LEGAL · DATA PROCESSING AGREEMENT
Data Processing Agreement
Part of the Terms when we process personal data for you.
Version: 2026-09-15.
Forms part of the Terms of Service when Vantuz processes personal data on the Customer's behalf.
This DPA is between the Customer ("Controller") and Vantuz Ltd ("Processor"), 71-75 Shelton Street, Covent Garden, London WC2H 9JQ.
1. Roles and scope
For security telemetry generated within the Customer's workspace, and for the Exposure Sonar's findings, evidence and any data about the Customer's personnel, the Customer is the Controller and Vantuz is the Processor, processing only on the Customer's documented instructions (these Terms, the platform configuration, and any written instruction). Verifying a domain, recording consent, choosing which checks and connections are enabled, and acknowledging staff processing are documented instructions. For Vantuz's own account/billing data, its records of the Customer's authorisation, operator access records, and aggregated service-quality statistics that identify no workspace, Vantuz is an independent controller (see Privacy Policy).
2. Subject matter and duration
Subject matter: detection-by-deception security monitoring, and exposure checking of assets the Customer has proven it controls (the Exposure Sonar). Duration: for the term of the Customer's subscription plus any retention period in Section 11.
3. Nature and purpose of processing
Capturing, enriching, scoring, alerting on and (where enabled) containing access to the Customer's honeytokens.
Exposure checking: sending read-only requests to hosts under domains the Customer has proven it controls; where the Customer connects them, reading its own identity directory and cloud configuration read-only; storing findings and the redacted, encrypted evidence that proves them; recommending fixes; creating tripwires the Customer accepts; notifying the Customer of changes; and deleting all of it on schedule.
4. Types of personal data
Source IP addresses, user agents, request metadata, IP-derived enrichment (geolocation, ASN, reputation), and incident metadata.
Exposure Sonar: hostnames (which may contain a person's name); personal data incidentally contained in redacted evidence of an exposure; and, where the Customer enables it, account identifiers, admin-role membership, two-step verification status, permitted sign-in methods, last sign-in time of accounts, and the fact that an email address at the Customer's domain appears in a known third-party breach (never a password or a hash of one). Vantuz does not read mailbox content, files, chat or calendars.
No special-category data is intentionally processed.
5. Categories of data subjects
Individuals who access a Customer's honeytokens (typically attackers or unauthorised actors); the Customer's own authorised users; the Customer's personnel whose accounts or addresses are covered by checks the Customer enables; and individuals whose data the Customer has published by accident on its own internet-facing hosts.
6. Processor obligations
Vantuz will:
- process only on the Controller's documented instructions, including for transfers, unless required by law (and will notify unless prohibited), and inform the Controller if, in its opinion, an instruction infringes data protection law;
- ensure persons authorised to process are bound by confidentiality;
- implement appropriate technical and organisational measures (Section 9);
- engage sub-processors only under Section 7;
- assist the Controller, taking into account the nature of processing, with data-subject requests and with Articles 32–36 (security, breach notification, DPIAs);
- notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal-data breach affecting the Controller's data, with the information then available (nature of the breach, categories and approximate number of data subjects and records, likely consequences, measures taken or proposed), and supplement it as more becomes known. Notifying is not an admission of fault;
- at the Controller's choice, delete or return personal data at the end of the service and delete existing copies unless retention is required by law.
7. Sub-processors
The Controller gives general authorisation for Vantuz to use the sub-processors named in the sub-processor list in the Privacy Policy (Section 3), which forms part of this DPA. Vantuz will:
- impose on each sub-processor, by contract, data-protection obligations no less protective than this DPA;
- give the Controller at least 30 days' notice of any intended addition or replacement, by email and in the product;
- if the Controller objects on reasonable data-protection grounds within that period, discuss the objection in good faith. If it is not resolved, the Controller may terminate the affected service before the change takes effect and receive a pro-rata refund of prepaid fees for the unused period. That is the Controller's remedy for an unresolved objection;
- remain liable to the Controller for its sub-processors' performance of their data-protection obligations, as Article 28(4) requires, subject to Section 12.
8. International transfers
Core processing and storage of security telemetry takes place within the UK/EEA (EU-region hosting and database). Limited transfers outside the UK/EEA occur for AI narrative generation (Anthropic), IP-reputation enrichment (VirusTotal, AbuseIPDB, Shodan), and — where the Controller has enabled exposure checking and verified ownership of the assets — lookups of the Controller's own domains and hostnames against those providers, public Certificate Transparency logs, and breach-exposure data providers. Transfers are confined to the minimum data necessary. For incident enrichment that is the source IP address which is itself the subject of the lookup. For exposure checking it is the Controller's own verified domain and hostnames; the response may include personal data relating to the Controller's personnel (for example, an email address at the Controller's domain appearing in a known third-party breach), which is subject to the retention ceiling in Section 11. For these transfers Vantuz relies on appropriate safeguards — the UK International Data Transfer Agreement/Addendum and/or EU Standard Contractual Clauses incorporated into the relevant sub-processor's data-processing terms.
