Skip to main content

Data Processing Agreement

Last updated August 20, 2026

On this page
  1. 01Introduction
  2. 02Definitions
  3. 03Roles and Scope
  4. 04Categories of Data
  5. 05Special Category Data
  6. 06Processor Obligations
  7. 07Security and Insurance
  8. 08Sub-processors
  9. 09Data Subject Rights
  10. 10International Transfers
  11. 11Government Requests
  12. 12Personal Data Breach
  13. 13Audit Rights
  14. 14Retention and Deletion
  15. 15Liability
  16. 16General
  17. 17Governing Law
  18. 18Contact
  19. 19Changes
  20. 20Annex I: Processing
  21. 21Annex II: Measures
  22. 22Annex III: Sub-processors
  23. 23Annex IV: Transfers

This Data Processing Agreement sets out how AIPTx processes personal data on your behalf under the UK GDPR and the Data Protection Act 2018: the scope of processing, the security measures behind it, our sub-processors, how international transfers are made lawful, and your rights as the controller.

1. Introduction

1.1 This Data Processing Agreement ("DPA") forms part of the agreement between AIPTx, a company registered in England and Wales, whose registered office is at 167-169 Great Portland Street, Fifth Floor, London, W1W 5PF, United Kingdom ("AIPTx", "we", "Processor") and the customer identified in the Service Agreement ("Customer", "you", "Controller").

1.2 This DPA governs the Processing of Personal Data by AIPTx on behalf of the Customer in connection with the AIPTx platform and related services (the "Services").

1.3 This DPA is made to comply with:

  • the UK General Data Protection Regulation ("UK GDPR"), being Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018;
  • the Data Protection Act 2018 ("DPA 2018");
  • the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR"), where the Customer or the relevant Data Subjects are established in the European Economic Area; and
  • the Privacy and Electronic Communications (EC Directive) Regulations 2003 ("PECR"), where applicable.

1.4 In this DPA, "Data Protection Laws" means all of the above, together with any other applicable law relating to the Processing of Personal Data, in each case as amended, replaced or superseded from time to time.

1.5 Where this DPA conflicts with the Service Agreement in relation to the Processing of Personal Data, this DPA prevails.

1.6 The Annexes form part of this DPA. Annex I describes the Processing, Annex II sets out the technical and organisational measures, Annex III lists the Sub-processors, and Annex IV governs the completion of transfer instruments.

2. Definitions

2.1 The terms "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" have the meanings given to them in the UK GDPR.

2.2 Special Category Data means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and genetic data, biometric data processed for the purpose of uniquely identifying a natural person, data concerning health, and data concerning a natural person's sex life or sexual orientation, as described in Article 9 of the UK GDPR. It includes, where the context requires, personal data relating to criminal convictions and offences within the meaning of Article 10 of the UK GDPR.

2.3 Sub-processor means any third party engaged by AIPTx to Process Personal Data on behalf of the Customer.

2.4 Affiliate means any entity that controls, is controlled by, or is under common control with a party, where control means direct or indirect ownership of more than 50% of the voting interests.

2.5 UK Addendum means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the Information Commissioner under section 119A(1) of the DPA 2018.

2.6 UK IDTA means the International Data Transfer Agreement issued by the Information Commissioner under section 119A(1) of the DPA 2018.

2.7 EU SCCs means the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914.

2.8 ICO means the Information Commissioner's Office, the United Kingdom's supervisory authority for data protection.

2.9 Target System means any system, network, application, endpoint or infrastructure that the Customer instructs AIPTx to test.

2.10 "Services" has the meaning given in clause 1.2.

3. Roles, Scope and Customer Obligations

3.1 The Customer is the Controller and AIPTx is the Processor in respect of Personal Data Processed under this DPA.

3.2 The Customer determines the purposes and means of Processing and is responsible for ensuring it has a lawful basis under Article 6 of the UK GDPR, and where applicable a condition under Article 9, for the Processing it instructs.

3.3 AIPTx Processes Personal Data for the following purposes only:

  • (a) providing penetration testing, vulnerability assessment and security testing Services;
  • (b) generating findings, evidence and reports;
  • (c) account administration, authentication and support;
  • (d) maintaining the security, availability and integrity of the Services; and
  • (e) irreversibly anonymising Personal Data, in accordance with clause 3.4, for statistical analysis, service improvement and product development.

