Public unsigned copy

Data Processing Agreement

Version 1.5 · Effective date: 1 October 2026. This public copy contains no customer details or signatures.

The DPA forms part of our Terms of Service and applies without signature as described in section 1.2. For an executed counterpart, contact support@securitytrackr.com.

Contents

SecurityTrackr ApS — GDPR Article 28 Processor Terms

Version 1.5
Effective date 1 October 2026
Processor SecurityTrackr ApS, CVR no. 46602846, Denmark
Contact support@securitytrackr.com

1. Scope, incorporation, and execution

1.1 Relationship to the Agreement. This Data Processing Agreement ("DPA") supplements and forms part of the SecurityTrackr Terms of Service (the "Agreement") between SecurityTrackr ApS ("SecurityTrackr", "we", "us") and the customer organisation that accepts the Agreement ("Customer", "you"). In the event of a conflict between this DPA and the rest of the Agreement, this DPA prevails in respect of the processing of Personal Data.

1.2 Automatic application — no signature required. This DPA is incorporated into the Agreement by reference and applies automatically to every Customer whose use of the Service involves SecurityTrackr processing Personal Data on the Customer's behalf. It takes effect on the date the Customer accepts the Agreement, and no signature is required for it to be binding.

1.3 Signed counterpart on request. Where the Customer's internal, procurement, or regulatory requirements call for an executed document, SecurityTrackr will execute a counterpart of this DPA on request at no charge. Signature is a formality that evidences terms already in force under §1.2; it does not alter, extend, or add to those terms. Requests: support@securitytrackr.com.

1.4 Standard terms. This DPA is offered on standard terms to all Customers. SecurityTrackr does not, as a matter of course, negotiate amendments, and a Customer's own processor-terms template does not displace this DPA unless SecurityTrackr expressly agrees in writing.

1.5 Bring Your Own Key (BYOK) exclusion. Where the Customer configures AI features with its own API key from a third-party AI provider, that provider is engaged under the Customer's own contract with it and is not a SecurityTrackr Sub-processor. SecurityTrackr transmits the Customer's prompt to the provider the Customer selected, using the key the Customer supplied; that provider's handling of the data is governed by the Customer's agreement with it and falls outside this DPA. Accordingly, SecurityTrackr is not liable for the acts or omissions of a BYOK provider, including its retention, disclosure, or use of data the Customer directed SecurityTrackr to send to it, and the warranties in §7.2 do not extend to such a provider.


2. Definitions

2.1 "GDPR" means Regulation (EU) 2016/679, together with any national implementing legislation, and — where applicable to the Customer — the UK GDPR and Data Protection Act 2018.

2.2 "Personal Data", "processing", "controller", "processor", "data subject", "personal data breach", and "supervisory authority" have the meanings given in Article 4 GDPR.

2.3 "Customer Content" means the data the Customer and its authorised users submit to, store in, or generate through the Service — including security observations, comments, reports, evidence files, organisation profile data, and uploaded images.

2.4 "Customer Personal Data" means Personal Data contained in Customer Content or otherwise processed by SecurityTrackr on the Customer's behalf under the Agreement, as described in Annex I.

2.5 "Sub-processor" means a third party engaged by SecurityTrackr to process Customer Personal Data on the Customer's behalf, as listed in Annex III.

2.6 "SCCs" means the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914.


3. Roles of the parties

3.1 Customer as controller. The Customer is the controller of Customer Personal Data. The Customer determines the purposes and means of the processing, decides what data is entered into the Service, and is responsible for: establishing a valid lawful basis under Article 6 (and, where relevant, Article 9) GDPR; providing the transparency information required by Articles 13 and 14 to its own personnel and to any individual identifiable in Customer Content; and ensuring that the Personal Data it submits is accurate, relevant, and lawfully obtained.

3.2 SecurityTrackr as processor. SecurityTrackr is the processor of Customer Personal Data and processes it only on the Customer's documented instructions, as set out in §4.

3.3 SecurityTrackr as controller for its own purposes. SecurityTrackr acts as an independent controller — not as processor, and outside this DPA — in respect of: account administration and the contractual relationship with the Customer; billing, tax, and accounting records; security monitoring, abuse prevention, and audit logging of the Service as a whole; and aggregated service-usage statistics that do not identify any data subject. That processing is governed by the SecurityTrackr Privacy Policy.

3.4 No joint controllership. Nothing in this DPA makes the parties joint controllers within the meaning of Article 26 GDPR.


4. Processing instructions

4.1 Documented instructions. SecurityTrackr processes Customer Personal Data only on the Customer's documented instructions, including in respect of transfers to a third country, unless required to do so by Union or Member State law to which SecurityTrackr is subject. The Agreement, this DPA (including Annex I), and the Customer's use of the Service's features constitute the Customer's complete documented instructions.

