Legal — Standard Template

Data Processing Agreement

Last updated: [DATE] · Vulnus (KVK 91502691)
This is Vulnus's standard Data Processing Agreement (DPA), provided in accordance with Article 28 of the EU General Data Protection Regulation (GDPR). It applies automatically as an addendum to your Service Agreement with Vulnus whenever Vulnus processes personal data on your behalf while performing security testing services. Questions? Contact contact@vulnus.io.

This Data Processing Agreement ("DPA") is entered into between the client identified in the applicable Service Agreement or Statement of Work ("Controller") and Vulnus, a sole proprietorship (eenmanszaak) registered with the Dutch Chamber of Commerce (KVK) under number 91502691, registered address Krommehoekstraat 122, 1104 KV Amsterdam, the Netherlands ("Processor"), together the "Parties."

This DPA forms part of, and is incorporated into, the Service Agreement between the Parties. In the event of a conflict between this DPA and the Service Agreement regarding the processing of personal data, this DPA prevails.

1. Definitions

Terms such as "personal data," "processing," "controller," "processor," "data subject," "personal data breach," and "supervisory authority" have the meanings given to them in the GDPR (Regulation (EU) 2016/679).

2. Subject Matter and Duration

The Processor provides automated and manual security testing services (vulnerability scanning, attack simulation, and related reporting) to the Controller under a separate Service Agreement. In the course of delivering these services, the Processor may incidentally encounter or process personal data present within the Controller's systems, applications, or infrastructure.

This DPA takes effect on the start date of the applicable engagement and remains in force for as long as the Processor processes personal data on behalf of the Controller, including any period reasonably required for secure deletion after the engagement ends.

3. Nature and Purpose of Processing

Processing under this DPA is limited to what is strictly necessary to perform security testing services, including:

The Processor does not process personal data for any purpose other than delivering the agreed security testing services, and does not use personal data encountered during testing for its own purposes, marketing, or profiling.

4. Categories of Data Subjects and Personal Data

CategoryExamples
Data subjectsEmployees, customers, or end users of the Controller whose data may be present in the systems tested
Personal dataNames, email addresses, IP addresses, session/cookie identifiers, and other data incidentally exposed through vulnerabilities, misconfigurations, or system access during testing
Special categoriesNot intentionally targeted; if encountered incidentally, handled under the same safeguards described in this DPA and reported to the Controller without unnecessary delay

5. Obligations of the Processor

The Processor shall:

6. Personal Data Breach Notification

The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Controller's personal data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it.

7. Sub-processors

The Processor may engage third-party sub-processors solely for hosting and infrastructure purposes necessary to deliver services (for example, cloud hosting or infrastructure providers). Current sub-processors are listed below and may be updated from time to time; the Controller will be notified of any new sub-processor and may object on reasonable data-protection grounds.

Sub-processorPurposeLocation
[e.g. Vercel Inc.]Application hostingEU / US (SCCs where applicable)
[e.g. Supabase Inc.]Data storageEU
[e.g. Anthropic, PBC]AI-assisted report generationUS (SCCs where applicable)

Confirm and finalize this list against your actual infrastructure before publishing.

8. International Transfers

Where personal data is transferred outside the European Economic Area, the Processor ensures such transfers are subject to appropriate safeguards, such as the European Commission's Standard Contractual Clauses (SCCs), or another valid transfer mechanism recognised under GDPR.

9. Security Measures

The Processor maintains technical and organisational measures appropriate to the risk, including: encrypted data storage and transmission, access restricted to personnel directly involved in the engagement, secure credential management, regular rotation of access credentials, and secure deletion of client data and findings following engagement completion and any agreed retention period.

10. Liability

Each Party's liability arising out of or in connection with this DPA is subject to the limitations of liability set out in the Service Agreement between the Parties, except where such limitation is not permitted under applicable law (including in respect of GDPR obligations).

11. Governing Law

This DPA is governed by the laws of the Netherlands. Any disputes arising from this DPA are subject to the exclusive jurisdiction of the competent courts of the Netherlands, unless mandatory law provides otherwise.

Signatures

Processor — Vulnus
Ryan Veldbloem
Date: __________
Controller — [Client name]
[Name, title]
Date: __________