Data Processing Addendum
This DPA governs SecuryxAI’s processing of personal data on behalf of customers. It is incorporated into and forms part of our Terms of Service.
1. Definitions
In this DPA:
- “Controller” means the Customer — the natural or legal person who determines the purposes and means of processing of Personal Data.
- “Processor” means SecuryxAI — processing Personal Data on behalf of the Controller.
- “Personal Data” has the meaning given in the GDPR: any information relating to an identified or identifiable natural person.
- “Processing” means any operation performed on Personal Data, including collection, storage, retrieval, alteration, disclosure, or deletion.
- “Data Subject” means the individual to whom Personal Data relates.
- “GDPR” means the EU General Data Protection Regulation 2016/679 and, where applicable, the UK GDPR.
- “Sub-Processor” means any processor engaged by SecuryxAI to process Personal Data on behalf of the Controller.
- “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data adopted by the European Commission.
2. Scope & Nature of Processing
2.1 Subject Matter
SecuryxAI processes Personal Data uploaded to or generated within the platform by the Customer in connection with providing the GRC Service, including compliance content, control evidence, policy documents, vendor questionnaire data, and audit workspace data.
2.2 Duration
Processing continues for the duration of the Customer’s subscription, and for 30 days thereafter to allow data export, unless a longer period is required by applicable law.
2.3 Categories of Data Subjects
- Customer’s employees and personnel whose data is referenced in compliance records
- Customer’s vendors and third parties referenced in evidence and assessments
- Auditors and reviewers granted access to the platform
2.4 Categories of Personal Data
- Names and business contact details (email, job title)
- User account credentials (hashed passwords)
- Activity and audit log data
- Any personal data contained within documents or evidence uploaded by the Customer
3. Obligations of the Processor (SecuryxAI)
In accordance with GDPR Article 28(3), SecuryxAI shall:
- Process Personal Data only on documented instructions from the Controller, unless required to do so by EU or Member State law
- Ensure that personnel authorised to process Personal Data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality
- Implement appropriate technical and organisational security measures (see Section 5)
- Respect the conditions for engaging Sub-Processors (see Section 4)
- Assist the Controller in responding to Data Subject rights requests, taking into account the nature of processing
- Assist the Controller with obligations under GDPR Articles 32–36 (security, breach notification, DPIAs, prior consultation)
- Delete or return all Personal Data to the Controller at the end of the Service, and delete existing copies unless EU or Member State law requires storage
- Make available all information necessary to demonstrate compliance with this Article and allow for audits
4. Sub-Processors
4.1 Authorisation
The Controller provides general written authorisation for SecuryxAI to engage Sub-Processors, subject to the conditions in this Section.
4.2 Sub-Processor Requirements
SecuryxAI will:
- Engage Sub-Processors under data processing agreements that impose equivalent data protection obligations as this DPA
- Remain liable to the Controller for the acts and omissions of Sub-Processors to the same extent as if SecuryxAI had performed the processing itself
- Maintain an up-to-date list of Sub-Processors at securyxai.com/subprocessors
4.3 Changes to Sub-Processors
SecuryxAI will provide at least 14 days’ notice before adding or replacing a Sub-Processor. The Controller may object to the change in writing within 14 days. If the Controller objects and SecuryxAI cannot accommodate the objection, the Controller may terminate the affected Services.
5. Security Measures
SecuryxAI implements the following technical and organisational measures appropriate to the risk:
- Encryption in transit: All data is encrypted using TLS 1.2 or higher between client and server, and between platform components.
- Encryption at rest: Database storage is encrypted at rest by the underlying infrastructure provider (Supabase/AWS).
- Access control: Role-based access control (OWNER, ADMIN, CONTRIBUTOR, REVIEWER, AUDITOR, VIEWER) with session-scoped tenant isolation. No cross-tenant data access is architecturally possible.
- Authentication: bcrypt password hashing (cost factor 12), JWT sessions (8-hour lifetime), rate limiting on authentication endpoints.
- Audit logging: Immutable, append-only audit log of all significant actions within the platform.
- Incident response: Internal procedures for detecting, containing, and notifying data breaches within 72 hours where required.
- Vulnerability management: Dependency scanning, security review of code changes, periodic penetration testing.
Full details are available at securyxai.com/security.
6. Data Breach Notification
SecuryxAI will notify the Controller of a confirmed Personal Data breach involving Customer data without undue delay and, where feasible, within 72 hours of becoming aware of it. Notification will be sent to the account owner email address and will include:
- A description of the nature of the breach
- The categories and approximate number of Data Subjects affected
- The categories and approximate number of Personal Data records affected
- Likely consequences of the breach
- Measures taken or proposed to address the breach
7. Data Subject Rights
SecuryxAI will, to the extent technically feasible, assist the Controller in responding to Data Subject rights requests. The Controller remains the primary point of contact for Data Subjects and is responsible for honouring such requests under applicable law.
8. International Data Transfers
Personal Data may be transferred to and processed in countries outside the European Economic Area, including the United States, where SecuryxAI and its Sub-Processors operate. Such transfers are subject to:
- Standard Contractual Clauses (SCCs) issued by the European Commission (Commission Decision 2021/914)
- The EU-US Data Privacy Framework, where applicable
- Equivalent transfer mechanisms for UK data transfers (International Data Transfer Agreement)
By entering into this DPA, the Controller authorises the transfers described above subject to the applicable transfer mechanisms. If required, SecuryxAI will execute the SCCs as a separate document — contact privacy@securyxai.com.
9. Data Deletion & Return
Upon termination of the Service:
- Customer Content and Personal Data will be available for export for 30 days after termination
- After 30 days, Personal Data will be securely deleted from live systems
- Encrypted backup copies will be purged within 90 days
- Audit logs may be retained in anonymised form for up to 12 months
- Financial records associated with the account will be retained for 7 years as required by law
10. Audits & Inspections
SecuryxAI will make available all information necessary to demonstrate compliance with GDPR Article 28. At the Controller’s request (no more than once per year, with 30 days’ notice), SecuryxAI will complete a security questionnaire or provide access to relevant compliance documentation, including SOC 2 reports when available.
11. Governing Law
This DPA is governed by the same law as the Terms of Service, except where EU or UK data protection law mandates otherwise.
12. Contact
Data protection enquiries: privacy@securyxai.com