Talsec logo

DATA PROCESSING AGREEMENT

This Data Processing Agreement ("Agreement") forms part of the General Terms and Conditions ("Terms") between:
Processor
Lynx SFT s.r.o.
Incorporated and organized under laws of the Czech Republic
ID number (IČO): 19490259
Registered office: Za Dvorem 505, Štípa, 763 14 Zlín, Czech Republic
Represented by
Name: Sergiy Yakymchuk, Managing Director
Contact e-mail: info@talsec.app
Phone: +420 731 196 750
(hereinafter referred to as “Processor“)
Controller
The legal entity or individual who has registered for, accessed, or used the Provider’s Software or Services (including freeRASP) and has accepted the General Terms and Conditions.
(hereinafter referred to as "Controller" or "Company")

(together as the "Parties")

1. SCOPE AND APPLICABILITY
This Agreement applies to the processing of personal data by the Processor on behalf of the Controller to provide the services outlined in the Terms. It complies with the Regulation (EU) 2016/679 (GDPR) and accommodates global data privacy standards for non-EU customers.
‍
2. PROCESSING OF PERSONAL DATA
Compliance & Instructions: The Processor shall comply with all applicable Data Protection Laws and process Personal Data only on the documented instructions of the Controller.
Details of Processing: The subject-matter, nature, and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex A (Description of Processing).
Unlawful Instructions: The Processor shall immediately inform the Controller if, in its opinion, an instruction for the processing of personal data infringes the GDPR or other applicable Union or Member State data protection provisions.

3. PROCESSOR PERSONNEL AND SECURITY
Confidentiality: The Processor shall ensure that all personnel authorized to process the data are subject to strict confidentiality undertakings.
Security Measures: The Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk. The specific measures currently implemented by the Processor are described in Annex B (Technical and Organizational Measures).
‍
4. SUB-PROCESSING
General Authorization: The Controller grants a general written authorization for the Processor to engage sub-processors. The Processor shall ensure that any engaged sub-processor is subject to the same data protection obligations as set out in this Agreement.
Notice Period: The Processor must notify the Controller at least seven (7) days prior to the engagement or change of any sub-processor, giving the Controller the opportunity to object.
Current Sub-processors: The list of sub-processors authorized as of the effective date of this Agreement is set out in Annex C (List of Sub-processors).

5. DATA SUBJECT RIGHTS AND BREACHES
Assistance: The Processor will assist the Controller through appropriate technical and organizational measures to respond to Data Subject requests.
Breach Notification: The Processor shall notify the Controller without undue delay upon becoming aware of a Personal Data Breach affecting the Controller's data. The Processor will take reasonable commercial steps to assist in investigating and mitigating the breach.
DPIA Assistance: The Processor shall provide reasonable assistance to the Controller with any data protection impact assessments and prior consultations with competent data privacy authorities, as required by Article 35 or 36 of the GDPR, taking into account the nature of the processing and information available to the Processor.
Supervisory Authorities: The Processor shall cooperate, on request, with supervisory authorities and shall immediately inform the Controller of any inspections or measures executed by a supervisory authority that relate to the processing of the Controller's data.

6. INTERNATIONAL DATA TRANSFERS (STANDARD CONTRACTUAL CLAUSES)
To ensure data is adequately protected when transferred outside the European Economic Area (EEA), the Parties enter into the Standard Contractual Clauses (SCCs) (Module 2: Transfer controller to processor). The Parties adopt the SCCs as set by the Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
SCC Modalities:
- Clause 7 (Docking clause): The optional docking clause is included.
- Clause 9 (Use of sub-processors): Option 2 (General written authorisation) applies. The Processor shall notify the Controller at least seven (7) days prior to the engagement or change of any sub-processor.
- Clause 11 (Redress): The optional language regarding independent dispute resolution is omitted.
- Clause 17 (Governing law): Option 1 applies. The SCCs shall be governed by the laws of the Czech Republic.
- Clause 18 (Choice of forum and jurisdiction): Any dispute arising from these Clauses shall be resolved by the courts of the Czech Republic. (Note: This applies specifically to data subject rights and regulatory matters under the SCCs; general commercial disputes between the Parties remain subject to arbitration in Vienna as per Section 8).
- SCC Annexes: For the purposes of the SCCs, Annex A, Annex B, and Annex C of this Agreement shall serve as Annex I, Annex II, and Annex III of the SCCs, respectively.

