Data Processing Addendum

Last updated: 2026-05-09 · Status: PLACEHOLDER — review with counsel before relying on it.

TODO: This is a placeholder DPA shell. The full executed DPA is available on request and should be drafted/reviewed by qualified counsel.

1. Scope

This DPA applies where secaudit processes Personal Data on behalf of a Client in the course of providing security testing services.

2. Roles

Client is the Controller. secaudit is the Processor.

3. Subprocessors

An up-to-date list is provided on request and updated on material change with reasonable notice to the Client.

4. Security measures

Encryption at rest and in transit, role-based access, audit logging, principle of least privilege, and per-engagement data isolation. Detailed in the executed DPA.

5. International transfers

Where applicable, EU Standard Contractual Clauses 2021/914 apply. UK Addendum attached on request.

6. Requesting an executed DPA

Email [email protected] with subject line “DPA request”.