Trust & Compliance
Data Processing Agreement (Public Template, Version 1.0)
Markdown version below for reference / search / accessibility. Counter-signed copies on Controller's paper available via [email protected].
This Data Processing Agreement (the “DPA”) forms part of the agreement between IntegSec LLC (“Processor”) and you (the “Controller”) for use of TurboPentest. It applies whenever Processor processes Personal Data on Controller's behalf in connection with the Service. This DPA is effective as of 2026-05-03.
To request a counter-signed copy on your paper, email [email protected] with your entity name and signatory.
1. Definitions
Capitalized terms used in this DPA have the meanings given to them in Article 4 of Regulation (EU) 2016/679 (“GDPR”), including without limitation:
- “Controller” - the natural or legal person which determines the purposes and means of the Processing of Personal Data.
- “Processor” - the natural or legal person which Processes Personal Data on behalf of the Controller.
- “Personal Data” - any information relating to an identified or identifiable natural person.
- “Processing” - any operation or set of operations performed on Personal Data, whether or not by automated means.
- “Data Subject” - the identified or identifiable natural person to whom Personal Data relates.
- “Sub-processor” - any third-party processor engaged by Processor to Process Personal Data on behalf of Controller.
- “Supervisory Authority” - an independent public authority established by a Member State pursuant to GDPR Article 51, or the equivalent authority under applicable data protection law.
Where the Controller is subject to UK GDPR, CCPA/CPRA, the Swiss FADP, or other applicable data protection law, equivalent terms in those regimes carry equivalent meaning.
2. Subject matter and duration
Processor Processes Personal Data only to provide the Service to the Controller, for the duration of the underlying agreement between the parties, plus a 90-day post-termination retention period (consistent with the retention statements at /for/auditors and /subprocessors).
3. Nature and purpose of processing
Processing types: collection, storage, organization, structuring, retrieval, consultation, use, transmission, restriction, erasure, and destruction.
Purpose:delivering AI-driven penetration testing of Controller's specified targets, generating findings reports, and supporting customer success.
4. Categories of data and data subjects
Personal Data categories (typical)
- Customer account data: name, work email, organization name, role/title.
- Authentication data: hashed credentials, OAuth tokens (where Controller authorizes).
- Operational data: IP addresses, browser identifiers, session tokens.
- Pentest-related data: target URLs/domains specified by Controller, source code if Controller connects a repository, and findings produced by the Service.
Data subjects
- Controller's authorized users of the Service.
- Individuals whose data may incidentally appear in pentest scope (e.g., test accounts on Controller's target environment).
5. Sub-processors
Processor uses the sub-processors listed at /subprocessors. Controller authorizes Processor to engage these sub-processors. Processor will provide notice of any new sub-processors at least 14 days before granting them access to Personal Data, via email to administrators of record. Controller may object in writing to a new sub-processor; if Processor cannot reasonably accommodate the objection, Controller may terminate the affected portion of the Service.
6. Security measures
Processor will implement appropriate technical and organizational measures designed to protect Personal Data, including:
- Encryption in transit (TLS 1.2+) and at rest.
- Role-based access control with least-privilege defaults.
- Quarterly third-party penetration testing of the platform itself.
- Logging and monitoring of access to Personal Data.
- Secure software development practices.
- Vendor security review and ongoing monitoring of sub-processors.
- Annual security training for personnel.
- Vulnerability management program covering the platform and infrastructure.
The full security program is documented at /security and the controls catalog at trust.integsec.com.
7. Personnel confidentiality
Processor ensures that personnel authorized to Process Personal Data are bound by confidentiality obligations.
8. Data subject rights assistance
Processor will assist Controller, taking into account the nature of Processing, in fulfilling Controller's obligations to respond to Data Subject rights requests under applicable data protection laws (access, rectification, erasure, restriction, portability, objection). Processor will direct any Data Subject requests received directly to Controller.
9. Personal Data breach notification
Processor will notify Controller without undue delay (and in any case within 72 hours) after becoming aware of a Personal Data breach affecting Controller's data, providing all information reasonably required to fulfill Controller's notification obligations.
10. Deletion and return of Personal Data
On termination of the Service, at Controller's choice, Processor will delete or return all Personal Data within 90 days, except to the extent retention is required by applicable law. Backup deletion follows Processor's documented retention schedule.
11. Audits and information
Processor will make available to Controller the information necessary to demonstrate compliance with this DPA. Processor's published security and compliance documentation (including /security, /compliance/methodology, trust.integsec.com) constitutes the primary audit information. Controller may request a security questionnaire response or a summary of Processor's most recent third-party pentest report (NDA may be required).
12. International transfers
Where Processor transfers Personal Data outside the European Economic Area, the United Kingdom, or Switzerland to a country not deemed adequate, the parties agree the transfer shall be governed by:
- The European Commission's Standard Contractual Clauses (SCCs), Module Two (Controller-to-Processor), incorporated by reference, with the parties as defined in this DPA.
- The UK International Data Transfer Addendum (IDTA) where the UK is the originating jurisdiction.
- The Swiss Federal Data Protection Act amendments where Switzerland is the originating jurisdiction.
The optional clauses of the SCCs that apply are: docking clause (Clause 7) - yes; redress (Clause 11) optional language - included; governing law (Clause 17) - Delaware where permitted, otherwise the law of the originating Member State.
13. Liability
Liability under this DPA is governed by the limitations and exclusions set forth in the underlying agreement between the parties.
14. Order of precedence
If there is any conflict between this DPA and the underlying agreement, this DPA prevails as to data protection matters.
15. Governing law
This DPA is governed by the laws of the State of Delaware, USA, except as superseded by mandatory applicable law (e.g., GDPR for Processing of EEA Personal Data).
16. Contact
- Data protection matters: [email protected]
- Phone: +1 (207) 200-3288
- Address: IntegSec LLC, 5305 Limestone Road, Suite 200, Wilmington, DE 19808
Status:Public template. To request a counter-signed copy on Controller's paper or with negotiated changes, email [email protected].
Version: 1.0 - initial public publication 2026-05-03.