Version 2.4 · Last updated: 20 May 2026 · Effective: 15 June 2026
This Data Processing Addendum ("DPA") supplements the Master Services Agreement, any SOW, and our Terms of Service (collectively, the "Agreement") between SentinelForge Security, Inc. ("Processor") and the Client identified in the Agreement ("Controller").
It applies whenever the Processor processes Personal Data on behalf of the Controller in the course of providing Services.
Terms used in this DPA have the meanings set out in Article 4 of the EU General Data Protection Regulation (2016/679) ("GDPR") and the equivalent provisions of the UK GDPR and Data Protection Act 2018. In particular: "Personal Data", "Processing", "Controller", "Processor", "Sub-processor", "Data Subject", "Supervisory Authority", and "Personal Data Breach" have those meanings.
"Applicable Data Protection Law" means, as applicable to a given Processing, the GDPR, UK GDPR, Swiss Federal Act on Data Protection, California CPRA, Colorado CPA, Virginia VCDPA, and any similar comprehensive privacy law.
The parties agree that in relation to the Personal Data described below, the Controller is the controller and the Processor is a processor (or, under the CPRA, a service provider).
Provision of offensive-security services (penetration testing, code review, red teaming, threat modeling, incident response) as set out in the applicable SOW.
The Processing continues for the duration of the engagement plus the retention period in section 11, unless a longer retention is required by law.
Testing, analysis, and evaluation of Controller's systems for security vulnerabilities. Personal Data is Processed only to the extent necessary to execute the Services and produce the Deliverables.
The types of Personal Data Processed depend on the in-scope systems and typically include: names, contact details, account identifiers, IP addresses, authentication tokens, session data, log entries, and any Personal Data incidentally exposed by a vulnerability. The Processor takes reasonable steps to minimize Personal Data collected during testing.
By default, Special Categories of Personal Data (GDPR Art. 9) and criminal-offense data (Art. 10) are not intentionally Processed. Where in-scope systems contain such categories (e.g., healthcare Clients), additional safeguards are described in the SOW.
The Processor will:
The Controller grants a general authorization for the Processor to engage sub-processors, subject to the following conditions:
The Processor will, taking into account the nature of the Processing, assist the Controller by appropriate technical and organizational measures to fulfil the Controller's obligations to respond to Data Subject requests. If the Processor receives a request directly from a Data Subject, it will not respond substantively (except to acknowledge receipt) and will forward the request to the Controller without undue delay.
The Processor implements the technical and organizational measures described in Annex B. Controller acknowledges these measures are appropriate for the Processing, given the nature, scope, context, and purposes of the Services and the risk to Data Subjects. The Processor may update the measures over time provided the updates do not materially reduce the level of protection.
The Processor will notify the Controller of a Personal Data Breach affecting the Controller's Personal Data without undue delay and in any case within 48 hours of becoming aware, and provide:
The Processor will cooperate with the Controller's own breach-notification obligations to Supervisory Authorities and Data Subjects.
The Processor will not transfer Personal Data outside the EEA, UK, or Switzerland unless it ensures an adequate level of protection through:
Where the SCCs apply, the parties agree: for Module Two (Controller-to-Processor), Clause 7 (docking) applies; Clause 9(a) Option 2 with 30-day notice applies; Clause 11(a) optional independent-dispute language does not apply; Clause 17 Option 1 with governing law of Ireland applies (EU) / England & Wales (UK); Clause 18 forum is Ireland (EU) / England & Wales (UK); Annexes I, II, and III are as set out in this DPA and its Annexes.
The Processor makes available to the Controller, on written request no more than once per year:
If, after reviewing those documents, the Controller has a legitimate concern that cannot be resolved, the Controller may conduct or authorize an audit on 30 days' written notice, during business hours, at the Controller's expense, subject to reasonable confidentiality and safety controls, and no more than once every 24 months (unless required by law or a Supervisory Authority, or in response to a Personal Data Breach).
On expiry or termination of the Services and after the retention period stated in the SOW (default 90 days after Deliverable acceptance), the Processor will, at the Controller's choice, return or securely delete all Personal Data and delete existing copies unless retention is required by law. Deletion is performed by cryptographic erasure of the storage volume and confirmed in writing on request.
This DPA supersedes any prior DPA between the parties. In case of conflict, the following order applies: (1) the SCCs (where they apply and to the extent of the conflict), (2) this DPA, (3) the Terms of Service, (4) the MSA, (5) the SOW.
This DPA takes effect on the effective date of the underlying Agreement and continues until the Processor has ceased Processing Controller Personal Data.
As of the effective date of this DPA:
| Sub-processor | Service | Location | Transfer mechanism |
|---|---|---|---|
| Amazon Web Services, Inc. | Hosting of engagement data and internal systems | US-West-2 (Oregon) or EU-West-1 (Ireland) at Controller's election | Adequacy (EU→UK), SCCs (Ireland→US intra-AWS) |
| Cloudflare, Inc. | CDN, WAF, DNS for our website | Global (EU POPs prioritized for EU traffic) | SCCs / UK IDTA |
| Google LLC (Workspace) | Email, docs, calendar for staff | US and EU regions | SCCs / EU-US DPF |
| Atlassian, Inc. (Jira) | Engagement tracking | EU-Central-1 | SCCs |
| Slack Technologies, LLC | Client-shared engagement channels | US and EU regions | SCCs / EU-US DPF |
| 1Password, LLC | Secret storage for delivery staff | Canada | Adequacy (EU→Canada) |
| Stripe, Inc. | Client invoicing and payment | US, Ireland | SCCs / EU-US DPF |
| Sentry, Inc. | Error monitoring for internal tools | US-East-1 | SCCs |
These measures form the appropriate technical and organizational measures pursuant to Art. 32 GDPR.