Data Processing Agreement
Version 2.0 · Effective 22 September 2026
These are the terms on which we process personal data on behalf of our clients. They are published in full so that your legal review can begin immediately, rather than waiting on a document request.
Drafted against Article 28(3) of the UK and EU GDPR, section 21 of POPIA, and — for financial sector clients — Article 30 of the Digital Operational Resilience Act. Clause numbering is stable so that it can be cited in correspondence.
1. Status of this document
These are the data processing terms on which ZeroRisk Labs ("we", "us", the Processor) processes personal data on behalf of a client ("you", the Controller) when delivering an engagement. They are published so that your legal and procurement teams can complete their review before commercial discussions conclude, rather than discovering the terms at signature.
These terms form part of the engagement agreement between us and take effect on the date that agreement takes effect. Where an engagement agreement and these terms conflict on a data protection matter, these terms prevail unless the engagement agreement expressly states otherwise and the result is more protective of data subjects.
We will execute a countersigned copy of this agreement, including the transfer mechanism appropriate to your jurisdiction, on request and before processing begins. We will also complete your own template where your procurement process requires it.
This document is drafted to satisfy Article 28(3) of the UK GDPR and the EU GDPR and section 21 of the Protection of Personal Information Act 4 of 2013. It is published as a statement of the terms we will accept, and it does not replace the advice of your own legal advisers on your own obligations.
2. Definitions
- Applicable Data Protection Law — the UK GDPR and the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025; Regulation (EU) 2016/679 together with the national data protection legislation implementing and supplementing it in the relevant Member State; the California Consumer Privacy Act as amended by the California Privacy Rights Act and the CCPA Regulations, together with the comparable comprehensive consumer privacy statutes of other US states and any sectoral federal law applicable to the engagement; the Protection of Personal Information Act 4 of 2013 in South Africa; and the Digital Personal Data Protection Act, 2023 in India, in each case to the extent applicable to the processing.
- Controller, Processor, Personal Data, Processing, Personal Data Breach, and Data Subject — as defined in the UK and EU GDPR. In South Africa, Controller means responsible party, Processor means operator, and Personal Data means personal information. In the United States, Controller corresponds to business, Processor to service provider, Personal Data to personal information, and Data Subject to consumer, in each case as those terms are defined in the CCPA. The obligations in this agreement apply under whichever terminology governs.
- Engagement Data — personal data contained in or derived from your systems, networks, applications, personnel records, or supplied material, which we process in order to deliver the services.
- Sub-processor — a third party engaged by us to process personal data on your behalf.
- Services — the cybersecurity services described in the engagement agreement.
3. Roles of the parties
You are the Controller of Engagement Data. You determine the purposes and means of its processing, you are responsible for the lawfulness of the instructions you give us, and you warrant that you have a lawful basis for the processing you instruct.
We are the Processor of Engagement Data and act only on your documented instructions. Where the CCPA applies we are your service provider, and clause 17 sets out the additional commitments that status carries. We do not determine the purposes of processing Engagement Data, and we do not use it for our own purposes.
We are an independent Controller for the limited personal data we process for our own purposes — your contacts' business contact details, our records of the commercial relationship, and the records we must keep by law. That processing is governed by our Privacy Notice rather than by this agreement.
If we ever act outside your instructions in a way that determines the purpose and means of processing, we accept that we become a Controller for that processing and assume Controller liability for it.
4. Details of the processing
Article 28(3) requires the subject matter, duration, nature, and purpose of the processing, the type of personal data, and the categories of data subjects to be set out. The engagement-specific detail is recorded in Annex 1 below and is completed for your engagement in the engagement agreement.
5. Processing only on documented instructions
We process Engagement Data only on your documented instructions, including in relation to any international transfer, unless we are required to process it by a law to which we are subject that respects the essence of fundamental rights and freedoms and is proportionate to a legitimate aim. Where we are compelled by law, clause 15 governs how we respond, and we do not treat legal compulsion as a general licence to depart from your instructions.
Your instructions are the engagement agreement, the agreed scope and rules of engagement, and any subsequent written instruction. Instructions given by email are documented instructions for this purpose.
