Skip to content

Legal

Data processing agreement

Processor obligations, transfers and security measures.

Last updated

Our standard data processing agreement is offered to every customer and is signed alongside the order form. It covers the following, and is available for redlining on the Enterprise tier.

  • Subject matter, duration, nature and purpose of processing, and the categories of data and data subjects.
  • Technical and organisational security measures, including encryption, access control and isolation.
  • General authorisation of subprocessors with advance notice of additions and a right to object.
  • Assistance with data subject requests, DPIAs and regulator enquiries.
  • Personal data breach notification without undue delay, with the contractual timeline stated in the agreement.
  • Deletion or return of data on termination, and the audit and inspection rights available to you.

International transfers

Standard Contractual Clauses are incorporated for transfers out of the EEA, and the UK International Data Transfer Addendum for UK transfers. Where you select EU or UK residency, personal data is not transferred outside that region for processing or backup.

Security measures

The agreement's security schedule reflects what is described in the trust centre: TLS 1.2+ in transit, encryption at rest, secrets in a managed vault, repository-level tenant scoping plus Postgres row-level security, enforced administrator MFA and an append-only audit log.

Questions about this document? Email legal@safeloop.com or contact us.

See your human risk in 20 minutes

Book a demo and we’ll run a sample campaign against a test group.