7. DELETION OF DATA AND AUDITS
Deletion or Return: Subject to the Controller's choice, the Processor shall promptly and in any event within 10 business days of the cessation of services, delete or return all copies of the Personal Data to the Controller, and provide written certification of this upon request, unless Union or Member State law requires storage of the personal data.
Audit Rights: The Processor shall make available all necessary information to demonstrate compliance and allow for audits conducted by the Controller or an independent auditor.

8. GENERAL PROVISIONS
Confidentiality: Both parties must keep this Agreement and related business information confidential unless disclosure is required by law.
Governing Law: This Agreement and any dispute or claim arising out of or in connection with it or its subject matter or formation shall be governed by and construed in accordance with the laws of the Czech Republic, excluding its conflicts of law rules.
Dispute Resolution: Any dispute, controversy, or claim arising under, out of, or relating to this Agreement and any subsequent amendments of this Agreement, including, without limitation, its formation, validity, binding effect, interpretation, performance, breach or termination, as well as non-contractual claims, shall be referred to and finally determined by arbitration in accordance with the rules of an arbitration centre in Vienna, Austria (such as the Vienna International Arbitral Centre - VIAC). The language to be used in the arbitral proceedings shall be English.
Execution: This Agreement is incorporated by reference into the Terms. By accessing or using the Software or Services, the Controller automatically accepts and agrees to be bound by the terms of this DPA. No physical or digital signature is required.

9. APPENDICES
ANNEX A: DESCRIPTION OF PROCESSING
ANNEX B: TECHNICAL AND ORGANIZATIONAL MEASURES (TOMS)
ANNEX C: LIST OF SUB-PROCESSORS

ANNEX A: DESCRIPTION OF PROCESSING

(This Annex serves as Annex I to the SCCs, where applicable)
‍
A.1 Identification of Parties
The details of the Data Controller and Data Processor, including their relevant contact persons, are as set out in the preamble of this Agreement.
‍
A.2 Scope and Configuration of Data Processing
The Controller authorizes the Processor to process personal data strictly under the following configuration:
- Service: Security Insights (Talsec freeRASP SDK)
- Data Subjects: End-Users of the Controller's applications.
- Personal Data: Email Addresses, IP Addresses, Anonymous App Instance IDs, Anonymous Device Identifiers, and Technical Diagnostics Information (e.g., Root/JB info, App Integrity signals).
- Purpose: Collecting and visualizing security insights; fraud prevention; technical support; and data analytics to improve the product.
- Deployment Model: Processor-Hosted (Cloud).  The Processor hosts the data utilizing authorized cloud sub-processors.
- Retention Period: Diagnostic and aggregated-event records received from end-user devices are retained by the Processor for a period of 12 months before being permanently deleted or irreversibly anonymized.
- Duration of Processing: Data will be processed for the duration of the Terms, unless agreed otherwise.

ANNEX B: TECHNICAL AND ORGANIZATIONAL MEASURES (TOMS)

(This Annex serves as Annex II to the SCCs, where applicable)

Description of the technical and organizational measures implemented by the Processor to ensure an appropriate level of security, taking into account the nature, scope, context, and purpose of the processing:

Information Security Standards: Internal security processes, policies, and controls are strictly based on OWASP guidelines and are implemented in accordance with the ISO 27001 standard.

Access Control: Access to personal data is protected by robust authentication methods and is strictly limited only to authorized employees required to fulfill the purposes of this Agreement.

Data Encryption: All personal data processed by the Processor is encrypted in transit over public networks using HTTPS/TLS 1.2 or higher. Furthermore, data stored at rest on the Processor's infrastructure is encrypted using industry-standard methods (e.g., AES-256).

Infrastructure & Physical Security: Data is stored securely on the Processor's cloud infrastructure. The Processor relies on the rigorous, industry-certified physical security measures (e.g., SOC 2, ISO 27001) of its cloud sub-processors as listed in Annex C.

Data Residency: All primary databases, backups, and logs containing personal data processed under this Agreement shall remain strictly localized within the jurisdictions of the authorized sub-processors listed in Annex C.

ANNEX C: LIST OF SUB-PROCESSORS

(This Annex serves as Annex III to the SCCs, where applicable)

The Controller grants a general written authorization to engage the following sub-processors to deliver the cloud-hosted services:
- Google Cloud Platform
- Purpose: Cloud infrastructure, backend hosting, and data storage.
- Location: EU
- Cloudflare
- Purpose: Cloud infrastructure, proxy for log forwarding.
- Location: Anywhere
- Elasticsearch
- Purpose: Temporary log collection (1 week) for backup purposes and quick analytics..
- Location: US
- Sendgrid
- Purpose: Email delivery for watcherMail reports.
- Location: US

.