Data Processing Agreement

September 5, 2026

1. Scope and applicability

This Data Processing Agreement ("DPA") applies when EVYNUM processes personal data on behalf of a customer in connection with the Orathos Service and applicable data protection laws require a processor agreement, including the EU General Data Protection Regulation ("GDPR"), the UK GDPR, and similar laws.

This DPA supplements the Terms of Service and Privacy Policy. If there is a conflict between this DPA and a separately executed data processing agreement signed by both parties, the signed agreement controls.

2. Roles and processing instructions

The customer is the controller (or business) and EVYNUM is the processor (or service provider) with respect to personal data contained in systems, files, applications, and backups that the customer chooses to protect with the Service.

EVYNUM will process personal data only on documented instructions from the customer, including configuration of backup scope, retention, storage destinations, user access, integrations, and restore operations enabled through the Service, unless processing is required by applicable law. In that case, EVYNUM will inform the customer of the legal requirement unless prohibited by law.

3. Categories of data subjects and data

Categories of data subjects may include the customer's employees, contractors, end users, and other individuals whose personal data resides in backed-up systems.

Categories of personal data may include identification data, contact details, authentication logs, file metadata, application data, communications, and any other personal data submitted by the customer to or generated within protected systems. The customer determines what personal data is processed through the Service.

4. Confidentiality and personnel

EVYNUM ensures that personnel authorized to process personal data are bound by confidentiality obligations and receive appropriate training regarding data protection and security.

5. Security measures

EVYNUM implements appropriate technical and organizational measures to protect personal data, including encryption, access controls, RBAC, MFA options, audit logging, and vulnerability management, as described in the Security Policy and Terms of Service.

The customer is responsible for securing its source systems, credentials, encryption keys, BYOS storage accounts, and internal access to restored data.

6. Subprocessors

The customer authorizes EVYNUM to engage subprocessors to support delivery of the Service, including infrastructure, email, monitoring, payment, and support vendors. EVYNUM imposes data protection obligations on subprocessors by contract.

A current list of key subprocessors is available on request at support@orathos.com. EVYNUM will provide notice of material changes to subprocessors where required by applicable law and offer reasonable objection mechanisms where mandated.

7. International transfers

Where personal data is transferred outside the EEA, UK, or Switzerland, EVYNUM will implement appropriate safeguards, including Standard Contractual Clauses and the UK International Data Transfer Addendum, supplemented by additional measures where required.

8. Data subject requests and assistance

Taking into account the nature of processing, EVYNUM will assist the customer by appropriate technical and organizational measures, insofar as possible, in fulfilling the customer's obligations to respond to data subject requests under applicable law.

The customer is responsible for determining whether a request relates to personal data processed through Orathos and for providing lawful instructions to EVYNUM.

9. Personal data breach notification

EVYNUM will notify the customer without undue delay after becoming aware of a personal data breach affecting personal data processed on the customer's behalf, and will provide information reasonably available to assist the customer in meeting its breach notification obligations.

10. Deletion and return of data

Upon termination or expiration of the Service, EVYNUM will delete or return personal data processed on behalf of the customer in accordance with the Terms of Service and customer instructions, except where retention is required by applicable law or resides in routine backup systems subject to scheduled deletion.

11. Audits and signed agreements

Upon reasonable request, EVYNUM will provide information necessary to demonstrate compliance with this DPA and allow audits mandated by applicable law, subject to confidentiality, security, and frequency limitations.

Enterprise customers may request a countersigned DPA or subprocessors list at support@orathos.com.

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Acceptable Use
  • Refunds & Cancellation
  • Security
  • Data Processing Agreement
  • Legal Notice