Sekura
HomeEnterpriseBlog
Sign inScan free
HomeEnterpriseBlogSign in

DATA PROCESSING ADDENDUM

This Data Processing Addendum ("DPA") forms part of the Master Subscription Agreement or Online Terms of Service between Sekura Inc. ("Sekura," "Processor") and [CUSTOMER LEGAL NAME] ("Customer," "Controller") (the "Agreement"). Where this DPA conflicts with the Agreement, this DPA governs as to the processing of Personal Data.

Contents

  1. 1. DEFINITIONS
  2. 2. ROLES AND SCOPE
  3. 3. PROCESSOR OBLIGATIONS
  4. 4. SUBPROCESSORS
  5. 5. INTERNATIONAL TRANSFERS
  6. 6. SECURITY INCIDENTS
  7. 7. AUDIT
  8. 8. DELETION AND RETURN
  9. 9. LIABILITY AND TERM
  10. ANNEX 1 — DESCRIPTION OF PROCESSING
  11. ANNEX 2 — TECHNICAL AND ORGANIZATIONAL MEASURES
  12. ANNEX 3 — SUBPROCESSORS
  13. SIGNATURES

1. DEFINITIONS

"Data Protection Laws" means all laws applicable to the processing of Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the CPRA ("CCPA"), and any other applicable state, federal, or foreign privacy law.

"Personal Data" means any information relating to an identified or identifiable natural person that is contained within Customer Data and processed by Sekura under the Agreement.

"Processing," "Controller," "Processor," "Data Subject," and "Supervisory Authority" have the meanings given in the GDPR. Where CCPA applies, Sekura is a "Service Provider" and Customer is a "Business."

"Security Incident" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by Sekura.

"Subprocessor" means any third party engaged by Sekura to process Personal Data.

2. ROLES AND SCOPE

2.1 Customer is the Controller and Sekura is the Processor in respect of Personal Data processed under the Agreement.

2.2 Nature of the processing. Sekura's Services are security assessment services. Personal Data is not the object of the Services and is processed only incidentally — for example, names and email addresses appearing in source code, commit history, configuration files, log data, or application databases encountered during assessment.

2.3 Customer shall not intentionally submit special categories of personal data (Article 9 GDPR), data relating to criminal convictions, payment card data, or personal health information to the Services, and shall take reasonable steps to minimise the Personal Data present in environments submitted for assessment.

2.4 The subject matter, duration, nature, purpose, categories of Data Subjects, and types of Personal Data are described in Annex 1.

3. PROCESSOR OBLIGATIONS

Sekura shall:

3.1 Documented instructions. Process Personal Data only on Customer's documented instructions, including as set out in the Agreement and this DPA, unless required otherwise by law — in which case Sekura shall inform Customer before processing, unless prohibited by that law.

3.2 No sale or independent use. Not sell or share Personal Data as those terms are defined under the CCPA, and not retain, use, or disclose Personal Data for any purpose other than performing the Services, or outside the direct business relationship with Customer. Sekura certifies that it understands and will comply with these restrictions.

3.3 Confidentiality. Ensure that personnel authorized to process Personal Data are bound by confidentiality obligations and have received appropriate data protection training.

3.4 Security. Implement and maintain the technical and organizational measures described in Annex 2, appropriate to the risk.

3.5 Assistance with Data Subject rights. Taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures in fulfilling its obligation to respond to requests to exercise Data Subject rights. Where Sekura receives such a request directly, it shall promptly forward it to Customer and shall not respond except to confirm the request has been forwarded.

3.6 Assistance with compliance. Provide Customer with reasonable assistance in relation to data protection impact assessments, prior consultation with Supervisory Authorities, and Security Incident notification obligations, taking into account the nature of processing and information available to Sekura.

3.7 Records. Maintain records of processing activities carried out on behalf of Customer as required by Article 30(2) GDPR.

4. SUBPROCESSORS

4.1 Customer grants Sekura general authorization to engage Subprocessors. The current list is maintained at sekura.ai/subprocessors and reproduced in Annex 3.

4.2 Sekura shall give Customer at least thirty (30) days' notice before adding or replacing a Subprocessor, by email or by posting to the subprocessor page where Customer has subscribed to notifications.

4.3 Customer may object on reasonable data protection grounds within the notice period. The Parties shall discuss in good faith. If no resolution is reached, Customer may terminate the affected Services on written notice, with a pro-rata refund of prepaid fees for the terminated portion.

4.4 Sekura shall impose on each Subprocessor data protection obligations no less protective than those in this DPA, and remains fully liable to Customer for the performance of each Subprocessor.

4.5 Customer-selected AI providers. Where Customer supplies its own AI or LLM credentials, that provider is engaged by Customer, not by Sekura, and is not a Sekura Subprocessor. Customer is the Controller in respect of that relationship.

5. INTERNATIONAL TRANSFERS

5.1 Sekura shall not transfer Personal Data outside the country of origin except where an appropriate transfer mechanism is in place.

5.2 Where Personal Data originating in the EEA, UK, or Switzerland is transferred to a country without an adequacy decision, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (Controller to Processor), are incorporated into this DPA by reference and completed as follows: Customer is the data exporter, Sekura is the data importer; Clause 7 (docking) applies; Clause 9 option 2 (general authorization) with a thirty-day notice period applies; Clause 11 optional redress language does not apply; Clause 17 governing law is Ireland; Clause 18(b) forum is Ireland. Annexes I, II, and III of the SCCs are populated by Annexes 1, 2, and 3 of this DPA.

5.3 For UK transfers, the UK International Data Transfer Addendum to the SCCs applies, with Tables 1 to 4 populated by reference to this DPA.

