Data Processing Agreement
Version date: August 24, 2026
1. Preamble
1.1 This Data Processing Agreement (“DPA”) supplements and forms part of the Master Service Agreement, Terms of Service or other written or electronic agreement (“Agreement”) between Telesign (a Proximus Global company), hereinafter called “Contractor” , that has entered into such Agreement to provide messaging, communications, mobile connectivity, identity verification, analytics, and/or fraud detection services (“Services”) to a user of such Services (“Client”) . Contractor and Client are also hereinafter, each referred to as a “Party” and collectively as the “Parties” .
1.2 For the purposes of this DPA, the Services include services provided directly by the Contractor as well as services resold or otherwise made available by the Contractor from other entities within the Proximus Global group or, where applicable, its Affiliates. This DPA is necessary to ensure secure information processing since the provision of the Services under the Agreement may give rise to the exchange of certain information including personal data about individuals.
2. Definitions
2.1 Unless the context requires otherwise, the following terms shall when used in this DPA have the meaning set out hereunder:
a) “Affiliate” means a company, person or entity that is owned or controlled by, that owns or controls or is under common ownership or control with a Party. Ownership means direct or indirect ownership of more than 50% of the shares in a company or entity, and control means any power to appoint persons to the board of directors of a company or entity.
b) “Applicable Data Protection Law” means all applicable data protection, privacy, and information security laws and regulations – including but not limited to the EU General Data Protection Regulation (“EU GDPR”) and any national implementing legislation, the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (“CCPA”), the UK GDPR and the UK Data Protection Act 2018 (“UK GDPR”), Colombia’s Statutory law 1581 of 2012, Brasil’s Lei Geral de Proteção de Dados Pessoais 13.709/2018 (“LGPD”), the Swiss Federal Act on Data Protection (“Swiss DPA”), India’s Digital Personal Data Protection Act 2023 (“DPDP”) and Indonesia’s Law No. 27 of 2022 concerning Personal Data Protection (“PDP Law”), together with their implementing rules – that are applicable to either Party and/or its processing of personal data in connection with the Agreement.
c) “Controller” means the natural or legal person, which, alone or jointly with others, determines the purposes and means of the processing of personal data.
d) “Data Subject” means an identified or identifiable natural person whose personal data is processed.
e) “Processor” means a natural or legal person which processes personal data on behalf of a Controller.
f) “Restricted Transfer” means: (i) where the EU GDPR applies, a transfer of personal data from the European Economic Area to a country outside of the European Economic Area which is not subject to an adequacy determination by the European Commission; (ii) where the UK GDPR applies, a transfer of personal data from the United Kingdom to any other country which is not based on adequacy regulations pursuant to Section 17A of the United Kingdom Data Protection Act 2018; and (iii) where the Swiss DPA applies, a transfer of personal data from Switzerland to any other country which is not based on an adequacy decision recognized under the Swiss DPA.
g) “Standard Contractual Clauses” means: (i) where the EU GDPR applies, the contractual clauses annexed to the European Commission’s Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (“EU SCCs”); (ii) where the UK GDPR applies, the “International Data Transfer Addendum to the EU Commission Standard Contractual Clauses” issued by the Information Commissioner under s.119A(1) of the Data Protection Act 2018 (“UK Addendum”); and (iii) where the Swiss DPA applies, the EU SCC’s with the Swiss additions (“Swiss SCCs”).
h) “Sub-processor” means any sub-contractor or agent who is engaged by a Processor and agrees to receive personal data and process same on behalf of the Controller and/or Processor.
i) “Supervisory Authority” means any independent public authority, regulatory authority, or governmental body responsible for the enforcement or supervision of Applicable Data Protection Law, including, where applicable, data protection authorities.
2.2 The terms “personal data”, “personal data breach”, “process”, and “processing” when used shall have the meanings given to them under Article 4 of the EU GDPR.
2.3 The terms “sell” and “share” when used shall have the meanings given to them under the CCPA.
2.4 The terms used in this DPA not defined hereunder shall have their meanings given within the Applicable Data Protection Law.
2.5 Words used in the singular, where the context so permits, shall be deemed to include the plural and vice versa.
3. Processing of Personal Data
3.1 Each Party shall comply with its obligations under the Applicable Data Protection Law in relation to the processing of personal data, including obtaining valid consent or other applicable lawful basis for processing. For the avoidance of doubt, this DPA is in addition to, and does not relieve, remove or replace, a Party’s obligations under the Applicable Data Protection Law.
