• Phishing IQ
  • Pricing
  • FAQ
securitytask
Sign In
Sign Up
securitytask

Swiss-made gamified security awareness training for SMBs. Turn compliance into a habit your team actually keeps — with NIS2, ISO 27001 & nFADP training evidence.

© Copyright 2026 SecurityTask. All Rights Reserved.

Product
  • Pricing
  • Phishing IQ test
  • FAQ
Get Started
  • Sign In
  • Sign Up
Legal
  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Trust & Security
  • DPA

Data Processing Agreement (DPA)

Pursuant to Article 28 GDPR

Draft — to be reviewed by your legal counsel. This is a template DPA provided for information; complete the party details and have it reviewed before signing. A signable version is available on request at privacy@securitytask.com.

This Agreement (“DPA”) governs the processing of personal data by SecurityTask (the “Processor”) on behalf of the customer (the “Controller”) in connection with the provision of the SecurityTask service.

1. Subject matter, duration, nature & purpose

The Processor processes personal data solely to provide the service (security-awareness training, phishing simulations, compliance reporting) for the term of the agreement and per the Controller’s documented instructions.

2. Types of data & categories of data subjects

Contact and identity data of the Controller’s personnel (name, email, department, role) and training usage data (progress, scores, simulation outcomes). Data subjects: the Controller’s employees and contractors. No special categories of data are required.

3. Documented instructions

The Processor processes personal data only on the Controller’s documented instructions, including for transfers, unless required by law — in which case it informs the Controller before processing, where permitted.

4. Confidentiality

Persons authorized to process the data are bound by a duty of confidentiality.

5. Security (Article 32)

The Processor implements appropriate technical and organizational measures: encryption in transit and at rest, tenant isolation via RLS, append-only logs, role-based access control, and backups with recovery. See the Trust & Security page.

6. Sub-processors

The Controller generally authorizes the sub-processors listed on the Trust & Security page. The Processor informs the Controller before adding or replacing a sub-processor, allowing objection, and imposes the same data-protection obligations on sub-processors.

7. Assistance to the Controller

The Processor assists the Controller, by appropriate measures, in responding to data-subject requests and in meeting its obligations under Articles 32–36 (security, breach notification, impact assessments).

8. Personal data breaches

The Processor notifies the Controller without undue delay after becoming aware of a personal-data breach, providing the information reasonably available.

9. Deletion or return

On termination of the service, the Processor deletes or returns the personal data at the Controller’s choice, subject to statutory retention. Evidence is exportable at any time.

10. Audits

The Processor makes available the information needed to demonstrate compliance and allows for reasonable audits, including via third-party reports or certifications where available.

11. International transfers

Personal data is hosted in the EU. Where a sub-processor processes data outside the EU/EEA, appropriate safeguards (e.g. Standard Contractual Clauses) apply.

12. Governing law

Unless otherwise agreed in the main agreement, the law and venue stated there apply.

Annexes: (I) Processing details; (II) Technical & organizational measures — see the Trust & Security page; (III) Sub-processors — see the current list on the Trust & Security page.