Where Vantuz reads public Certificate Transparency logs itself, no Customer data is transferred for that purpose. Providers used for exposure checking that are not yet enabled will be added to the sub-processor list, with notice under Section 7, before they process any Customer data.
9. Security measures
Encryption in transit (TLS) and at rest (AES-256-GCM for integration credentials); strict tenant isolation enforced at application and database (RLS) layers; least-privilege access; signed JWT authentication with optional TOTP MFA; signed webhooks; audit logging; sensitive-header stripping; secret redaction in logs; and regular security testing.
9A. Additional commitments for the Exposure Sonar
- Possession before processing. Vantuz contacts only hosts under a domain the Customer has proven it controls, re-proves that possession before it lapses, and stops when it lapses.
- Read-only. Checks send only read requests, at a deliberately limited rate, and connected accounts are used through clients that cannot express a write or read content (mail, files, chat, secret values).
- Staff data needs the Customer's acknowledgement. Checks that process data about the Customer's personnel do not run until the Customer confirms it has informed them; Vantuz provides wording for that notice. The Customer remains responsible for any consultation duty towards its personnel or their representatives.
- No default staff access. Vantuz personnel access the Customer's exposure data only under a written, time-limited grant for a stated reason; every access is logged before it happens and the log is available to the Customer.
- Erasure is not undone. An instruction to stop processing data about an individual is applied before any write in later checks and does not expire.
- Deletion with proof. At the end of the service, or on the Customer's instruction, Vantuz deletes the Customer's data, destroys the key that encrypts its evidence, and provides a deletion receipt recording what was deleted. Backups age out on the database provider's schedule; the evidence in them remains encrypted.
- Mistakes are corrected and disclosed. If Vantuz determines a finding was wrong, it withdraws it and tells the Customer.
- No AI processing of Exposure Sonar data.
10. Audit
Vantuz will make available to the Controller the information necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits, including inspections, by the Controller or an independent auditor it mandates.
To keep audits proportionate for both parties:
- Vantuz will first answer written questions and provide its security documentation and any available third-party reports or certifications. An inspection takes place only if that information is reasonably insufficient to demonstrate compliance, or if a supervisory authority requires it, or after a personal-data breach affecting the Controller;
- inspections require at least 30 days' written notice, take place during business hours, no more than once in any 12 months (except as just stated), and are limited to Vantuz's systems and records that relate to the Controller;
- auditors must be bound by confidentiality and must not be a competitor of Vantuz;
- each party bears its own costs, except that the Controller pays Vantuz's reasonable time for an inspection beyond one business day, unless the audit reveals a material breach by Vantuz.
Nothing in this Section limits the rights of a supervisory authority.
10A. The Controller's responsibilities
The Controller is responsible, as controller, for:
- having a lawful basis for the processing it instructs, and for the accuracy and lawfulness of the data it provides;
- informing individuals as data protection law requires, including its personnel before enabling checks that involve them (Vantuz provides wording, which the Controller adapts to its circumstances);
- any consultation with, or approval by, a works council, staff representatives or supervisory authority that its law requires (for example in Germany or the Netherlands) before enabling such checks;
- deploying decoys and choosing checks so that they protect systems and do not target individuals;
- responding to data-subject requests, with Vantuz's assistance under Section 6;
- its own notifications to supervisory authorities and individuals after a breach.
Vantuz may rely on the Controller's instructions and confirmations given in the product.
11. Retention
Retention follows the per-class table published in the Privacy Policy, Section 4, which forms part of this DPA. Each period there is a maximum, and an absolute ceiling applies even where a matter remains open.
Two classes carry a ceiling that no active matter and no legal hold may extend: raw evidence captured to prove a finding (30 days) and personal data relating to the Controller's personnel (12 months). This is a deliberate limit on Vantuz, not a limit on the Controller: it means Vantuz cannot accumulate an indefinite record of the Controller's weaknesses or of identifiable individuals.
The Controller may instruct a shorter period. A longer period applies only where required for an active security or legal matter or by law, and never beyond the ceilings above.
12. Liability
12.1 Each party's liability arising out of or in connection with this DPA is subject to the exclusions, limits and cap in Section 12 of the Terms of Service, which apply to this DPA and the Terms together and not separately. That includes Vantuz's liability for its sub-processors.
12.2 Vantuz does not indemnify the Controller against fines or penalties imposed by a supervisory authority on the Controller.
12.3 Nothing in this DPA limits either party's liability to data subjects under Article 82, or the rights of a supervisory authority. As between the parties, each bears the part of any compensation paid to a data subject that corresponds to its share of responsibility for the damage (Article 82(5)).
12.4 If this DPA and the Terms conflict on a data protection matter, this DPA prevails.
13. Acceptance
This DPA is accepted together with the Terms of Service, and Vantuz keeps the record of that acceptance. A Controller that needs a countersigned copy can request one at legal@vantuz.co; the terms are the same.