CybAura
DRAFT — PENDING LEGAL REVIEW — NOT FOR PUBLIC USE UNTIL REVIEWED BY COUNSELThis document has been generated as a starting point and has not yet been reviewed by a qualified solicitor. It must not be shown to customers or published on any public-facing page until legal review is complete.

Data Processing Agreement

Last updated: [DATE]  ·  Effective: [DATE]

This Data Processing Agreement (“DPA”) is entered into between CybAura Ltd (“Processor”) and the Customer who has agreed to CybAura’s Terms of Service (“Controller”), and forms part of those Terms. It is intended to satisfy the requirements of GDPR Article 28 and the UK GDPR equivalent.

1. Subject Matter and Duration

Subject matter:
The processing of personal data by CybAura as Processor on behalf of the Customer as Controller in connection with the provision of the CybAura cybersecurity management platform.
Duration:
This DPA applies for the term of the Customer’s subscription plus the post-termination period during which CybAura retains Customer Data pending deletion (up to 30 days following termination).

2. Nature and Purpose of Processing

The Processor will process personal data for the following purposes on behalf of the Controller:

  • Hosting and storing Customer Data on infrastructure managed by CybAura
  • Running AI agent analysis over Customer Data to provide security recommendations, compliance assessments, and risk scoring
  • Processing employee training records for the Awareness Training module
  • Processing data subject request information for the Privacy/DSAR module
  • Generating security and compliance reports on the Controller’s behalf
  • Sending automated notifications and alerts to authorised Users on behalf of the Controller
  • Providing customer support access to data where explicitly authorised by the Controller

3. Types of Personal Data

The personal data processed under this DPA may include, depending on how the Controller uses the platform:

  • Employee and contractor names, work email addresses, job titles, and department information
  • Employee training completion records, assessment scores, and certification status
  • Data subject request (DSAR) information: requester name, contact details, request type, and processing status
  • Security incident reports that may reference specific individuals, user accounts, or devices
  • Vulnerability data associated with specific accounts, endpoints, or user actions
  • Phishing simulation results, including individual participation and click-through data
  • Any other personal data the Controller chooses to upload to the platform

The Controller is responsible for ensuring that any special category data or criminal offence data is only uploaded where there is a valid legal basis and, if necessary, explicit consent. CybAura does not request or require special category data for core platform functionality.

4. Categories of Data Subjects

  • Employees and contractors of the Controller
  • Data subjects who have submitted DSAR or data rights requests to the Controller
  • Third parties whose personal data appears in documents uploaded by the Controller (e.g. vendor contacts in vendor assessments)
  • Any other individuals whose personal data is included in Customer Data by the Controller

5. Processor Obligations

5.1 Documented Instructions

The Processor shall process personal data only on the documented instructions of the Controller, as set out in these Terms, this DPA, and any subsequent written instructions. If the Processor is required by law to process beyond these instructions, it shall notify the Controller before doing so unless prohibited from notification by law.

5.2 Confidentiality of Processing Personnel

The Processor shall ensure that all personnel authorised to process personal data are bound by written confidentiality obligations, whether through employment contracts, contractor agreements, or dedicated NDAs. These obligations shall survive the termination of employment or engagement.

5.3 Technical and Organisational Security Measures

The Processor shall implement and maintain appropriate technical and organisational measures, including:

  • Encryption of personal data in transit using TLS 1.2 or higher
  • Encryption of personal data at rest using AES-256
  • Role-based access controls and the principle of least privilege
  • Multi-factor authentication for all administrative access to production systems
  • Regular penetration testing and vulnerability scanning
  • A documented incident response procedure
  • Notification to the Controller within 72 hours of becoming aware of a personal data breach

5.4 Sub-processors

The Processor shall not engage sub-processors to process personal data other than those listed in Schedule 1 of this DPA. Before engaging any new sub-processor or materially changing an existing sub-processor’s role, the Processor shall give the Controller at least 30 days’ written notice, specifying the sub-processor and the nature of the processing. The Controller may object to the engagement within that period by providing written notice. If the parties cannot resolve the objection, the Controller may terminate the subscription for convenience. The Processor shall impose equivalent data protection obligations on all sub-processors and remains liable for sub-processor compliance.

