Legal

Data Processing Agreement

Last updated June 16, 2026

This DPA describes how SecNxt processes personal data on behalf of our customers (controllers) and supplements our Terms of Service. A signed counterpart is available for enterprise customers on request.

1. Roles

When you use SecNxt, you (the customer) act as the data controller and SecNxt acts as the data processor for personal data contained in your account, targets, and scan results. We process such data only on your documented instructions.

2. Scope and purpose of processing

We process personal data solely to provide the platform: running scans, generating findings, operating your console, and supporting your account. We do not use customer personal data for advertising and do not sell it.

3. Security measures

We maintain technical and organizational measures appropriate to the risk, including encryption in transit and at rest, role-based access controls, row-level security isolating each workspace, logging, and least-privilege access for staff.

4. Subprocessors

You authorize us to engage subprocessors to deliver the service, listed on our Subprocessor page. We impose data-protection obligations on subprocessors no less protective than this DPA and remain responsible for their performance.

5. Data subject rights & assistance

We will assist you, taking into account the nature of processing, in responding to requests from data subjects and in meeting your obligations regarding security, breach notification, and impact assessments.

6. International transfers

Where personal data is transferred across borders, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms recognized under applicable law, including India's DPDP Act 2023 and the GDPR.

7. Breach notification

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide information reasonably necessary for you to meet your notification obligations.

8. Return and deletion

On termination, we will delete or return customer personal data in accordance with our retention practices, except where retention is required by law. To request a signed DPA, contact us via the Contact page.