If we are required by law to process Engagement Data otherwise than on your instructions, we will inform you of that legal requirement before processing, unless the law prohibits us from doing so.
We will inform you without undue delay if, in our opinion, an instruction infringes Applicable Data Protection Law. We will say so in writing and pause the affected work rather than proceeding under protest.
6. Confidentiality
We ensure that every person we permit to process Engagement Data is subject to a binding duty of confidentiality, whether by contract of employment, contractor agreement, or statutory duty, and that the duty survives the end of their engagement with us.
Access to Engagement Data is limited to those personnel who require it to deliver the services, and is withdrawn when it is no longer required.
We do not disclose your identity, the existence of an engagement, or any finding arising from it to any third party without your prior written authorisation, except where disclosure is required by a binding legal obligation.
7. Security of processing
We implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 of the UK and EU GDPR and section 19 of POPIA. Those measures are described by category in Annex 2.
We take account of the state of the art, the cost of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to data subjects, when assessing what is appropriate.
We do not publish control parameters, configuration values, or architectural detail, because that information would materially assist an attacker while adding nothing to your assessment. Full detail is provided under a non-disclosure agreement as part of due diligence, and we will complete your security questionnaire.
8. Sub-processors
You give general written authorisation for us to engage the Sub-processors listed in our published register. That register is maintained as a living document and forms Annex 3 to this agreement.
- We give at least 30 days' notice before a new Sub-processor begins processing Engagement Data, so that your objection right is real rather than nominal.
- You may object on reasonable data protection grounds within that notice period. If you do, we will work with you to make the service available without the proposed Sub-processor, or by an alternative means. If no reasonable accommodation is possible, you may terminate the affected part of the engagement without penalty and receive a pro-rata refund of prepaid fees for services not delivered.
- We impose on each Sub-processor, by written contract, data protection obligations equivalent to those in this agreement, including obligations to provide sufficient guarantees of appropriate technical and organisational measures.
- We remain fully liable to you for the performance of each Sub-processor's data protection obligations. A Sub-processor's failure is our failure.
- We maintain no undisclosed Sub-processors. If a Sub-processor is not in the register, it does not process Engagement Data.
9. Assistance with data subject rights
We assist you in fulfilling your obligations to respond to data subject requests, taking into account the nature of the processing and the information available to us.
- We will not respond directly to a data subject request concerning Engagement Data unless you instruct us to in writing, or we are legally required to.
- We forward any such request we receive to you without undue delay and within 3 business days of receipt, together with the information needed to identify the requester and the nature of the request.
- We provide the technical and organisational assistance reasonably required for you to give effect to rights of access, rectification, erasure, restriction, portability, and objection in respect of Engagement Data in our possession.
- Where you instruct us to delete, correct, or restrict specific Engagement Data, we give effect to that instruction and confirm completion in writing.
10. Assistance with your wider compliance obligations
Taking into account the nature of the processing and the information available to us, we assist you in meeting the obligations set out below. This clause gives effect to Article 28(3)(f).
- Security of processing — providing the information you need to satisfy yourself that our measures are appropriate under Article 32.
- Notifying a Personal Data Breach to a supervisory authority — providing the information required for your notification under Article 33 within the timescale set out in clause 11.
- Notifying affected data subjects — providing the information required for your communication under Article 34.
- Data protection impact assessments — supplying the information about our processing, sub-processing, security measures, and transfer mechanisms that you require to complete a DPIA under Article 35.
- Prior consultation with a supervisory authority — supporting you in any consultation under Article 36 arising from a DPIA concerning our processing.
This assistance is provided at no additional charge where it relates to our own processing or to an incident affecting it. Where you request extensive assistance that goes beyond our processing, we will agree the basis for it in advance and in writing rather than invoicing you unexpectedly.
11. Personal Data Breach notification
We notify you of a Personal Data Breach affecting Engagement Data without undue delay and in any event within 24 hours of becoming aware of it. This deadline is deliberately shorter than the 72 hours you have under Article 33, so that the majority of your own notification window remains available to you. Where POPIA applies, section 21(2) requires us to notify you *immediately*, and clause 16 governs — the 24-hour figure is an outer limit, not a permission to wait.