4.2 Legally required processing. Where SecurityTrackr is required by Union or Member State law to process Customer Personal Data other than on the Customer's instructions, SecurityTrackr will inform the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

4.3 Unlawful instructions. SecurityTrackr will immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions. SecurityTrackr may suspend performance of the affected instruction until it is confirmed, withdrawn, or amended, and such suspension is not a breach of the Agreement. Where the Customer confirms an instruction that SecurityTrackr has identified as potentially unlawful and SecurityTrackr performs it, the Customer is responsible for the consequences of that instruction and indemnifies SecurityTrackr against third-party claims, regulatory penalties, and reasonable legal costs arising from it, on the terms of the indemnity in the Agreement.

4.4 No independent use. SecurityTrackr will not sell Customer Personal Data, use it for its own advertising or marketing, or use it to train machine-learning models. SecurityTrackr's contracts with its managed AI Sub-processors prohibit those providers from training their models on data submitted through SecurityTrackr's API access (see Annex III).

4.5 Prohibited data. The Service is not designed or offered for the processing of special categories of Personal Data (Article 9 GDPR), Personal Data relating to criminal convictions and offences (Article 10 GDPR), payment card numbers, or government identification numbers. The Customer must not submit such data to the Service. SecurityTrackr's technical and organisational measures are calibrated to the data categories described in Annex I and are not represented as appropriate to the heightened risk of prohibited data. Free-text fields do not become an appropriate destination for such data merely because they will accept it.

Submission of prohibited data is a breach of this DPA by the Customer. SecurityTrackr accepts no liability arising from or relating to the Customer's submission of prohibited data, the Customer indemnifies SecurityTrackr against third-party claims, regulatory penalties, and reasonable legal costs arising from it on the terms of the indemnity in the Agreement, and any assessment of the adequacy of SecurityTrackr's measures under §6.1 is made by reference to the data categories in Annex I rather than to data the Customer was prohibited from submitting.


5. Confidentiality

5.1 SecurityTrackr ensures that any person authorised to process Customer Personal Data — whether personnel, contractor, or officer — is bound by an appropriate contractual or statutory duty of confidentiality, and that the duty survives the end of their engagement.

5.2 Access minimisation. Access to Customer Personal Data in production is restricted to those personnel who require it to operate, support, secure, or repair the Service, is granted on a least-privilege basis, and is recorded in the Service's audit log. The administrative interface through which such access is possible is protected by network-level access control and a separate second authentication factor (see Annex II).

5.3 Honest statement of capability. The Customer acknowledges that SecurityTrackr is not a zero-knowledge provider. SecurityTrackr holds the master key that wraps each organisation's data encryption key and is therefore technically capable of decrypting Customer Content. That capability is inherent in providing server-side search, AI assistance, reporting, and support. SecurityTrackr's commitment not to access Customer Content except as permitted by §5.2 is accordingly a contractual and organisational commitment backed by audit logging — not a mathematical impossibility. SecurityTrackr makes this limitation explicit rather than implying a stronger guarantee than its architecture provides.


6. Security of processing

6.1 Technical and organisational measures. Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to data subjects, SecurityTrackr implements and maintains the technical and organisational measures set out in Annex II to ensure a level of security appropriate to the risk, as required by Articles 28(3)(c) and 32 GDPR.

6.2 Changes to measures. SecurityTrackr may update the measures in Annex II from time to time provided that it does not materially reduce the overall level of security of the Service. Security is an evolving discipline; Annex II describes the measures in force at the effective date of the applicable version of this DPA.

6.3 Customer's own responsibilities. The Customer is responsible for the security decisions within its own control, including: administering its users and their roles; promptly deprovisioning users who leave the organisation; safeguarding its users' authentication factors and backup codes; configuring the Service's optional security features (including enforced single sign-on) appropriately for its risk profile; managing the issue and revocation of API tokens; and deciding which AI processing option (and therefore which processing location) is suitable for its data.

6.4 Allocation of risk for Customer-controlled decisions. SecurityTrackr is not liable for loss, unauthorised access, or unauthorised disclosure to the extent it results from a matter within the Customer's control under §6.3 — including an act or omission of one of the Customer's own authorised users, the Customer's failure to deprovision a departed user, compromise or sharing of a user's credentials or API token otherwise than through a failure of SecurityTrackr's measures, or the Customer's decision not to enable an available security feature. This §6.4 allocates responsibility between the parties for matters each actually controls; it does not limit SecurityTrackr's own obligations under §6.1.


7. Sub-processors

7.1 General authorisation. The Customer grants SecurityTrackr general written authorisation to engage Sub-processors for the purposes of providing the Service, in accordance with Article 28(2) GDPR. The Sub-processors engaged at the effective date are listed in Annex III.

