// terms & policies

Centrum zgodności danych

One place for the frameworks, data-handling practices, and documentation that clients and auditors most often ask us for.

// frameworks we work under

What we're aligned to

GDPR

Our own processing activities, and the advisory work we do for clients, are built around GDPR principles and data subject rights.

NIS2

Incident classification, reporting timelines, and resilience requirements under the NIS2 Directive and its Lithuanian transposition.

DORA

ICT risk management and third-party oversight for financial-sector clients under the Digital Operational Resilience Act.

ISO 27001 / EU AI Act

Information security management aligned to ISO 27001, and AI system risk classification aligned to the EU AI Act and ISO 42001.

// data handling

Where your data lives

Client data is hosted primarily within the EU. Where processing occurs outside the EEA — for example through CYBORA LLC in the United States — it is covered by appropriate safeguards such as Standard Contractual Clauses. Full details are available under a signed NDA or Data Processing Agreement.

// documentation on request

What you can ask us for

Data Processing Agreement (DPA)

A standard DPA covering our processing activities on your behalf, ready to countersign.

Sub-processor list

The current list of third parties we use to deliver our platform and services.

Security questionnaire responses

Pre-filled answers to common vendor security questionnaires (SIG Lite, CAIQ, or your own format).

// request documentation

Need a DPA or sub-processor list?

Email us and we'll send over the current version, or set up time to walk through it.