Skip to main content
Threatstealth
Login

Data Processing Agreement

Last updated: May 16, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Threatstealth Ltd (“Processor”) and the Customer (“Controller”) and governs the processing of personal data under Regulation (EU) 2016/679 (GDPR) and applicable data protection law.

1. Definitions

2. Scope and nature of processing

Threatstealth processes personal data only on documented instructions from the Controller, for the purpose of providing the Threatstealth cybersecurity platform and related services. The categories of data subjects include Controller employees, platform users, and any individuals whose data the Controller submits to the platform for security monitoring purposes.

3. Processor obligations

4. Security measures (Annex II)

5. Sub-processors

The Controller grants general authorisation to engage the sub-processors listed at /legal/subprocessors. Threatstealth will provide at least 30 days' notice before engaging a new sub-processor, giving the Controller the opportunity to object. If the Controller objects and Threatstealth cannot accommodate the objection, the Controller may terminate the agreement without penalty.

6. International transfers

Where Personal Data is transferred to a third country, Threatstealth ensures such transfers are subject to appropriate safeguards under GDPR Article 46 — specifically, Standard Contractual Clauses (SCCs) approved by the European Commission. Customer data is stored in the EU (AWS eu-west-1) by default.

7. Data subject rights

Threatstealth will notify the Controller of any Data Subject request received within 48 hours and will assist the Controller in responding within the applicable legal timeframe. Threatstealth will not respond directly to Data Subjects unless instructed by the Controller.

8. Personal data breaches

In the event of a Personal Data breach, Threatstealth will notify the Controller without undue delay and within 48 hours of becoming aware. Notification will include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed.

9. Termination and return of data

Upon termination of the agreement, Threatstealth will return all Personal Data in a structured, machine-readable format within 30 days. After 30 days and upon confirmation from the Controller, Threatstealth will securely delete all copies of Personal Data.

10. Contact

DPA and data protection enquiries: privacy@threatstealth.com