Data Processing Addendum
Last updated: 2026-05-09 · Status: PLACEHOLDER — review with counsel before relying on it.
TODO: This is a placeholder DPA shell. The full executed DPA is available on request and should be drafted/reviewed by qualified counsel.
1. Scope
This DPA applies where secaudit processes Personal Data on behalf of a Client in the course of providing security testing services.
2. Roles
Client is the Controller. secaudit is the Processor.
3. Subprocessors
An up-to-date list is provided on request and updated on material change with reasonable notice to the Client.
4. Security measures
Encryption at rest and in transit, role-based access, audit logging, principle of least privilege, and per-engagement data isolation. Detailed in the executed DPA.
5. International transfers
Where applicable, EU Standard Contractual Clauses 2021/914 apply. UK Addendum attached on request.
6. Requesting an executed DPA
Email [email protected] with subject line “DPA request”.