Procurement and data protection
Data Processing Addendum Overview
Updated: 22 July 2026
This page summarises the processor terms available for anydefect customers. It is not a countersigned agreement. The executed DPA identifies both legal entities, the contracted deployment, approved subprocessors, transfer mechanisms and the applicable security and deletion schedules.
1. Roles and scope
The customer is normally controller of personal data contained in connected environments, scan results, findings, ownership records and evidence. The contracting entity for anydefect acts as processor for that customer content and processes it only to provide the contracted security service and follow documented customer instructions. We act separately as controller for account administration, platform security, billing, procurement and our own legal obligations, as explained in the Privacy Notice.
2. Processing details
Nature and purpose
Ingest authorised configuration and security metadata; operate scans; correlate assets and findings; support remediation, evidence and reporting workflows; secure and support the service.
Duration
For the subscription term plus the return/deletion period in the executed order and DPA, subject to documented legal holds and records the customer instructs us to retain.
Data subjects
Customer users, administrators, workforce members, asset owners, assignees, contacts and people whose identifiers are present in authorised customer systems.
Personal-data categories
Business identity and contact data, IP addresses, hostnames, account or tenant identifiers, activity/audit data, ownership and assignment data, and security metadata supplied by or observed within the authorised scope.
The service is not designed for special-category data, payment-card data or production secrets. Customers must minimise scope and must not intentionally submit those categories unless expressly agreed in a signed order and risk assessment.
3. Processor commitments
- Process customer personal data only on documented instructions, including authorised transfers, and notify the customer if an instruction appears unlawful unless prohibited.
- Ensure authorised personnel are subject to confidentiality duties and access is limited to their operational need.
- Maintain the technical and organisational measures recorded in the executed security schedule.
- Flow equivalent data-protection duties to authorised subprocessors and remain responsible as required by the executed DPA.
- Assist with data-subject rights, security obligations, breach response, DPIAs and regulator consultation, taking account of the processing and information available.
- Notify the customer of a confirmed personal-data breach without undue delay under the contractual incident process.
- Provide compliance information and support proportionate audits or inspections under the agreed confidentiality, frequency and cost safeguards.
- At the customer's choice, return or delete customer personal data at the end of services, except where applicable law requires retention.
4. Subprocessors and transfers
The production subprocessor register is deployment-specific. It identifies the contracting provider, service and purpose, data categories, processing locations, effective date and applicable transfer safeguard. The executed DPA defines prior notice, objection and resolution mechanics for changes. Customer-enabled integrations act on the customer's documented instruction and are recorded separately from core service providers.
Restricted transfers use an applicable adequacy decision or contractual safeguard. Depending on the transfer, this may include the EU Standard Contractual Clauses and the UK IDTA or UK Addendum, together with the required transfer assessment and supplementary measures. Hosting and support geography must be stated in the order form; a generic product label is not a residency commitment.
5. Security, retention and deletion
Deployment-specific measures cover tenant-scoped authorisation, role-based access, protected session cookies, MFA controls, audit events, credential encryption, secret redaction, vulnerability handling, backup/recovery and incident response. The executed security schedule is authoritative; the public security overview is not a certification.
Retention is set by data category and contracted deployment. An individual account-deletion request removes or anonymises direct account identifiers after its recovery period; it does not itself delete customer workspace findings, scans, evidence, audit records or backups. Workspace return/deletion is handled under the customer termination schedule and documented legal holds. We do not state a universal 12-month default or 90-day backup purge on this page.
6. Customer responsibilities
Customers must have a lawful basis and authority for connected targets and submitted personal data, provide lawful instructions, configure least-privilege access, manage their users, avoid unnecessary sensitive data and evaluate whether the service is suitable for their legal and regulatory obligations.