7.2 Flow-down obligations. SecurityTrackr will impose on each Sub-processor, by written contract, data protection obligations that are no less protective than those in this DPA, in particular the obligation to provide sufficient guarantees to implement appropriate technical and organisational measures. SecurityTrackr remains fully liable to the Customer for the performance of each Sub-processor's obligations.

7.3 Notice of changes. SecurityTrackr will give the Customer at least thirty (30) days' prior notice of the addition or replacement of any Sub-processor that processes Customer Personal Data. Notice is given by email to the Customer's registered administrative contact and by updating the Sub-processor list published with the Privacy Policy.

7.4 Right to object. The Customer may object to a new Sub-processor on reasonable, documented data protection grounds by notifying support@securitytrackr.com within the notice period. The parties will discuss the objection in good faith and SecurityTrackr will use reasonable efforts to make available a change in configuration or a commercially reasonable alternative. If no such alternative can be provided within a reasonable period, the Customer may terminate the affected Service by written notice and receive a pro-rata refund of any prepaid fees covering the period after termination. Termination on this basis is the Customer's sole and exclusive remedy in respect of a Sub-processor objection.

7.5 Emergency replacement. Where a Sub-processor must be replaced urgently to preserve the security or continuity of the Service, SecurityTrackr may do so before the notice period expires, and will notify the Customer as soon as reasonably practicable thereafter. The Customer's objection right under §7.4 applies from the date of that notice.


8. International transfers

8.1 Primary location. SecurityTrackr is established in Denmark. Customer Content is stored at rest in the European Union. The processing locations of each Sub-processor are stated in Annex III.

8.2 Transfer mechanisms. Where the provision of the Service involves a transfer of Customer Personal Data to a third country that is not the subject of an adequacy decision, that transfer is made under an appropriate safeguard within the meaning of Chapter V GDPR — the SCCs (including the processor-to-processor Module Three, where SecurityTrackr as processor onward-transfers to a Sub-processor), an applicable adequacy decision such as the EU–US Data Privacy Framework where the recipient is certified, or another lawful mechanism.

8.3 Supplementary measures. SecurityTrackr applies supplementary technical measures to third-country transfers, in particular application-layer encryption of Customer Content at rest under per-organisation keys (see Annex II), so that data transferred to or stored by a Sub-processor operating outside the EEA is not intelligible to that Sub-processor beyond what is functionally required to perform the service.

8.4 Customer control over AI processing location. Where the Customer requires that AI processing also take place in the EU, the Customer may select the EU-based managed AI provider identified in Annex III through the Service's account settings, or use BYOK with a provider of its choosing (§1.5). In the absence of such a selection, AI processing takes place in the United States under the terms described in Annex III. The Customer acknowledges that its own configuration choice determines this outcome, that the available options and their processing locations are disclosed in Annex III and in the Service's account settings, and that SecurityTrackr is not liable for the consequences of the Customer's choice of processing location where SecurityTrackr has processed in the location the Customer selected or, absent a selection, in the disclosed default.

8.5 Copies on request. A copy of the relevant transfer mechanism for any Sub-processor is available on request to support@securitytrackr.com.


9. Assistance with data subject rights

9.1 Customer's primary responsibility. As controller, the Customer is responsible for responding to requests from data subjects to exercise their rights under Chapter III GDPR.

9.2 Self-service. The Service provides functionality enabling the Customer to access, correct, export, and delete Customer Personal Data directly, without SecurityTrackr's involvement. The Customer will use that functionality in the first instance.

9.3 Assistance. Taking into account the nature of the processing, SecurityTrackr will assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to data subject requests — including requests for access, rectification, erasure, restriction, portability, and objection. Where the Service's self-service functionality is not sufficient for a particular request, SecurityTrackr will provide reasonable assistance within ten (10) business days of a written request.

9.4 Requests received directly. If SecurityTrackr receives a request from a data subject relating to Customer Personal Data, it will not respond to that request substantively other than to direct the data subject to the Customer, and will notify the Customer of the request without undue delay.

9.5 Two-party controls. Certain assisted operations — notably a full organisational data export produced by SecurityTrackr — require authorisation by both SecurityTrackr and the Customer's organisation administrator, by design, so that neither party can unilaterally extract the Customer's data. The Customer acknowledges that this control may extend the time needed to complete such a request and agrees to respond promptly to consent requests.

9.6 Charges. Assistance under §9.3 is provided free of charge unless requests are manifestly unfounded, excessive, or repetitive, in which case SecurityTrackr may charge a reasonable fee based on its administrative cost, notified to the Customer in advance.