3.4 Anonymised data. AIPTx may irreversibly anonymise Personal Data so that no individual, Customer or Target System is identifiable and no re-identification is reasonably possible, and may thereafter use the resulting anonymous data for statistical analysis, service improvement and product development. Anonymisation is carried out as part of the Processing described in clause 3.3. Once anonymised, the data is no longer Personal Data and this DPA does not apply to it. AIPTx does not use Personal Data to train shared machine learning models.

3.5 The duration of Processing is the term of the Service Agreement, plus the retention period set out in clause 14.

Customer warranties and obligations

3.6 The Customer warrants and undertakes that, in respect of every Target System and every instruction it gives:

  • (a) it either owns the Target System or holds valid, current written authorisation from the owner to permit the testing instructed, and it will retain evidence of that authorisation for the duration of this DPA and for two years afterwards;
  • (b) the testing it instructs is lawful in every jurisdiction in which the Target System, the Customer and the relevant Data Subjects are located, including under the Computer Misuse Act 1990 and equivalent legislation;
  • (c) it has a lawful basis under Article 6 of the UK GDPR, and where applicable a condition under Article 9 or Article 10, for the Processing of any Personal Data contained within or reachable from the Target System;
  • (d) it has provided all privacy notices and obtained all consents, permissions and authorisations required under Data Protection Laws in connection with the Processing it instructs;
  • (e) it has assessed whether a Data Protection Impact Assessment is required under Article 35 of the UK GDPR and, where required, has completed one; and
  • (f) its instructions will not put AIPTx in breach of Data Protection Laws.

3.7 The Customer will indemnify AIPTx against all claims, losses, fines and reasonable costs arising from a breach of clause 3.6, subject to clause 15.

3.8 Affiliates. Where the Service Agreement permits the Customer's Affiliates to use the Services, this DPA applies to Processing carried out for those Affiliates. The Customer remains responsible for its Affiliates' compliance and acts as their single point of contact under this DPA, unless AIPTx agrees otherwise in writing.

4. Categories of Data Subject and Personal Data

4.1 The categories of Data Subject and Personal Data, and the nature, purpose and duration of Processing, are set out in Annex I.

4.2 The Customer may vary the Target Systems and configuration within the Services, and Annex I is to be read as covering Processing arising from that configuration.

5. Special Category Data and Incidental Capture

5.1 The Customer acknowledges that penetration testing and vulnerability assessment involve interacting with live systems, and that evidence captured to demonstrate a vulnerability (including HTTP requests and responses) may incidentally contain Personal Data, and may in some circumstances contain Special Category Data.

5.2 AIPTx does not seek out, target or deliberately Process Special Category Data. The Services are not designed for, and must not be instructed for, the purpose of Processing Special Category Data.

5.3 Incidental exposure is nonetheless foreseeable where a Target System holds such data. The Customer is responsible for identifying that possibility in advance, for establishing the applicable Article 9 or Article 10 condition, and for informing AIPTx in writing before testing begins so that additional safeguards can be agreed. Where the Customer has informed AIPTx, AIPTx will Process any Special Category Data so encountered solely as necessary to deliver the Services and in accordance with this DPA.

5.4 In respect of Personal Data incidentally captured as evidence, AIPTx will:

  • (a) limit capture to what is necessary to demonstrate the vulnerability;
  • (b) apply the measures in Annex II;
  • (c) restrict access to personnel who require it to deliver the Services; and
  • (d) on the Customer's written request, redact or delete specified evidence within 10 business days, provided that doing so does not prevent AIPTx from meeting a legal obligation.

5.5 The Customer may define out-of-scope paths and systems, and may configure the Services to restrict testing accordingly. AIPTx will respect those exclusions.