3.2 The Parties acknowledge that, depending on the nature of the Services, Contractor may act either as a Processor (or Sub-processor) on behalf of Client, or as an independent Controller. The applicable role shall be determined based on the specific processing activities described in Annex I. To the extent that Contractor processes personal data as a Processor, on behalf of the Client (or Client’s customer) acting as a Controller, in connection with the Agreement, Contractor shall fully comply with the obligations as set out hereunder:
a) process the personal data only as necessary for the performance of the Agreement and strictly in accordance with the Client’s documented instructions, and inform the Client immediately if, in its opinion, an instruction of the Client infringes Applicable Data Protection Law. The permitted purposes of Contractor’s processing of persona data are as outlined in Annex I to this DPA. If the Contractor would be required by any law to process any personal data otherwise than as permitted by the Client, the Contractor shall inform the Client of the requirement before processing, unless that law prohibits such information on important grounds of public interest.
b) treat the personal data as confidential information, entrust only such employees or agents who have been bound to confidentiality and have previously been familiarised with the data protection provisions relevant to their work with the processing of personal data, and ensure that disclosure of or access to personal data is restricted to its employees or agents that strictly require such personal data to perform the tasks assigned to them in relation to the Services.
c) implement appropriate technical and organizational security measures as set out in Annex II to this DPA, prior to and during processing of any personal data to protect the security, confidentiality and integrity of the personal data and to protect the personal data against any form of accidental, unlawful or unauthorized processing.
d) co-operate with Client to enable Client comply with its obligations with regard to personal data security, taking into account the nature of the processing and the information available to Contractor.
e) provide reasonable co-operation and assistance to the Client, if and when the Client is required to perform a data protection impact assessment, an international data transfer impact assessment, or consultation with a Supervisory Authority having appropriate jurisdiction. Contractor shall promptly inform the Client if Contractor becomes aware that certain processing activities are likely to result in a high risk to the rights and freedoms of data subjects.
f) co-operate, at its own expense, as requested by the Client to enable it to respond and comply with (i) the exercise of rights of data subjects pursuant to Applicable Data Protection Law (such as their right of access, right to rectification, right to object to the processing of their personal data, right to erasure and right to restrict processing of their personal data and their right to data portability) and (ii) any other correspondence, enquiry or complaint received from a Data Subject, Supervisory Authority or any other third party in respect of personal data processed by Contractor under this DPA.
g) promptly inform the Client of any requests relating to the exercise of such rights or complaints, enquiry or correspondence if they are received directly by Contractor and shall provide all details thereof. Contractor shall provide all information requested by the Client, within a reasonable timescale specified by the Client and shall provide such assistance to the Client to comply with the relevant request within the applicable timeframes. If necessary, Contractor shall co-operate with the competent Supervisory Authority.
h) upon Client’s request, make available to the Client all records, appropriate personnel, data processing facilities, and any relevant materials relating to personal data processing, to enable the Client to demonstrate compliance with its obligations under Applicable Data Protection Law.
i) promptly return or delete the personal data and any existing copies thereof, as soon as it is no longer required for the performance of the Services, unless any applicable law requires the further storage of the personal data. Where deletion is necessary and the Contractor cannot destroy or delete the personal data due to technical reasons, the Contractor will take all appropriate steps to (a) come to the closest possible to a complete and permanent deletion of the personal data and to fully and effectively anonymize the remaining personal data; and (b) make the remaining personal data which is not deleted or effectively anonymized unavailable for any further processing except to the extent required by any applicable law.
j) promptly notify the Client if: (i) the Contractor cannot comply with this DPA; (ii) it has breached or is likely to breach Applicable Data Protection Law; or (iii) Applicable Data Protection Law no longer permits lawful processing or transfer of personal data. The Contractor shall take reasonable steps to remedy such issues or cease processing as instructed by the Client.
3.3 Client allows Contractor to be assisted by Contractor’s subcontractors and Affiliates, and to appoint those subcontractors and Affiliates as Sub-processors of personal data involved in the Services, with a view to delivering, facilitating and improving the Services, provided that Contractor shall: (i) prior to appointing a Sub-processor, carry out appropriate due diligence on the Sub-processor; (ii) inform the Client at least 30 days in advance and by means of a written communication about its intention to engage a new Sub-processor, including details on the identity of the Sub-processor, the location where the personal data will be processed by such Sub-processor and the concerned data processing activities; (iii) enter into written agreements with such appointed Sub-processor guaranteeing at least the level of data protection and information security provided in this DPA; and (iv) remain liable to the Client for the Sub-processor’s acts, errors or omissions resulting in a breach of Applicable Data Protection Law. Client may within 15 days of Contractor’s notification of a new Sub-processor, object to the appointment of the Sub-processor on reasonable grounds relating to the protection of the personal data, in which case the Parties shall then work together promptly and in good faith to resolve the Client’s objections and to agree upon a mutually satisfactory solution. Contractor’s current subcontractors and Affiliates are detailed in Annex III to this DPA.
3.4 To the extent Contractor is an independent Controller of personal data that is collected, exchanged, or otherwise processed in connection with Contractor’s performance of the Agreement or delivery of the Services, Contractor will comply with its Controller obligations under Applicable Data Protection Law, for example by providing protection for the personal data, ensuring data minimization and that the personal data is processed lawfully, fairly and in a transparent manner in relation to the Data Subject, as well as responding to Data Subjects’ requests to exercise their rights. The provisions of Section 3.2 shall not apply in such circumstances.