10. Personal data breaches

10.1 Notification to the Customer. SecurityTrackr will notify the Customer of a personal data breach affecting Customer Personal Data without undue delay after becoming aware of it, and in any event within forty-eight (48) hours of becoming aware. This window is deliberately shorter than the Customer's own 72-hour obligation under Article 33(1) GDPR so that the Customer retains time to assess and notify its supervisory authority.

10.2 Content of the notification. The notification will describe, to the extent known at the time and supplemented as further information becomes available: the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and the name and contact details of a point of contact for further information.

10.3 No delay for completeness. SecurityTrackr will not delay an initial notification in order to complete its investigation. Information not available at the time of the initial notification will be provided in phases without undue further delay.

10.4 Notification to data subjects and authorities. The Customer is responsible for notifying its supervisory authority and, where required, affected data subjects. SecurityTrackr will not notify the Customer's supervisory authority or the Customer's data subjects on the Customer's behalf unless legally required to do so or expressly instructed by the Customer in writing.

10.5 Cooperation. SecurityTrackr will cooperate with the Customer and take such reasonable commercial steps as are directed by the Customer to assist in the investigation, mitigation, and remediation of the breach.

10.6 Not an admission. SecurityTrackr's notification of or response to a breach under this section is not an acknowledgement of fault or liability.


11. Assistance with DPIAs and prior consultation

Taking into account the nature of processing and the information available to it, SecurityTrackr will provide reasonable assistance to the Customer with data protection impact assessments under Article 35 GDPR and prior consultations with a supervisory authority under Article 36 GDPR, where the Customer's assessment relates to the processing carried out by SecurityTrackr. This assistance takes the form of the documentation described in §12 and reasonable written responses to the Customer's questions.


12. Audits and information

12.1 Documentation-first. SecurityTrackr will make available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR. It does so primarily through: this DPA and its Annexes; the published Privacy Policy and Sub-processor list; the published security documentation describing the Service's architecture and controls; and written responses to the Customer's reasonable security and data protection questionnaires, provided within thirty (30) days of receipt.

12.2 On-site and hands-on audits. The Customer may conduct, or mandate an independent third-party auditor to conduct, an audit of SecurityTrackr's processing of Customer Personal Data, subject to all of the following conditions:

(a) the information available under §12.1 is insufficient to demonstrate compliance, or the audit is required by the Customer's supervisory authority, or the audit follows a confirmed personal data breach affecting the Customer's Personal Data;

(b) the Customer gives at least thirty (30) days' prior written notice;

(c) audits take place during normal business hours, no more than once in any twelve-month period (save where required by a supervisory authority or following a confirmed breach), and are conducted so as to cause minimum disruption to the Service;

(d) any third-party auditor is not a competitor of SecurityTrackr and executes a confidentiality undertaking in favour of SecurityTrackr;

(e) the scope is limited to systems, documentation, and personnel relevant to the processing of that Customer's Personal Data, and excludes any access to other customers' data, to shared infrastructure to the extent access would expose other customers' data, to SecurityTrackr's internal financial information, or to information subject to legal privilege or third-party confidentiality obligations; and

(f) the Customer bears its own costs and reimburses SecurityTrackr's reasonable costs for time and materials expended on audits beyond the first in any twelve-month period.

12.3 Findings. Audit findings are the Confidential Information of both parties and may be disclosed only to the Customer's supervisory authority where required, or as otherwise required by law.

12.4 Sub-processor audits. Audit rights in respect of Sub-processors are exercised through SecurityTrackr. On request, SecurityTrackr will provide such Sub-processor compliance documentation as it holds and is permitted to share.


13. Deletion and return of data

13.1 Customer-initiated deletion. The Customer may delete Customer Content, individual user accounts, and its entire organisation at any time through the Service's account settings. On organisation deletion, Customer Personal Data is permanently and irreversibly deleted from the live application database in the same request, and associated evidence files and images are removed from object storage as part of the same operation.

13.2 On termination. On expiry or termination of the Agreement, SecurityTrackr will, at the Customer's election notified in writing within thirty (30) days of termination, delete or return all Customer Personal Data, and delete existing copies, unless Union or Member State law requires continued storage. Where the Customer elects return, data is returned in the structured, machine-readable formats the Service's standard export functionality produces; SecurityTrackr is not obliged to develop bespoke formats, migration tooling, or transformations for a particular destination system, and may charge on a time-and-materials basis for any such work it agrees to undertake. If the Customer makes no election within that period, SecurityTrackr will delete the data in accordance with the retention periods published in the Privacy Policy.

13.3 Export before deletion. The Customer is responsible for exporting any Customer Content it wishes to retain before initiating deletion or allowing the Agreement to terminate. The Service provides export functionality for this purpose. The Service provides no self-service recovery of deleted Customer Content. Backup copies retained under §13.4 are held solely for disaster recovery, not as a customer archive or a means to undo a deletion.