We do not delay an initial notification in order to complete our investigation. We notify on the facts available, clearly marked as preliminary, and supply further detail in phases as it is established.
- A description of the nature of the breach, including the categories and approximate number of data subjects and records concerned, so far as known.
- The likely consequences of the breach.
- The measures taken or proposed to address it, including measures to mitigate possible adverse effects.
- A named point of contact at ZeroRisk Labs from whom further information can be obtained.
- Our assessment of whether the breach is likely to result in a risk, or a high risk, to the rights and freedoms of data subjects, together with our reasoning.
We cooperate fully with your investigation, preserve evidence relevant to it, and do not make any public statement about a breach affecting your Engagement Data without your prior written agreement, unless we are legally required to.
12. Deletion and return at the end of the engagement
On termination or expiry of the engagement, and at your choice, we delete or return all Engagement Data. We then delete existing copies unless we are required by law to retain them, in which case we tell you what we are retaining and on what legal basis.
Where your engagement agreement provides for the deliverable set to be retained for a defined period — commonly the term plus 24 months, to support retesting, audit evidence, or the defence of legal claims — that agreed period is your documented instruction to retain under clause 5, and it operates as an exception to the paragraph above. We retain only the material covered by that instruction, only for the period stated, and we delete it at the end of that period without needing a further instruction. Absent such a provision, the default is deletion or return on termination. We never retain Engagement Data on our own initiative.
Working material generated during delivery — testing artefacts, captured credentials, forensic working copies, and interim analysis — is the highest-risk category of data we hold. We delete it within 30 days of your acceptance of the final deliverable unless you instruct us in writing to retain it for longer. This applies regardless of any longer retention period agreed for the deliverable set.
Deletion is performed securely. Where data in backup media cannot be deleted immediately, it is placed beyond use and destroyed on the next scheduled destruction cycle. We confirm completion of deletion in writing on request.
13. Audits, inspections, and information rights
We make available to you all information necessary to demonstrate compliance with this agreement and with Article 28, and we allow for and contribute to audits and inspections conducted by you or by an auditor you appoint.
- We respond to a written request for compliance information within 30 days.
- We complete security and data protection questionnaires, including industry-standard formats, without charge.
- We accommodate an on-site or remote audit on reasonable prior notice, during business hours, subject to the auditor accepting confidentiality obligations and to reasonable measures protecting the data of our other clients.
- Where an audit would require us to disclose another client's confidential information, we will offer an alternative form of assurance that satisfies your requirement without breaching that confidence.
- We do not charge for the first audit in any twelve-month period. We may charge our reasonable costs for additional audits in the same period, agreed in advance in writing, unless the audit follows a Personal Data Breach or a substantiated compliance concern, in which case no charge applies.
14. International transfers
We are established in India. Your instruction to process Engagement Data therefore involves a transfer out of the United Kingdom, the European Economic Area, or South Africa as applicable. India is not the subject of a UK or EU adequacy decision, and we do not suggest otherwise.
We enter into the transfer mechanism appropriate to your jurisdiction before processing begins:
Where the Standard Contractual Clauses are incorporated, the annexes to those Clauses are populated from Annex 1, Annex 2, and Annex 3 of this agreement, and Clause 17 governing law and Clause 18 forum are completed in the engagement agreement. We supply our transfer impact assessment or transfer risk assessment for the relevant corridor on request.
European Economic Area to India
Standard Contractual Clauses, Module Two (controller to processor)
We enter into the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021. India is not the subject of an adequacy decision under Article 45 of the EU GDPR, so transfers rely on Article 46 safeguards supported by a transfer impact assessment and, where that assessment requires them, supplementary technical and organisational measures.
United Kingdom to India
International Data Transfer Agreement, or the EU SCCs with the UK International Data Transfer Addendum
The EU Standard Contractual Clauses are not a valid transfer mechanism on their own under the UK GDPR. We therefore enter into either the ICO's International Data Transfer Agreement or the EU SCCs together with the ICO's International Data Transfer Addendum, at the controller's election, supported by a transfer risk assessment.
