This Data Processing Agreement ("DPA") is entered into between the client identified in the applicable Service Agreement or Statement of Work ("Controller") and Vulnus, a sole proprietorship (eenmanszaak) registered with the Dutch Chamber of Commerce (KVK) under number 91502691, registered address Krommehoekstraat 122, 1104 KV Amsterdam, the Netherlands ("Processor"), together the "Parties."
This DPA forms part of, and is incorporated into, the Service Agreement between the Parties. In the event of a conflict between this DPA and the Service Agreement regarding the processing of personal data, this DPA prevails.
Terms such as "personal data," "processing," "controller," "processor," "data subject," "personal data breach," and "supervisory authority" have the meanings given to them in the GDPR (Regulation (EU) 2016/679).
The Processor provides automated and manual security testing services (vulnerability scanning, attack simulation, and related reporting) to the Controller under a separate Service Agreement. In the course of delivering these services, the Processor may incidentally encounter or process personal data present within the Controller's systems, applications, or infrastructure.
This DPA takes effect on the start date of the applicable engagement and remains in force for as long as the Processor processes personal data on behalf of the Controller, including any period reasonably required for secure deletion after the engagement ends.
Processing under this DPA is limited to what is strictly necessary to perform security testing services, including:
The Processor does not process personal data for any purpose other than delivering the agreed security testing services, and does not use personal data encountered during testing for its own purposes, marketing, or profiling.
| Category | Examples |
|---|---|
| Data subjects | Employees, customers, or end users of the Controller whose data may be present in the systems tested |
| Personal data | Names, email addresses, IP addresses, session/cookie identifiers, and other data incidentally exposed through vulnerabilities, misconfigurations, or system access during testing |
| Special categories | Not intentionally targeted; if encountered incidentally, handled under the same safeguards described in this DPA and reported to the Controller without unnecessary delay |
The Processor shall:
The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Controller's personal data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it.
The Processor may engage third-party sub-processors solely for hosting and infrastructure purposes necessary to deliver services (for example, cloud hosting or infrastructure providers). Current sub-processors are listed below and may be updated from time to time; the Controller will be notified of any new sub-processor and may object on reasonable data-protection grounds.
| Sub-processor | Purpose | Location |
|---|---|---|
| [e.g. Vercel Inc.] | Application hosting | EU / US (SCCs where applicable) |
| [e.g. Supabase Inc.] | Data storage | EU |
| [e.g. Anthropic, PBC] | AI-assisted report generation | US (SCCs where applicable) |
Confirm and finalize this list against your actual infrastructure before publishing.
Where personal data is transferred outside the European Economic Area, the Processor ensures such transfers are subject to appropriate safeguards, such as the European Commission's Standard Contractual Clauses (SCCs), or another valid transfer mechanism recognised under GDPR.
The Processor maintains technical and organisational measures appropriate to the risk, including: encrypted data storage and transmission, access restricted to personnel directly involved in the engagement, secure credential management, regular rotation of access credentials, and secure deletion of client data and findings following engagement completion and any agreed retention period.
Each Party's liability arising out of or in connection with this DPA is subject to the limitations of liability set out in the Service Agreement between the Parties, except where such limitation is not permitted under applicable law (including in respect of GDPR obligations).
This DPA is governed by the laws of the Netherlands. Any disputes arising from this DPA are subject to the exclusive jurisdiction of the competent courts of the Netherlands, unless mandatory law provides otherwise.