// LEGAL
Data Processing Agreement
Last updated: 21 June 2026. This DPA forms part of the engagement agreement between Acta Security and each client.
1. Parties and scope
Data Processor: Acta Security, EU ("Acta" or "we").
Data Controller: the client entity identified in the onboarding submission or engagement agreement ("Client" or "you").
This Data Processing Agreement ("DPA") governs all processing of personal data that Acta carries out on behalf of the Client in connection with the delivery of security services. It applies from the point of onboarding and for the duration of the engagement.
2. Subject matter and nature of processing
Acta processes personal data solely to the extent necessary to deliver the agreed security services, which may include:
- Penetration testing, attack surface mapping and vulnerability assessment of assets the Client controls and has authorised us to test.
- Delivery of written reports, findings and remediation guidance via the client portal.
- Virtual CISO (vCISO) advisory — reviewing policies, programmes and governance documentation that may reference individuals.
- Incident response — analysis of logs, artefacts and communications containing personal data to the extent provided by the Client.
3. Categories of data subjects and personal data
Depending on the engagement scope and materials provided by the Client, processing may involve:
- Client personnel: names, email addresses, roles, system access credentials (in scope targets only).
- End users of the Client's systems: authentication artefacts, session tokens, or data incidentally observed during testing — limited to what is technically necessary and removed from deliverables unless explicitly required.
- Third-party data: Acta will not retain personal data of individuals beyond what is required to substantiate a finding. We redact PII from reports wherever its inclusion is not necessary to evidence the vulnerability.
4. Processor obligations
Acta shall:
- Process personal data only on the documented instructions of the Client, including with regard to transfers to third countries.
- Ensure that personnel authorised to process personal data are bound by confidentiality obligations.
- Implement appropriate technical and organisational security measures as set out in Section 7.
- Assist the Client, at the Client's cost, in fulfilling its obligations to respond to data subject rights requests, data protection impact assessments, and supervisory authority consultations.
- Delete or return all personal data upon completion or termination of the engagement, at the Client's choice, within 30 days, and delete existing copies unless EU law requires storage.
- Make available all information necessary to demonstrate compliance with this DPA and allow for audits and inspections — either directly or through an appointed third-party auditor.
- Inform the Client immediately if any instruction infringes the GDPR or applicable data protection law.
5. Sub-processors
Acta uses the following sub-processors. The Client provides general authorisation for their use. Acta will notify the Client of intended additions or replacements, giving the Client the opportunity to object.
| Sub-processor | Country | Safeguard | Purpose |
|---|---|---|---|
| Infomaniak Network SA | Switzerland | EU adequacy decision | Cloud hosting (VMs), email relay (SMTP/IMAP), object storage for file attachments and encrypted backups |
| Gcore Luxembourg S.A. | Luxembourg (EU) | — | Content delivery network (CDN), web application firewall (WAAP), and DDoS protection. All public HTTP traffic passes through Gcore edge nodes; IP addresses, request headers, and User-Agent strings are processed for security and delivery purposes |
| ALTCHA (self-hosted) | EU (Acta infrastructure) | — | Proof-of-work bot-check on the contact form and portal sign-in — challenge generation and verification run entirely on Acta's EU servers; no personal data is sent to any third party |
| Mollie B.V. | Netherlands (EU) | — | Payment processing — Mollie acts as an independent controller for PCI purposes; only the payment reference and buyer email are passed to Acta |
| Bird B.V. | Netherlands (EU) | — | Transactional SMS notifications — phone numbers and message content are passed to Bird only when an SMS is dispatched to a portal user |
| meetergo GmbH | Germany (EU) | — | Appointment booking for discovery and engagement calls — optional; only if a booking is made |
| Sage Group plc | United Kingdom | UK adequacy decision | Accounting and invoicing — client name, email, company name, and purchase details are passed to Sage when an engagement is created following onboarding approval |
| Google LLC (VirusTotal) | USA | SCC | Malware scanning of file uploads — file content is submitted to VirusTotal at upload time to detect malicious content; no copy is retained by Google beyond the scan result |
All sub-processors are bound by data processing agreements at least as protective as this DPA. Acta will notify the Client of any intended additions or replacements with reasonable notice, giving the Client the opportunity to object before the change takes effect.
6. International transfers
Processing takes place primarily within the EU/EEA. Switzerland (Infomaniak) and the United Kingdom (Sage) are covered by European Commission adequacy decisions. Where sub-processors are based outside the EEA (Google LLC/VirusTotal), transfers are made under European Commission Standard Contractual Clauses (SCCs) in accordance with GDPR Article 46(2)(c). A copy of the applicable SCCs is available on request.
7. Security measures
- Encryption in transit: all portal and marketing site traffic is TLS 1.2+ enforced at the CDN edge; no plain-HTTP communication for client data.
- Encryption at rest: SIEM data volumes are LUKS-encrypted; database backups are AES-256 encrypted before upload to object storage; report and attachment storage is access-controlled.
- Authentication: passwordless email OTP for portal client access; SSH key-only access to all infrastructure; sessions carried in signed, HttpOnly cookies.
- Secrets management: all credentials and API keys are stored in OpenStack Barbican and fetched at container runtime — never persisted in configuration files or environment variables on disk.
- Least privilege: each service runs under its own OS user or container with minimal permissions; admin access to the portal is gated by a separate flag from client access.
- Network isolation: the client portal runs on a dedicated VM isolated from the marketing infrastructure; all services bind to loopback or a private network and are proxied via nginx; UFW firewall restricts inbound traffic to Gcore CDN CIDR ranges only, so direct-to-origin access is blocked.
- Edge security: Gcore WAAP enforces OWASP Top Threats, L7 DDoS, and protocol-validation rulesets in front of all public-facing services.
- Intrusion prevention: CrowdSec monitors nginx, SSH, and application logs; confirmed attack signatures result in automatic IP blocking at the iptables (host) and Gcore CDN (edge) layers simultaneously.
- Security monitoring: a dedicated SIEM (Wazuh) aggregates logs from all VMs in real time; custom detection rules cover authentication anomalies, file-integrity changes, and MITRE ATT&CK-aligned patterns; alerts are relayed to on-call personnel by SMS and email.
- Vulnerability scanning: Trivy performs daily automated scans of all container images; critical findings block deployment via CI gate; Ubuntu Pro / Landscape manages OS-level patch compliance across all VMs.
- Backup and recovery: encrypted database backups run nightly (01:00 UTC) to EU-resident object storage; SIEM configuration and indices are snapshotted nightly (02:00 UTC); restore procedures are documented and periodically tested.
- Log retention and purge: security and access logs are retained for 90 days and then automatically purged via an index lifecycle management policy.
- File upload safety: all user-uploaded files are subjected to VirusTotal malware scanning; MIME-type validation and magic-byte checks are applied before storage; rejected files are never written to persistent storage.
8. Personal data breach notification
Acta shall notify the Client without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting Client data. Notification will be made to the contact email on record and will include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed. Acta will cooperate fully in any required supervisory authority notification.
9. Duration and termination
This DPA applies for the duration of the engagement and any retention period thereafter. On expiry or termination, Acta will securely delete or return all personal data within 30 days unless a longer retention period is required by EU law, in which case Acta will protect the data and limit processing to what is legally required.
10. Governing law
This DPA is governed by the laws of the European Union. Disputes arising in connection with this DPA are subject to the exclusive jurisdiction of the competent EU courts, without prejudice to the Client's right to lodge a complaint with its local data protection supervisory authority.
11. Contact
Questions about this DPA or data protection matters: privacy@actasecurity.eu.