United States to India
Contractual protection — no statutory transfer mechanism is imposed by US law
Neither federal law nor the state privacy statutes impose a GDPR-style restriction on transferring personal information outside the United States, so there is no equivalent of the Standard Contractual Clauses to execute. We do not treat that as a reason to offer less protection. Our service provider commitments under the CCPA Regulations apply in full wherever the processing occurs, and we extend the same technical and organisational measures, breach notification timescales, sub-processor controls, and government access commitments to US client data as we do to data originating in the United Kingdom or the European Economic Area. Where an engagement involves protected health information, a Business Associate Agreement is executed before processing begins.
South Africa to India
Operator agreement satisfying section 72 of POPIA
Transfers are made under a written agreement that subjects the personal information to a level of protection substantially similar to the conditions for lawful processing under POPIA, including the further-processing and security-safeguard provisions, as contemplated by section 72(1)(a).
15. Government and law enforcement access
We are established in India, outside the United Kingdom, the European Economic Area, and the Republic of South Africa. A controller's transfer impact assessment therefore has to consider whether a public authority in our jurisdiction could compel access to your Engagement Data. We address that question directly rather than leaving you to assume the worst.
The commitments below mirror Clauses 14 and 15 of the EU Standard Contractual Clauses and apply whether or not those Clauses have been signed:
- We have received no government or law enforcement request for client personal data to date, and no order requiring us to build or maintain any facility for bulk access to it.
- We assess every request we receive for legal validity, jurisdiction, and proportionality before responding, and we reject any request that is overbroad or defective on its face.
- We disclose only the minimum data strictly necessary to comply with a valid and binding order, never the whole of a dataset where a subset will satisfy it.
- We notify the affected controller before disclosing, or as soon afterwards as we lawfully can, and we provide whatever detail about the request the law permits us to share.
- We challenge a request through available legal channels, including seeking interim relief, where there are reasonable grounds to consider it unlawful under the applicable law or inconsistent with our obligations to the controller.
- We will tell a controller if we ever become subject to a law or measure that would prevent us from honouring these commitments, so that the controller can suspend transfers and exercise its termination rights.
- We maintain a record of any request received and the response given, and make it available to controllers and, where required, to supervisory authorities.
The first of these is a statement of fact as at the effective date of this agreement, and we will correct it here if it ceases to be true. We recognise that a controller may suspend transfers and terminate under the Standard Contractual Clauses if we become unable to honour these commitments, and we do not contest that right.
16. South African operator provisions
Where you are a responsible party subject to POPIA, the following apply in addition to the clauses above, giving effect to sections 19, 20, 21, and 72 of that Act.
- We process personal information only with your knowledge or authorisation, as required by section 20(a).
- We treat all personal information that comes to our knowledge as confidential and do not disclose it unless required by law or in the course of the proper performance of our duties, as required by section 20(b).
- We establish and maintain the security measures referred to in section 19, taking appropriate, reasonable technical and organisational measures to prevent loss of, damage to, or unauthorised destruction of personal information and unlawful access to or processing of it. Your obligation to secure this by written contract under section 21(1) is discharged by this agreement.
- We notify you immediately where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, as required by section 21(2). Immediately means immediately: the 24-hour outer limit in clause 11 is a backstop for breaches affecting other jurisdictions and does not dilute this obligation.
- Your own duty to notify the Information Regulator and affected data subjects under section 22 remains yours as responsible party. We support it under clause 10 but we do not discharge it for you, and nothing in this agreement should be read as transferring it.
- Where personal information is transferred to us outside the Republic, the transfer relies on section 72(1)(a), on the basis that this agreement subjects the information to a level of protection that is substantially similar to the conditions for lawful processing under POPIA, including the further-processing and security-safeguard conditions. Where we engage a sub-processor outside the Republic, we impose the same standard on that sub-processor by written contract, so that the section 72 standard is preserved through the whole chain.
17. United States service provider provisions
Where you are a business subject to the California Consumer Privacy Act as amended by the California Privacy Rights Act, we act as your service provider and not as a third party. The following give effect to the contract requirements in section 7051 of the CCPA Regulations, which are mandatory and which a GDPR-style processor clause does not satisfy on its own.
