Data Processing Agreement

Effective – September 18, 2026

This Data Processing Agreement, including its Annexes (“DPA” or “Addendum”), is entered into by and between Cogent, Inc., a Delaware corporation (“Cogent”), and Customer (as set forth in the applicable terms between Cogent and Customer regarding use of the Service) (the “Agreement”). 

Customer” means a person or entity that accepts and agrees to the terms of this DPA as of the earlier date on which such person or entity either clicks a box indicating acceptance of this DPA or uses the Service.

Cogent provides its proprietary AI-powered vulnerability management Software-as-a-Service solution (the “Service”) to Customers. The provision of the Service involves the Processing of Personal Data subject to the Data Protection Laws, and the purpose of this DPA is to set forth the terms under which Cogent Processes the Personal Data. 

IF YOU DO NOT ACCEPT THIS DPA, YOU MAY NOT ACCESS OR USE THE SERVICE. THE SERVICE IS INTENDED FOR THE CUSTOMER AND ITS AUTHORIZED USERS ONLY AND IS NOT FOR USE BY CHILDREN UNDER 13 YEARS OF AGE. IF AN INDIVIDUAL IS ENTERING INTO THIS DPA ON BEHALF OF A LEGAL ENTITY, SUCH PERSON REPRESENTS AND WARRANTS THAT IT HAS THE LEGAL AUTHORITY TO BIND SUCH LEGAL ENTITY TO THIS DPA AND THIS DPA APPLIES TO SUCH ENTITY, WHICH IS DEEMED CUSTOMER.

Cogent reserves the right to modify or update this DPA in its sole discretion. If Customer and Cogent have executed a written data processing agreement governing the processing of personal data by means of the Service, then the terms of such signed data processing agreement between the parties will supersede this DPA.

This DPA is incorporated into and made part of the Agreement (as defined below). 

  1. Definitions. All capitalized terms used in this DPA will have the meanings given to them herein, in applicable Data Protection Laws, or as set forth in the applicable Agreement between Cogent and the Customer.

Agreement” means the applicable terms between Cogent and Customer regarding use of or integration with the Service.

Controller” means the entity or Business which solely or jointly with other entities determines the purposes and means of the Processing of Personal Data and for the purposes of this   means Customer.

Data Breach” means a breach of security leading to accidental or unlawful destruction, loss, or alteration, unauthorized disclosure of, or access to, Personal Data Processed by Cogent on behalf of Customer.

"Data Protection Laws” means all applicable data protection and privacy laws, their implementing regulations, regulatory guidance, and secondary legislation, each as updated or replaced from time to time, including, as they may apply: (i) the General Data Protection Regulation ((EU) 2016/679) (the “GDPR”) and any applicable national implementing laws; (ii) the UK General Data Protection Regulation (“UK GDPR”) and the UK Data Protection Act 2018; (iii) U.S. legislation (e.g., the California Consumer Privacy Act and the California Privacy Rights Act); and (iv) any other laws that may be applicable. 

“Data Subject” means the identified or identifiable person to whom the Personal Data relates, as defined in the applicable Data Protection Laws. 

EU Standard Contractual Clauses” or “SCCs” or “Clauses” means the terms available at https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32021D0914&from=EN and promulgated pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council 4 June.

Personal Data” means any information relating to a Data Subject that is subject to the Data Protection Laws and that Cogent Processes on behalf of Customer as described in Section 4 of this DPA.

Processing” has the meaning given to it in the Data Protection Laws and “process”, “processes” and “processed” will be construed accordingly.

Processor” means the entity or Service Provider which Processes Personal Data on behalf of the Controller, as defined in the applicable Data Protection Laws and for the purposes of this DPA means Cogent.

  1. Compliance with Laws. Each party will comply with the Data Protection Laws as applicable to it.

  2. Personal Data Obligations. Customer undertakes that all instructions for the Processing of Personal Data under the Agreement or this DPA or as otherwise agreed will comply with the Data Protection Laws, and such instructions will not cause Cogent to be in breach of any Data Protection Laws. Customer, to the extent that it shares Personal Data with Cogent, is responsible for the means by which the Personal Data was acquired.

  3. Data Processing. Cogent will Process the Personal Data solely for the purposes of providing the Service and in accordance with Customer’s instructions as outlined in the Agreement and this DPA, or as otherwise documented by Customer, in either event only as permitted by applicable Data Protection Laws.

Unless prohibited by applicable law, Cogent will notify Customer if in its opinion, an instruction infringes any Data Protection Laws to which it is subject, in which case Cogent will be entitled to suspend performance of such instruction without liability to Cogent, until Customer confirms in writing that such instruction is valid under the Data Protection Laws. Any additional instructions regarding the manner in which Cogent Processes the Personal Data will require prior written agreement between Cogent and Customer.

Cogent will not disclose Personal Data to any government, except as necessary to comply with applicable law or a valid and binding order of a law enforcement agency (such as a subpoena or court order). If Cogent receives a binding order from a law enforcement agency for Personal Data, Cogent will notify Customer of the request it has received so long as Cogent is not legally prohibited from doing so.

