Procurement and data protection

Data Processing Addendum Overview

Updated: 22 July 2026

This page summarises the processor terms available for anydefect customers. It is not a countersigned agreement. The executed DPA identifies both legal entities, the contracted deployment, approved subprocessors, transfer mechanisms and the applicable security and deletion schedules.

Request the current counsel-approved DPA and annexes from legal@anydefect.com. Do not rely on this overview as a substitute for the signed document.

1. Roles and scope

The customer is normally controller of personal data contained in connected environments, scan results, findings, ownership records and evidence. The contracting entity for anydefect acts as processor for that customer content and processes it only to provide the contracted security service and follow documented customer instructions. We act separately as controller for account administration, platform security, billing, procurement and our own legal obligations, as explained in the Privacy Notice.

2. Processing details

Nature and purpose

Ingest authorised configuration and security metadata; operate scans; correlate assets and findings; support remediation, evidence and reporting workflows; secure and support the service.

Duration

For the subscription term plus the return/deletion period in the executed order and DPA, subject to documented legal holds and records the customer instructs us to retain.

Data subjects

Customer users, administrators, workforce members, asset owners, assignees, contacts and people whose identifiers are present in authorised customer systems.

Personal-data categories

Business identity and contact data, IP addresses, hostnames, account or tenant identifiers, activity/audit data, ownership and assignment data, and security metadata supplied by or observed within the authorised scope.

The service is not designed for special-category data, payment-card data or production secrets. Customers must minimise scope and must not intentionally submit those categories unless expressly agreed in a signed order and risk assessment.

3. Processor commitments

  • Process customer personal data only on documented instructions, including authorised transfers, and notify the customer if an instruction appears unlawful unless prohibited.
  • Ensure authorised personnel are subject to confidentiality duties and access is limited to their operational need.
  • Maintain the technical and organisational measures recorded in the executed security schedule.
  • Flow equivalent data-protection duties to authorised subprocessors and remain responsible as required by the executed DPA.
  • Assist with data-subject rights, security obligations, breach response, DPIAs and regulator consultation, taking account of the processing and information available.
  • Notify the customer of a confirmed personal-data breach without undue delay under the contractual incident process.
  • Provide compliance information and support proportionate audits or inspections under the agreed confidentiality, frequency and cost safeguards.
  • At the customer's choice, return or delete customer personal data at the end of services, except where applicable law requires retention.

4. Subprocessors and transfers

The production subprocessor register is deployment-specific. It identifies the contracting provider, service and purpose, data categories, processing locations, effective date and applicable transfer safeguard. The executed DPA defines prior notice, objection and resolution mechanics for changes. Customer-enabled integrations act on the customer's documented instruction and are recorded separately from core service providers.

Restricted transfers use an applicable adequacy decision or contractual safeguard. Depending on the transfer, this may include the EU Standard Contractual Clauses and the UK IDTA or UK Addendum, together with the required transfer assessment and supplementary measures. Hosting and support geography must be stated in the order form; a generic product label is not a residency commitment.

5. Security, retention and deletion

Deployment-specific measures cover tenant-scoped authorisation, role-based access, protected session cookies, MFA controls, audit events, credential encryption, secret redaction, vulnerability handling, backup/recovery and incident response. The executed security schedule is authoritative; the public security overview is not a certification.

Retention is set by data category and contracted deployment. An individual account-deletion request removes or anonymises direct account identifiers after its recovery period; it does not itself delete customer workspace findings, scans, evidence, audit records or backups. Workspace return/deletion is handled under the customer termination schedule and documented legal holds. We do not state a universal 12-month default or 90-day backup purge on this page.

6. Customer responsibilities

Customers must have a lawful basis and authority for connected targets and submitted personal data, provide lawful instructions, configure least-privilege access, manage their users, avoid unnecessary sensitive data and evaluate whether the service is suitable for their legal and regulatory obligations.