The specific business purposes for which we process personal information are those set out in the engagement agreement and Annex 1. They are stated specifically rather than by generic reference to the contract as a whole, as section 7051(a)(2) requires.
- We do not sell or share personal information collected under our contract with you, within the meaning the CCPA gives those terms.
- We do not retain, use, or disclose that personal information for any purpose other than the specific business purposes identified, including for any commercial purpose of our own, and we do not retain, use, or disclose it outside our direct business relationship with you.
- We do not combine the personal information we receive from you with personal information received from any other source or collected from our own interactions, except where the CCPA expressly permits it.
- We comply with the CCPA and its Regulations in respect of that personal information and provide the same level of privacy protection the CCPA requires of you, including reasonable security procedures and practices appropriate to the nature of the information, as contemplated by Cal. Civ. Code § 1798.81.5.
- You have the right to take reasonable and appropriate steps to satisfy yourself that our use is consistent with your CCPA obligations, including manual review, automated scanning of the systems we use for your engagement, and internal or third-party assessment at least once every twelve months. Clause 13 governs how that is exercised.
- We will notify you promptly if we determine that we can no longer meet our obligations under the CCPA and its Regulations.
- You have the right, on notice, to take reasonable and appropriate steps to stop and remediate any unauthorised use of personal information by us, and we will provide documentation verifying that we no longer retain or use personal information covered by a valid deletion request.
- We enable you to comply with consumer requests under the CCPA. If a consumer contacts us directly, we will either act on your documented instructions or inform the consumer that the request must be directed to you, as section 7050(c) requires. We will not simply ignore it.
- Any subcontractor we engage is bound by a written contract meeting these same requirements, as section 7051(b) requires. Our sub-processor register at Annex 3 is the definitive list.
- We are not a data broker, we do not provide cross-context behavioural advertising, and we would not qualify as a third party in respect of your personal information.
One permitted use is worth stating plainly because it is the substance of our work: section 7050(a)(4) of the Regulations allows a service provider to use personal information to prevent, detect, or investigate data security incidents and to protect against malicious, deceptive, fraudulent, or illegal activity, even where that purpose is not separately specified. Our engagements fall squarely within it. We rely on that provision only for the security purposes you have engaged us for, and never as a route to a purpose of our own.
18. Provisions specific to security testing and incident response
Generic processor terms do not adequately address what actually happens during offensive security testing or a forensic investigation. The following provisions are specific to the services we deliver and form part of our instructions from you.
- Authorisation before access. We do not begin any testing activity until you have confirmed in writing that you own the in-scope assets or are authorised to permit testing of them, and have identified the assets, the permitted techniques, and the testing window.
- Data minimisation during testing. Where a finding can be evidenced without extracting live personal data, we evidence it that way. Where extraction is unavoidable to demonstrate impact, we take the minimum necessary and record why it was necessary.
- Redaction in deliverables. Personal data appearing in reports is redacted or replaced with synthetic equivalents unless you instruct otherwise in writing, so that the deliverable itself does not become a new copy of your sensitive data.
- Credentials and secrets. Credentials, tokens, and keys recovered during an engagement are treated as the highest sensitivity, are never included in a deliverable in usable form, and are destroyed on completion. We recommend rotation of anything recovered and will identify what should be rotated.
- Special category and sensitive data. Where the engagement is likely to expose special category data, criminal offence data, or children's data — as is common in forensic, data loss prevention, and discovery work — that exposure is identified at scoping, recorded in the engagement agreement, and subjected to additional handling restrictions agreed with you.
- Chain of custody. Forensic evidence is acquired, stored, and transferred under documented chain of custody, and is returned or destroyed on your instruction.
- Incident response urgency. During an active incident we will act on urgent instructions given over the live channel agreed for that response — typically a dedicated chat channel, bridge, or video call established at the outset — and we will confirm them in writing within 24 hours. We do not operate a telephone line; the response channel is agreed with you when the incident is declared so that there is never ambiguity about how to reach us. Response speed is never a reason to leave an instruction undocumented.
