Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Foundation One Terms of Service and is incorporated by reference into any Order between Aphelion Ltd (“Foundation One”, “Processor”, “we”) and the entity subscribing to the Service (“Customer”, “Controller”). It reflects the parties’ agreement regarding the processing of personal data, and is principally governed by Part V (sections 33–40) of the Mauritius Data Protection Act 2017, which implements Article 28 of the GDPR and is enforced by the Data Protection Commission of Mauritius. Where the Customer is subject to the EU GDPR or UK GDPR, the equivalent Article 28 requirements apply concurrently, and the higher standard prevails.
Foundation One reaches general availability on 1 October 2026. This DPA applies to all processing of Client Personal Data from that date.
1. Definitions
- “Client Personal Data” — personal data the Customer (or its users) uploads, creates or processes through the Service, in its capacity as controller.
- “Personal Data”, “Controller”, “Processor”, “Sub-processor”, “Data Subject”, “Personal Data Breach” — as defined in the Mauritius DPA 2017 (sections 2 & 71) and the GDPR.
- “Applicable Data Protection Law” — the Mauritius Data Protection Act 2017 (and regulations made thereunder), the EU GDPR, the UK GDPR, and any other data-protection law applicable to the processing of Client Personal Data.
- “Supervisory Authority” — the Data Protection Commission of Mauritius, or, where the Customer is subject to the EU/UK GDPR, the relevant EU/EEA national supervisory authority or the UK Information Commissioner’s Office (ICO).
2. Roles & scope
The Customer is the controller (or, where applicable, a processor acting on behalf of a third-party controller) of Client Personal Data. Foundation One acts as a processor on the Customer’s documented instructions. The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are described in Annex 1 below.
3. Processor obligations
Foundation One will:
- Process Client Personal Data only on the Customer’s documented instructions, including with regard to international transfers, unless required by law (in which case we will inform the Customer unless prohibited);
- Ensure that personnel authorised to process Client Personal Data are subject to confidentiality obligations and have accessed relevant training;
- Implement and maintain appropriate technical and organisational measures designed to ensure a level of security appropriate to the risk (described in Annex 2);
- Not engage another processor (“Sub-processor”) without the Customer’s prior authorisation, and shall impose data-protection terms no less protective than this DPA on each Sub-processor;
- Assist the Customer, by appropriate technical and organisational measures, in fulfilling the Customer’s obligations to respond to data-subject requests;
- Assist the Customer in meeting its obligations regarding security of processing, breach notification, data-protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to us;
- At the Customer’s choice, delete or return all Client Personal Data after the end of the Services, and delete existing copies, unless law requires storage;
- Make available to the Customer all information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits and inspections conducted by the Customer or another auditor mandated by the Customer (subject to confidentiality and security conditions).
4. Sub-processors
The Customer grants Foundation One general written authorisation to engage Sub-processors to provide hosting, infrastructure, support tooling and similar services. The current list of Sub-processors is maintained at Annex 3below and is available to customers on request. We will give the Customer at least 30 days’ notice of any intended addition or replacement of a Sub-processor, and the Customer may object on reasonable data-protection grounds by notifying us in writing within that period. Where the objection is sustained and we cannot provide an alternative, the Customer may terminate the affected portion of the Service with a pro-rata refund.
5. Data-subject rights
Foundation One will promptly notify the Customer if it receives a request from a data subject to exercise rights in respect of Client Personal Data. We will not respond to the request ourselves except on the Customer’s documented instructions or where required by law. Where reasonably possible, we will provide functionality (such as export and erasure tools) that enables the Customer to respond to such requests directly.
6. Personal data breaches
Foundation One will notify the Customer without undue delay (and in any event within 72 hours) of becoming aware of a Personal Data Breach affecting Client Personal Data. The notification will describe the nature of the breach, the likely consequences, the measures taken or proposed, and the contact for further information. We will take reasonable steps to identify the root cause, mitigate the impact and prevent recurrence, and will cooperate with the Customer in its notifications to supervisory authorities and data subjects where required.