3.5 Telesign shall use Data only to provide, maintain, and improve the Services. Data, including any Personal Data therein, may be stored and processed in the United States or any other countries in which Telesign maintains facilities. Client consents to any such transfer and appoints Telesign to conduct such a transfer on Client’s behalf in order to provide the Services. Client acknowledges that as part of the Services, for every Transaction, an assessment is carried out as to the fraud risk of a particular Transaction. Client consents to the results of each such Transaction, including the telephone number, IP address, and email related to such Transaction, being re-used by Telesign for the purposes of future fraud identification and prevention as part of the Services, and for purposes of providing the Services to other Telesign customers.
4. Security and Accountability
4.1 Contractor shall implement appropriate and sufficient, technical and organisational security measures prior to and during processing of any personal data to protect the security, confidentiality and integrity of the personal data and to protect the personal data against any form of accidental, unlawful or unauthorized processing. In particular, without limitation, Contractor shall protect the personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, use or access to personal data transmitted, stored or otherwise processed and against any form of unlawful processing.
4.2 Contractor shall ensure a level of security appropriate to the risks presented by the processing of personal data and the nature of such personal data. Such measures shall include, as appropriate: (i) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; (ii) the ability to restore the availability and access to the personal data in a timely manner in the event of a physical or technical incident; and (iii) a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing. At a minimum, such measures shall include the organisational and technical measures, which meet or exceed relevant industry practice. These measures shall remain in place throughout the duration that Contractor provides Services to the Client or until Contractor ceases to process personal data, whichever is later. As of the effective date of the Agreement, Contractor has implemented the security measures set out in Annex II to this DPA. Contractor may update or modify such security measures from time to time provided that such updates and modifications do not result in the material degradation of the security of the Services.
4.3 Contractor shall upon becoming aware of any personal data breach, promptly inform the Client of the breach without undue delay and shall provide all such timely information and cooperation as the Client may reasonably require including in order for the Client to fulfil its personal data breach reporting obligations under and in accordance with the timescales required by Applicable Data Protection Law. Contractor shall further take all such measures and actions as are necessary to remedy or mitigate the effects of the breach and shall keep the Client up to date about all developments in connection with the breach.
4.4 Contractor shall make available to Client, on request, all information reasonably necessary to demonstrate compliance with this DPA. Contractor may demonstrate compliance by providing either (i) a certification as to compliance with ISO 27001 or another information security management standard implemented by Contractor; or (ii) an audit or attestation report of an independent third-party. To the extent that Client requires further evidence of Contractor’s compliance with the DPA or further assurances of information security, Client or its appointed third-party auditor may upon written reasonable request conduct an inspection of the Contractor’s records, processes and systems, to the extent necessary according to Applicable Data Protection Law. Such inspection shall be conducted (i) with at least 90 days prior notice; (ii) during regular business hours and under a duty of confidentiality; (iii) with minimal disruption to Contractor’s business operations; and (iv) entirely at Client’s expense. Such inspection shall be conducted no more than once annually unless (i) further inspections are required by instruction of a competent Supervisory Authority or (ii) the Client believes that further inspections are necessary due to a personal data breach suffered by Contractor. Client and its agents may (at Contractor’s election) be accompanied by a member of Contractor’s staff should Client require access to Contractor’s premises during the inspection.
5. Jurisdiction-Specific Terms
5.1 To the extent that either Party processes personal data originating from or otherwise subject to the data protection or security law of a particular jurisdiction, the corresponding jurisdiction-specific terms set out below shall apply in addition to, and in the event of conflict prevail over, the foregoing terms of this DPA.
5.2 Contractor shall not make or permit a Restricted Transfer of any personal data (whether as an exporter or as an importer) unless an adequate level of protection in accordance with the Applicable Data Protection Law is ensured. The applicable transfer mechanism and Standard Contractual Clauses module shall be determined based on the Parties’ roles as set out in Annex I The Parties agree that when the transfer of personal data from Client to Contractor is a Restricted Transfer it shall be subject to the appropriate Standard Contractual Clauses as follows:
a) EU GDPR (Controller to Controller): in relation to personal data that is protected by the EU GDPR where Contractor is a Controller, the EU SCCs will apply completed as follows: (i) Module One will apply; (ii) in Clause 7, the optional docking clause will apply; (iii) in Clause 11, the optional language will not apply; (iv) in Clause 17, Option 1 will apply, and the EU SCCs will be governed by Belgian law; (v) in Clause 18(b), disputes shall be resolved before the courts of Belgium; (vi) Annex I of the EU SCCs shall be deemed completed with the information set out in Annex I to this DPA; and (vii) Annex II of the EU SCCs shall be deemed completed with the information set out in Annex II to this DPA.
