Data processing agreement
Version 2026-10
Subject
For the data its users enter in the service, the customer is the controller and we are the processor under article 28 of the GDPR. This agreement is part of the terms of service.
Nature and purpose
Storage, display, search, reporting and email delivery of security records, only on the customer's documented instructions, which are the settings and actions taken in the application.
Categories of data
User accounts (name, email, sign-in history), and whatever the customer puts in records: incident details, reported emails including their senders and recipients, assets, indicators, documents.
Sub-processors
OVH SAS (hosting, France) and Sendinblue SAS, trading as Brevo (email delivery, France). We give notice before adding or replacing one, and the customer may object.
Security
Organization-scoped access control on every request, encrypted transport, encrypted connector credentials, audit logging, and staff access limited to operating the service.
Personal data breaches
We notify the customer without undue delay after becoming aware of a breach affecting its data, with what is known at that time.
Return and deletion
Data can be exported at any time. When an organization is deleted, at the customer's request or after inactivity, every record it holds is erased, then its users, roles and licence.
Audits
On request, we provide the information needed to demonstrate compliance with this agreement.