13.4 Residual copies in backup media — disclosed limitation. Customer Personal Data may persist after deletion from the live Service in the following disaster-recovery copies:

  • Hosting-provider snapshots. Point-in-time recovery snapshots of the application database roll forward automatically, and deleted data is fully aged out within thirty (30) days of deletion.
  • Offline database backups. SecurityTrackr produces encrypted monthly backups of the application database and keeps them on offline media under its control in Denmark, for no more than twelve (12) months from creation. This maximum applies to every offline copy, including any annual copy; no indefinite archive is kept. An older backup may contain Personal Data deleted from the live Service until that backup is securely deleted at the end of its retention period, or earlier where required by applicable law.

Backup copies remain subject to this DPA throughout retention. Access is restricted to authorised personnel and use is limited to disaster recovery and verification of the restore procedure. Before restored data is made available through the Service, SecurityTrackr will reapply applicable deletions and restrictions so that recovery does not reintroduce data that should no longer be processed. These retention limits do not displace an obligation under applicable law to erase backup data earlier where required and technically feasible.

Offline backups cover the application database, not evidence files or images in object storage. Object storage and the key-value store do not maintain a customer-recoverable backup tier; deletions there are immediate. SecurityTrackr discloses these limits rather than representing deletion as instantaneous across all media.

13.5 Legally required retention. SecurityTrackr retains billing and tax records for the period required by applicable Danish accounting and tax law after account closure. Such records are retained by SecurityTrackr as controller (§3.3), are limited to what the law requires, and are not used for any other purpose.


14. Term, changes, and general provisions

14.1 Term. This DPA takes effect in accordance with §1.2 and continues for as long as SecurityTrackr processes Customer Personal Data on the Customer's behalf. The obligations in §5 (Confidentiality), §12 (Audits), and §13 (Deletion) survive termination to the extent required.

14.2 Changes to this DPA. SecurityTrackr may update this DPA where necessary to reflect a change in applicable law, a regulatory decision, a change to the Service, or a change to its Sub-processors or security measures — provided no update materially reduces the protections afforded to the Customer. SecurityTrackr will give at least thirty (30) days' notice of any material change, by email to the Customer's registered administrative contact and by publishing the updated version. Sub-processor changes follow §7.3 and §7.4.

14.3 Liability — single aggregate cap. Each party's liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Agreement. Claims under this DPA and claims under the rest of the Agreement are subject to one and the same single aggregate cap. This DPA does not create an additional, separate, or supplementary cap, and sums recovered under this DPA reduce the amount recoverable under the Agreement (and vice versa) pound for pound. The exclusions of indirect and consequential loss in the Agreement apply equally to claims under this DPA.

14.4 Statutory allocation between the parties. The parties record that, under Article 82(2) GDPR, a processor is liable for damage caused by processing only where it has not complied with obligations of the GDPR specifically directed to processors, or where it has acted outside or contrary to the controller's lawful instructions. Nothing in this DPA is intended to widen that statutory position, and this DPA does not make SecurityTrackr responsible for the Customer's compliance with obligations directed to controllers — including lawful basis, transparency, accuracy, data minimisation in what the Customer chooses to upload, and the legitimacy of the Customer's instructions.

14.5 Contribution. Where SecurityTrackr has paid compensation in full for damage under Article 82(4) GDPR, it is entitled under Article 82(5) GDPR to claim back from the Customer that part of the compensation corresponding to the Customer's part of the responsibility for the damage. The Customer will reimburse such amounts on demand, together with reasonable legal costs incurred in defending the underlying claim, subject to §14.6.

14.6 What cannot be limited. Nothing in this DPA or the Agreement excludes or limits:

(a) either party's liability to a data subject under Article 82 GDPR — a cap agreed between controller and processor governs claims between the parties and cannot bind a third party or a supervisory authority;

(b) any administrative fine imposed on a party by a supervisory authority in respect of that party's own infringement;

(c) liability for fraud or fraudulent misrepresentation, for death or personal injury caused by negligence, or for gross negligence or wilful misconduct where applicable law prohibits their limitation; or

(d) any other liability that cannot lawfully be excluded or limited.

To the extent any limitation in this DPA is held unenforceable, it applies to the maximum extent permitted by law and the remainder is unaffected (§14.8).

14.7 Third-party rights. Save for the rights of data subjects under applicable law, no third party has any right to enforce this DPA.

14.8 Severability. If any provision of this DPA is held invalid or unenforceable, the remainder continues in full force, and the invalid provision is replaced by a valid provision that most closely reflects the parties' original intent.

14.9 Governing law and jurisdiction. This DPA is governed by the laws of Denmark, and the parties submit to the exclusive jurisdiction of the Danish courts — save that this does not deprive a data subject or a supervisory authority of any right or forum available to them under mandatory applicable law.


