DATA PROCESSING ADDENDUM
Last updated on 27 August 2026
Data Processing Addendum
GDPR Compliance for Personal Data Processing
DPA
This DPA explains how Cadmos LTD ("Cadmos") processes Personal Data on behalf of any customer ("Customer") who uses the Cadmos Wallet and Cadmos Tokenization Platform (the "Services"). By accessing or using the Services, the Customer accepts this DPA.
1 DEFINITIONS
- Applicable Data-Protection Laws - all privacy and data-protection laws that apply to the Processing, including Regulation (EU) 2016/679 (the "GDPR"), the UK GDPR, and applicable national data-protection laws.
- Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Supervisory Authority, Processing, International Transfer - as defined in Applicable Data-Protection Laws.
- Standard Contractual Clauses ("SCCs") - the clauses adopted by Commission Implementing Decision (EU) 2021/914 (Modules Two and Three) and, where the UK GDPR applies, the applicable UK Addendum.
- Sub-processor - a third party engaged by Cadmos to Process Personal Data.
2 ROLES OF THE PARTIES
2.1 Customer acts as Controller (or as a Processor acting for a third-party Controller).
2.2 Cadmos acts as Processor for the Personal Data handled through the Services.
2.3 Each party complies with the obligations that apply to it under Applicable Data-Protection Laws.
2.4 Customer is responsible for:
- obtaining any required consents;
- providing all notices to Data Subjects; and
- ensuring a lawful basis for Cadmos to Process Personal Data.
3 DURATION & PURPOSE
Cadmos Processes Personal Data only:
- while the Customer uses the Services, and
- for the purposes listed in Annex I.
Afterwards, Cadmos deletes or returns the data as described in Section 11.
4 DOCUMENTED INSTRUCTIONS
Cadmos Processes Personal Data, including making an International Transfer, solely on Customer's documented instructions (this DPA and any later written instructions), unless EU, Member-State, or UK law requires otherwise. Where a legal requirement applies, Cadmos will inform Customer before Processing unless that law prohibits notice on important grounds of public interest. If an instruction appears to breach Applicable Data-Protection Laws, Cadmos will inform Customer.
5 CONFIDENTIALITY & SECURITY
5.1 Cadmos ensures that all personnel authorised to Process Personal Data are bound by confidentiality obligations.
5.2 Cadmos applies the technical and organisational measures in Annex II and any additional measures required by Article 32 of the GDPR.
6 SUB-PROCESSORS
6.1 Authorised Sub-processors are listed in Annex III.
6.2 Cadmos relies on the standard, publicly available Data-Processing Agreements (or equivalent terms) provided by each Sub-processor. Those online DPAs already incorporate the EU Standard Contractual Clauses or reference the Sub-processor's certification under the EU-US Data-Privacy Framework (DPF) where applicable. Cadmos keeps a registry of these DPAs and makes them available to Customers on request.
6.3 Cadmos will notify Customer at least 10 days before appointing or replacing a Sub-processor; Customer may object on reasonable data-protection grounds.
7 INTERNATIONAL TRANSFERS
Cadmos or a Sub-processor will not make an International Transfer unless:
a) the destination benefits from an adequacy decision, or
b) appropriate safeguards such as SCCs are in place (with supplementary measures where required).
Cadmos will provide copies of the relevant transfer mechanism on request (redacted where necessary).
8 CUSTOMER ASSISTANCE
- Data-Subject requests - Cadmos assists Customer, as far as practicable, to respond to verified requests to exercise rights under Applicable Data-Protection Laws.
- Data-Protection Impact Assessments - Cadmos gives reasonable help with DPIAs and prior consultations.
- Information - Cadmos makes available information demonstrating compliance with this DPA.
9 PERSONAL DATA BREACH
Cadmos notifies Customer without undue delay after becoming aware of a Personal Data Breach and cooperates with Customer's efforts to meet any notification duties.
10 AUDIT RIGHTS
On reasonable written notice, Cadmos will allow and contribute to audits (including inspections) carried out by Customer or an independent auditor mandated by Customer, provided that audits:
- occur no more than once per year (unless required by law or following a material incident);
- take place during normal business hours; and
- are subject to customary confidentiality undertakings.
11 DELETION OR RETURN
Upon termination of the Customer's use of the Services (or earlier on written request), Cadmos will delete or return all Personal Data, unless EU, Member-State or UK law requires retention. Cadmos will confirm deletion in writing if requested.
12 CO-OPERATION WITH SUPERVISORY AUTHORITIES
Cadmos will cooperate, on request, with any competent Supervisory Authority in the performance of its tasks.
13 LIABILITY
Any liability arising under or in connection with this DPA is subject to the exclusions, limitations, and caps in Cadmos's publicly posted Terms of Service, to the extent permitted by Applicable Data-Protection Laws and the SCCs.