6. Processor Obligations

6.1 AIPTx will:

  • (a) Process Personal Data only on the Customer's documented instructions, including in relation to international transfers, unless required to do otherwise by law, in which case AIPTx will inform the Customer of that legal requirement before Processing, unless the law prohibits it on important grounds of public interest;
  • (b) immediately inform the Customer if, in AIPTx's opinion, an instruction infringes the UK GDPR, the DPA 2018 or other applicable Data Protection Laws, in accordance with Article 28(3) of the UK GDPR, and may suspend the affected Processing until the instruction is amended or confirmed;
  • (c) ensure that persons authorised to Process Personal Data are subject to an appropriate duty of confidentiality that survives the end of their engagement;
  • (d) implement and maintain the technical and organisational measures set out in Annex II;
  • (e) respect the conditions in clause 8 for engaging Sub-processors;
  • (f) taking into account the nature of the Processing, assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to Data Subject requests under Chapter III of the UK GDPR;
  • (g) assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the UK GDPR, taking into account the nature of Processing and the information available to AIPTx;
  • (h) provide reasonable assistance to the Customer in carrying out Data Protection Impact Assessments under Article 35 of the UK GDPR, and in any prior consultation with the ICO under Article 36;
  • (i) at the Customer's election, delete or return all Personal Data at the end of the provision of the Services, in accordance with clause 14;
  • (j) make available to the Customer all information necessary to demonstrate compliance with Article 28 of the UK GDPR, and allow for and contribute to audits in accordance with clause 13; and
  • (k) maintain a written record of all categories of Processing carried out on behalf of the Customer, in accordance with Article 30(2) of the UK GDPR.

Record of Processing Activities

6.2 The record maintained under clause 6.1(k) contains:

  • (a) the name and contact details of AIPTx, of each Controller on whose behalf AIPTx acts, of any representative, and of the data protection contact identified in clause 18;
  • (b) the categories of Processing carried out on behalf of each Controller;
  • (c) where applicable, details of transfers of Personal Data to a third country or international organisation, including the identification of that country or organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1) of the UK GDPR, documentation of the suitable safeguards; and
  • (d) a general description of the technical and organisational security measures referred to in Article 32(1) of the UK GDPR.

6.3 The record is maintained in writing, including in electronic form, and is kept current.

6.4 AIPTx will make the record available to the ICO or any other competent Supervisory Authority on request, in accordance with Article 30(4) of the UK GDPR, and will make the portion relating to the Customer's Processing available to the Customer on reasonable written request.

6.5 Annex I and Annex II to this DPA together constitute the record in respect of Processing carried out for the Customer, and are maintained as part of it. Where the Customer requires the record in a different form for its own Article 30(1) obligations, AIPTx will provide reasonable assistance.

6.6 AIPTx does not rely on the exemption in Article 30(5) of the UK GDPR. That exemption does not apply where Processing is other than occasional, and Processing under this DPA is continuous for the term of the Service Agreement.

7. Security Measures and Insurance

7.1 AIPTx implements and maintains the technical and organisational measures set out in Annex II, which are appropriate to the risk under Article 32 of the UK GDPR.

7.2 AIPTx maintains the certifications recorded in Annex II.

7.3 AIPTx may update the measures in Annex II provided the level of protection is not reduced. Material reductions require the Customer's prior written agreement.

7.4 The Customer is responsible for its own configuration of the Services, including scope definition, credential management, user access and rate limits.

Insurance

7.5 AIPTx maintains, with reputable insurers, insurance appropriate to the risks arising under this DPA, comprising at minimum:

  • (a) cyber liability insurance, covering data breach response, regulatory defence costs and third-party liability arising from a Personal Data Breach;
  • (b) professional indemnity insurance, covering liability arising from the performance of the Services; and
  • (c) any insurance required by law, including employers' liability insurance where applicable.

The indemnity limits under clause 7.5 are set in the Service Agreement or the applicable order form. Customers requiring a stated minimum should raise it during contracting.

7.6 AIPTx will maintain that cover for the term of the Service Agreement and for the run-off period stated in the Service Agreement, and will notify the Customer without undue delay if any policy is cancelled, materially reduced or not renewed.

7.7 On reasonable written request, and no more than once in any twelve-month period, AIPTx will provide a certificate or broker's letter evidencing the cover in force. AIPTx is not required to disclose the policies themselves.

7.8 The existence of insurance does not limit, and is not limited by, either party's liability under clause 15, and nothing in this clause creates a right for the Customer to claim directly against any insurer.

8. Sub-processors

8.1 The Customer grants AIPTx general written authorisation to engage Sub-processors, subject to this clause.

8.2 The current list of Sub-processors, including each Sub-processor's name, the service provided and the country in which Processing takes place, is set out in Annex III.

8.3 The Customer may request notification of changes to the Sub-processor list by writing to [email protected].

8.4 AIPTx will give the Customer at least 30 days' written notice before engaging a new Sub-processor or replacing an existing one.

