Data processing agreement
Roles
For data an organisation places in the service, the customer is the controller and CyberRisk Protection Ltd is the processor. For account and billing data we are a controller in our own right.
Instructions
We process customer data only on documented instructions, which are these terms and the customer's use of the service, unless required otherwise by law. Where law requires otherwise, we will tell the customer first unless that law forbids it.
Security measures
Set out on the security page, which forms part of this agreement: tenant isolation enforced at the data layer, encryption in transit and at rest, role-based access with time-boxed external access, an append-only audit trail, and least-privilege operational access.
Sub-processors
Listed on the sub-processors page. We give thirty days' notice of a new sub-processor, during which a customer may object on reasonable data protection grounds.
Breach notification
We will notify affected customers without undue delay, and in any event within seventy-two hours of becoming aware of a personal data breach affecting their data, with the information needed for them to meet their own notification obligations.
Deletion and return
On termination, customer data is available for export for ninety days and then deleted. Export is available on every plan and is not withheld as commercial leverage.
Last updated September 2026 · CyberRisk Protection Ltd