7. International transfers
Where Client Personal Data is transferred outside its origin jurisdiction (for example, from the EU/EEA, UK or Switzerland to a third country), the transfer will be subject to appropriate safeguards under Article 46 GDPR, including:
- The European Commission’s Standard Contractual Clauses (SCCs) for controller-to-processor and processor-to-processor transfers;
- The UK International Data Transfer Agreement / Addendum, for transfers subject to the UK GDPR;
- A recognised adequacy decision, where applicable.
Foundation One will sign the SCCs (or an equivalent addendum) with customers on request, as a data-importer. A copy of the SCCs and the list of third-country Sub-processors is available under NDA.
8. Audits
The Customer may audit Foundation One’s compliance with this DPA no more than once per calendar year, on at least 30 days’ notice and subject to confidentiality. Audits will be conducted during business hours, in a manner that does not unreasonably interfere with our operations or breach the rights of other customers. In lieu of an on-site audit, we may provide a third-party audit report (for example, a SOC 2 Type II report once available, an ISO 27001 certificate once available, or a pen-test summary) that addresses substantially the same controls.
9. Deletion on termination
On termination of the Services, Foundation One will, at the Customer’s choice, return or delete Client Personal Data (including existing copies) within 90 days, unless Applicable Data Protection Law requires storage. Return is provided through the Service’s standard export functionality in open formats.
10. Liability & term
This DPA will remain in force for as long as Foundation One processes Client Personal Data on the Customer’s behalf. Liability under this DPA is subject to the limitations in the Terms of Service, except where liability cannot be limited under Applicable Data Protection Law.
11. Contact
Data Protection Officer — Aphelion Ltd, Foundation One
2nd Floor, KL House, M2 Motorway, Riche Terre, 21813 Mauritius
dpo@aphelion-group.com
Annex 1 — Details of processing
| Subject matter | Provision of the Foundation One SaaS platform to the Customer. |
|---|---|
| Duration of processing | The term of the Customer’s subscription, plus the post-termination deletion period (90 days). |
| Nature & purpose | Hosting, operating and securing the Service so the Customer can administer trusts, companies, portfolios, compliance and related operations on one governed platform. |
| Types of personal data | Identity and contact data of clients, beneficial owners, directors, officers, beneficiaries, employees and prospects; KYC/AML documentation; financial and portfolio data; transaction records; communications and documents stored in the Service. |
| Categories of data subjects | The Customer’s clients and their related parties (beneficiaries, directors, UBOs), employees, Authorised Users and prospects. |
Annex 2 — Technical & organisational measures
- Encryption: AES-256 at rest, TLS 1.3 in transit; customer-managed keys available on Enterprise.
- Access control: role-based permissions down to the field, least-privilege, multi-factor authentication, time-boxed delegation and break-glass.
- Tenant isolation: logical isolation with row-level security; no cross-tenant data access.
- Monitoring & logging: continuous monitoring for anomalous access and transactions; immutable audit trail with field-level lineage.
- Resilience: multi-region active-active deployment, nightly verified backups, 99.99% uptime target and disaster-recovery runbooks.
- Vulnerability management: regular vulnerability scanning, annual penetration testing, and responsible-disclosure handling.
- Personnel: background checks where lawful, confidentiality agreements, security and privacy training, and least-privilege access reviews.
- Incident response: documented incident-response plan with defined roles, breach-detection tooling and 72-hour breach-notification capability.
- AI governance: Privacy-First AI framework, AI Risk Register, EU AI Act compliance module, no Client Personal Data used to train external models.
Foundation One is control-mapped to SOC 2 Type II and ISO 27001 (we implement the full controls set; formal certification is in progress). See our security & shared responsibility overview.
Annex 3 — Sub-processors
The indicative categories of Sub-processors we rely on are:
| Category | Purpose | Location |
|---|---|---|
| Cloud infrastructure & hosting | Application hosting, storage, compute | Mauritius / EU (customer-selected region) |
| Database & caching | Managed data persistence | Same region as primary hosting |
| Email & transactional delivery | System notifications, password resets | EU / US |
| Analytics (opt-in) | Aggregated product analytics | EU |
| Error & performance monitoring | Service reliability | EU / US |
| Support tooling | Customer support ticketing | EU |
| KYC / identity verification (customer-activated) | Provider-integrated KYC checks | Per provider & jurisdiction |
A named, entity-level Sub-processor list is available to customers under NDA and updated at least 30 days before any change.