Legal

Data Processing Agreement

Public enterprise data artifact for privacy, governance, auditability, and data-boundary review.

Template version 1.1 - July 2026

Controller and Processor roles defined before enterprise deployment
Subprocessor list linked from a public legal surface
Security, privacy, and audit support treated as product requirements
Customer-specific data boundaries handled through signed deployment terms

Overview

This public Data Processing Agreement ("DPA") template describes how SimOracle expects to process personal data on behalf of an enterprise customer identified in an applicable service agreement ("Controller"). It is intended to be incorporated by reference into a SimOracle Master Service Agreement, Order Form, pilot agreement, or statement of work executed between the parties.

This page is published as an enterprise readiness artifact. Final terms, annexes, subprocessors, security exhibits, and deployment boundaries may be completed or modified in the signed agreement for a specific customer.

Scope and roles

Where SimOracle processes personal data on behalf of a customer, the customer acts as Controller and SimOracle acts as Processor for the categories of personal data and processing purposes described in the applicable agreement, order form, configuration, or written instruction.

Each party shall comply with its obligations under applicable data protection law. The Controller is responsible for the lawfulness of the underlying data collection and for providing all required notices to Data Subjects. SimOracle is responsible for processing personal data only as described in this DPA and in accordance with the Controller's documented instructions.

Processing instructions

SimOracle shall process personal data only on documented instructions from the Controller. SimOracle shall inform the Controller promptly if it believes an instruction infringes applicable data protection law.

The service agreement, order form, statement of work, configuration settings, support instructions, and written security or privacy requirements constitute the Controller's documented processing instructions as of the effective date.

Confidentiality

SimOracle ensures that all personnel authorized to process personal data are subject to binding confidentiality obligations. Access to personal data is limited to personnel who require it to perform their duties in connection with the Services.

Security measures

SimOracle will implement and maintain appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, alteration, or disclosure. These measures may include encryption in transit, encryption at rest where supported by the deployment environment, role-based access controls, least-privilege administrative access, audit logging, environment separation, backup controls, incident response procedures, and personnel confidentiality obligations.

Enterprise deployments may use customer-specific infrastructure, private cloud configuration, tenant isolation, bring-your-own-key patterns, region controls, or additional logging requirements when specified in the applicable agreement. Additional security information is available at simoracle.com/security.

Subprocessors

SimOracle maintains a public list of subprocessors at simoracle.com/subprocessors. SimOracle will provide notice before engaging a new subprocessor or making a material change to subprocessors used for enterprise services. The Controller may object to a new subprocessor on legitimate data protection grounds within the objection period stated in the applicable agreement.

SimOracle imposes data protection obligations on all subprocessors that are no less protective than those set forth in this DPA, and remains liable to the Controller for the acts and omissions of its subprocessors.

Data subject rights

SimOracle shall provide reasonable assistance to the Controller to fulfill its obligations to respond to Data Subject rights requests, including access, rectification, erasure, restriction, portability, and objection. Upon receiving a Data Subject request directly, SimOracle will promptly forward it to the Controller without responding on the Controller's behalf.

Security incident notification

SimOracle shall notify the Controller without undue delay, and in any event within 72 hours where required by applicable law or the signed agreement, upon becoming aware of a Security Incident affecting personal data processed under this DPA. Notification will include the information reasonably available to SimOracle, including the nature of the incident, affected systems or data categories, likely consequences, and measures taken or proposed to address the incident.

Data transfers

Where SimOracle transfers personal data from the European Economic Area or United Kingdom to a country without an adequacy decision, SimOracle will implement Standard Contractual Clauses (SCCs) or equivalent UK transfer mechanisms.

Enterprise clients may request deployment or processing boundaries designed to minimize cross-border transfers, subject to product capability, cloud-region availability, and the final service agreement.

Audit rights

SimOracle shall provide information reasonably necessary to demonstrate compliance with this DPA and the applicable service agreement. Audit support may include security questionnaires, architecture summaries, access-control evidence, subprocessor information, incident-response documentation, or independent reports when available.

Customer audits must be scoped to relevant systems, scheduled with reasonable prior notice, and conducted in a manner that protects SimOracle confidential information, other customers, production reliability, and security posture.

Deletion and return of data

Upon termination of the service agreement, or upon the Controller's written request, SimOracle shall cease all processing, and at the Controller's election securely delete or return all personal data within 30 days, with written confirmation of deletion available upon request.

Governing law

This DPA is governed by the laws of the State of Delaware, consistent with the governing law of the applicable service agreement, except to the extent that applicable data protection law mandates otherwise.

Questions

For enterprise-specific data processing inquiries, email hello@simoracle.com with "DPA Inquiry" in the subject line, or contact your account manager directly.