15. Execution

This DPA is in force under §1.2 without signature. The block below is provided solely so that a Customer requiring an executed counterpart under §1.3 may obtain one. Executing this block does not vary the terms above.

SecurityTrackr ApS (Processor)

Signature ............................................................
Name ............................................................
Title ............................................................
Date ............................................................

Customer (Controller)

Legal entity name ............................................................
Registration no. ............................................................
Registered address ............................................................
Signature ............................................................
Name ............................................................
Title ............................................................
Date ............................................................
Notice email for §7.3 / §10.1 / §14.2 ............................................................

Annex I — Details of the processing

A. List of parties

Data exporter / Controller: The Customer — the organisation that accepts the Agreement. Contact details are those held in the Customer's account, or as stated in the execution block in §15.

Data importer / Processor: SecurityTrackr ApS, CVR no. 46602846, Denmark. Contact: support@securitytrackr.com.

B. Description of the processing

Categories of data subjects

  • The Customer's personnel and other individuals whom the Customer authorises to use the Service (named users of the Customer's organisation).
  • Individuals identifiable within Customer Content — for example, individuals named or described in security observations, comments, risk assessments, reports, and uploaded evidence files.
  • Business contacts recorded by the Customer in relation to third-party companies or vendors it tracks in the Service.

Categories of personal data

Category Examples
Identity and account data Name, work email address, organisational role and permissions, account status and dates (creation, last sign-in, email verification, terms acceptance)
Authentication data Hashed password, encrypted multi-factor authentication secrets, registered passkey credential identifiers, backup codes (hashed), identifiers returned by the Customer's identity provider where SSO is used
Organisation profile data Organisation name, industry, country, size, selected regulatory frameworks, domains, IP ranges, website and social links, logo and brand colour
Customer Content Security observations and their free-text fields, comments, risk treatment records, reports, uploaded evidence files, and any Personal Data the Customer chooses to include within them
Audit and security records Actor identifier, action type, target, timestamp, and source IP address for security-relevant events within the Customer's organisation
Service usage metadata Feature usage counters and AI usage/spend records attributable to the Customer's organisation

Special categories of personal data

None. The Service is not designed for special-category data and the Customer is contractually prohibited from submitting it (§4.5). No additional restrictions or safeguards are therefore specified for such data, because none is expected to be processed.

Frequency of the processing

Continuous, for the duration of the Agreement.

Nature and purpose of the processing

Provision of the SecurityTrackr security observation and governance service, comprising: collection, recording, organisation, structuring, storage, encryption, retrieval, consultation, display, and export of Customer Content; authentication and access control for the Customer's users; duplicate and relationship detection across observations using semantic similarity; AI-assisted drafting, analysis, and reporting where the Customer's users explicitly invoke an AI feature; transactional email to the Customer's users; audit logging; backup and disaster recovery; and support, security, and maintenance of the Service.

Duration of the processing

For the term of the Agreement, followed by deletion or return in accordance with §13 and the retention periods published in the Privacy Policy.

C. Competent supervisory authority

Datatilsynet (the Danish Data Protection Agency), being the supervisory authority of the Member State in which SecurityTrackr ApS is established. Where the Customer is established in another Member State, its own lead supervisory authority remains competent in respect of the Customer's processing as controller.


Annex II — Technical and organisational measures

Measures in force at the effective date, implemented under Articles 28(3)(c) and 32 GDPR. Subject to §6.2.

1. Encryption

  • At rest. Customer Content classified as sensitive — including observation fields, discussion comments, organisation profile data, evidence files and their filenames, and stored credentials and secrets — is encrypted using AES-256-GCM via the Web Crypto API.
  • Per-organisation key hierarchy. A two-tier envelope scheme is used. Each organisation has its own randomly generated 256-bit data encryption key; that key is wrapped by a master key held outside the application database as an environment secret. The master key's only function is wrapping organisation keys. The practical effect is that every tenant is cryptographically isolated from every other tenant, and a copy of the database alone does not yield plaintext.
  • Context binding. Every encryption operation binds an organisation-and-field label as authenticated additional data (AAD), so a ciphertext's authentication tag proves not only that it was encrypted under a given key but that it belongs to a specific organisation and a specific field. Ciphertext relocated between organisations or between columns fails authentication rather than decrypting.
  • In transit. All connections to the Service are protected by TLS.
  • Key management. Keys are managed under a documented lifecycle aligned with NIST SP 800-57 Part 1 Rev. 5, covering generation, storage, use, rotation, and destruction.