6. SECURITY INCIDENTS

6.1 Sekura shall notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident affecting Personal Data in Sekura's possession or control.

6.2 The notification shall describe, to the extent known: the nature of the incident, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed. Where information is not available at the time of notification, it shall be provided in phases without undue delay.

6.3 Sekura shall take reasonable steps to contain and remediate the incident and shall cooperate with Customer's investigation and any required notifications.

6.4 Notification of a Security Incident is not an acknowledgement of fault or liability.

7. AUDIT

7.1 Sekura shall make available information reasonably necessary to demonstrate compliance with this DPA.

7.2 Customer may, no more than once per twelve-month period and on thirty (30) days' prior written notice, conduct an audit of Sekura's processing. Audits shall be conducted during business hours, subject to reasonable confidentiality obligations, and shall not unreasonably disrupt Sekura's operations.

7.3 Sekura may satisfy an audit request by providing a current third-party audit report, certification, or completed security questionnaire, where such materials reasonably address Customer's inquiry.

7.4 Customer bears the cost of any audit it conducts, except where the audit identifies a material breach by Sekura.

8. DELETION AND RETURN

8.1 On termination or expiry of the Agreement, Sekura shall, at Customer's election, delete or return all Personal Data and delete existing copies, within thirty (30) days, except to the extent retention is required by law.

8.2 Personal Data residing in routine encrypted backup media remains subject to this DPA until overwritten or deleted in the ordinary course of Sekura's disaster recovery cycle.

8.3 On written request, Sekura shall certify deletion.

8.4 Aggregated Data. Aggregated, anonymized, and de-identified data generated in accordance with the Agreement does not constitute Personal Data and is not subject to this Section, provided it cannot reasonably be used to identify any Data Subject.

9. LIABILITY AND TERM

9.1 Each Party's liability under this DPA is subject to the limitations and exclusions in the Agreement, except where Data Protection Laws prohibit such limitation.

9.2 This DPA takes effect on the Effective Date of the Agreement and continues until Sekura ceases all processing of Personal Data on Customer's behalf.

ANNEX 1 — DESCRIPTION OF PROCESSING

Subject matter

Provision of automated security assessment, vulnerability validation, and reporting services

Duration

The term of the Agreement, plus the deletion period in Section 8

Nature and purpose

Scanning, analysis, validation, storage, and reporting for the purpose of identifying and evidencing security vulnerabilities

Categories of Data Subjects

Customer's employees, contractors, and developers; end users of Customer's applications; any individual whose data is incidentally present in systems submitted for assessment

Types of Personal Data

Names, email addresses, usernames, and identifiers appearing in source code, commit metadata, configuration files, logs, or application data encountered during assessment; account identifiers of Customer users of the Platform

Special categories

None intentionally processed. Customer undertakes not to submit special category data.

Frequency of transfer

Continuous during the term

ANNEX 2 — TECHNICAL AND ORGANIZATIONAL MEASURES

Control area

Measures

Encryption

TLS 1.2 or above in transit; AES-256 at rest. Customer credentials encrypted at rest and never logged.

Access control

Role-based access; least privilege; multi-factor authentication for all personnel with production access; access reviewed at least quarterly.

Segregation

Customer environments logically separated. Assessment runners isolated per engagement with no access to the control plane.

Credential handling

Customer-supplied credentials decrypted only at point of use, scrubbed after use, and destroyed on termination of the engagement.

Logging and monitoring

Tamper-evident, hash-chained audit logging of assessment activity. Centralized monitoring and alerting on the control plane.

Secure development

Version-controlled source; peer review; automated static analysis, dependency scanning, and secret detection in CI; pinned dependencies.

Vulnerability management

Continuous self-assessment using the Sekura Platform; documented remediation targets by severity.

Personnel

Confidentiality obligations for all personnel; background checks where permitted by law; security awareness training.

Business continuity

Encrypted backups; documented recovery procedures; periodic restoration testing.

Incident response

Documented incident response plan with defined roles, escalation, and 72-hour notification commitment.

Data minimisation

Evidence capture redacts sensitive values. Only data necessary to evidence a finding is retained.

Deletion

Documented deletion procedures with certification on request.

Sekura may update these measures provided the level of protection is not materially reduced.

ANNEX 3 — SUBPROCESSORS

See the current list at sekura.ai/subprocessors. As at the date of this DPA:

Subprocessor

Purpose

Location

Personal Data processed

Google Cloud Platform

Infrastructure hosting and compute

United States

All categories, as hosted

[AI provider — where Sekura-managed inference is selected]

Model inference for assessment analysis

United States

Incidental data present in analysed content

[Payment processor]

Subscription billing

United States

Billing contact name, email, payment details

[Support and ticketing platform]

Customer support

United States

Support contact name, email, correspondence

[Error monitoring]

Platform reliability

United States

Technical identifiers, limited log data

SIGNATURES

SEKURA INC.

Name: ________________________ Title: ________________________

Signature: ____________________ Date: ________________________

[CUSTOMER LEGAL NAME]

Name: ________________________ Title: ________________________

Signature: ____________________ Date: ________________________

Version dpa-2026-08-a

Product

  • Home
  • Enterprise
  • Pricing
  • Request a POC
  • Sekura Once
  • Sekura Always

Blog

  • Latest
  • Guides
  • Who built Sekura
  • RSS

Legal

  • Privacy
  • Terms
  • Data processing addendum

© 2026 Sekura, Inc. · Built in Silicon Valley

We use essential cookies for sign-in and scans, and cookieless analytics. No tracking cookies. Privacy policy