Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Service Agreement. It applies whenever we process personal data on your behalf as a processor under UK GDPR Article 28.
1. Roles
Customer is the controller. Threat Detective Ltd is the processor. Where Customer is itself a processor for an upstream controller, this DPA applies on a sub-processor basis.
2. Subject matter and duration
Subject matter: provision of the Service. Duration: for as long as the Service is provided plus any post-termination data retention period described in the Terms.
3. Nature, purpose, and types of personal data
The following describes our processing for the purposes of UK GDPR Article 28(3):
- Subject matter: provision of the Service to Customer.
- Nature and purpose: hosting, storing, indexing, retrieving and transmitting personal data submitted to the Service so that Customer can track software components and vulnerability advisories across its projects.
- Duration: for the term of Customer's subscription, plus the post-termination retention periods set out in the Terms.
- Categories of data subjects: Customer's authorised users (employees, contractors and other personnel granted access to the Service); individuals identified within Customer content uploaded to the Service.
- Categories of personal data: contact data (name, email address, organisation), authentication data (hashed passwords or federated identity tokens), usage data (audit-log entries, request metadata), and any personal data that Customer chooses to include in customer content.
- Special categories of personal data: none, unless Customer chooses to upload them as customer content. We do not knowingly request or require special category data.
- Frequency of processing: continuous for the term of the subscription.
- Erasure or return: as set out in section 6 of the Terms (export window followed by deletion).
4. Sub-processors
Customer authorises the sub-processors listed at /subprocessors. We will give 30 days' notice of any new sub-processor. Customer may object on reasonable data-protection grounds.
5. International transfers
Where personal data is transferred outside the UK, the parties enter into the UK International Data Transfer Agreement (UK IDTA) or the UK Addendum to the EU Standard Contractual Clauses (whichever is applicable), incorporated by reference.
6. Security measures
We maintain appropriate technical and organisational measures, including encryption in transit and at rest, role-based access control, audit logging, and incident response procedures. Detail on request.
7. Personal data breach
We will notify Customer without undue delay (and in any event within 72 hours) of becoming aware of a personal data breach affecting Customer personal data, providing the information required by UK GDPR Article 33(3).
8. Audit
On reasonable written request and no more than once per 12-month period, we will make available to Customer the information necessary to demonstrate compliance with UK GDPR Article 28. Customer's audit right will, in the first instance, be satisfied by the most recent independent third-party audit reports we hold (for example ISO 27001 or SOC 2 reports, where available).
Where those reports do not, in Customer's reasonable opinion, address the matter under audit, Customer may carry out an on-site audit subject to: (a) at least 30 days' written notice; (b) the audit being conducted at a mutually convenient time during normal business hours; (c) the auditor (which must not be a competitor) signing reasonable confidentiality undertakings; (d) the audit not unreasonably interfering with our business or compromising the confidentiality of other customers' data.
Customer bears its own and our reasonable costs for an audit, save where the audit identifies a material breach by us of this DPA, in which case we bear our own costs.
Nothing in this section limits Customer's audit rights to the extent that those rights are mandatory under applicable data-protection law.
9. Governing law
This DPA is governed by the laws of England and Wales.