Notice: This document describes AXORYN Technology's practices for the website axoryn.tech, the Virtual Classroom aula.axoryn.tech, and associated digital services. It has been drafted in accordance with international data-protection and digital-consumer principles (EU GDPR, Peru's Law 29733, and ISO/IEC 27701 good practices). It does not replace personalized legal advice; for specific cases, please contact contacto@axoryn.tech.
This document sets out the general confidentiality framework applicable to information that clients and prospects share with AXORYN Technology in connection with assessments, proposals, GRC consulting, internal audits, ISO 27001 implementations, or other professional services. A signed bilateral NDA may supplement or take precedence over this public version where the parties so agree in writing.
1. Purpose and parties
Disclosing Party: the client, prospect, or organization that provides information.
Receiving Party: AXORYN Technology and its authorized personnel.
The Receiving Party undertakes to protect the Confidential Information with the same degree of care it applies to its own sensitive information, and in no case less than a reasonable professional standard.
Policies, procedures, control evidence, business continuity plans
Commercial data, pricing, strategies, client or supplier lists
Personal data processed in the context of the engagement
Any information marked as confidential or that, by its nature, should be understood as such
3. Obligations of the Receiving Party
Not to disclose the Confidential Information to third parties without prior written authorization, except to collaborators under an equivalent confidentiality obligation and a need-to-know basis.
To use it solely for the purpose of the agreed service or assessment.
To apply appropriate technical and organizational measures (encryption in transit, access control, segregation).
To notify without undue delay any security incident affecting such information.
4. Exclusions
Information shall not be deemed confidential if it:
Is or becomes publicly available without breach of this agreement
Was already lawfully in the Receiving Party's possession before it was received
Is obtained from a third party legitimately entitled to disclose it without a duty of confidentiality
Must be disclosed by law, court order, or competent authority (in which case the Disclosing Party will be notified when legally possible)
5. Term
The confidentiality obligations shall remain in force during the business relationship and for five (5) additional years after its termination, or the longer period required by law or a specific contract (e.g., trade secrets for as long as they retain that character).
6. Return and destruction
Upon completion of the service, or at the Disclosing Party's written request, AXORYN will return or securely destroy any copies of Confidential Information in its possession, except for information it must retain due to a legal obligation or for the defense of claims, which shall remain subject to this agreement.
7. Intellectual property
The Confidential Information remains the property of the Disclosing Party. Nothing herein grants any license over trademarks, software, or proprietary methodologies of the client or of AXORYN, except as expressly agreed in the services contract. AXORYN's generic methodologies, templates, and know-how do not cease to be AXORYN's property merely because they are used in a project.
8. Breach
Breach may cause damages that are difficult to quantify. The Disclosing Party may seek injunctive relief in addition to compensation for damages under applicable law and the venue agreed in the principal contract.
9. GRC consulting and role as data processor
When AXORYN processes personal data on behalf of the client (as processor), the following will apply in addition to this NDA:
The client's (controller's) documented instructions
The processing agreement / DPA, where required (GDPR Art. 28 or equivalent)