8.5 The Customer may object to a proposed Sub-processor on reasonable data protection grounds by written notice within 14 days of AIPTx's notice. The parties will discuss the objection in good faith. If it cannot be resolved within 30 days of the objection, the Customer may terminate the affected Services on written notice, without penalty and with a pro-rata refund of prepaid fees for the terminated portion.

8.6 AIPTx will impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for the performance of each Sub-processor's obligations.

8.7 Where a Sub-processor is located outside the United Kingdom, AIPTx will ensure an appropriate transfer mechanism under clause 10 is in place before any transfer occurs.

9. Data Subject Rights

9.1 Taking into account the nature of the Processing, AIPTx will assist the Customer by appropriate technical and organisational measures, insofar as possible, in responding to requests to exercise rights of access, rectification, erasure, restriction of Processing, data portability, objection, and rights relating to automated decision-making under Article 22 of the UK GDPR.

9.2 If AIPTx receives a request directly from a Data Subject relating to Personal Data Processed on the Customer's behalf, AIPTx will not respond substantively, and will forward the request to the Customer without undue delay and in any event within 5 business days, unless legally required to respond.

9.3 AIPTx will notify the Customer without undue delay of any complaint or communication from a Supervisory Authority relating to Processing carried out on the Customer's behalf.

10. International Transfers

10.1 AIPTx Processes Personal Data in the locations recorded in Annex I and Annex III. The Services are offered in United States, European Union and Asia-Pacific regions. No United Kingdom region is currently offered, so Personal Data subject to UK GDPR is transferred outside the United Kingdom and clause 10.2 applies.

10.2 Transfers from the United Kingdom. Where Personal Data subject to UK GDPR is transferred outside the United Kingdom to a country not covered by UK adequacy regulations, that transfer is made under:

  • (a) the UK International Data Transfer Agreement (IDTA); or
  • (b) the EU Standard Contractual Clauses as supplemented by the UK Addendum issued by the Information Commissioner under section 119A(1) of the DPA 2018,

in each case completed in accordance with Annex IV, together with any supplementary measures identified as necessary by a transfer risk assessment.

10.3 For the avoidance of doubt, the EU Standard Contractual Clauses alone do not constitute a valid transfer mechanism for Personal Data subject to UK GDPR.

10.4 Transfers from the EEA. Where Personal Data subject to EU GDPR is transferred outside the EEA to a country without an adequacy decision, that transfer is made under the EU SCCs, completed in accordance with Annex IV.

10.5 AIPTx carries out and documents a transfer risk assessment for each restricted transfer, and will make the assessment available to the Customer on reasonable request.

10.6 The transfer instruments identified in Annex IV are incorporated into this DPA and take effect on execution of the Service Agreement, with the Annexes to this DPA populating the corresponding tables, appendices and annexes of those instruments.

10.7 If a transfer mechanism relied on ceases to be valid, AIPTx will implement an alternative lawful mechanism without undue delay, or cease the affected transfer.

11. Government and Law Enforcement Requests

11.1 If AIPTx receives a legally binding request from a public authority, including a law enforcement or national security authority, for disclosure of Personal Data Processed on the Customer's behalf, AIPTx will:

  • (a) notify the Customer of the request without undue delay, so that the Customer may seek a protective order or other relief, unless prohibited from doing so by law;
  • (b) where notification is prohibited, use all reasonable and lawful efforts to obtain a waiver of that prohibition, and document those efforts so they can be shown to the Customer or a Supervisory Authority afterwards;
  • (c) challenge the request where there are reasonable grounds to consider it unlawful, overbroad, or inconsistent with Data Protection Laws or with the obligations in the applicable transfer instrument, including by pursuing available avenues of appeal;
  • (d) disclose only the minimum amount of Personal Data necessary to respond to the request, based on a reasonable interpretation of it; and
  • (e) provide the Customer with a summary of the request and of the data disclosed, as soon as it is lawful to do so.

11.2 AIPTx will maintain a record of all such requests received, and will make aggregate information about them available to the Customer on reasonable request.

11.3 AIPTx warrants that, as at the effective date of this DPA, it has no reason to believe that any law applicable to it or to any Sub-processor prevents it from fulfilling its obligations under this DPA, and it will notify the Customer promptly if that position changes.

11.4 Nothing in this clause requires AIPTx to act unlawfully.

12. Personal Data Breach

12.1 AIPTx will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Personal Data Processed on the Customer's behalf.

12.2 Notification will be given to the Customer's designated security contact recorded in the Customer's account, and where none is recorded, to the Customer's registered administrative contact. The Customer is responsible for keeping that contact current.