Cogent will ensure that individuals with access to or involved in the Processing of Personal Data are subject to appropriate confidentiality obligations and/or are bound by related obligations under Data Protection Laws or other applicable laws.

Where Cogent acts as Customer’s Service Provider, Cogent shall not: (i) sell or share Personal Data; (ii) collect, retain, use, or disclose Personal Data (a) for any purpose other than providing the Service specified in the Agreement and this Addendum or (b) outside of the direct business relationship between Cogent and Customer; or (iii) combine this Personal Data with Personal Data that Cogent obtains from other sources except as permitted by applicable Data Protection Laws. Cogent certifies that it understands the prohibitions outlined in this Section and will comply with them.

The duration of the Processing, the nature and specific purposes of the Processing, the types of Personal Data Processed, and categories of Data Subjects under this Addendum are further specified in the Annexes to this Addendum and, on a more general level, in the Agreement.

  1. Transfers of Personal Data. 

Cogent shall transfer Personal Data between jurisdictions as a Data Processor in accordance with applicable Data Protection Laws.

  1. Transfers of Personal Data Outside the EEA.

    1. Transfers to countries that offer adequate level of data protection. Personal Data may be transferred from EEA to other jurisdictions where such jurisdictions are deemed to provide an adequate level of data protection under applicable Data Protection Laws.

    2. Transfers to other third countries. If the Processing of Personal Data includes transfers from EEA/EU Member States to countries outside the EEA/EU which have not been deemed adequate under applicable Data Protection Laws, the parties’ EU Standard Contractual Clauses are hereby incorporated into and form part of this Addendum. The Parties agree to include the optional Clause 7 (Docking clause) to the EU SCCs incorporated into this Addendum. With regards to clauses 8 to 18 of the EU SCCs, the module and options will apply as follows:

      1. Module Three shall apply. 

      2. The Option within Clause 11(a) of the EU SCCs, providing for the optional use of an independent dispute resolution body, is not selected. 

      3. The Options and information required for Clauses 17 and 18 of the EU SCCs, covering governing law and jurisdiction, are outlined in Section 12 of this Addendum.

      4. Option 2 within Clause 9(a) of the EU SCCs, covering authorization for subprocessors, is selected, as discussed within Section 11 of this Addendum.

  2. Transfers of Personal Data Outside Switzerland. If Personal Data is transferred from Switzerland in a manner that would trigger obligations under the Federal Act on Data Protection of Switzerland (“FADP”), the EU SCCs shall apply to such transfers and shall be deemed to be modified in a manner to that incorporates relevant references and definitions that would render such EU SCCs an adequate tool for such transfers under the FADP.

  3. Transfers of Personal Data Outside the UK. If Personal Data is transferred in a manner that would trigger obligations under UK GDPR, the parties agree (i) that Annex IV shall apply.

  4. Annexes. This Addendum and its Annexes, together with the Agreement, including as relevant applicable Clauses, serve as a binding contract that sets out the subject matter, duration, nature, and purpose of the Processing, the type of Personal Data and categories of data subjects as well as the obligations and rights of the parties. Cogent may execute relevant contractual addenda, including as relevant the EU SCCs (Module 3) with any relevant Subprocessor (as hereinafter defined, including Affiliates). Unless Cogent notifies Customer to the contrary, if the European Commission subsequently amends the EU SCCs at a later date, such amended terms will supersede and replace any EU SCCs executed between the parties.

  5. Alternative Data Export Solution. The parties agree that the data export solutions identified in this Section 5 will not apply if and to the extent that Cogent adopts an alternative data export solution for the lawful transfer of Personal Data (as recognized under applicable Data Protection Laws), in which event, Customer shall reasonably cooperate with Cogent to implement such solution and such alternative data export solution will apply instead (but solely to the extent such alternative data export solution extends to the territories to which Personal Data is transferred under this Addendum).

  1. Technical and organizational measures. Cogent will implement appropriate technical and organisational measures to ensure a level of security of the Personal Data appropriate to the risk, as further described in Annex II hereto. In assessing the appropriate level of security, Cogent will take into account the risks that are presented by Processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored or otherwise Processed.

  2. Data Subject rights. Cogent will assist Customer in responding to Data Subjects’ requests exercising their rights under the Data Protection Laws. To that effect, Cogent will (a) to the extent permitted by applicable law, promptly notify Customer of any request received directly from Data Subjects to access, correct or delete its Personal Data without responding to that request, and (b) upon written request from Customer, provide Customer with information that Cogent has available to reasonably assist Customer in fulfilling its obligations to respond to Data Subjects exercising their rights under the Data Protection Laws.

