This Agreement (“DPA”) governs the processing of personal data by SecurityTask (the “Processor”) on behalf of the customer (the “Controller”) in connection with the provision of the SecurityTask service.
The Processor processes personal data solely to provide the service (security-awareness training, phishing simulations, compliance reporting) for the term of the agreement and per the Controller’s documented instructions.
Contact and identity data of the Controller’s personnel (name, email, department, role) and training usage data (progress, scores, simulation outcomes). Data subjects: the Controller’s employees and contractors. No special categories of data are required.
The Processor processes personal data only on the Controller’s documented instructions, including for transfers, unless required by law — in which case it informs the Controller before processing, where permitted.
Persons authorized to process the data are bound by a duty of confidentiality.
The Processor implements appropriate technical and organizational measures: encryption in transit and at rest, tenant isolation via RLS, append-only logs, role-based access control, and backups with recovery. See the Trust & Security page.
The Controller generally authorizes the sub-processors listed on the Trust & Security page. The Processor informs the Controller before adding or replacing a sub-processor, allowing objection, and imposes the same data-protection obligations on sub-processors.
The Processor assists the Controller, by appropriate measures, in responding to data-subject requests and in meeting its obligations under Articles 32–36 (security, breach notification, impact assessments).
The Processor notifies the Controller without undue delay after becoming aware of a personal-data breach, providing the information reasonably available.
On termination of the service, the Processor deletes or returns the personal data at the Controller’s choice, subject to statutory retention. Evidence is exportable at any time.
The Processor makes available the information needed to demonstrate compliance and allows for reasonable audits, including via third-party reports or certifications where available.
Personal data is hosted in the EU. Where a sub-processor processes data outside the EU/EEA, appropriate safeguards (e.g. Standard Contractual Clauses) apply.
Unless otherwise agreed in the main agreement, the law and venue stated there apply.
Annexes: (I) Processing details; (II) Technical & organizational measures — see the Trust & Security page; (III) Sub-processors — see the current list on the Trust & Security page.