12.3 The notification will describe, to the extent known:

  • (a) the nature of the breach, including the categories and approximate number of Data Subjects and records concerned;
  • (b) the name and contact details of AIPTx's data protection contact;
  • (c) the likely consequences of the breach; and
  • (d) the measures taken or proposed to address the breach and mitigate its effects.

12.4 Where the information is not available at the time of notification, it will be provided in phases without undue further delay.

12.5 Responsibility for notifying the ICO. As Controller, the Customer is responsible for assessing whether a Personal Data Breach must be notified to the ICO under Article 33 of the UK GDPR, and for making that notification, and for communicating the breach to Data Subjects under Article 34 where required. AIPTx will provide the Customer with reasonable assistance and the information necessary to make that assessment and any resulting notification. AIPTx will not notify the ICO on the Customer's behalf unless expressly instructed to do so in writing.

12.6 AIPTx will document all Personal Data Breaches, including the facts, effects and remedial action taken, and make that documentation available to the Customer on request.

12.7 AIPTx will cooperate with the Customer in investigating and remediating any Personal Data Breach, and will not make any public statement identifying the Customer without the Customer's prior written consent, unless legally required.

13. Audit Rights

13.1 AIPTx will make available to the Customer information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR.

13.2 On reasonable written notice of at least 30 days, and no more than once in any twelve-month period unless required by a Supervisory Authority or following a Personal Data Breach, the Customer may audit AIPTx's compliance with this DPA.

13.3 AIPTx may satisfy an audit request by providing its current certification reports and supporting documentation, as recorded in Annex II, where these reasonably address the scope of the audit. Reports are made available under NDA.

13.4 Audits must be conducted during business hours, must not unreasonably disrupt AIPTx's operations, must not access other customers' data, and are subject to confidentiality obligations. The Customer bears its own costs and AIPTx's reasonable costs of assistance.

13.5 AIPTx will submit to audit or inspection by a Supervisory Authority where required by Data Protection Laws, and will cooperate with any such audit.

14. Retention, Deletion and Return

14.1 AIPTx retains Personal Data for the term of the Service Agreement and for no longer than necessary for the purposes in clause 3.3.

14.2 On termination or expiry, AIPTx will, at the Customer's election notified in writing within 30 days of termination, delete or return all Personal Data within 30 days of that election and delete existing copies. For complex cases where the deletion or return of Personal Data requires additional technical or operational steps, AIPTx may take up to 60 days to complete the process, subject to applicable UK GDPR requirements, except where retention is required or permitted under clause 14.4 or applicable law.

14.3 Return format. Where the Customer elects return, Personal Data is provided in a structured, commonly used, machine-readable format (JSON or CSV) together with any reports generated during the term in PDF. Where the Customer requires an alternative format, AIPTx will discuss it in good faith and may charge its reasonable costs. If the Customer makes no election within 30 days of termination, AIPTx will delete.

14.4 AIPTx may retain Personal Data to the extent, and for as long as, required by the laws of England and Wales, or by any other law to which AIPTx is subject. Retention on this basis is limited to what the relevant law requires, and the Personal Data remains subject to the measures in Annex II and is not Processed for any other purpose.

14.5 Backups are deleted in accordance with AIPTx's backup rotation schedule, which does not exceed 30 days from the deletion request. Personal Data held in backups is inert pending deletion and is not restored to production except as part of a documented disaster recovery event.

14.6 AIPTx will provide written certification of deletion within 15 business days of the Customer's request.

15. Liability

15.1 Nothing in this DPA or the Service Agreement limits or excludes either party's liability for:

  • (a) death or personal injury caused by negligence;
  • (b) fraud or fraudulent misrepresentation;
  • (c) any liability that cannot lawfully be limited or excluded, including under the Unfair Contract Terms Act 1977 and, where the Customer contracts as a consumer, the Consumer Rights Act 2015.

15.2 Subject to clause 15.1, the liability of each party under this DPA is subject to the limitations and exclusions set out in the Service Agreement, which are governed by the laws of England and Wales. Where the Service Agreement is expressed to be governed by any other law, the limitations and exclusions in it apply to this DPA as if governed by the laws of England and Wales, and nothing in the Service Agreement operates to exclude a liability that cannot lawfully be excluded under clause 15.1.