b) EU GDPR (Controller to Processor): in relation to personal data that is protected by the EU GDPR where Contractor is a Processor and Client is the Controller, the EU SCCs will apply completed as follows: (i) Module Two will apply; (ii) in Clause 7, the optional docking clause will apply; (iii) in Clause 9, Option 1 will apply, and the time period for prior notice of Sub-processor changes shall be as set out in Clause 5.1 of this DPA; (iv) in Clause 11, the optional language will not apply; (v) in Clause 17, Option 1 will apply, and the EU SCCs will be governed by Belgian law; (vi) in Clause 18(b), disputes shall be resolved before the courts of Belgium; (vii) Annex I of the EU SCCs shall be deemed completed with the information set out in Annex I to this DPA; (viii) Annex II of the EU SCCs shall be deemed completed with the information set out in Annex II to this DPA; and (ix) Annex III of the EU SCCs shall be deemed completed with the information set out in Annex III to this DPA.
c) EU GDPR (Processor to Processor): in relation to personal data that is protected by the EU GDPR where Contractor is a Sub-processor and Client is a Processor of the personal data on behalf of a third party Controller, the EU SCCs will apply completed as follows: (i) Module Three will apply; (ii) in Clause 7, the optional docking clause will apply; (iii) in Clause 9, Option 1 will apply, and the time period for prior notice of Sub-processor changes shall be as set out in Clause 2.2(c) of this DPA; (iv) in Clause 11, the optional language will not apply; (v) in Clause 17, Option 1 will apply, and the EU SCCs will be governed by Belgian law; (vi) in Clause 18(b), disputes shall be resolved before the courts of Belgium; (vii) Annex I of the EU SCCs shall be deemed completed with the information set out in Annex I to this DPA; (viii) Annex II of the EU SCCs shall be deemed completed with the information set out in Annex II to this DPA; and (ix) Annex III of the EU SCCs shall be deemed completed with the information set out in Annex III to this DPA.
d) UK GDPR: in relation to personal data that is protected by the UK GDPR, the UK Addendum will apply completed as follows: The EU SCCs, completed as set out above in Clause 3.2(a)-(c) of this DPA shall also apply to transfers of such personal data; Tables 1 to 3 of the UK Addendum shall be deemed completed with relevant information from the EU SCCs, completed as set out above; and the option “neither party” shall be deemed checked in Table 4. The start date of the UK Addendum (as set out in Table 1) shall be the date of this DPA.
e) Swiss DPA: In relation to personal data that is protected by the Swiss DPA, the EU SCCs as implemented in accordance with Clause 3.2(a)-(c) will apply provided that: (i) references in the EU SCCs to “Regulation (EU) 2016/679” or the “GDPR” shall be interpreted as references to the Swiss DPA; (ii) references to “EU”, “Union” and “Member State law” shall be interpreted as references to Switzerland and to Swiss law, as the case may be; (iii) the term ‘member state’ shall not be interpreted in such a way as to exclude Data Subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (Switzerland); (iv) the EU SCCs should be interpreted as protecting the data of legal entities until the entry into force of the revised Swiss DPA; (v) references to the “competent supervisory authority” and “competent courts” shall be interpreted as references to the Swiss Federal Data Protection and Information Commissioner (FDPIC) and competent courts in Switzerland; and (vi) if the Restricted Transfer is subject to both the Swiss DPA and the GDPR, then a parallel supervision takes place: FDPIC, insofar as the data Restricted Transfer is governed by the Swiss DPA; and the competent EU Supervisory Authority insofar as the Restricted Transfer is governed by the GDPR (the criteria of Clause 13a for the selection of the competent authority must be observed).
European Economic Area – Digital Operational Resilience Act (Regulation (EU) 2022/2554) (“DORA”) and Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (“NIS2 Directive”)
5.3 To the extent applicable, the Contractor shall provide the Client with all necessary information and assistance to enable the Client to comply with its obligations under the DORA and NI2 Directive, including with respect to ICT risk management, incident handling, and operational resilience. Contractor will:
a) implement and maintain risk management measures aligned with the DORA conducting regular risk assessments related to data processing, performing impact analyses to evaluate the potential consequences of ICT-related incidents on data security and availability, and ensuring continuous monitoring of systems and controls to promptly detect, mitigate, and respond to operational and security risks. In alignment with DORA and NIS2 requirements, Contractor shall classify and report major ICT-related incidents to the relevant authorities and impacted parties within 72 hours of becoming aware of such incidents, based on severity and applicable regulatory thresholds.
b) conduct annual Threat-Led Penetration Testing (TLPT), performed by qualified and independent third-party security experts, simulating realistic and targeted cyberattacks to assess the effectiveness of Contractor’s security controls and incident response capabilities. The scope of such testing shall include critical systems and infrastructure involved in the data processing. Contractor shall remediate any identified vulnerabilities or weaknesses within a reasonable timeframe based on severity. Upon written request, Contractor shall provide the Client with a high-level summary of the TLPT findings and remediation actions, subject to reasonable confidentiality and security considerations.
c) appoint one or more designated security officers responsible for overseeing and ensuring compliance with applicable cybersecurity and operational resilience regulations, including the DORA and the NIS2 Directive. These officers shall coordinate internal security efforts, monitor regulatory developments, and ensure that relevant policies, controls, and response procedures remain aligned with legal and industry obligations.
