is at least suitable to protect the confidentiality, integrity, availability and traceability of the data processed in the Service.

Mynder AS selects and maintains the technical and organisational security measures necessary to achieve the agreed level of security. As a minimum, the following measures shall be in place:

Pseudonymisation and encryption

Personal data shall be encrypted in transit and at rest where technically and practically relevant.

Traffic to and from the Service shall be protected with modern encryption protocols.

Secrets, keys and access information shall be handled securely and not stored in clear text where this can be avoided.

Pseudonymisation shall be considered and used where suitable for the processing activity in question.

Confidentiality, integrity, availability and resilience

Access shall be granted according to the principle of least privilege.

User access shall be role-based and limited to what is necessary.

Administrative access shall be limited, secured and reviewed regularly.

Mynder AS shall have procedures for handling security incidents, vulnerabilities and errors.

The Service shall be operated in a way that ensures reasonable availability and resilience.

Restoration

Mynder AS shall have procedures for backup and restoration of data.

Mynder AS shall be able to restore availability and access to personal data in a timely manner in the event of a physical or technical incident.

Restoration procedures shall be tested or assessed regularly.

Testing, assessment and evaluation

Mynder AS shall have processes for regular assessment of technical and organisational security measures.

Relevant security measures shall be evaluated upon material changes to the Service, system architecture or risk landscape.

Identified vulnerabilities and areas for improvement shall be handled on a risk-based approach.

Access via the internet

Access to the Service via the internet shall be protected with authentication and access control.

Where relevant, multi-factor authentication or equivalent security mechanisms shall be used or offered.

Sessions, log-in and access to administrative functions shall be protected against unauthorised access.

Protection during transfer

Personal data shall be protected against unauthorised access, alteration or loss during transfer.

Transfers between system components, sub-processors and users shall be secured with appropriate technical measures.

Protection during storage

Personal data shall be stored in approved operating environments and regions as set out in Annex B.

Access to stored data shall be limited to authorised persons and system components.

Data at rest shall be encrypted where this is offered by the underlying infrastructure or otherwise technically suitable.

Physical security

Physical security of data centres and infrastructure is primarily handled by approved sub-processors.

Mynder AS shall use sub-processors that provide sufficient guarantees for the physical and environmental security of locations where personal data is processed.

Home and remote working

Persons processing personal data on behalf of Mynder AS from a home or remote workplace shall be subject to requirements of confidentiality and secure use of equipment, systems and networks.

Access from a home or remote workplace shall take place through approved solutions and with the necessary access restrictions.

Logging

Mynder AS shall maintain logs necessary for security, traceability, troubleshooting and detection of unauthorised access or misuse.

Logs shall be protected against unauthorised access and alteration.

Access and activity logs shall be retained for as long as necessary for security, documentation and operations, and deleted or anonymised when no longer necessary.

C.3 Assistance to the controller

Mynder AS shall, to the extent possible and taking into account the nature of the processing, assist the controller in fulfilling its obligations under the GDPR and the Terms. The assistance covers in particular:

Giving the controller access to its own data and content in the Service

Assisting with export, rectification, deletion or restriction of processing where technically possible

Assisting with handling requests from data subjects for access, rectification, erasure, restriction, data portability or other rights

Assisting with information necessary for data protection impact assessments and any prior consultation

Assisting in the event of a personal data breach, including by providing available information about the nature and scope of the breach, the data affected, possible consequences and measures taken or proposed

Making available relevant documentation on technical and organisational security measures, sub-processors and processing locations

The assistance is provided within the framework of the Service's functionality and the information available to Mynder AS. If the controller requests assistance that requires specific development, manual review or other extensive work beyond ordinary assistance under the Agreement, the execution, scope and any payment may be agreed separately.

C.4 Retention period / deletion procedures

Personal data is retained for as long as the processing services are provided to the controller, unless the controller instructs Mynder AS to delete it earlier, or continued retention is necessary under the agreement, a legal obligation or a documented instruction.

Upon termination of the processing services, Mynder AS shall, at the controller's choice, delete or return the personal data in accordance with clause 11. The controller shall be given the opportunity to extract data before deletion where technically possible.

Deletion shall be carried out in the production environment within 30 calendar days after termination or after the controller has instructed deletion, unless EEA law or national law requires continued retention of specific data. Backups are not deleted individually, but are overwritten in the ordinary backup cycle within 35 days. The data is therefore finally deleted no later than 65 calendar days after termination or the instruction to delete.

Retention periods for access and activity logs, security logs, backups, support requests, transactional communication and data upon disconnection of integrations follow from Annex A.5.

C.5 Processing locations

Personal data is processed within approved locations and by approved sub-processors. An overview of processing locations and sub-processors is available on a separate page.

See sub-processor overview

C.6 Instructions for transfer of personal data to third countries

Personal data shall as a rule be processed within the EU/EEA. Mynder's Zitadel instance for identity and access management is self-hosted in Mynder's own Azure environment in Norway and therefore does not in itself involve processing in Switzerland or any other third-country transfer.

Mynder AS may not transfer personal data to third countries or international organisations without documented instructions from the controller, unless the transfer is required under EEA law or national law to which Mynder AS is subject. If such law requires a transfer, Mynder AS shall notify the controller before the processing, unless such notification is prohibited on grounds of important public interest.

Any transfer to a third country shall have a valid basis under Chapter V of the GDPR, for example an adequacy decision, the EU standard contractual clauses with necessary supplementary measures, or another valid transfer mechanism.

If the controller does not, in the Terms or subsequently, give a documented instruction concerning the transfer of personal data to a third country or an international organisation, Mynder AS may not, within the framework of the Terms, carry out such transfers.

C.7 Procedures for the controller's audits, including inspections

The controller may request information and documentation necessary to demonstrate Mynder AS' compliance with GDPR Article 28 and the Terms. Mynder AS may satisfy this through relevant security documentation, audit reports, third-party attestations, Trust Profile, documentation of technical and organisational measures or equivalent documentation.

If such documentation does not give the controller a sufficient basis to assess compliance, the controller may require a further audit, including an inspection, carried out by the controller or an independent auditor authorised by the controller.

Audits shall be notified with reasonable notice, carried out within normal working hours and limited to what is necessary to verify compliance with GDPR Article 28 and the Terms. Audits shall be carried out in a manner that does not unduly disturb Mynder AS' operations, weaken the security of the Service or give access to information about other customers, trade secrets or security-sensitive information that is not necessary for the audit purpose.

The auditor shall be subject to appropriate confidentiality obligations. Mynder AS may require the auditor to document independence, competence and confidentiality obligations before the audit is carried out.

Any costs incurred by the controller for an audit or inspection are borne by the controller, unless otherwise agreed or the audit reveals material non-conformities for which Mynder AS is responsible.

C.8 Procedures for audits, including inspections, at sub-processors

Mynder AS shall exercise reasonable control that sub-processors fulfil their privacy and security obligations. This may be done through assessment of agreements, security documentation, audit reports, third-party attestations, certifications, security descriptions or other relevant documentation.

Audits of sub-processors shall as a rule be carried out using available audit reports, third-party attestations or other relevant documentation from the sub-processor. Upon request, Mynder AS shall make relevant documentation available to the controller to the extent permitted under the agreement with the sub-processor and provided it does not disclose information about other customers, trade secrets or security-sensitive information.

Direct audits or inspections at sub-processors may only be required where this is necessary, practically possible and follows from the agreement with the sub-processor or applicable law. The controller's participation in any inspection of a sub-processor does not change Mynder AS' responsibility for the sub-processor's processing under the Terms.

Related documents