APEX Pando APEX PandoDigital Signage
Advertising Meetings Templates Access Pricing Resources
Sign in Start free
Home Legal Data Processing Agreement
Legal

Data Processing Agreement

Version 1.0 Effective 7 July 2026

This DPA forms part of, and is incorporated into, the APEX Pando Terms and Conditions between:

  • EXOR Group Ltd ("EXOR", the "Processor"), and
  • the Tenant (the "Controller").

It governs EXOR's processing of personal data on behalf of the Tenant — that is, personal data the Tenant processes through the Service relating to the Tenant's own staff, customers or other data subjects. It does not cover EXOR's own processing as a Controller (see the Privacy Policy).


1. Definitions

Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings in the General Data Protection Regulation (EU) 2016/679 ("GDPR"). "Applicable Data Protection Law" means the GDPR and the Maltese Data Protection Act (Cap. 586).


2. Roles and scope

2.1. The Tenant is the Controller and EXOR is the Processor of Tenant Personal Data processed through the Service. 2.2. EXOR processes Tenant Personal Data only to provide the Service and only on the Controller's documented instructions, including as set out in the Terms, this DPA, and use of the Service's features. 2.3. If EXOR is required by law to process beyond the Controller's instructions, it will inform the Controller first, unless legally prohibited. 2.4. EXOR will inform the Controller if, in its opinion, an instruction infringes Applicable Data Protection Law.


3. Subject-matter, duration, nature and purpose (Art. 28(3))

  • Subject-matter: provision of the APEX Pando digital signage Service.
  • Duration: the term of the Terms, plus any wind-down/export period.
  • Nature and purpose: hosting, storing, displaying and processing content and account data to operate the Service.
  • Types of personal data: account-user identifiers (name, email); any personal data the Controller chooses to include in content or configuration. The Service is not designed to process special-category data or attendance/behavioural data about individuals.
  • Categories of data subjects: the Controller's authorised users and any individuals the Controller includes in content.

4. Processor obligations

EXOR will: 4.1. Process only on documented instructions (clause 2). 4.2. Ensure persons authorised to process are bound by confidentiality. [Art. 28(3)(b)] 4.3. Implement appropriate technical and organisational security measures (clause 7). [Art. 28(3)(c), Art. 32] 4.4. Respect the conditions for engaging sub-processors (clause 5). [Art. 28(3)(d)] 4.5. Assist the Controller, so far as possible, in responding to data-subject rights requests. [Art. 28(3)(e)] 4.6. Assist the Controller with security, breach notification, data-protection impact assessments and prior consultation. [Art. 28(3)(f), Arts. 32–36] 4.7. At the Controller's choice, delete or return Tenant Personal Data at the end of the Service, and delete existing copies unless law requires retention. [Art. 28(3)(g)] 4.8. Make available information necessary to demonstrate compliance and allow for and contribute to audits. [Art. 28(3)(h); see clause 8]


5. Sub-processors

5.1. The Controller gives general authorisation for EXOR to engage sub-processors (for example infrastructure, hosting, storage, backup and payment providers). 5.2. EXOR maintains a list of sub-processors, available on request, and will inform the Controller of intended changes, giving the Controller the opportunity to object on reasonable data-protection grounds. 5.3. EXOR imposes on each sub-processor data-protection obligations equivalent to those in this DPA, and remains liable for its sub-processors' performance. [Art. 28(4)]


6. International transfers

6.1. Tenant Personal Data is processed within the EU. EXOR will not transfer it outside the EEA without an appropriate transfer mechanism under Chapter V GDPR (for example an adequacy decision or Standard Contractual Clauses).

7. Security (Art. 32)

7.1. Taking into account the state of the art and risk, EXOR implements appropriate measures, which may include: encryption in transit; access controls and authentication; tenant isolation (database-per-tenant); backup and recovery processes; logging and monitoring; and staff confidentiality. 7.2. No measures guarantee absolute security; EXOR's obligation is to maintain a level of security appropriate to the risk.

8. Audit

8.1. EXOR will make available information reasonably necessary to demonstrate compliance with Art. 28, and allow for audits by the Controller or its mandated auditor. 8.2. Audits are at the Controller's expense, on reasonable prior notice, no more than once per year (save where required by a supervisory authority or following a breach), during business hours, and subject to confidentiality and minimal disruption. EXOR may satisfy audit rights by providing third-party certifications or reports where available.


9. Personal-data breach

9.1. EXOR will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Tenant Personal Data, and provide information reasonably available to assist the Controller's own obligations under Arts. 33–34. 9.2. This is separate from the Tenant's 48-hour notification duty to EXOR under the Terms.


10. Data-subject requests

10.1. Taking into account the nature of processing, EXOR will assist the Controller by appropriate technical and organisational measures, insofar as possible, to respond to data-subject rights requests. 10.2. If EXOR receives a request directly from a data subject, it will not respond substantively (save to confirm receipt where appropriate) but will forward it to the Controller.


11. Deletion and return

11.1. On termination or expiry, and at the Controller's choice, EXOR will delete or return Tenant Personal Data. The Service provides export in CSV format for [30] days after termination, after which data may be permanently deleted. 11.2. Personal data in routine backups ages out on the normal backup cycle; EXOR is not required to surgically purge historical backups.


12. Liability

12.1. Liability under this DPA is subject to the limitations and cap in the Terms, to the extent permitted by Applicable Data Protection Law. Nothing in this DPA limits liability that cannot lawfully be limited.


13. General

13.1. This DPA prevails over the Terms in the event of conflict on data-protection matters. 13.2. It is governed by the laws of Malta, consistent with the Terms. 13.3. If any Standard Contractual Clauses or successor mechanism apply, they prevail over this DPA to the extent of any conflict.

Related documents

Legal

Terms and Conditions

Legal

Privacy Policy

Legal

Acceptable Use Policy

APEX Pando APEX PandoDigital Signage

One platform for every screen you run — ads and menu boards out front, live meeting-room panels out back, with role-based control built in.

Platform

Advertising Meetings & rooms Templates Access control AI engine Pricing

Company

About EXOR Group Customers Partners & resellers Contact

Resources

The Signage Playbook What is digital signage? Dayparting explained
© 2026 EXOR Group Ltd. APEX Pando is a product of EXOR Group Ltd. Privacy Terms Acceptable use Data Processing Agreement