14 GOVERNING LAW & JURISDICTION
Unless the SCCs or mandatory Applicable Data-Protection Laws specify otherwise, this DPA is governed by French law and disputes are subject to the exclusive jurisdiction of the competent courts of Paris, France.
15 ORDER OF PRECEDENCE
If there is a conflict between this DPA and any other Cadmos terms:
- the SCCs (if applicable) take precedence;
- then this DPA;
- then the Terms of Service or other applicable service agreement.
ANNEX I - DETAILS OF PROCESSING
Subject-matter and purpose
Operation of the Cadmos Wallet (self-custody and access to third-party on-ramp, off-ramp and DeFi integrations) and Cadmos Tokenization Platform (issuance, subscription and transfer of tokenised securities), plus related support and compliance operations. Cadmos does not take custody of Customer assets or act as a transaction counterparty.
Nature of Processing
Collection, recording, structuring, storage, retrieval, transmission, analysis, identity verification (including KYC/AML facial-image and liveness checks), communication, electronic-signature workflows and deletion.
Data-Subject categories
- End-users (investors, wallet holders)
- Directors, beneficial owners, authorised representatives and signatories
- Prospective users
- Customer-support contacts
Personal-data types
Identification data (name, date of birth, nationality, ID numbers, identity documents, facial images and liveness-check results); contact data (email, phone, address, WhatsApp handle); financial and compliance data (IBAN, bank statements, source-of-funds information, wallet address, transaction records and sanctions-screening results); one-time-passcode and consent records; e-signature artefacts; support and call logs; IP address, mobile-device identifiers and other device data.
Special-category data
Facial images and liveness-check results are intentionally processed for identity verification. To the extent facial features are technically processed for the purpose of uniquely identifying a person, that Processing may involve biometric data under Article 9 GDPR. No other special-category data is intentionally collected.
Duration
While Customer uses the Services plus up to 90 days for orderly deletion or longer where legally required.
ANNEX II - TECHNICAL & ORGANISATIONAL SECURITY MEASURES
- Encryption in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent).
- Role-based access control; multi-factor authentication for privileged accounts; quarterly access reviews.
- Segmented VPCs, firewall rules, and DDoS mitigation via Cloudflare.
- Secure-development lifecycle with code reviews, SAST/DAST and penetration tests.
- Centralised, tamper-resistant logging with automated alerting; 24 × 7 incident response.
- Encrypted backups replicated across multiple AWS regions and regular restoration tests.
- Logical segregation of customer data in multi-tenant systems.
- Personnel screening (where legal) and mandatory privacy/security training.
ANNEX III - AUTHORISED SUB-PROCESSORS
| Sub-processor | Service | Hosting Region(s)* | International-transfer safeguard |
|---|---|---|---|
| Amazon Web Services (AWS) | Hosting & infra | EU / USA | AWS online DPA with SCCs; AWS is DPF-certified (aws.amazon.com, dataprivacyframework.gov) |
| Cloudflare, Inc. | CDN, WAF, DDoS | EU / USA | Cloudflare online DPA with SCCs; DPF-certified (dataprivacyframework.gov, cloudflare.com) |
| Vonage (Nexmo) | SMS / voice | EU / USA | Vonage online DPA incl. SCCs; DPF-certified (vonage.com) |
| Meta Platforms (WhatsApp Business API) | WhatsApp messaging | USA | Meta Data-Transfer Addendum with SCCs; DPF-certified (dataprivacyframework.gov, facebook.com) |
| Postmark (ActiveCampaign) | Transaction-al email | USA | ActiveCampaign online DPA with SCCs; DPF-certified (activecampaign.com, help.activecampaign.com) |
| Sumsub Ltd. | KYC / AML | UK (primary) / EU | Sumsub online DPA with SCCs (UK → EEA transfer is adequate) (sumsub.com, sumsub.com) |
| Didit Technologies Ltd. | KYC / AML | EEA | No international transfer (EEA-hosted) |
| Assentify Ltd. | KYC / AML | Cyprus | No international transfer (EEA-hosted) |
| DocuSign, Inc. | E-signature | USA | DocuSign online DPA with SCCs; DPF-certified (docusign.com, docusign.com) |
| Docuseal Inc. | E-signature & document automation | EU / USA | Docuseal GDPR DPA incl. SCCs (docuseal.com, docuseal.com) |
Cadmos will give at least 10 days' prior notice before adding or replacing a Sub-processor and will honour any reasonable objection as set out in Section 6.
Data-Protection Officer
Cadmos LTD
Tzon Kennenty 8, IRIS HOUSE, 3rd floor
3106 Limassol, Cyprus
privacy@cadmos.finance
Contact
For questions about data processing or this DPA