California US – CCPA
5.4 To the extent that Contractor acts as a “Service Provider” as defined in CCPA Section 1798.140(ag)(1), Contractor will:
a) comply with the restrictions imposed on Service Providers under the CCPA, and accordingly (i) not sell or share personal data; (ii) not retain, use, or disclose personal data for any purpose other than for the business purposes specified in the Agreement (including retaining, using, or disclosing it for a commercial purpose other than the business purposes specified in the Agreement or as otherwise permitted under Applicable Data Protection Law); (iii) not retain, use, or disclose personal data outside of the direct business relationship between Client and Contractor; and (iv) not combine it with personal data it receives from or on behalf of another entity or that it collects from its own interaction with the Data Subject unless permitted by the CCPA.
b) regardless of its role under the CCPA, (i) process personal data only for the limited and specified purposes under the Agreement and this DPA; (ii) comply with applicable obligations under the CCPA and provide the same level of privacy protection as is required by the CCPA; (iii) allow Client to take reasonable and appropriate steps to ensure that Contractor uses personal data in a manner consistent with Client’s obligations under the CCPA; (iv) notify Client if Contractor makes a determination that it can no longer meet its obligations under the CCPA; and (v) allow Client upon reasonable notice to stop and remediate Contractor’s unauthorized use of personal data.
6. Indemnification
6.1 Contractor acknowledges that the obligations set forth in this DPA are essential and that any violation thereof may seriously harm the Client. Contractor shall have full and sole liability for all damages resulting from a failure on its part to comply with the provisions of this DPA subject to the limitations of liability set forth in the Agreement. Should any Data Subject to whom the personal data relates, a Supervisory Authority, a court or any other regulatory body lodge a claim for compensation against the Client that results from Contractor’s breach of its obligations under the Applicable Data Protection Law, Contractor shall assist and intervene in the Client’s defence against such claim upon the Client’s request and shall indemnify and hold harmless the Client against all costs and damages resulting from such claim subject to the limitations of liability set forth in the Agreement. The Client shall give Contractor prompt written notice of any such claim and shall provide all reasonable co-operation in the defence and settlement of such claim, at Contractor’s expense. The Client shall not make any admission as to Contractor’s liability in respect any claim and shall not agree to any settlement in respect of a claim without Contractor’s written consent.
7. General
7.1 If any provision in this DPA shall be held to be illegal, invalid or unenforceable, in whole or in part, the provision shall apply with whatever modification is necessary so that the provision is legal, valid and enforceable and gives effect to the Parties’ intent.
7.2 In the event of a conflict between the provisions of this DPA and those of the Agreement in respect of the processing and protection of personal data, the provisions of this DPA will prevail.
7.3 This DPA shall be governed by and construed in accordance with the governing law and jurisdiction provisions set out in the Agreement, and any disputes arising out of or in connection with this DPA shall be subject to such provisions.
7.4 This DPA may from time to time be updated by Contractor, as necessary, to reflect regulatory or operational changes. DPA updates shall be deemed automatically incorporated into and made a part of this DPA upon (i) Contractor’s publication of the updates on its website (at https://www.telesign.com/DPA) and (ii) Contractor’s notification of the updates to Client.
Annex I
MODULE ONE: Transfer controller to controller
Categories of data subjects whose personal data is transferred:
- Clients and potential Clients of data exporter
- Employees of data exporter
Categories of personal data transferred
- Clients and potential Clients of data exporter: contact and identity information provided by the data exporter dependent on the Service such as name, address, e-mail address, telephone number and other messaging identifiers, and date of birth; message content provided by the data exporter for transmission such as details of bookings, reservations and appointments, security alerts and one time passcodes; content provided by the data exporter for support and error resolution.
- Employees of data exporter: contact information such as name, email address and phone number; customer login and portal profile information; preferences and settings.
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.
- Sensitive data is not processed.
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).
- Continuous basis.
Nature of the processing
- Clients and potential Clients of data exporter: Data exporter will access one or more fraud detection, prevention and communications Services to communicate with the individual and/or evaluate attributes or accuracy of the individual’s phone number and other personal details.
- Staff of data exporter: Providing access to the Services.
