Legal / Data Processing Information

Data Processing Information

The data-processing topics to establish before connecting customer security telemetry.

Revision prepared 2026-09-13 · Draft for business and legal review

This policy is a prepared draft. The contracting legal entity, registered address, and direct privacy contact still require confirmation before this notice can be treated as final.

Separate website inquiries from customer data

The public website’s Privacy Policy covers browsing and inquiries. A customer deployment can involve security logs, identifiers, user activity, assets, and other sensitive operational information. That processing requires a deployment-specific assessment and agreement.

This page is an overview of contracting topics. It is not a signed data-processing agreement and does not establish terms for an unconfigured deployment.

Define roles, scope, and instructions

The agreement should identify the contracting entities, controller and processor roles where applicable, the service purpose, processing duration, categories of data, categories of individuals, and documented customer instructions.

Only connect systems and data that your organization is authorized to process. Choose the minimum telemetry needed for the agreed security workflow.

Review technical and organizational measures

Review access controls, encryption, logging, administrative access, data separation, incident handling, and response authorization for the actual deployment. Security design principles on this website are not a substitute for a verified description of implemented controls.

Identify any AI services involved, what information they receive, and their applicable data-use and retention terms.

Agree on providers and transfers

Obtain the relevant subprocessor list, service functions, processing locations, and applicable change-notification procedure. Assess international transfers and required safeguards under the laws that apply to the customer.

See subprocessor information for the distinction between public website providers and product processing.

Specify lifecycle and assistance

Establish retention and deletion instructions, end-of-service handling, assistance with applicable data-subject requests, breach notification requirements, and the process for reviewing evidence of compliance.

Do not infer a retention period, data residency commitment, audit right, or incident notification deadline from a marketing description. These requirements should be agreed in the relevant contract.

Start the review

Use Book a meeting to discuss your deployment and data requirements. Privacy correspondence should use the contact channel provided in your service agreement. Share detailed security or personal information only after a suitable secure channel is agreed.