2. Pseudonymisation and data minimisation

  • A blind index enables search over encrypted observation content without decrypting it, so routine search operations do not require plaintext access.
  • Application logging passes through a PII-scrubbing logger that strips personal identifiers before records are written.
  • Data submitted to AI providers is limited to the content required to perform the function the user invoked, with user-controlled fields passed through a sanitisation step before inclusion in a prompt.

3. Access control and authentication

  • Multi-factor authentication is mandatory for every account. Each user enrols at least one strong factor — a passkey (WebAuthn) or a TOTP authenticator — and MFA cannot be disabled while an account is active.
  • Role-based permissions govern what each user may see and do within their organisation.
  • Session security. Session tokens are encrypted (JWE), expire after 24 hours, and can be revoked server-side; revocation takes effect across the Service rather than waiting for token expiry.
  • Single sign-on. Customers may enforce SSO (OIDC) for their organisation, delegating authentication to their own identity provider.
  • Administrative access. SecurityTrackr's internal administrative interface sits behind network-level access control at the edge and a separate administrator second factor. Full organisational data exports additionally require two-party authorisation — both SecurityTrackr and the Customer's organisation administrator — so no single party can unilaterally extract a Customer's data.

4. Multi-tenant isolation

  • Tenant separation is enforced at three independent layers: cryptographic (per-organisation keys with AAD binding, §1), query-level (every data access is scoped to the acting organisation), and compile-time — every entity identifier in the codebase is a distinct nominal type, so code that passes one organisation's identifier where another's is expected fails to build rather than failing at runtime.
  • Automated linting enforces the identifier-typing rule across the codebase, so the boundary does not depend on individual developers remembering it.

5. Logging, monitoring, and traceability

  • Audit logging records security-relevant events within each organisation — including authentication events, permission changes, data access of note, and administrative actions — with actor, action, target, timestamp, and source IP.
  • Audit records are retained for 180 days (approximately six months) by an automated retention sweep, and are exportable by the Customer for ingestion into its own SIEM.
  • Service availability is monitored by two independent external probes with alerting to the operator; a health endpoint reports datastore and email-subsystem canaries.
  • An error-rate health signal is available on the internal operations dashboard for investigation following an alert.

6. Resilience, backup, and recovery

  • Customer Content is stored at rest in the European Union.
  • The application database maintains point-in-time recovery for up to 30 days.
  • Encrypted offline backups of the application database are produced monthly, kept on offline media in Denmark, and retained for no more than 12 months from creation, including any annual copy (§13.4). Evidence files and images in object storage are outside this offline-backup scope. A documented restore procedure verifies decryption, restores into an isolated database, and reconciles row counts against production; restore drills are scheduled at least quarterly. Applicable deletions and restrictions must be reapplied before a recovered Service is made available.
  • A documented incident response runbook defines severity levels, a first-response checklist, communication templates, and post-mortem requirements.

7. Secure development and vulnerability management

  • Changes pass automated linting, an automated test suite, and a production-equivalent build before deployment.
  • Structured security review of the codebase is performed on a recurring basis, with findings tracked to resolution or documented acceptance in a maintained register.
  • Third-party dependencies are inventoried and risk-tiered; dependency installation is hardened against install-time script execution.
  • A published security contact and disclosure policy (/.well-known/security.txt) provides a route for external vulnerability reports.
  • Security headers, rate limiting on sensitive endpoints, bot mitigation on authentication flows, and fail-secure defaults are applied at the application edge.

8. Evidence file handling

  • Uploaded evidence files are encrypted under the organisation's key before storage.
  • Files are checked against a malware-reputation service using a cryptographic hash of the file only — the file itself and its contents are never transmitted to that service.

9. Measures binding on Sub-processors

Sub-processors are engaged under written terms imposing data protection obligations no less protective than those in this DPA (§7.2), including confidentiality, security measures appropriate to the risk, assistance with breach notification, and restrictions on onward transfer.

10. Stated limitations

SecurityTrackr states the following limitations expressly, so that the Customer's own risk assessment rests on accurate information:

  • Provider-managed keys, not zero-knowledge. SecurityTrackr holds the master key and is technically capable of decrypting Customer Content (§5.3). The measures above defend against theft of the database, compromise of a single tenant, and unauthorised access by unprivileged parties. They do not, and are not represented to, prevent access by SecurityTrackr itself, by a compelled legal process, or by an authorised insider acting in bad faith.
  • No customer-managed encryption keys. The Service does not currently offer customer-held or customer-revocable encryption keys.
  • Certification status. SecurityTrackr does not currently hold an ISO/IEC 27001 certification or a completed SOC 2 audit report. The measures described in this Annex are contractual commitments supported by internal documentation, not third-party attestations.

Annex III — Sub-processors

Sub-processors engaged at the effective date. The current list is also published with the Privacy Policy. Changes are notified under §7.3.