15.3 The parties acknowledge that under Article 82 of the UK GDPR, a Data Subject may bring a claim against either the Controller or the Processor, and that where both are responsible for the same damage each may be held liable for the entire damage. Where one party has paid full compensation, it is entitled to claim back from the other that part of the compensation corresponding to the other's responsibility for the damage.

15.4 Each party will indemnify the other against fines, penalties and claims arising from its own breach of Data Protection Laws, to the extent of its responsibility, subject to clauses 15.1 and 15.2.

16. General, Term and Termination

16.1 Notices. Notices under this DPA must be in writing and sent to [email protected] in the case of AIPTx, and to the Customer's registered administrative contact in the case of the Customer. Notices sent by email are deemed received on the next business day.

16.2 Assignment. Neither party may assign or transfer this DPA without the other's prior written consent, except that either party may assign to an Affiliate or to a successor in connection with a merger, acquisition or sale of substantially all assets, on written notice.

16.3 Severability. If any provision of this DPA is held invalid or unenforceable, it is severed to the minimum extent necessary and the remainder continues in force. The parties will negotiate in good faith a replacement provision achieving the original intent so far as lawful.

16.4 Variation. Except as provided in clause 19, any variation must be in writing and agreed by both parties.

16.5 Waiver. A failure or delay in exercising a right is not a waiver of it.

16.6 Counterparts. This DPA may be executed in counterparts, including by electronic signature, each of which is an original and which together constitute one agreement.

16.7 Third party rights. Except as expressly provided, a person who is not a party has no right under the Contracts (Rights of Third Parties) Act 1999 to enforce any term of this DPA. This does not affect any right or remedy of a Data Subject under Data Protection Laws or under any transfer instrument.

16.8 Entire agreement. This DPA, together with its Annexes and the Service Agreement, constitutes the entire agreement between the parties in relation to the Processing of Personal Data and supersedes all prior arrangements on that subject.

16.9 Order of precedence. In the event of conflict, the order of precedence is: (a) any applicable transfer instrument under clause 10; (b) this DPA including its Annexes; (c) the Service Agreement.

16.10 Survival. Clauses 6.2 to 6.4, 7.6, 11, 12, 14, 15, 16 and 17 survive termination or expiry of this DPA, together with any other provision which by its nature is intended to survive.

Term and Termination

16.11 Term. This DPA takes effect on the effective date of the Service Agreement, or on the date the Customer first submits Personal Data to the Services if earlier, and continues for as long as AIPTx Processes Personal Data on the Customer's behalf.

16.12 Automatic termination. This DPA terminates automatically on termination or expiry of the Service Agreement, save that the clauses identified in 16.10 continue to apply.

16.13 Termination for breach. Either party may terminate this DPA and the Service Agreement, in whole or in respect of the affected Services, by written notice with immediate effect where the other party:

  • (a) commits a material breach of this DPA which is incapable of remedy;
  • (b) commits a material breach of this DPA which is capable of remedy and fails to remedy it within 30 days of written notice requiring it to do so; or
  • (c) is subject to an insolvency event as defined in the Service Agreement.

16.14 Termination for unlawful instruction. Where AIPTx has notified the Customer under clause 6.1(b) that an instruction infringes Data Protection Laws and the Customer confirms the instruction without amendment, AIPTx may suspend the affected Processing and, if the matter is not resolved within 30 days, terminate the affected Services on written notice, without liability.

16.15 Termination where a transfer mechanism fails. Where a transfer mechanism relied on under clause 10 ceases to be valid and no lawful alternative is available, either party may terminate the affected Services on written notice, in accordance with clause 10.7.

16.16 Termination following a Sub-processor objection. The Customer's right to terminate following an unresolved objection to a Sub-processor is set out in clause 8.5.

16.17 Consequences of termination. On termination:

  • (a) AIPTx will cease Processing Personal Data except as permitted by clause 14.4;
  • (b) Personal Data is deleted or returned in accordance with clause 14;
  • (c) each party returns or destroys the other's confidential information, subject to legal retention requirements; and
  • (d) termination does not affect any right or liability accrued before the termination date.

16.18 No penalty for exercising a data protection termination right. Where the Customer terminates under clause 8.5, 16.14 or 16.15, AIPTx will refund prepaid fees for the terminated Services on a pro-rata basis and will not apply an early termination charge.