19. Financial sector and regulated clients
Where you are a financial entity within the scope of Regulation (EU) 2022/2554 (the Digital Operational Resilience Act), we will enter into a contractual annex addressing the elements required by Article 30(2), including a complete description of the services and any subcontracting, the locations in which services are provided and data is processed together with advance notice of any change, provisions on availability, authenticity, integrity and confidentiality of data, provisions on access, recovery, and return of data, service level descriptions, assistance in the event of an ICT incident, cooperation with your competent and resolution authorities, termination rights and notice periods, and participation in your security awareness and digital operational resilience training.
Where the services support a critical or important function, we will additionally address the requirements of Article 30(3), including quantitative and qualitative performance targets, unrestricted rights of access, inspection, and audit, participation in threat-led penetration testing, and an exit strategy with a defined transition period.
Where you are an essential or important entity under Directive (EU) 2022/2555 (NIS2), we will provide the supplier assurance information you require to discharge your supply chain security obligations under Article 21(2)(d), and to account for our specific practices as required by Article 21(3).
Where an engagement involves protected health information and you are a covered entity or business associate under HIPAA, we execute a Business Associate Agreement before processing begins, apply the Security Rule administrative, physical, and technical safeguards to that information, and observe the minimum necessary standard. The Breach Notification Rule allows a business associate up to 60 days to report; our commitment in clause 11 is 24 hours and we do not rely on the longer statutory period.
Where you are a financial institution subject to the GLBA Safeguards Rule (16 C.F.R. Part 314), we provide the service provider oversight evidence you need to satisfy § 314.4(f), including our security measures documentation and the right of periodic assessment under clause 13.
Where you are a covered entity under 23 NYCRR Part 500, we support your third party service provider security policy obligations under § 500.11, including representations on access controls, encryption, notification, and your right to audit.
Where you are an SEC registrant, we recognise that Item 1.05 of Form 8-K requires disclosure within four business days of your determining that a cybersecurity incident is material. During an incident we prioritise giving you the factual findings you need to make and document that determination inside that window, and we will say clearly what is established fact and what remains under investigation.
We will not claim that a generic agreement satisfies a sector-specific regulatory requirement. Where an annex is needed, we produce one.
20. Liability and precedence
Each party is liable for its own compliance with Applicable Data Protection Law. Nothing in this agreement relieves either party of its own statutory obligations.
Where the Standard Contractual Clauses or the International Data Transfer Agreement are incorporated, and any provision of this agreement conflicts with them, those instruments prevail to the extent of the conflict.
Limitations of liability agreed in the engagement agreement apply to claims under this agreement, save that no limitation applies to the extent it would be unenforceable under Applicable Data Protection Law, and no limitation restricts a data subject's rights against either party.
Annex 1 — Details of the processing
This annex satisfies the descriptive requirements of Article 28(3) and populates Annex I of the Standard Contractual Clauses. Engagement-specific values are completed in the engagement agreement.
Subject matter and duration
- Subject matter — provision of the cybersecurity services described in the engagement agreement.
- Duration — the term of the engagement, followed by the deletion periods in clause 12. Processing is not open-ended.
Nature and purpose of the processing
- Security assessment and penetration testing of in-scope systems, networks, and applications.
- Adversary simulation and red team exercises against agreed objectives.
- Incident response, containment, eradication, and recovery support.
- Digital forensic acquisition, preservation, and analysis.
- Cloud, application, mobile, and operational technology security review.
- Compliance readiness assessment and control gap analysis.
- Threat intelligence and exposure monitoring against agreed identifiers.
- Security awareness training and simulated phishing exercises.
- The purpose in every case is to identify, evidence, and help you reduce security risk. We do not process Engagement Data for any other purpose.
Types of personal data
- The categories present depend on the engagement scope. Typically: identity and contact data, employment and role data, authentication and credential data, device and network identifiers, system and access log data, and the content of files or messages encountered in the environment under assessment.
- Special category data, criminal offence data, and children's data are in scope only where the engagement makes that unavoidable. Where that is the case it is identified at scoping and recorded in the engagement agreement, together with the additional restrictions that apply.
- The definitive list for your engagement is recorded in the engagement agreement rather than assumed from this annex.
