DATA PROCESSING ADDENDUM
This Data Processing Addendum ("DPA") forms part of the Master Subscription Agreement or Online Terms of Service between Sekura Inc. ("Sekura," "Processor") and [CUSTOMER LEGAL NAME] ("Customer," "Controller") (the "Agreement"). Where this DPA conflicts with the Agreement, this DPA governs as to the processing of Personal Data.
1. DEFINITIONS
"Data Protection Laws" means all laws applicable to the processing of Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the CPRA ("CCPA"), and any other applicable state, federal, or foreign privacy law.
"Personal Data" means any information relating to an identified or identifiable natural person that is contained within Customer Data and processed by Sekura under the Agreement.
"Processing," "Controller," "Processor," "Data Subject," and "Supervisory Authority" have the meanings given in the GDPR. Where CCPA applies, Sekura is a "Service Provider" and Customer is a "Business."
"Security Incident" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by Sekura.
"Subprocessor" means any third party engaged by Sekura to process Personal Data.
2. ROLES AND SCOPE
2.1 Customer is the Controller and Sekura is the Processor in respect of Personal Data processed under the Agreement.
2.2 Nature of the processing. Sekura's Services are security assessment services. Personal Data is not the object of the Services and is processed only incidentally — for example, names and email addresses appearing in source code, commit history, configuration files, log data, or application databases encountered during assessment.
2.3 Customer shall not intentionally submit special categories of personal data (Article 9 GDPR), data relating to criminal convictions, payment card data, or personal health information to the Services, and shall take reasonable steps to minimise the Personal Data present in environments submitted for assessment.
2.4 The subject matter, duration, nature, purpose, categories of Data Subjects, and types of Personal Data are described in Annex 1.
3. PROCESSOR OBLIGATIONS
Sekura shall:
3.1 Documented instructions. Process Personal Data only on Customer's documented instructions, including as set out in the Agreement and this DPA, unless required otherwise by law — in which case Sekura shall inform Customer before processing, unless prohibited by that law.
3.2 No sale or independent use. Not sell or share Personal Data as those terms are defined under the CCPA, and not retain, use, or disclose Personal Data for any purpose other than performing the Services, or outside the direct business relationship with Customer. Sekura certifies that it understands and will comply with these restrictions.
3.3 Confidentiality. Ensure that personnel authorized to process Personal Data are bound by confidentiality obligations and have received appropriate data protection training.
3.4 Security. Implement and maintain the technical and organizational measures described in Annex 2, appropriate to the risk.
3.5 Assistance with Data Subject rights. Taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures in fulfilling its obligation to respond to requests to exercise Data Subject rights. Where Sekura receives such a request directly, it shall promptly forward it to Customer and shall not respond except to confirm the request has been forwarded.
3.6 Assistance with compliance. Provide Customer with reasonable assistance in relation to data protection impact assessments, prior consultation with Supervisory Authorities, and Security Incident notification obligations, taking into account the nature of processing and information available to Sekura.
3.7 Records. Maintain records of processing activities carried out on behalf of Customer as required by Article 30(2) GDPR.
4. SUBPROCESSORS
4.1 Customer grants Sekura general authorization to engage Subprocessors. The current list is maintained at sekura.ai/subprocessors and reproduced in Annex 3.
4.2 Sekura shall give Customer at least thirty (30) days' notice before adding or replacing a Subprocessor, by email or by posting to the subprocessor page where Customer has subscribed to notifications.
4.3 Customer may object on reasonable data protection grounds within the notice period. The Parties shall discuss in good faith. If no resolution is reached, Customer may terminate the affected Services on written notice, with a pro-rata refund of prepaid fees for the terminated portion.
4.4 Sekura shall impose on each Subprocessor data protection obligations no less protective than those in this DPA, and remains fully liable to Customer for the performance of each Subprocessor.
4.5 Customer-selected AI providers. Where Customer supplies its own AI or LLM credentials, that provider is engaged by Customer, not by Sekura, and is not a Sekura Subprocessor. Customer is the Controller in respect of that relationship.
5. INTERNATIONAL TRANSFERS
5.1 Sekura shall not transfer Personal Data outside the country of origin except where an appropriate transfer mechanism is in place.
5.2 Where Personal Data originating in the EEA, UK, or Switzerland is transferred to a country without an adequacy decision, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (Controller to Processor), are incorporated into this DPA by reference and completed as follows: Customer is the data exporter, Sekura is the data importer; Clause 7 (docking) applies; Clause 9 option 2 (general authorization) with a thirty-day notice period applies; Clause 11 optional redress language does not apply; Clause 17 governing law is Ireland; Clause 18(b) forum is Ireland. Annexes I, II, and III of the SCCs are populated by Annexes 1, 2, and 3 of this DPA.
5.3 For UK transfers, the UK International Data Transfer Addendum to the SCCs applies, with Tables 1 to 4 populated by reference to this DPA.
6. SECURITY INCIDENTS
6.1 Sekura shall notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident affecting Personal Data in Sekura's possession or control.
