Data Processing Agreement
Last updated: May 16, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Threatstealth Ltd (“Processor”) and the Customer (“Controller”) and governs the processing of personal data under Regulation (EU) 2016/679 (GDPR) and applicable data protection law.
1. Definitions
- Controller — the Customer, who determines the purposes and means of processing
- Processor — Threatstealth Ltd, who processes personal data on the Controller's behalf
- Personal Data — any information relating to an identified or identifiable natural person
- Processing — any operation performed on Personal Data including storage, use, disclosure, or erasure
- Sub-processor — a third party engaged by Processor to process Personal Data
2. Scope and nature of processing
Threatstealth processes personal data only on documented instructions from the Controller, for the purpose of providing the Threatstealth cybersecurity platform and related services. The categories of data subjects include Controller employees, platform users, and any individuals whose data the Controller submits to the platform for security monitoring purposes.
3. Processor obligations
- Process Personal Data only on documented instructions from the Controller
- Ensure that persons authorised to process Personal Data are bound by confidentiality obligations
- Implement appropriate technical and organisational security measures as described in Annex II
- Engage Sub-processors only with the Controller's prior written authorisation or general authorisation as set out in Section 5
- Assist the Controller in responding to Data Subject requests, regulatory enquiries, and DPIAs
- Delete or return all Personal Data upon termination of the agreement
- Make available all information necessary to demonstrate compliance with GDPR Article 28
4. Security measures (Annex II)
- AES-256-GCM encryption at rest for all stored Personal Data
- TLS 1.3 encryption in transit with HSTS enforced
- Multi-factor authentication required for all personnel with access to Personal Data
- Role-based access control with least-privilege enforcement and quarterly access reviews
- Immutable audit logging of all Personal Data access and modification events
- Annual third-party penetration testing with remediation within 90 days
- Continuous SAST and DAST scanning in the deployment pipeline
- Row-level database isolation ensuring no cross-tenant data access
5. Sub-processors
The Controller grants general authorisation to engage the sub-processors listed at /legal/subprocessors. Threatstealth will provide at least 30 days' notice before engaging a new sub-processor, giving the Controller the opportunity to object. If the Controller objects and Threatstealth cannot accommodate the objection, the Controller may terminate the agreement without penalty.
6. International transfers
Where Personal Data is transferred to a third country, Threatstealth ensures such transfers are subject to appropriate safeguards under GDPR Article 46 — specifically, Standard Contractual Clauses (SCCs) approved by the European Commission. Customer data is stored in the EU (AWS eu-west-1) by default.
7. Data subject rights
Threatstealth will notify the Controller of any Data Subject request received within 48 hours and will assist the Controller in responding within the applicable legal timeframe. Threatstealth will not respond directly to Data Subjects unless instructed by the Controller.
8. Personal data breaches
In the event of a Personal Data breach, Threatstealth will notify the Controller without undue delay and within 48 hours of becoming aware. Notification will include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed.
9. Termination and return of data
Upon termination of the agreement, Threatstealth will return all Personal Data in a structured, machine-readable format within 30 days. After 30 days and upon confirmation from the Controller, Threatstealth will securely delete all copies of Personal Data.
10. Contact
DPA and data protection enquiries: privacy@threatstealth.com
