Data Processing Addendum (DPA)
Last updated: 23/07/2026
1. Roles
Customer is the Controller; Cyber Essential Check Ltd is the Processor for personal data submitted to the Service. Where we determine purpose and means (e.g. billing, fraud prevention, aggregate analytics) we act as an independent Controller.
2. Subject-matter, duration and nature
- Subject-matter: providing the Cyber Essentials readiness Service.
- Duration: term of the Customer subscription plus deletion window.
- Nature: hosting, scanning, analysis, storage, evidence generation.
- Categories of data subjects: Customer's staff/administrators; individuals identified in connector metadata.
- Categories of personal data: identifiers, contact data, authentication metadata, device/user counts, OAuth tokens (encrypted), IP addresses.
- No special-category data is required.
3. Processor obligations (Art. 28)
- Process only on documented Customer instructions.
- Ensure staff are under confidentiality.
- Implement Art. 32 technical and organisational measures (see §6).
- Assist with data subject rights, DPIAs and breach notifications.
- Notify Customer of a personal-data breach without undue delay (≤ 72 hours).
- Delete or return personal data at end of the relationship.
- Make information available to demonstrate compliance.
4. Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, auth, storage | EU (Ireland) |
| Cloudflare | Edge compute, WAF, DDoS | Global edge |
| Stripe or Paddle | Payments | EU / UK / US |
| Resend or equivalent | Transactional email | EU / US |
Customer gives general written authorisation to engage sub-processors. We give 30 days' notice of new sub-processors; Customer may terminate the affected Service if they reasonably object.
5. International transfers
Transfers of personal data outside the UK/EEA are covered by the EU Standard Contractual Clauses (Commission Decision 2021/914) and the UK International Data Transfer Addendum (IDTA), together with transfer risk assessments where required.
6. Security (Art. 32)
- TLS 1.2+ in transit; AES-256 at rest.
- OAuth tokens encrypted with AES-256-GCM using a rotated master key.
- Row-level security in the database; least-privilege service roles.
- MFA on all administrative accounts.
- Vulnerability management, patching, dependency scanning.
- Access, audit and change-management logging.
- Business continuity: daily encrypted backups, tested restore.
7. Deletion / return
On termination, Customer may export data for 30 days. Thereafter personal data is deleted from live systems within 30 days and from backups within 90 days, save where retention is required by law.
8. Audit
Customer may audit compliance once per 12 months on 30 days' written notice, at Customer's cost, subject to reasonable confidentiality and security controls. Third-party audit reports (e.g. SOC 2 or ISO 27001) satisfy this obligation where available.
9. Liability and governing law
Liability under this DPA is subject to the caps and exclusions in the main Terms. Governed by the laws of England and Wales.