Legal · Version 1.0 · Effective 27 July 2026
Data processing addendum
The Article 28 GDPR processor terms, already in force for every customer. No signature needed, no procurement queue to join.
This addendum is already part of your agreement. You do not need to request it, negotiate it or get it signed. If your procurement process needs a countersigned copy on paper, email us and we will sign one, but nothing is waiting on that.
1. What this is
This addendum forms part of the terms of service between you (the "Customer") and DNS Ventures LLC ("we", "us") and applies whenever we process personal data on your behalf. It is written to satisfy Article 28 of Regulation (EU) 2016/679 and the equivalent provisions of the UK GDPR.
Where this addendum and the terms of service conflict on the handling of personal data, this addendum wins.
2. Roles
You are the controller. We are the processor. We process personal data only on your documented instructions, and your use of the product is the instruction. If we ever believe an instruction breaks data protection law, we will tell you and will not carry it out.
For your own account and billing data we are the controller, and the privacy policy covers that.
3. Subject matter, duration, nature and purpose
- Subject matter: providing CRA Kit.
- Duration: while your account is open, plus the retention periods set out in the privacy policy.
- Nature and purpose: hosting, storing, analysing and displaying the compliance data you put into the product, and sending the alerts and notifications you configure.
4. Types of personal data
- Work contact details of your staff who use the account: email address, name, role.
- Work contact details you publish as a single point of contact or a coordinated vulnerability disclosure contact for your product.
- Names and contact details of individuals you name in your technical documentation, such as the person signing a declaration of conformity.
- Any personal data you choose to type into a free-text field or upload inside a document. There is no reason to put special category data anywhere in the product.
5. Categories of data subject
- Your employees and contractors.
- Individuals named in your compliance documentation.
- Security researchers and others who contact you through the vulnerability reporting details you publish.
6. Confidentiality
Everyone with access to personal data processed for you is bound to confidentiality. Access is limited to the people who need it to run and support the service.
7. Security
We keep appropriate technical and organisational measures under Article 32. In concrete terms:
- Encryption in transit and at rest.
- Firmware analysed inside a per-scan temporary directory that is destroyed when the job ends. Your image is not retained.
- Upload authorisation by a short-lived signed token bound to a single scan, so the analysis endpoint cannot be used as an open file-analysis service.
- Role-based access inside your account: owner, admin, editor, viewer. Entitlement checks run in the backend, never only in the interface.
- An append-only audit chain for reporting cases. The database refuses updates and deletes on it outright, with a single authorised erasure path used for deletion requests.
- Sign-in by emailed link with a 30-minute expiry and single use. No password to leak.
- No IP address logging and no third-party analytics, which removes a whole category of data to secure.
8. Sub-processors
You authorise the sub-processors listed on our sub-processors page. Each is bound by written terms no less protective than this addendum, and we remain liable for what they do.
We give at least 30 days notice by email to account owners before a new sub-processor starts. You can object within that period. If we cannot resolve your objection you can cancel and we refund the unused part of the period you have paid for.
9. International transfers
Processing takes place in the United States. Transfers of personal data out of the European Economic Area or the United Kingdom rely on the European Commission’s standard contractual clauses, and on the UK International Data Transfer Addendum where the UK GDPR applies. Where the standard contractual clauses apply, module two governs controller to processor transfers and module three governs onward transfers to our sub-processors.
10. Helping you with data subject requests
The product already lets you read, correct, export and delete the data in your account yourself, which handles most requests without involving us. Where you need more, we help within a reasonable time and at no charge. If a data subject contacts us directly about your data, we will not answer for you: we tell them to contact you, and we tell you.
11. Personal data breaches
If we become aware of a personal data breach affecting your data, we tell you without undue delay and in any event within 48 hours of becoming aware. The notice says what we know, who is affected as far as we can tell, what we are doing, and what we recommend you do. We will not wait until the picture is complete before telling you.
We will also help you meet your own Article 33 and 34 obligations, which is exactly the situation the Article 14 console in this product exists for.
12. Deletion and return
You can export everything in open formats at any time, including after cancelling. On request we delete the personal data we hold for you, except what we must keep by law and except the suppression list that exists to stop us emailing someone who opted out. Deletion runs through the authorised erasure path described in section 7.
13. Audit
We give you the information you need to show compliance with Article 28. You can audit once in any twelve-month period on 30 days notice, at your cost, and more often if a supervisory authority requires it or after a breach affecting your data. Most questions are answered by this page, the security page and the sub-processor list. Email hello@synthworx.com and we will answer directly.
14. Duration
This addendum runs for as long as we process personal data for you, and the confidentiality and security obligations survive the end of your account.
Signing a copy
Email hello@synthworx.com and say which entity name should be on it. We countersign and return it. Nothing about your account waits on that, because these terms already apply.
Version history
| Version | Date | What changed |
|---|---|---|
| 1.0 | 27 July 2026 | First published. |
DNS Ventures LLC, 30 N Gould St, STE R, Sheridan, WY 82801, United States of America. Questions about this document go to hello@synthworx.com and a person answers.
The rest of the policies
The contract between you and DNS Ventures LLC for CRA Kit. What we do, what we do not do, what you pay, and who is responsible for what.
Refund and cancellation policyCancel from a screen, keep what you paid for until the period ends, and the cases where we give money back.
Privacy policyWhat personal data CRA Kit holds, why, for how long, who else touches it, and how to get it back or get it deleted.
Sub-processorsEvery third party that touches customer data, what it does, and what it sees.
Acceptable use policyWhat you may point the firmware analysis engine at, and the small number of things that get an account suspended.