5.5 Assistance with Data Subject Rights

The Processor shall assist the Controller in responding to data subject rights requests (access, erasure, portability, rectification, restriction, and objection) by providing the technical capabilities within the platform to export, delete, or modify personal data. Where a data subject rights request requires action that cannot be taken through the platform, the Processor shall use reasonable commercial efforts to assist, on request.

5.6 Assistance with GDPR Obligations

Taking into account the nature of the processing, the Processor shall assist the Controller in ensuring compliance with obligations relating to: (a) the security of processing; (b) notification of personal data breaches; (c) data protection impact assessments; and (d) prior consultation with supervisory authorities where required.

5.7 Deletion and Return on Termination

On termination of the subscription, at the Controller’s written election, the Processor shall, within 30 days: (a) securely delete all personal data processed on behalf of the Controller; or (b) return all personal data in a standard, machine-readable format (CSV, JSON, or PDF). On request, the Processor shall provide a written deletion certificate. Personal data contained in automated backup systems will be overwritten in the normal course of the Processor’s backup rotation cycle.

5.8 Audit Rights

The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA and shall allow and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, with at least 30 days’ prior written notice. The Processor may satisfy this obligation in the first instance by providing current third-party audit reports (ISO 27001 certificate, SOC 2 Type II report). If the Controller requires a specific audit beyond what third-party reports cover, the parties shall agree reasonable terms including confidentiality obligations and cost allocation.

6. Controller Obligations

The Controller represents and warrants that:

  • It has a valid lawful basis for processing the personal data it provides to CybAura under GDPR Article 6 (and Article 9 where applicable)
  • All personal data provided to CybAura has been collected in accordance with applicable data protection law
  • It has provided all required privacy notices to data subjects whose data it uploads to the platform
  • It will promptly notify CybAura if it becomes aware of any claim, complaint, or potential non-compliance related to personal data processed under this DPA

Schedule 1 — Approved Sub-Processors

Sub-processorPurposeLocationTransfer basis
Amazon Web Services (AWS)Cloud infrastructure — primary hosting, storage, databasesEU (eu-west-2 / eu-central-1)Data in-region; BCRs / SCCs where onward transfer occurs
Google Cloud Platform (GCP)Cloud infrastructure — secondary / DR regionEU (europe-west)Data in-region; SCCs where onward transfer occurs
Anthropic, PBCAI model API processing for AI agent featuresUnited StatesEU: SCCs (Commission Decision 2021/914) · UK: IDTA
Twilio SendGridTransactional and notification email deliveryUnited StatesEU: SCCs · UK: IDTA
Stripe, Inc.Payment processing (billing data only — not Customer Data)United StatesEU: SCCs · UK: IDTA
Intercom, Inc.Customer support tooling (support tickets, in-app chat)United StatesEU: SCCs · UK: IDTA

7. International Transfers

7.1 General

CybAura’s primary hosting is in the EU/UK. Where personal data is transferred to sub-processors outside the UK/EEA, the mechanisms in Schedule 1 apply.

7.2 Special Provisions for Anthropic (AI Processing)

To provide AI agent functionality, personal data present in Customer Data may be transmitted to Anthropic’s API (United States) for inference processing. CybAura’s agreement with Anthropic includes the following data protection provisions:

  • Anthropic processes data only to provide the API service to CybAura and does not use input data to train or improve its models
  • Data is not retained beyond the duration necessary to complete the API request, subject to Anthropic’s published data retention policy
  • Standard Contractual Clauses (EU) and the UK IDTA are in place

Customers who do not wish their data to be processed by Anthropic may disable AI agent features. Core security and compliance modules function without AI processing. Contact support@cybaura.io for guidance on disabling AI features.

7.3 SCC / IDTA Copies

Copies of the applicable Standard Contractual Clauses or UK International Data Transfer Agreements are available on request from privacy@cybaura.io.

8. Governing Law

This DPA shall be governed by and construed in accordance with the laws of England and Wales. For customers established in EU member states, the parties agree to comply with the GDPR as applicable. Supervisory authority jurisdiction is determined by the Controller’s establishment location.

EU Representative (GDPR Article 27)

CybAura Ltd is established in the United Kingdom. Where Article 27 of the EU GDPR requires a representative in the Union for the processing of EU personal data, CybAura will appoint one. Article 27 Representative: [To be appointed before EU customer onboarding].

Questions about this DPA? Contact our Data Protection Officer at legal@cybaura.io.

Need a countersigned DPA?

Enterprise customers can request a countersigned copy.