Data Processing Addendum.
Our DPA is pre-signed, incorporates the EU Standard Contractual Clauses and the UK Addendum, and carries processor terms for India's DPDP Act. No negotiation required to get GDPR-grade terms.
01 · Overview
This page summarizes the SecurityVault Data Processing Addendum ("DPA") so legal and procurement teams can assess it before requesting the executable document. The DPA is incorporated into our customer agreement by reference and applies whenever SecurityVault processes personal data on a customer's behalf. In any conflict, the executed DPA controls over this summary.
02 · Roles & scope
- Customer tenant data — the customer is the controller (or a processor acting for its own controllers); SecurityVault is the processor. Under India's DPDP Act, the customer is the Data Fiduciary and SecurityVault the Data Processor.
- Account and billing data — SecurityVault is an independent controller, as described in theprivacy notice.
- Scope of processing — hosting, scan orchestration, findings correlation, policy evaluation, evidence sealing, and support, strictly per documented customer instructions. Processing purposes, categories, and durations are fixed in Annex I of the DPA.
03 · Core terms (GDPR Article 28)
- Documented instructions only — we process tenant personal data solely per the agreement and customer configuration; we notify you if an instruction appears to violate law.
- Confidentiality — all personnel with potential access are bound by confidentiality obligations; production access is zero-standing and audited.
- Security — technical and organizational measures are fixed in Annex II, including TLS 1.3 in transit, AES-256-GCM at rest, tenant isolation, and hardware-key MFA for staff. Current detail:security page.
- Breach notification — we notify affected customers without undue delay and within 72 hours of confirming a personal-data breach, with the facts needed for your own regulatory notifications.
- Assistance — we assist with data-subject requests, DPIAs, and consultations with supervisory authorities.
- Audit — annual third-party audit reports and pen-test summaries are provided under NDA; customers may audit directly where their regulator requires it.
- Deletion — on termination, tenant data is deleted from production within 30 days and from backups on backup expiry, with written confirmation on request.
04 · International transfers
Tenant data residency is customer-elected at onboarding. Where personal data leaves the EEA, UK, or Switzerland, transfers rest on the EU Standard Contractual Clauses (Module 2, controller-to-processor; Module 3 where you act as processor), the UK International Data Transfer Addendum, and the Swiss FDPIC amendments — all incorporated in the DPA — plus the supplementary technical measures documented in our transfer impact assessment, available on request.
05 · Subprocessors
The current subprocessor list, with purpose and region for each, is published at securityvault.io/subprocessors. Material changes are announced at least 30 days in advance; customers may object on reasonable data-protection grounds, and if we cannot resolve the objection you may terminate the affected service with a pro-rata refund. Every subprocessor is bound by written terms equivalent to the DPA.
06 · DPDP addendum (India)
For customers subject to India's Digital Personal Data Protection Act, 2023, the DPA includes a DPDP addendum: SecurityVault processes personal data only under the customer's valid contract as Data Processor, implements reasonable security safeguards, notifies the customer of personal-data breaches so the Data Fiduciary can meet its obligations to the Data Protection Board and affected Data Principals, deletes data when the specified purpose is served, and supports grievance redressal timelines. Our India-facing contacts are listed under Your privacy choices.
07 · How to execute
Email legal@securityvault.io from your corporate domain with your legal entity name and the agreement it attaches to. We return a countersigned copy — typically the same business day. Existing customers can also download the pre-signed DPA from the trust center in the product.