17. Governing Law and Jurisdiction

17.1 This DPA is governed by the laws of England and Wales.

17.2 The parties submit to the exclusive jurisdiction of the courts of England and Wales in respect of any dispute arising out of or in connection with this DPA.

17.3 Nothing in this clause affects any right a Data Subject has to bring proceedings, or to lodge a complaint with a Supervisory Authority, under Data Protection Laws.

18. Contact and Registration

Data protection enquiries

Registered office

  • 167-169 Great Portland Street
  • Fifth Floor
  • London, W1W 5PF
  • United Kingdom

Registered in England and Wales.

Your right to complain

You have the right to lodge a complaint with the Information Commissioner's Office, the UK supervisory authority for data protection.

  • Information Commissioner's Office
  • Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
  • Telephone: 0303 123 1113
  • ico.org.uk

19. Changes to this DPA

19.1 AIPTx may update this DPA where necessary to reflect changes in Data Protection Laws, the Services or AIPTx's Processing activities.

19.2 AIPTx will give at least 30 days' notice of any material change, by email to the Customer's registered contact and by notice on this page.

19.3 Termination on material change. Where a change materially reduces the Customer's rights or AIPTx's obligations under this DPA, the Customer may terminate the affected Services by written notice given before the change takes effect. On such termination AIPTx will refund prepaid fees for the terminated Services on a pro-rata basis and will not apply an early termination charge. If the Customer does not give notice before the effective date, the change applies from that date.

19.4 A change made solely to comply with a change in Data Protection Laws, or to reflect a decision or guidance of a Supervisory Authority, takes effect on the date required by that law, decision or guidance, and clause 19.3 does not apply to it.

19.5 Changes to Annex III are governed by clauses 8.4 and 8.5 rather than by this clause.

19.6 A record of previous versions and their effective dates:

VersionEffective dateSummary of changes
2.2To be confirmedArticle 30 record of processing (clause 6.2–6.6); insurance (clause 7.5–7.8); term and termination (clause 16.11–16.18); termination on material change (clause 19.3–19.4)
2.1To be confirmedAnnexes I–IV added; government and law enforcement request clause; Customer warranties; Affiliates; general boilerplate; return format and deletion certificate deadlines; anonymisation reframed; liability cross-jurisdiction patch
2.0To be confirmedUK GDPR and DPA 2018 alignment; UK transfer mechanisms; sub-processor notice and objection rights; DPIA assistance; Article 28(3) notification duty; Special Category Data provisions; UK registered office
1.01 January 2025Initial version

20. Annex I: Description of the Processing

Populates Annex I of the EU SCCs and Tables 2 and 3 of the UK IDTA.

Categories of Data Subject

  • The Customer's personnel, administrators and authorised users of the Services
  • Individuals whose Personal Data is present within, or reachable from, a Target System that the Customer instructs AIPTx to test

Categories of Personal Data

CategoryExamples
Identity and contactName, email address, telephone number
ProfessionalJob title, employer, role, team
Account and authenticationUsernames, hashed account credentials, and credentials supplied for authenticated testing, which are stored encrypted
TechnicalIP addresses, device and browser information, session identifiers, log data
BillingBilling name, address, transaction records
Incidental evidencePersonal Data appearing within captured HTTP requests and responses used to demonstrate a vulnerability

Special Category Data

Not sought, not targeted and not an intended purpose of the Services. Incidental exposure is possible where a Target System holds such data . See clause 5. No categories have been notified under clause 5.3 in respect of this Annex; notifications are recorded per engagement.

Nature and purpose of the Processing

Automated security testing of Target Systems, including reconnaissance, vulnerability discovery, exploit validation, risk prioritisation and reporting; account administration and support; and maintaining the security and availability of the Services.

Frequency of transfer

Continuous, for the duration of the Service Agreement.

Duration of Processing

The term of the Service Agreement, plus the retention period in clause 14.

Retention

DataRetention
Account dataTerm of the account, period to be confirmed
Assessment data, findings and evidencePer the Customer's plan, maximum to be confirmed
Billing and accounting recordsSix years from the end of the relevant financial year, to be confirmed
Security and audit logsTo be confirmed
Backups30 days

Processing locations

The Services are offered in United States, European Union and Asia-Pacific regions, and Personal Data is processed and stored in the region the Customer selects. No United Kingdom region is currently offered. See clause 10.1. The specific data centre locations per region are to be confirmed and recorded here.