Purpose(s) of the data transfer and further processing
Data importer may process personal data in accordance with the purposes set out in the Agreement and:
- Clients and potential Clients of data exporter: to provide its Services to the data exporter including obtaining, formatting, cleansing, combining and providing personal data to the Client, and routing messages; to resolve bugs, errors and technical issues including with carriers; to secure the Services; to reconcile bills; to comply with legal, tax, and audit obligations, ensure compliance with Telesign’s Acceptable Use Policy, to resolve disputes and meet contractual obligations with carriers; to detect violations of our Agreement;
- Staff of data exporter: to offer, maintain and enhance the Services it or its Affiliates offer; for billing, account and customer relationship purposes (including marketing our Services to staff of the data exporter); to resolve bugs, errors and technical issues; to secure the Services; to comply with legal, tax, and audit obligations, ensure compliance with Telesign’s Acceptable Use Policy, resolve disputes and meet contractual obligations with carriers; to detect violations of our Agreement;
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period
- The duration of the processing is for as long as necessary to enable Telesign’s purposes as a controller. The criteria used to determine Telesign’s retention periods include: the length of time of Telesign’s relationship with data exporter users(for example, the duration of a Telesign customer portal account); whether data exporters modify or their users delete information through their accounts; whether Telesign has a legal or contractual obligation to keep the personal data(for example, certain laws require Telesign to keep records for a certain period of time); whether retention is required by Telesign’s legal position(such as in regard to the enforcement of agreements, the resolution of disputes, and applicable statutes of limitations, litigation, or regulatory investigation); and whether Telesign needs to retain certain personal data to deliver and improve its Services.
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing
- In performing its services, data importer will use computing and personnel resources from its processors in the United States, United Kingdom, Serbia, Singapore, Colombia, China and the European Economic Area for the duration needed to perform its obligations under the Agreement.
C. COMPETENT SUPERVISORY AUTHORITY
As per the criteria set out in Clause 13(a) of the EU SCCs.
MODULE TWO: Transfer Controller to Processor
Categories of data subjects whose personal data is transferred
- Clients and potential Clients of data exporter
- Employees of data exporter
Categories of personal data transferred
- Clients and potential Clients of data exporter: message content provided by the data exporter for transmission such as details of bookings, reservations and appointments, security alerts and one time passcodes; content provided by the data exporter for support and error resolution.
- Employees of data exporter: contact information such as name, email address and phone number.
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.
- Sensitive data is not processed.
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).
- Continuous basis.
Nature of the processing
- Clients and potential Clients of data exporter: Data exporter will access one or more fraud detection, prevention and communications Services to communicate with the individual and/or evaluate attributes or accuracy of the individual’s phone number and other personal details.
- Staff of data exporter: Providing access to the Services.
Purpose(s) of the data transfer and further processing
Data importer may process personal data in accordance with the purposes set out in the Agreement and:
- Clients and potential Clients of data exporter: to provide its Services to the data exporter including delivering message content; to resolve bugs, errors and technical issues as requested by data exporter;
- Staff of data exporter: to provide and update the Services as licensed, configured and used by Client and its staff; to resolve bugs, errors and technical issues as requested by data exporter.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period
- The duration of the processing is limited to the duration needed to perform data importer’s obligations under the main Agreement unless a legal obligation applies. The obligations of the data importer with regard to the personal data processing shall in any case continue until the personal data have been properly deleted or have been returned at the request of the data exporter.
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing
- In performing its services, data importer will use computing and personnel resources from its employees, affiliates and sub-processors in the United States, United Kingdom, Serbia, Singapore, Colombia, China and the European Economic Area for the duration needed to perform its obligations under the main Agreement.
C. COMPETENT SUPERVISORY AUTHORITY
As per the criteria set out in Clause 13(a) of the EU SCCs.
MODULE THREE: Transfer processor to processor
Categories of data subjects whose personal data is transferred
- Clients and potential Clients of data exporter
- Employees of data exporter
Categories of personal data transferred
- Clients and potential Clients of data exporter: message content provided by the data exporter for transmission such as details of bookings, reservations and appointments, security alerts and one time passcodes; content provided by the data exporter for support and error resolution.
- Employees of data exporter: contact information such as name, email address and phone number.
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.
- Sensitive data is not processed.
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).
- Continuous basis.
Nature of the processing
- Clients and potential Clients of data exporter: Data exporter will access one or more fraud detection, prevention and communications Services to communicate with the individual and/or evaluate attributes or accuracy of the individual’s phone number and other personal details.
- Staff of data exporter: Providing access to the Services.
Purpose(s) of the data transfer and further processing
Data importer may process personal data in accordance with the purposes set out in the Agreement and:
- Clients and potential Clients of data exporter: to provide its Services to the data exporter including delivering message content; to resolve bugs, errors and technical issues as requested by data exporter;
- Staff of data exporter: to provide and update the Services as licensed, configured and used by Client and its staff; to resolve bugs, errors and technical issues as requested by data exporter.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period
- The duration of the processing is limited to the duration needed to perform data importer’s obligations under the main Agreement unless a legal obligation applies. The obligations of the data importer with regard to the personal data processing shall in any case continue until the personal data have been properly deleted or have been returned at the request of the data exporter.