Infrastructure and operations — engaged for all Customers

Sub-processor Purpose Processing location
Cloudflare, Inc. Cloud hosting, application database, file and object storage, content delivery, DDoS protection, logging, internal usage metering, and the built-in AI service used on the Free plan and for the signup organisation-profile draft Data stored at rest in the EU region; edge and AI processing on Cloudflare's global network; US (corporate)
Google Ireland Limited (Google Workspace) Transactional email delivery via the Gmail API (email verification, password reset, team invitations, billing notifications) and the support mailbox EU / US

AI providers — engaged only where the corresponding feature is used

The applicable AI Sub-processor depends on the Customer's plan and its configuration in account settings. No AI Sub-processor receives Customer Content unless a user of the Customer's organisation explicitly invokes an AI feature, except for the semantic-matching embeddings noted below, which the Customer may disable.

Sub-processor When engaged Processing location Data terms
Anthropic, PBC Default provider for the Advanced AI tier included with paid plans United States Data Processing Agreement and zero-data-retention agreement both in force; inputs and outputs are not retained beyond generating the response, and are not used for training
Mistral AI Advanced AI tier where the Customer selects Mistral for EU data residency; and the embeddings used for semantic duplicate/relationship matching on every plan, unless the Customer disables semantic matching European Union (France) Data Processing Agreement and zero-data-retention agreement both in force; inputs and outputs are not stored beyond generating the response, and are not used for training
OpenAI, L.L.C. Advanced AI tier where the Customer selects OpenAI United States Data Processing Agreement in force; no training on data submitted via the API. No zero-data-retention agreement — a limited abuse-monitoring retention window applies under standard terms
Cloudflare, Inc. (Workers AI) AI text generation on the Free plan, and the organisation-profile draft at signup Cloudflare's global network Covered by the Cloudflare terms referenced above

Customers using BYOK engage their chosen provider under their own contract; that provider is not a SecurityTrackr Sub-processor (§1.5).

Billing and payments — outside the Customer Personal Data processor scope

Stripe Payments Europe, Limited and the Stripe affiliates providing the applicable services, including Sold through Link, LLC for Managed Payments, process billing, payment, and tax data in the EU / US. SecurityTrackr acts as controller for billing and account administration under §3.3, rather than processing that data on the Customer's behalf under this DPA. Stripe is therefore disclosed here as a billing recipient, not as a Sub-processor of Customer Personal Data for that activity.

Stripe acts as a processor where it processes data on SecurityTrackr's instructions, and as an independent controller for purposes it determines, including fraud prevention and compliance with financial and tax obligations. That processing is governed by the applicable Stripe services terms and incorporated Stripe Data Processing Agreement, and, for Stripe's controller activities, its Privacy Policy. Checkout is hosted by Stripe; SecurityTrackr does not receive or store payment card numbers.

Services that receive no personal data

The following are not personal-data Sub-processors, and are listed for transparency only:

Service What it receives
VirusTotal (operated by Google) A cryptographic hash of an uploaded evidence file, for malware reputation lookup. Never the file or its contents
Shodan, LLC The IP addresses or hostnames the Customer enters as lookup targets when it triggers an infrastructure enrichment. No personal data about the Customer or its users

Version history

Version Date Change
1.5 2026-10-01 Clarified offline database backups: monthly encrypted copies held in Denmark, all copies retained for at most 12 months, scope excluding object-storage files, and deletion/restriction handling before restored data is made available. Clarified Stripe billing processing outside the Customer Personal Data processor scope and its processor/controller roles under Stripe terms. Published a public unsigned web copy.
1.4 2026-09-24 Updated the organisation role label from owner to administrator in §9.5 and Annex II §3 to match the application rename. The role's authority and the two-party export consent requirement are unchanged.
1.3 2026-08-26 Annex II §1 updated to record that discussion comments and evidence filenames are now encrypted at rest under the per-organisation key. An increase in the level of security, not a reduction (§6.2).
1.2 2026-08-25 Updated Annex III to record the account-wide Zero Data Retention agreement approved by Anthropic.
1.1 2026-08-05 Risk-allocation pass, before first issue to any customer. Single shared liability cap with the Terms, explicitly non-stacking (§14.3). Added the Art. 82(2) statutory allocation (§14.4), Art. 82(5) contribution right (§14.5), and an explicit statement of what cannot be limited (§14.6). Added Customer indemnities for confirmed-unlawful instructions (§4.3) and prohibited data (§4.5), a risk allocation for Customer-controlled security decisions (§6.4), liability exclusions for BYOK providers (§1.5) and for the Customer's choice of AI processing location (§8.4), and a standard-export-format limit on the return-of-data obligation (§13.2). Terms of Service §5 amended in the same change to incorporate this DPA by reference.
1.0 2026-08-05 Initial version.