Competent Supervisory Authority

The Information Commissioner's Office (United Kingdom).

21. Annex II: Technical and Organisational Measures

Populates Annex II of the EU SCCs and Table 4 of the UK IDTA. These measures are the ones AIPTx publishes and stands behind; where a figure or a named provider has not been settled, the line says so rather than asserting one.

Encryption

  • At rest: AES-256 for databases, object storage and backups
  • In transit: TLS 1.3 with perfect forward secrecy, HTTPS enforced on all endpoints
  • Credentials supplied for authenticated testing: encrypted at rest and access-controlled
  • Separate encryption keys per customer
  • Database encryption with customer-managed keys, on the Enterprise plan
  • Key management: managed KMS, rotation frequency and separation of duties to be confirmed and recorded here.

Access control

  • Multi-factor authentication required for all personnel accessing production systems
  • Role-based access control on a least-privilege basis
  • Access to Customer data limited to personnel who require it to deliver the Services, on a need-to-know basis
  • Access revoked immediately on termination of engagement
  • Access review frequency to be confirmed.

Segregation

  • Logical separation of Customer environments and data with enforced boundaries
  • The separation mechanism is to be described here. It is the first question most enterprise reviewers ask.

Logging and monitoring

  • Access to production systems and Customer data is logged
  • 24/7 security monitoring, alerting and incident response
  • Logs retained for a period to be confirmed

Network and infrastructure security

  • DDoS mitigation and web application firewall at the perimeter
  • Multi-region deployment with automatic failover
  • Hosting provider: SOC 2 compliant cloud providers: Amazon Web Services and Google Cloud Platform

Secure development

  • Mandatory code review before merge
  • Static analysis and dependency scanning in the pipeline; dynamic testing against pre-production
  • Remediation targets by severity: to be confirmed. Critical vulnerabilities are patched within 24 hours.

Personnel

  • Background screening for personnel with production access
  • Contractual confidentiality obligations surviving engagement
  • Security and data protection training at induction and annually thereafter

Business continuity and backup

  • Automated daily backups, retained 30 days, encrypted and geographically distributed
  • Disaster recovery plan with defined recovery time and recovery point objectives
  • Restoration procedures tested at a frequency to be confirmed
  • Documented business continuity and incident response plans; incident response tested at a frequency to be confirmed

Assurance

  • Independent penetration testing annually; summary available under NDA
  • Continuous vulnerability scanning of all systems
  • Continuous internal assessment of AIPTx's own platform using the Services

Certifications

  • SOC 2 Type II: security, availability and confidentiality criteria, audited annually. Report available under NDA.
  • ISO/IEC 27001: certified information security management system.

The certifying body, audit period and ISMS scope statement are to be recorded here. A certification asserted without them is the claim an enterprise reviewer checks first.

Measures for transfers

  • Transfer risk assessment completed for each restricted transfer
  • Supplementary measures applied where identified
  • Government access request handling per clause 11

22. Annex III: Sub-processors

Populates Annex III of the EU SCCs, and is governed by clause 8.

The categories of Sub-processor engaged under clause 8.1 are:

  • Cloud infrastructure and hosting
  • Payment processing
  • Customer support and communications
  • Product analytics

The named register (each Sub-processor, the service it provides, the country in which it Processes and the categories of Personal Data involved) is maintained by AIPTx and provided to Customers on written request to [email protected]. It is not yet published at a public URL. Until it is, notice of changes under clause 8.4 is given by email to the Customer's registered contact, and the objection right in clause 8.5 applies in the same way.

23. Annex IV: Transfer Instruments

How the transfer mechanisms in clause 10 are completed.

For transfers of UK Personal Data

Two routes are available and the choice has not been made. The UK IDTA is a standalone instrument and is simpler where there is no EEA element; the EU SCCs supplemented by the UK Addendum are usually preferable where the same data flows are also subject to EU GDPR, because one set of clauses then serves both. Whichever is selected, Annexes I, II and III of this DPA populate its tables and appendices, and clause 10.2 operates on it.

For transfers of EEA Personal Data

EU SCCs, appropriate module, with Annexes I, II and III of this DPA populating the corresponding SCC annexes. Governing law and forum as required by the SCCs.

Docking clause

Where the Service Agreement permits Customer Affiliates to use the Services, the docking clause in the applicable instrument may be used to add them as parties.