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing
- In performing its services, data importer will use computing and personnel resources from its employees, affiliates and sub-processors in the United States, United Kingdom, Serbia, Singapore, Colombia, China and the European Economic Area for the duration needed to perform its obligations under the main Agreement.
C. COMPETENT SUPERVISORY AUTHORITY
As per the criteria set out in Clause 13(a) of the EU SCCs.
1. Technical and Organizational Security Measures
This document describes the technical and organizational security measures implemented by Contractor, as a Proximus Global company, in connection with the provision of the Services to Client, in order to ensure a level of security appropriate to the risks associated with the processing of personal data. These measures may evolve over time to reflect changes in technology, threats, and business operations, provided that the overall level of security is not decreased.
1. IT security governance
1.1 Contractor maintains an information security management framework and has implemented risk management processes, ensuring risks are properly identified, registered, treated and approved. The risk management practice ensures that measures remain appropriate to evolving threats and the state of the art.
1.2 A clear internal responsibility for security governance has been assigned in the company. A dedicated security team composed of security specialists, reports to the Proximus Global Chief Information Security Officer.
1.3 Contractor has documented and maintains security policies supporting these frameworks and measures.
2. Certification and assurance of processes and service delivery
2.1 Contractor maintains an information security management framework consistent with the requirements of internationally recognized standards such as ISO 27001, ensures compliance with applicable laws and regulations, and implements risk management measures aligned with industry best practices.
2.2 Contractor performs regular testing and evaluation of its security measures, to verify compliance with the predefined requirements, and remediate any identified gaps. Contractor conducts periodic penetration tests, under which sensitive applications, systems or platforms are tested by qualified and independent third-party security experts, who assess the effectiveness of the security controls and incident response capabilities.
3. Personnel Security.
3.1 Contractor’s personnel are required to conduct themselves in a manner consistent with the company’s guidelines regarding confidentiality, business ethics, appropriate usage, and professional standards. Contractor conducts reasonably appropriate background checks on any employees who will have access to Client data, to the extent legally permissible and in accordance with applicable local labour law, customary practice, statutory regulations, and in proportion to the data processed. Personnel are required to execute a confidentiality agreement and to always protect Client data.
3.2 Personnel are provided with privacy and security training on how to implement and comply with the information security program, at onboarding and periodically thereafter. Procedures are in place to ensure that personnel accesses are updated in the event of a role change and removed in the event of termination.
4. Data protection
4.1 Contractor protects sensitive data using strong encryption standards, to ensure information is secure both in transit and at rest, according to sensitivity, risk level and technical feasibility.
4.2 Encryption keys are managed through secure key management systems with strict access controls and segregation of duties to prevent unauthorized access.
4.3 When relevant and feasible, pseudonymisation techniques are applied.
5. Availability and resilience of processing systems and services
5.1 Contractor has developed and maintains a business continuity and disaster recovery program. The services that Contractor delivers are supported by redundant systems and backup mechanisms appropriate to the risks.
5.2 Backup procedures are in place, and periodic restoration testing is performed.
6. Access control
6.1 Contractor has implemented a formal access control policy that defines the principles, roles and responsibilities related to granting, modifying, reviewing and revoking access rights. Access is granted based on the principles of least privilege and need-to-know, ensuring that users only have access to the systems and data necessary to perform their job functions. Access provisioning and deprovisioning procedures are tied to HR processes.
6.2 A strong password policy is enforced, and multi-factor authentication is required for sensitive accesses (remote access, privileged activities).
6.3 Regular review of user privileges is performed, in order to validate the appropriateness of permissions, and remove those that are no longer necessary
7. Physical security
7.1 Physical access to any facility where data is being processed is controlled via badge systems or equivalent measures. Access is granted only to personnel who require such access to perform their duties.
7.2 A visitor process is in place: visitors’ accesses are logged, and visitors are escorted within the facilities.
7.3 Physical and environmental protections are in place in the facilities: fire detection, power backup, climate control, etc.
8. Secure system configuration
8.1 Contractor maintains documented secure configuration standards for infrastructure and applications. These standards are based on industry best practices and recognized frameworks. This includes system hardening procedures, removal and disabling of unnecessary services, ports and default accounts, enforcement of secure baseline configurations, and controlled change management procedures.
8.2 A vulnerability management program is in place, ensuring the identification, assessment and remediation of any identified weaknesses. Contractor performs periodic scanning of internal and external systems, prioritizes identified vulnerabilities based on their severity and associated risks, and defines remediation timelines. A patch management process is in place, to ensure timely application of security updates.
8.3 Contractor implements layered protection against malicious software across its network and infrastructure. Centrally managed anti-malware protection solutions are deployed and monitored. Email and web filtering are implemented, to detect malicious attachments and links, and to prevent access to known malicious domains.
