Data Processing Agreement
Last updated: 21 June 2026
1. Definitions
This Data Processing Agreement (“DPA”) forms part of the agreement between Vakteye (“Processor”) and the entity identified in the subscription agreement (“Controller”) for the provision of compliance scanning services (“Services”).
“Personal Data”, “Processing”, “Data Subject”, “Supervisory Authority”, and “Sub-processor” have the meanings given to them in the applicable Data Protection Laws, including the EU General Data Protection Regulation (GDPR).
This public template is not a signed agreement or proof of a vendor's current region or transfer mechanism. Before production processing, the executed DPA must include a controller-specific named sub-processor schedule reconciled to dated contract and account evidence. Any unresolved entry blocks production processing.
2. Scope of Processing
Nature and Purpose: Automated compliance scanning of Controller’s web properties to detect privacy law violations, cookie consent issues, third-party tracking, and data transfer risks.
Categories of Data Subjects: Website visitors of Controller’s web properties.
Types of Personal Data: Categories of personal data processed under this DPA: (a) IP addresses, pseudonymised at the earliest reasonable opportunity and in any event no later than at the distribution of scan report packages; (b) HTTP request headers, cookies and local-storage identifiers observed during the scan; (c) network-request metadata and timing; (d) screenshots and DOM extracts captured to verify consent behaviour, which may incidentally include personal data displayed on the Controller's pages (the Controller is responsible for ensuring lawful basis for that incidental capture under Article 6 GDPR).
Duration: For the term of the subscription agreement, plus 30 days for return or deletion of the data (after which backups are deleted within a further 90 days).
3. Obligations of the Processor
The Processor shall:
- Process Personal Data only on documented instructions from the Controller, including with regard to transfers to third countries.
- Ensure that persons authorized to process Personal Data have committed to confidentiality obligations.
- Implement appropriate technical and organizational security measures, including encryption at rest and in transit, access controls, and audit logging.
- Not engage another processor without prior written authorization of the Controller.
- Assist the Controller, by appropriate technical and organizational measures, in responding to Data Subject requests pursuant to Article 28(3)(e) GDPR, and assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 GDPR pursuant to Article 28(3)(f) GDPR, taking into account the nature of processing and the information available to the Processor.
- Delete or return all Personal Data after the end of the provision of Services, at the Controller’s choice.
- Make available all information necessary to demonstrate compliance with this DPA.
4. Sub-processors
The Controller authorizes the use of the following sub-processors:
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Primary database, authentication and file-storage provider | Hosts account data, scan results, report packages, and audit logs | Within the European Economic Area | Intra-EEA — no third-country transfer |
| Frontend hosting and edge-network provider | Serves the web application and API routes; deployment region pinned to the European Union | Within the European Economic Area | Intra-EEA — no third-country transfer for the deployed application runtime |
| Cloud infrastructure provider (scanner backend) | Scanner egress IPs, container runtime, and scan-report storage | Within the European Economic Area | Intra-EEA — no third-country transfer |
| Background task orchestration provider | Schedules and executes the asynchronous scanning workload | European Union region (provider's EU cloud) | Intra-EEA — no third-country transfer |
| Transactional email provider | Delivers DSAR confirmations, account notifications, and compliance reports | Configured account region and processing scope are recorded in the signed sub-processor schedule | Current DPA and transfer evidence for the exact contracting entity govern; an EU sending region alone is not a no-transfer guarantee |
| Error monitoring provider | Application error monitoring with redacted event details (no personal data) | Within the European Economic Area | Intra-EEA — no third-country transfer |
| Rate-limit cache provider | Short-TTL cache for abuse-prevention counters keyed on hashed IP and request signature | European Union region (provider's EU cluster) | Intra-EEA — no third-country transfer |
| DNS and edge bot-protection provider | Authoritative DNS for the service domains and bot-detection on public forms | Globally distributed anycast network (no EU-only residency option offered by the provider). Personal data exposure limited to DNS queries (domain names, source IP at resolution time) and bot-check challenge tokens; no application data is processed. | Where third-country routing occurs, the provider's standard data protection terms apply, including Standard Contractual Clauses Module 2 (Commission Implementing Decision (EU) 2021/914) |
Sub-processors are identified above by function and region rather than by corporate name. The Processor flows down the data protection obligations set out in this DPA to each sub-processor by written contract in accordance with Article 28(4) GDPR and remains fully liable to the Controller for the performance of each sub-processor's obligations. The Processor maintains the corresponding list of named sub-processor entities and contracting countries and provides it to Controllers on written request to legal@vakteye.com. The Processor does not engage any sub-processor to process scan-result personal data outside the European Union except for the limited DNS and bot-protection metadata described above. Internal-only tools used for the Processor's own marketing, billing, anonymous website analytics, and staff workflows (for example outbound dialer, sales-call transcription, internal staff AI assistants) are not listed above because they do not process Controller data and therefore are not sub-processors under Article 28 GDPR.
The Processor shall notify the Controller at least 30 days in advance of any intended changes to the list of sub-processors. The Controller may object within the 30-day notice period on reasonable grounds related to data protection. If no resolution is reached, the Controller may terminate the affected Services without penalty.