  3. Data Protection Impact Assessments. If Customer is required under the Data Protection Laws to conduct a Data Protection Impact Assessment, then upon written request from Customer, Cogent will assist where reasonably possible in the fulfilment of the Customer’s obligation as related to its use of the Service, to the extent Customer does not otherwise have access to the relevant information. If required under Data Protection Laws Cogent will provide reasonable assistance to Customer in the cooperation or prior consultation with Data Protection Authorities in relation to any applicable Data Protection Impact Assessment.

  4. Audit of Technical and Organizational Measures. Cogent agrees to make available all information necessary to demonstrate its compliance with data protection policies and procedures implemented as part of the Service. To this end, upon written request (not more than once annually) Customer may, at its sole cost and expense, verify Cogent’s compliance with its data protection obligations as specified in this DPA by: (i) submitting a security assessment questionnaire to Cogent; and (ii) if Customer is not satisfied with Cogent’s responses to the questionnaire, then Customer may conduct an audit in the form of meetings with Cogent’s information security experts upon a mutually agreeable date. Such interviews will be conducted with a minimum of disruption to Cogent’s normal business operations and subject to Cogent’s agreement on scope and timings. The Customer may perform the audit described above either by itself or through a mutually agreed upon third party auditor, provided that Customer or its authorized auditor executes a mutually agreed upon non-disclosure agreement. Customer will be responsible for any actions taken by its authorized auditor. All information disclosed by Cogent under this Section 9 will be deemed Cogent Confidential Information, and Customer will not disclose any audit report to any third party except as obligated by law, court order or administrative order by a government agency. Cogent will remediate any mutually agreed, material deficiencies in its technical and organizational measures identified by the audit procedures described in this Section 9 within a mutually agreeable timeframe.

  5. Breach notification. If Cogent becomes aware of a Data Breach that results in unlawful or unauthorized access to, or loss, disclosure, or alteration of the Personal Data, then Cogent will notify the Customer without undue delay and in any event, within seventy-two hours after becoming aware of such Data Breach and will co-operate with the Customer and take such reasonable commercial steps as agreed with the Customer to assist in the investigation, mitigation and remediation of such Data Breach. Cogent will provide all reasonably required support and cooperation necessary to enable Customer to comply with its legal obligations in case of a Data Breach pursuant to applicable Data Protection Laws.

  6. Subprocessing. Customer agrees that Cogent may engage either Cogent affiliated companies or third party providers as Subprocessors and hereby authorizes Cogent to engage such Subprocessors in the provision of the Service. Cogent will restrict the Processing activities performed by Subprocessors to only what is necessary to accomplish the purposes of the Agreement and this DPA. Cogent will impose appropriate contractual obligations in writing upon the Subprocessors that are no less protective than this DPA, and Cogent will remain responsible for the Subprocessors’ compliance with the obligations under this DPA.

Cogent maintains a list of all Subprocessors in the provision of Service used as set forth in Annex III hereto. Cogent may amend the list of Subprocessors by adding or replacing Subprocessors at any time and will use commercially reasonable efforts to provide Customer notice of any updates so long as. Customer will be entitled to object to a new Subprocessor by notifying Cogent in writing of the reasons for its objection. Cogent will work in good faith to address Customer’s objections. If Cogent is unable or unwilling to adequately address Customer’s objections to its reasonable satisfaction, then Customer may terminate this DPA and the Agreement, as specified in the Agreement.

  1. Governing Law. This Addendum shall be governed by and construed in accordance with governing law and jurisdiction provisions in the Agreement, unless required otherwise by applicable Data Protection Laws. For the purposes of Clauses 17 and 18 of the EU SCCs, where applicable, to the extent that the governing law and jurisdiction provisions in the Agreement do not meet the requirements of the EU SCCs, the parties select Option 2 of Clause 17, and agree that the EU SCCs shall be governed by the law of the EU Member State in which the data exporter is established; where such law does not allow for third-party beneficiary rights, the EU SCCs shall be governed by the laws of the country of Ireland. Pursuant to Clause 18, any dispute between the Parties arising from the EU SCCs shall be resolved by the courts of Ireland, and the Parties submit themselves to such jurisdiction. For the purposes of Clause 13 of the EU SCCs, the Supervisory Authority shall be the data exporter’s applicable Supervisory Authority. Data exporter shall notify data importer of the applicable Supervisory Authority by email at privacy@cogent.security and shall provide any necessary updates without undue delay.

  2. Return or Deletion of Personal Data. Unless otherwise required by applicable Data Protection Laws, Cogent will delete or return, in Customer’s discretion and upon Customer’s written request, Personal Data within a reasonable period of time following the termination or expiration of the Agreement.

  3. Termination. This Addendum shall automatically terminate upon the termination or expiration of the Agreement. This Addendum cannot, in principle, be terminated separately to the Agreement, except where the Processing ends before the termination of the Agreement, in which case, this Addendum shall automatically terminate.

  4. Entire Agreement; Conflict. Except as amended by this DPA, the Agreement will remain in full force and effect. If there is a conflict between the Agreement and this DPA, the terms of this DPA will control. This DPA may not be amended or modified except by a writing signed by both parties.