Data Processing Agreement
Effective Date: 25-Mar-2026 |Last Updated: 25-Mar-2026
Pion Global Private Limited (“Pion Global”, “we”, “us”, or “our”) respects your use of our digital platforms and is committed to providing secure, reliable, and compliant services.
This Data Processing Agreement (“DPA”) forms an integral part of the agreement between Pion Global Private Limited (“Pion Global”, “GRCNest”, “PIEDAP”, “Processor”, “we”, “us”, or “our”), provider of the GRCNest.ai product built on the PIEDAP (Pion Intelligent Enterprise Digital Assurance Platform), and the Customer (“Controller” or “Data Fiduciary”).
This DPA governs the processing of Personal Data by Pion Global on behalf of the Customer in connection with the provision of Services and is intended to ensure compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR), the Digital Personal Data Protection Act, 2023 (India), and other relevant global frameworks.
Roles & Responsibilities
For the purposes of applicable data protection laws, the Customer acts as the Data Controller (or Data Fiduciary), determining the purposes and means of processing Personal Data, while Pion Global acts as the Data Processor, processing Personal Data solely on documented instructions from the Customer. Pion Global shall not process Personal Data for any purpose other than to provide and improve the Services, unless required by applicable law.
Nature, Purpose & Context of Processing
Pion Global processes Personal Data as necessary to operate, deliver, and enhance the GRCNest platform and broader PIEDAP ecosystem, including functionalities such as governance workflows, compliance monitoring, control validation, risk assessment, reporting, and AI-driven analytics. Processing activities may include collection, storage, structuring, retrieval, analysis, transmission, and deletion of data, strictly within the scope of delivering enterprise GRC capabilities and supporting continuous assurance.
Categories of Data & Data Subjects
The Personal Data processed under this DPA may include, but is not limited to, identification data (such as names, email addresses), system and usage data (such as logs, access records), and compliance-related data (such as audit evidence, control records), relating to Customer employees, users, contractors, or stakeholders, as configured and provided by the Customer through the platform.
Processor Obligations
Pion Global shall process Personal Data only in accordance with documented instructions from the Customer, ensure that all personnel authorized to process Personal Data are bound by confidentiality obligations, and implement appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage. Pion Global shall promptly inform the Customer if, in its opinion, any instruction violates applicable data protection laws.
Confidentiality & Data Protection Governance
Pion Global ensures that all personnel involved in data processing are subject to strict confidentiality obligations and are trained in data protection, security, and compliance practices. Data processing activities are governed by internal policies aligned with ISO/IEC 27001, SOC 2 Trust Services Criteria, and industry best practices, ensuring accountability, traceability, and continuous monitoring.
Security Measures
Pion Global implements robust technical and organizational safeguards, including encryption of data at rest and in transit, role-based access control (RBAC), multi-factor authentication (MFA), secure APIs, network security controls, logging and monitoring, vulnerability management, and incident response procedures. These controls are aligned with internationally recognized standards such as ISO/IEC 27001 and SOC 2, ensuring the confidentiality, integrity, and availability of Personal Data.
Sub-Processors
Pion Global may engage trusted third-party sub-processors, including cloud infrastructure providers and service vendors, to support the delivery of the Services. All sub-processors are subject to contractual obligations ensuring equivalent levels of data protection, confidentiality, and security. Pion Global remains responsible for the acts and omissions of its sub-processors and shall provide transparency regarding sub-processor engagement.
International Data Transfers
Where Personal Data is transferred across jurisdictions, Pion Global ensures that such transfers are conducted in compliance with applicable data protection laws, including the implementation of appropriate safeguards such as Standard Contractual Clauses (SCCs) or equivalent mechanisms, ensuring an adequate level of data protection.
Data Subject Rights
Pion Global shall provide reasonable assistance to the Customer in enabling the Customer to respond to requests from Data Subjects exercising their rights under applicable laws, including rights of access, rectification, erasure, restriction, and data portability. Such assistance shall be provided to the extent that it is technically feasible and proportionate.
Data Breach Notification
In the event of a Personal Data Breach, Pion Global shall notify the Customer without undue delay and provide sufficient information to enable the Customer to meet its legal and regulatory obligations. Pion Global shall take all reasonable steps to investigate, mitigate, and remediate the breach, in accordance with established incident response procedures.
Data Retention & Deletion
Personal Data shall be retained only for as long as necessary to fulfil the purposes of processing or as required by applicable laws. Upon termination or expiration of the Services, Pion Global shall, at the Customer’s instruction, delete or return all Personal Data, unless retention is required for legal or regulatory purposes, and shall ensure secure deletion practices.
Audit, Compliance & Accountability
Pion Global shall make available to the Customer information necessary to demonstrate compliance with this DPA and applicable data protection laws and may support audits or assessments upon reasonable notice. Pion Global maintains records of processing activities and continuously evaluates its controls to ensure alignment with regulatory and industry standards.
AI Processing & Governance
GRCNest leverages AI-driven capabilities to analyse data, validate controls, and generate risk insights; however, all such processing is performed under Customer instructions and within defined use cases. Pion Global ensures that AI outputs are transparent, explainable where feasible, and subject to human oversight, and does not use Customer Personal Data to train generalized or external AI models without explicit authorization. AI processing is governed by principles of fairness, accountability, and compliance with emerging AI regulations and standards, including alignment with ISO 42001 (where applicable).
Assistance & Regulatory Cooperation
Pion Global shall provide reasonable assistance to the Customer in fulfilling obligations related to data protection impact assessments (DPIAs), regulatory inquiries, audits, and compliance reporting, to the extent that such assistance relates to processing activities carried out by Pion Global.
Liability & Indemnity
Each party’s liability under this DPA shall be subject to the limitations and exclusions set forth in the Master Agreement, except where otherwise required by applicable law. The Parties agree to allocate responsibility in accordance with their respective roles as Controller and Processor.
Governing Law & Jurisdiction
This DPA shall be governed by and construed in accordance with the laws of India, unless otherwise agreed in the Master Agreement, and shall be subject to the dispute resolution mechanisms defined therein.
Term & Amendments
This DPA shall remain in effect for the duration of the Services and any period during which Pion Global processes Personal Data on behalf of the Customer. Pion Global may update this DPA to reflect changes in legal, regulatory, or operational requirements, with appropriate notice provided to the Customer where required.
Changes to This Policy
Pion Global may update this Data Processing Agreement from time to time. The updated version will be posted on the website with a revised “Last Updated” date. Continued use of the Product and Platform after changes constitutes acceptance of the updated policy.
📩 For questions regarding this Data Processing Agreement, please contact[email protected]
This Data Processing Agreement defines permitted and prohibited use of the GRCNest product and PIEDAP Platform to protect security, integrity, and lawful operation.