5. International Transfers
Scan-result personal data and Controller account data are processed within the European Union by every sub-processor listed above. One narrow exception, contractually safeguarded, is noted in the table: the globally distributed DNS and bot-protection provider operates an anycast network for domain name resolution and bot-challenge tokens — personal data exposure on that path is limited to the source IP at resolution time and the queried hostname, and where any third-country routing occurs the provider's Standard Contractual Clauses Module 2 (Commission Implementing Decision (EU) 2021/914) apply. Intra-EU processing requires no separate transfer mechanism.
6. Security Measures
The Processor implements the following technical and organizational measures:
- Encryption: TLS 1.3 for data in transit; AES-256 for data at rest.
- Access Control: Role-based access with MFA enforcement for all administrative access.
- Audit Logging: Immutable chain of custody logs for all evidence collection and processing activities.
- Evidence Integrity: SHA-256 hashing of all collected evidence with tamper-evident storage.
- Data Minimization: Only metadata necessary for compliance analysis is collected.
- Row-Level Security: Database-level isolation ensuring each customer can only access their own data.
- Vulnerability Management: Regular security scanning of our own infrastructure.
7. Data Breach Notification
The Processor shall notify the Controller of any Personal Data breach without undue delay pursuant to Article 33(2) GDPR, and in any event no later than forty-eight (48) hours after the Processor becomes aware of the breach. The timeframe is intended to give the Controller sufficient time to fulfill its own 72-hour notification obligation to the supervisory authority under Article 33(1) GDPR. Initial notification may be preliminary and supplemented as further information becomes available. The notification shall include the nature of the breach, categories and approximate number of Data Subjects concerned, likely consequences, and measures taken or proposed.
8. Data Subject Rights
The Processor shall assist the Controller in fulfilling its obligation to respond to requests for exercising Data Subject rights under applicable Data Protection Laws.
9. Data Protection Impact Assessment
The Processor shall provide reasonable assistance to the Controller with data protection impact assessments and prior consultations with Supervisory Authorities.
10. Audit Rights
The Processor shall allow and contribute to audits, including inspections, conducted by the Controller or an independent auditor mandated by the Controller, to verify compliance with this DPA and Article 28 GDPR. Audits may be conducted no more than once per calendar year (plus ad-hoc following a confirmed Personal Data breach) and require at least 30 days' written notice. The Controller bears its own audit costs unless the audit reveals material non-compliance, in which case the Processor bears reasonable costs. The Controller may satisfy the audit right by reviewing independent third-party audit reports (including ISO/IEC 27001 certification or equivalent) in lieu of an on-site inspection, where such reports cover the scope of the intended audit. Auditors shall sign a confidentiality undertaking before accessing Processor systems.
11. Records of Processing Activities
The Processor shall maintain records of processing activities in accordance with Article 30(2) of the GDPR.
12. Term and Termination
This DPA shall remain in effect for the duration of the subscription agreement. No later than thirty (30) days after termination, the Processor shall, at the Controller's choice, either delete all Personal Data or return it in a structured, commonly used, machine-readable open format (JSON or CSV) in accordance with Article 20 GDPR. The Processor shall thereafter delete all copies, including backups, no later than 90 days after termination and shall provide a written certificate of deletion within fourteen (14) days of completion, in accordance with Clause 8.5 of European Commission Decision (EU) 2021/914. Storage requirements imposed by Union or Swedish law (including the Swedish Bookkeeping Act 1999:1078) are excepted in accordance with Article 28(3)(g) GDPR.
13. Liability and Indemnification
Each Party's aggregate liability under this DPA is governed by the limitation of liability provisions of the main subscription agreement between the Parties. For damages directly resulting from a Personal Data breach caused by the Processor's failure to meet its obligations under Articles 28 and 32 GDPR, the cap under the main subscription agreement is doubled. The Processor shall indemnify and hold the Controller harmless from administrative fines imposed by a Supervisory Authority under Article 83 GDPR, regulator-mandated remediation costs, and direct damages awarded to data subjects under Article 82 GDPR, in each case to the extent caused by the Processor's documented breach of this DPA. Nothing in this clause limits liability for: (a) wilful misconduct or gross negligence; (b) breach of confidentiality obligations; (c) infringement of intellectual property rights; (d) svikligt förledande enligt 30 § avtalslagen (1915:218); or (e) any liability that cannot be limited or excluded under mandatory Swedish or Union law. Allocation of joint and several liability towards data subjects under Article 82(4) GDPR is not affected by this clause; the contribution mechanism between the Parties under Article 82(5) GDPR applies after any such joint liability has been resolved.
14. Governing Law
This DPA shall be governed by the laws of Sweden, without regard to its conflict of laws rules. The GDPR and Swedish Data Protection Act (2018:218) apply to the substance of processing obligations regardless of choice of law. Disputes arising under this DPA shall be subject to the exclusive jurisdiction of the Stockholm District Court (Stockholms tingsrätt) as the court of first instance, with appeals to follow the ordinary Swedish court hierarchy.
Enterprise customers execute this DPA in onboarding. Vakteye retains the accepted text, SHA-256 hashes, signing event, and applicable sub-processor record internally. For manual review, contact legal@vakteye.com with your company details and subscription ID.