Categories of data subjects
- Your employees, officers, contractors, and other personnel.
- Your customers and end users, where their data is present in an environment under assessment.
- Your suppliers and business contacts, where their data is present in that environment.
- Participants in awareness training and simulated phishing exercises.
- Individuals identified in the course of a forensic investigation or threat intelligence enquiry.
Your obligations and rights as Controller
- You determine the purposes and means of processing Engagement Data and give us documented instructions.
- You warrant that you have a lawful basis for the processing you instruct, and that you have provided any notice and obtained any consent required from data subjects.
- You warrant that you own the in-scope assets or are authorised to permit their testing.
- You are responsible for responding to data subject requests concerning Engagement Data, with our assistance under clause 9.
- You retain the rights of audit and information set out in clause 13, and the right to object to a Sub-processor under clause 8.
Annex 2 — Technical and organisational measures
Described by category, in line with clause 7. Implementation detail, configuration values, and control parameters are supplied under a non-disclosure agreement, because publishing them would assist an attacker without improving your assessment.
Technical measures
- Encryption in transit for all connections to our public services, with transport security enforced rather than offered, and encryption at rest for stored data.
- Deny-by-default data access. Our datastore permits no client-side access; all reads and writes occur server-side through a credentialled service identity operating under least privilege.
- Input validation on every submission path, with strict typing and bounded field lengths.
- Automated abuse prevention, including rate limiting and automated-submission detection on public endpoints.
- Request origin verification on state-changing operations.
- Browser hardening, including a content security policy, framing and content-type protections, and a restrictive permissions policy denying access to camera, microphone, and location.
- Restrained logging and error handling, with error output sanitised and public responses carrying no internal record identifiers.
- No third-party tracking. We set no analytics, advertising, or profiling cookies and load no third-party analytics or advertising scripts, removing that category of data leakage entirely.
- Secure deletion at the end of a retention period or on your instruction.
Organisational measures
- Individual confidentiality undertakings binding every person permitted to process Engagement Data, surviving the end of their engagement with us.
- Need-to-know access, granted for a defined task and withdrawn when no longer required.
- Written authorisation and scope control before any testing activity begins, including confirmation of asset ownership and permitted techniques.
- Documented rules of engagement for every testing and response engagement, including control points and escalation routes.
- Chain of custody procedures for forensic evidence.
- Defined retention and destruction clocks for engagement working material, rather than retention by default.
- Incident response and breach notification procedures aligned to the timescales in clause 11.
- Sub-processor assessment before engagement and contractual flow-down of the obligations in this agreement.
Assurance position
- We hold no third-party certification against ISO/IEC 27001, SOC 2, or a comparable assurance standard at the date of this document, and we will not represent otherwise. Our Trust Centre states our position and roadmap in full.
- We will complete your security questionnaire, accept a client audit under clause 13, and provide the detailed measures documentation described above under a non-disclosure agreement.
Annex 3 — Approved Sub-processors
The Sub-processors you authorise under clause 8 are those published in our Sub-processor Register, which forms this annex and is maintained as a living document so that it cannot fall out of date relative to this agreement.
Our own operations are conducted from India. Our sub-processors are global providers that may process data in more than one jurisdiction in the course of delivering platform-level functions such as content delivery and mail routing. The specific processing regions applicable to an engagement are recorded in the engagement agreement and are available to clients on request.
Requesting an executed copy
To receive a countersigned Data Processing Agreement incorporating the transfer mechanism for your jurisdiction, or to have us complete your own template, contact us with the subject line below. We aim to return a countersigned agreement within 5 business days.
A note on citation, to avoid ambiguity in correspondence: a lower-case "clause" refers to a clause of this agreement, and a capitalised "Clause" refers to a clause of the EU Standard Contractual Clauses or the International Data Transfer Agreement. Numbering overlaps between the two, so the distinction is deliberate.
ZeroRisk Labs
Ambari, Guwahati, Assam 781001, India
Email: privacy@zerorisklabs.com
Please use the subject line Data Processing Agreement so your message is routed correctly on arrival.
Please tell us your jurisdiction so that we send the correct transfer mechanism with the agreement.