What it says
What this says
Current to 11 Oct 26Executed Data Processing Agreement between Ardcarne Life Assurance (controller) and BB-Demo (processor), signed 4 Sep 2026. The brain runs inside Ardcarne's own Snowflake account, with DORA support. It states no price, availability or P1 response figures.
What it is: an executed DPA under the MSA and order form, signed 4 Sep 2026. It says "If there is a conflict on the handling of personal data, this Agreement prevails."
Commits: BB-Demo processes data only on documented instructions and keeps it in the customer's Snowflake account and chosen region. It must notify a Security Incident "without undue delay" and tell the customer in writing before changing a sub-processor.
Unusual: it ties BB-Demo to DORA ICT third-party risk support and to audits by the customer or its appointed auditor. Any move to another region or dedicated residency needs a written change to the order form.
Not settled: no price, service levels, connector dates or renewal date appear here; they sit in the order form and MSA. The customer signatory is not named, only an authorised signatory.
As found in this document
Current to 9 Oct 26- Date signed4 Sep 2026Source: object_read:doc_008_009
- Date start4 Sep 2026Source: object_read:doc_008_009
- Data locationPersonal Data stays within that account and the region the Customer has selected.Personal Data stays within that account and the region the Customer has selected. · Source: object_read:doc_008_009
- Security incident noticeThe Supplier will notify the Customer without undue delay after becoming aware of a Security IncidentThe Supplier will notify the Customer without undue delay after becoming aware of a Security Incident · Source: object_read:doc_008_009
- Sub-processor changeThe Supplier will tell the Customer in writing before adding or replacing a sub-processorThe Supplier will tell the Customer in writing before adding or replacing a sub-processor · Source: object_read:doc_008_009
- Return and deletionOn ending the Services the Supplier will, at the Customer's choice, return or delete Personal Data.On ending the Services the Supplier will, at the Customer's choice, return or delete Personal Data. · Source: object_read:doc_008_009
- Termcontinues for as long as the Supplier processes Personal Data for the Customercontinues for as long as the Supplier processes Personal Data for the Customer · Source: object_read:doc_008_009
The document
Body
Ardcarne Life Assurance - Data Processing Agreement (signed)
Status: Executed Version: one Date of signature: 4 Sep 2026
Parties
This Data Processing Agreement (the "Agreement") is made between:
- Ardcarne Life Assurance, an Irish life and pensions insurer headquartered in Dublin, supervised by the Central Bank of Ireland (the "Customer" and the controller); and
- BB-Demo, a data business based in London (the "Supplier" and the processor).
The Customer's account owner at the Supplier is Matteo Ricci. The Customer success manager is Elena Novak.
Background
The Customer has chosen BB-Demo to give its broker distribution and customer service teams one view of each broker firm. The Supplier will build and run the company brain inside the Customer's own Snowflake account. The Customer is subject to the Digital Operational Resilience Act (DORA) and to the supervision of the Central Bank of Ireland, and the parties have agreed the terms below following the Customer's security review.
Read the whole document (6,991 characters)
This Agreement sits under the Master Services Agreement and the order form between the parties. If there is a conflict on the handling of personal data, this Agreement prevails.
Article One: Definitions
- Personal Data means any information relating to an identified or identifiable person that the Supplier processes on behalf of the Customer.
- Data Protection Law means the General Data Protection Regulation as it applies in Ireland and the Irish data protection legislation that supplements it.
- Services means the implementation and subscription services described in the order form.
- Security Incident means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
Article Two: Roles and scope
The Customer is the controller and the Supplier is the processor. The Supplier processes Personal Data only to provide the Services, only on the Customer's documented instructions, and only for the duration of the subscription. The categories of data are those held in the systems the Customer chooses to connect, such as its CRM, call recorder, email, helpdesk and finance systems. The data subjects are the Customer's brokers, broker staff, customers and employees to the extent their data appears in those systems.
Article Three: Where the data lives
- The brain runs inside the Customer's Snowflake account. Personal Data stays within that account and the region the Customer has selected.
- The Supplier does not copy Personal Data out of the Customer's Snowflake account except where the Customer has instructed it in writing.
- Any move to a different region or a dedicated data residency arrangement requires a written change to the order form.
Article Four: Security measures
The Supplier maintains technical and organisational measures appropriate to the risk, including:
- access limited to named staff who need it, with single sign-on and multi-factor authentication;
- encryption of data in transit and at rest;
- logging of access to the Customer's environment, available to the Customer on request;
- separation of the Customer's environment from those of other customers;
- regular review of access rights and prompt removal of access when a person leaves the Supplier.
The Supplier will support the Customer's reasonable ICT third-party risk requirements under DORA, including information needed for the Customer's register of arrangements and for its supervisor.
Article Five: Confidentiality and personnel
The Supplier ensures that everyone authorised to process Personal Data is bound by a duty of confidentiality and receives data protection training suitable to their role.
Article Six: Sub-processors
- The Customer gives general authorisation for the Supplier to use sub-processors, subject to this Article.
- The Supplier will bind each sub-processor to obligations no less protective than those in this Agreement and remains responsible for their performance.
- The Supplier will tell the Customer in writing before adding or replacing a sub-processor, so that the Customer has a reasonable opportunity to object. If the parties cannot resolve an objection, the Customer may end the affected part of the Services.
Article Seven: Security incidents
The Supplier will notify the Customer without undue delay after becoming aware of a Security Incident, and will give the Customer what it needs to meet its own duties to the Central Bank of Ireland, the Data Protection Commission and affected individuals. The notice will describe the nature of the incident, the data affected, the likely consequences and the steps taken. The Supplier will keep the Customer informed as the facts become clearer and will not withhold information from the Customer's security team.
Operational incidents that affect availability but not Personal Data are handled under the service levels in the order form and are reported to the Customer's named contacts.
Article Eight: Assistance to the Customer
Taking account of the nature of the processing, the Supplier will help the Customer to:
- respond to requests from individuals exercising their rights;
- carry out data protection impact assessments and prior consultations;
- demonstrate compliance with its obligations as a regulated insurer.
Article Nine: Audit and information
The Supplier will make available the information needed to show compliance with this Agreement and will allow and contribute to audits by the Customer or an auditor it appoints, on reasonable notice and during business hours. Nothing here limits the rights of the Customer's supervisory authorities.
Article Ten: Return and deletion
On ending the Services the Supplier will, at the Customer's choice, return or delete Personal Data. Because the brain lives in the Customer's own Snowflake account, the Customer keeps control of the underlying data throughout. The Supplier will remove its own access and any working copies it holds, and will confirm this in writing on request.
Article Eleven: Liability and term
Liability under this Agreement is governed by the limitations set out in the Master Services Agreement. This Agreement takes effect on the date of signature and continues for as long as the Supplier processes Personal Data for the Customer.
Article Twelve: Governing law
This Agreement is governed by the law of Ireland, and the courts of Ireland have jurisdiction, unless the Master Services Agreement states otherwise for matters outside data protection.
Signatures
Signed by the duly authorised representatives of the parties on 4 Sep 2026.
| For Ardcarne Life Assurance | For BB-Demo | |
|---|---|---|
| Name | Authorised signatory of the Customer | Matteo Ricci |
| Title | Authorised officer, as named in the Customer's signing authority | Account Executive |
| Date | 4 Sep 2026 | 4 Sep 2026 |
| Signature | Signed | Signed |
Unusual terms
Current to 9 Oct 26- DORA ICT third-party risk support
- Audit rights for customer or appointed auditor
- Irish governing law
- Region change needs order form amendment