6.2 The notification shall describe, to the extent known: the nature of the incident, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed. Where information is not available at the time of notification, it shall be provided in phases without undue delay.
6.3 Sekura shall take reasonable steps to contain and remediate the incident and shall cooperate with Customer's investigation and any required notifications.
6.4 Notification of a Security Incident is not an acknowledgement of fault or liability.
7. AUDIT
7.1 Sekura shall make available information reasonably necessary to demonstrate compliance with this DPA.
7.2 Customer may, no more than once per twelve-month period and on thirty (30) days' prior written notice, conduct an audit of Sekura's processing. Audits shall be conducted during business hours, subject to reasonable confidentiality obligations, and shall not unreasonably disrupt Sekura's operations.
7.3 Sekura may satisfy an audit request by providing a current third-party audit report, certification, or completed security questionnaire, where such materials reasonably address Customer's inquiry.
7.4 Customer bears the cost of any audit it conducts, except where the audit identifies a material breach by Sekura.
8. DELETION AND RETURN
8.1 On termination or expiry of the Agreement, Sekura shall, at Customer's election, delete or return all Personal Data and delete existing copies, within thirty (30) days, except to the extent retention is required by law.
8.2 Personal Data residing in routine encrypted backup media remains subject to this DPA until overwritten or deleted in the ordinary course of Sekura's disaster recovery cycle.
8.3 On written request, Sekura shall certify deletion.
8.4 Aggregated Data. Aggregated, anonymized, and de-identified data generated in accordance with the Agreement does not constitute Personal Data and is not subject to this Section, provided it cannot reasonably be used to identify any Data Subject.
9. LIABILITY AND TERM
9.1 Each Party's liability under this DPA is subject to the limitations and exclusions in the Agreement, except where Data Protection Laws prohibit such limitation.
9.2 This DPA takes effect on the Effective Date of the Agreement and continues until Sekura ceases all processing of Personal Data on Customer's behalf.
ANNEX 1 — DESCRIPTION OF PROCESSING
Subject matter
Provision of automated security assessment, vulnerability validation, and reporting services
Duration
The term of the Agreement, plus the deletion period in Section 8
Nature and purpose
Scanning, analysis, validation, storage, and reporting for the purpose of identifying and evidencing security vulnerabilities
Categories of Data Subjects
Customer's employees, contractors, and developers; end users of Customer's applications; any individual whose data is incidentally present in systems submitted for assessment
Types of Personal Data
Names, email addresses, usernames, and identifiers appearing in source code, commit metadata, configuration files, logs, or application data encountered during assessment; account identifiers of Customer users of the Platform
Special categories
None intentionally processed. Customer undertakes not to submit special category data.
Frequency of transfer
Continuous during the term
ANNEX 2 — TECHNICAL AND ORGANIZATIONAL MEASURES
Control area
Measures
Encryption
TLS 1.2 or above in transit; AES-256 at rest. Customer credentials encrypted at rest and never logged.
Access control
Role-based access; least privilege; multi-factor authentication for all personnel with production access; access reviewed at least quarterly.
Segregation
Customer environments logically separated. Assessment runners isolated per engagement with no access to the control plane.
Credential handling
Customer-supplied credentials decrypted only at point of use, scrubbed after use, and destroyed on termination of the engagement.
Logging and monitoring
Tamper-evident, hash-chained audit logging of assessment activity. Centralized monitoring and alerting on the control plane.
Secure development
Version-controlled source; peer review; automated static analysis, dependency scanning, and secret detection in CI; pinned dependencies.
Vulnerability management
Continuous self-assessment using the Sekura Platform; documented remediation targets by severity.
Personnel
Confidentiality obligations for all personnel; background checks where permitted by law; security awareness training.
Business continuity
Encrypted backups; documented recovery procedures; periodic restoration testing.
Incident response
Documented incident response plan with defined roles, escalation, and 72-hour notification commitment.
Data minimisation
Evidence capture redacts sensitive values. Only data necessary to evidence a finding is retained.
Deletion
Documented deletion procedures with certification on request.
Sekura may update these measures provided the level of protection is not materially reduced.
ANNEX 3 — SUBPROCESSORS
See the current list at sekura.ai/subprocessors. As at the date of this DPA:
Subprocessor
Purpose
Location
Personal Data processed
Google Cloud Platform
Infrastructure hosting and compute
United States
All categories, as hosted
[AI provider — where Sekura-managed inference is selected]
Model inference for assessment analysis
United States
Incidental data present in analysed content
[Payment processor]
Subscription billing
United States
Billing contact name, email, payment details
[Support and ticketing platform]
Customer support
United States
Support contact name, email, correspondence
[Error monitoring]
Platform reliability
United States
Technical identifiers, limited log data
SIGNATURES
SEKURA INC.
Name: ________________________ Title: ________________________
Signature: ____________________ Date: ________________________
[CUSTOMER LEGAL NAME]
Name: ________________________ Title: ________________________
Signature: ____________________ Date: ________________________