8.4 A defense-in-depth approach protects Contractor’s network, including network segmentation, firewalls controlling inbound and outbound traffic, and intrusion detection and prevention mechanisms.
8.5 Logging and monitoring systems are implemented, to detect and respond to suspicious activity. Security events are logged and, where feasible, collected centrally. Alert mechanisms are defined to ensure a timely response in the event of an incident. Log retention is aligned with business and legal requirements.
9. Data minimisation, retention and deletion
9.1 Contractor applies the principle of data minimisation, so that only personal and business data strictly necessary for defined and legitimate purposes is collected and processed. The processing of personal data is limited to what is necessary for contractual, legal, or operational requirements. A privacy-by-design approach is embedded in system and process development.
9.2 A data retention policy defines retention periods, based on legal and regulatory requirements, contractual obligations and business and operational needs.
9.3 When the data is no longer necessary, secure deletion is performed, ensuring that data is irreversibly removed from the systems. Secure erasure methods are used for electronic data. Secure disposal of physical media is performed by certified companies.
10. Supply chain security
10.1 Contractor conducts due diligence and security assessment before onboarding suppliers. Suppliers are contractually obliged to ensure at least the same level of security that Contractor upholds.
10.2 Contractor regularly monitors its supply chain, to verify compliance with the security requirements.
11. Incident management
11.1 Contractor maintains a formal incident management framework designed to quickly identify, assess, and respond to security events. Contractor’s systems are continuously monitored for suspicious activity, with defined escalation procedures to ensure timely containment and remediation.
11.2 In the event of a confirmed incident, a team of experts is gathered to manage the incident. The team follows documented response and communication processes, including root cause analysis, and corrective actions, and, where required, external notification towards impacted Clients and/or regulatory notification in line with applicable laws.
11.3 Regular testing and post-incident reviews are performed to strengthen the controls and improve resilience.
List of Sub-processors:
Telesign engages the following third-party service providers to perform specific processing activities in connection with the Services.
| Entity Name | Role | Processing Location | Address |
|---|---|---|---|
| Amazon Web Services | Cloud hosting, storage, and data processing |
US – North Virginia EU – Ireland EU – Germany |
410 Terry Avenue North, Seattle, WA 98109, United States |
| Microsoft Corporation | Cloud hosting, storage, and data processing |
US – Texas, Washington EU – Netherlands EU – Germany |
One Microsoft Way, Redmond, WA 98052, United States |
| Adroiti Technologies | Network infrastructure management |
Lithuania |
Pylimo st. 41A, LT-01308 Vilnius, Lithuania |
The following entities are Telesign companies and affiliates that may process data in connection with provision of the Services. Affiliates are engaged due to the global nature of Telesign’s operations, and each affiliate is bound by intra-group data processing agreements that impose data protection obligations no less protective than those set out in this DPA.
| Entity Name | Role | Location | Address |
|---|---|---|---|
| Telesign Corporation | Service provider | US | 13274 Fiji Way Suite 600, Marina del Rey, CA 90292, USA |
| Telesign d.o.o. Beograd-Novi Beograd | Operational service delivery, technical and billing support | Serbia | Tresnjinog cveta 1/IX, 11070 Novi Beograd, Serbia |
| Telesign Colombia S.A.S. | Operational service delivery, technical and billing support | Colombia | Carrera 13 No. 98 – 70, Office 305, Bogotá D.C., Colombia |
| Telesign DO Brasil LTDA | Client support operations | Brasil | Rua Doutor Sodré 122, conj. 43, Edifício São Luís Business Center, Vila Nova Conceição, São Paulo/SP, CEP 04535-110 |
| Telesign Singapore Pte. Ltd. | Client support operations (for Singapore clients only) | Singapore | 1 Robinson Road, #18-00, AIA Tower, Singapore (048542) |
| Telesign (Beijing) Technology Co., Ltd. | Client support operations (for China clients only) | China | Room 501, 5/F, Building 1, China Central Place, No. 81 Jianguo Road, Chaoyang District, Beijing, China 100025 |
| Telesign Mobile Limited | Operational support | United Kingdom | 2 New Bailey, 6 Stanley Street, Salford, Greater Manchester, M3 5GS |
| MrMessaging FZE | CPaaS backend technology platform provision and operational support | UAE | Business Centre 103-104 Al Shmook Building, Umm Al Quwain Free Trade Zone Authority, Umm Al Quwain, United Arab Emirates |
| Route Mobile Limited | CPaaS backend technology platform provision and operational support | India | SanRaj Corporate Park – 4th Dimension, 3rd Floor, Mind Space, Malad (West), Mumbai – 400 064, India |
| Belgacom International Carrier Services SA/NV | Operational support | Belgium | Boulevard du Roi Albert II 27, 1030 Brussels, Belgium |
| Proximus Global SA | Operational support | Belgium | Boulevard du Roi Albert II 27, 1030 Brussels, Belgium |