Version: 1.0 Effective date: 2026-05-22
This Data Processing Addendum (the "DPA") is incorporated into and forms part of the agreement (the "Agreement") between Penaxtra (the "Processor") and the customer entity identified in the Agreement (the "Controller"), regarding the Processor's processing of personal data on behalf of the Controller in the course of providing the Penaxtra LLM Security Posture Management platform (the "Service").
This DPA is drafted to comply with Article 28 of the EU General Data Protection Regulation (Regulation EU 2016/679, "GDPR") and the Turkish Personal Data Protection Law No. 6698 ("KVKK").
1. Definitions
Terms used in this DPA have the meanings set out in GDPR Article 4, unless otherwise defined here.
- Customer Data: personal data the Controller submits to or processes through the Service.
- Sub-processor: a third party engaged by the Processor to process Customer Data on the Controller's behalf.
- Standard Contractual Clauses or SCCs: the standard contractual clauses approved by the European Commission Decision 2021/914.
2. Subject matter, duration, nature, and purpose
The Processor processes Customer Data on the Controller's behalf to provide the Service. Processing continues for the duration of the Agreement. The nature of processing includes collection, storage, retrieval, transmission, alignment, restriction, erasure, and destruction, performed by automated means. The purpose is to deliver the LLM security posture management functions described in the documentation, including adversarial scanning, runtime gateway protection, compliance mapping, and audit logging.
3. Categories of data subjects and types of personal data
The Controller determines the categories of data subjects and the types of personal data submitted to the Service. Typical categories include the Controller's personnel (members, administrators) and end users of systems the Controller tests with the Service. Typical types include identifiers (email, name), authentication metadata, configuration metadata, and incidental personal data that may appear in adversarial probe responses or logged content.
4. Controller instructions
The Processor processes Customer Data only on documented instructions from the Controller, including the Agreement, this DPA, and the configuration the Controller selects in the Service. The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection law.
5. Confidentiality
The Processor ensures that personnel authorised to process Customer Data are bound by confidentiality obligations or are under appropriate statutory obligations of confidentiality.
6. Security measures
The Processor implements the technical and organisational measures set out in Annex II to ensure a level of security appropriate to the risk. The measures address pseudonymisation and encryption, ongoing confidentiality, integrity, availability, and resilience of processing systems, restoration of availability after incident, and a process for regularly testing the measures.
7. Sub-processing
The Controller authorises the Processor to engage the sub-processors listed in Annex III and on the Trust portal at /trust. The Processor will inform the Controller of any intended changes to the sub-processor list at least thirty days in advance and will give the Controller the opportunity to object on reasonable grounds.
The Processor enters into a written agreement with each sub-processor that imposes data protection obligations no less protective than those in this DPA.
8. Data subject rights
The Processor assists the Controller, by appropriate technical and organisational measures, in responding to requests by data subjects exercising their rights under GDPR Chapter III, taking into account the nature of the processing.
9. Personal data breach
The Processor notifies the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach. The notification includes at least the categories and approximate number of data subjects, the categories and approximate number of records, the likely consequences, and the measures taken or proposed.
10. Audit rights
The Processor makes available to the Controller information necessary to demonstrate compliance with this DPA, and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. Audit requests must be made in writing, scheduled at mutually agreeable times, and conducted in a manner that does not unreasonably disrupt the Processor's operations. The Processor may satisfy audit requests by providing third-party attestation reports (for example SOC 2 Type II, ISO 27001) once such reports are available.
11. International transfers
Where the Processor transfers Customer Data outside the European Economic Area, transfers are based on the European Commission's Standard Contractual Clauses (Decision 2021/914), supplemented by technical and contractual measures as required following the Schrems II ruling. The SCC modules applicable to controller-to-processor transfers (Module Two) and processor-to-sub-processor transfers (Module Three) are incorporated by reference.
12. Return and deletion
Upon termination of the Agreement, the Processor returns or deletes Customer Data, at the Controller's choice, except where retention is required by Union or Member State law. The Controller may specify the choice within thirty days of termination; absent a choice, the Processor will delete Customer Data after the same period.
13. Liability
The liability provisions of the Agreement apply to this DPA. Nothing in this DPA limits liability under the GDPR for damages caused by processing.
14. Order of precedence
In case of conflict between this DPA and the Agreement, this DPA prevails on matters of data protection. In case of conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.
---
Annex I: List of parties
Data Exporter (Controller): The customer entity identified in the Agreement.
Data Importer (Processor): Penaxtra, registered in the Republic of Turkiye, contactable at [email protected].
Competent supervisory authority: For Customer Data of EEA data subjects, the supervisory authority of the EEA Member State where the Controller is established. For Customer Data of Turkish data subjects, the Kisisel Verileri Koruma Kurumu (KVKK).
---
Annex II: Technical and organisational measures
The Processor implements the following technical and organisational measures (each of which is described in greater technical detail at /security):
- Encryption in transit: TLS 1.3 on the public edge; modern cipher suites only.
- Encryption at rest: database data files and backup archives encrypted; secret material encrypted under authenticated public-key cryptography (X25519 sealed-box AEAD).
- Access control: role-based access with the principle of least privilege; five distinct database roles separate web, backend, migrations, read-only analytics, and backup workloads.
- Multi-tenancy: row-level access policies enforced on every tenant-scoped table; the tenant isolation context is reset on every transaction-mode connection-pool checkout.
- Authentication: optional time-based one-time password and magic-link sign-in. Sessions use the __Host- cookie prefix with thirty-minute idle and twelve-hour absolute timeouts.
- Audit logging: append-only audit log with a tamper-evident database mirror; the role that writes events has INSERT-only grants.
- Backup: nightly compressed and age-encrypted backups shipped to an EU-region object store; seven-day local retention plus at least 90 days off-site.
- Incident response: published intake at the RFC 9116 security.txt machine-readable contact and a 90-day coordinated disclosure window. Personnel trained on incident response procedures.
- Personnel: confidentiality undertakings in place for all personnel with access to Customer Data; background checks where permitted by law.
- Vendor management: sub-processors contracted under data protection terms no less protective than this DPA.
---
Annex III: List of sub-processors
The current list is maintained at /trust and disclosed by name in the customer-facing DPA on request. Categories include:
- Cloud infrastructure provider (EU region, SOC 2 Type II + ISO 27001).
- Edge security network (DDoS, WAF, TLS termination).
- Three frontier LLM judge providers for the adversarial scan pipeline. Each operates under SCCs where international transfer applies and a no-training commitment for Customer Data.
- Payment processors (PCI DSS Level 1) for billing.
- Transactional email relay (EU region).
- Privacy-respecting analytics (cookie-less, EU-hosted).
Material changes are communicated at least thirty days in advance.