Legal · Version 1.0 · Effective 27 July 2026

Data processing addendum

The Article 28 GDPR processor terms, already in force for every customer. No signature needed, no procurement queue to join.

This addendum is already part of your agreement. You do not need to request it, negotiate it or get it signed. If your procurement process needs a countersigned copy on paper, email us and we will sign one, but nothing is waiting on that.

1. What this is

This addendum forms part of the terms of service between you (the "Customer") and DNS Ventures LLC ("we", "us") and applies whenever we process personal data on your behalf. It is written to satisfy Article 28 of Regulation (EU) 2016/679 and the equivalent provisions of the UK GDPR.

Where this addendum and the terms of service conflict on the handling of personal data, this addendum wins.

2. Roles

You are the controller. We are the processor. We process personal data only on your documented instructions, and your use of the product is the instruction. If we ever believe an instruction breaks data protection law, we will tell you and will not carry it out.

For your own account and billing data we are the controller, and the privacy policy covers that.

3. Subject matter, duration, nature and purpose

  • Subject matter: providing CRA Kit.
  • Duration: while your account is open, plus the retention periods set out in the privacy policy.
  • Nature and purpose: hosting, storing, analysing and displaying the compliance data you put into the product, and sending the alerts and notifications you configure.

4. Types of personal data

  • Work contact details of your staff who use the account: email address, name, role.
  • Work contact details you publish as a single point of contact or a coordinated vulnerability disclosure contact for your product.
  • Names and contact details of individuals you name in your technical documentation, such as the person signing a declaration of conformity.
  • Any personal data you choose to type into a free-text field or upload inside a document. There is no reason to put special category data anywhere in the product.

5. Categories of data subject

  • Your employees and contractors.
  • Individuals named in your compliance documentation.
  • Security researchers and others who contact you through the vulnerability reporting details you publish.

6. Confidentiality

Everyone with access to personal data processed for you is bound to confidentiality. Access is limited to the people who need it to run and support the service.

7. Security

We keep appropriate technical and organisational measures under Article 32. In concrete terms:

  • Encryption in transit and at rest.
  • Firmware analysed inside a per-scan temporary directory that is destroyed when the job ends. Your image is not retained.
  • Upload authorisation by a short-lived signed token bound to a single scan, so the analysis endpoint cannot be used as an open file-analysis service.
  • Role-based access inside your account: owner, admin, editor, viewer. Entitlement checks run in the backend, never only in the interface.
  • An append-only audit chain for reporting cases. The database refuses updates and deletes on it outright, with a single authorised erasure path used for deletion requests.
  • Sign-in by emailed link with a 30-minute expiry and single use. No password to leak.
  • No IP address logging and no third-party analytics, which removes a whole category of data to secure.

8. Sub-processors

You authorise the sub-processors listed on our sub-processors page. Each is bound by written terms no less protective than this addendum, and we remain liable for what they do.

We give at least 30 days notice by email to account owners before a new sub-processor starts. You can object within that period. If we cannot resolve your objection you can cancel and we refund the unused part of the period you have paid for.

9. International transfers

Processing takes place in the United States. Transfers of personal data out of the European Economic Area or the United Kingdom rely on the European Commission’s standard contractual clauses, and on the UK International Data Transfer Addendum where the UK GDPR applies. Where the standard contractual clauses apply, module two governs controller to processor transfers and module three governs onward transfers to our sub-processors.

10. Helping you with data subject requests

The product already lets you read, correct, export and delete the data in your account yourself, which handles most requests without involving us. Where you need more, we help within a reasonable time and at no charge. If a data subject contacts us directly about your data, we will not answer for you: we tell them to contact you, and we tell you.

11. Personal data breaches

If we become aware of a personal data breach affecting your data, we tell you without undue delay and in any event within 48 hours of becoming aware. The notice says what we know, who is affected as far as we can tell, what we are doing, and what we recommend you do. We will not wait until the picture is complete before telling you.

We will also help you meet your own Article 33 and 34 obligations, which is exactly the situation the Article 14 console in this product exists for.

12. Deletion and return

You can export everything in open formats at any time, including after cancelling. On request we delete the personal data we hold for you, except what we must keep by law and except the suppression list that exists to stop us emailing someone who opted out. Deletion runs through the authorised erasure path described in section 7.

13. Audit

We give you the information you need to show compliance with Article 28. You can audit once in any twelve-month period on 30 days notice, at your cost, and more often if a supervisory authority requires it or after a breach affecting your data. Most questions are answered by this page, the security page and the sub-processor list. Email hello@synthworx.com and we will answer directly.

14. Duration

This addendum runs for as long as we process personal data for you, and the confidentiality and security obligations survive the end of your account.

Signing a copy

Email hello@synthworx.com and say which entity name should be on it. We countersign and return it. Nothing about your account waits on that, because these terms already apply.

Version history

VersionDateWhat changed
1.027 July 2026First published.

DNS Ventures LLC, 30 N Gould St, STE R, Sheridan, WY 82801, United States of America. Questions about this document go to hello@synthworx.com and a person answers.