Data Processing Agreement (DPA)
Last updated: 17.07.2026
This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (the “Controller”) and Aegvale (the “Processor”) and governs the processing of personal data by the Processor on behalf of the Controller in connection with the Aegvale service, in accordance with Article 28 GDPR.
1. Parties
Processor: Aegvale (Einzelunternehmen), Anna-von-Fürstenberg-Weg 30, 59494 Soest, Germany. Contact: support@aegvale.com.
Controller: the customer entity that has accepted this DPA (details to be completed on signature below).
2. Subject matter and duration
The Processor processes personal data solely to provide the Aegvale AI-agent security testing service to the Controller. Processing continues for the duration of the service agreement and ends on termination, subject to Section 9 (deletion and return).
3. Nature and purpose of processing
Personal data is processed to create and administer accounts, authenticate users, run security scans configured by the Controller, generate reports, process billing, and provide support. The Processor does not process the data for any other purpose.
4. Types of personal data and categories of data subjects
Data subjects: the Controller’s authorised users and administrators. Personal data: account identifiers (name, email), authentication data, organisation/workspace data, billing status, usage and audit metadata, and any personal data the Controller chooses to include in agent configurations or test inputs.
5. Obligations of the Processor
The Processor shall: (a) process personal data only on documented instructions from the Controller; (b) ensure persons authorised to process the data are bound by confidentiality; (c) implement the technical and organisational measures in Section 7; (d) assist the Controller in responding to data-subject requests; (e) assist with security, breach notification and impact assessments; and (f) make available information necessary to demonstrate compliance.
6. Sub-processors
The Controller authorises the Processor to engage the following sub-processors, each bound by data-protection obligations no less protective than this DPA:
Vercel (frontend hosting), Render (backend hosting and managed PostgreSQL database), Stripe (payments), Resend (transactional email), Sentry (error monitoring, when enabled), and the AI/LLM provider used for optional model-graded evaluation (OpenAI by default).
Hosting and data location: Vercel (frontend hosting), Render (application hosting), and PostgreSQL (managed database on Render).. The Processor will inform the Controller of intended changes to sub-processors and give the Controller the opportunity to object.
7. Technical and organisational measures (Art. 32)
The Processor maintains appropriate measures including: encryption of stored credentials (AES-256-GCM) and encryption in transit (TLS); role-based access control and least-privilege access; two-factor authentication and rotating session tokens; audit logging; isolated, access-controlled infrastructure; and regular review of security controls. Further detail is available on the Security page.
8. Data-subject rights and breach notification
The Processor will, taking into account the nature of processing, assist the Controller in fulfilling its obligations to respond to data-subject rights requests. The Processor will notify the Controller without undue delay after becoming aware of a personal-data breach at support@aegvale.com.
9. Deletion and return of data
On termination, and at the Controller’s choice, the Processor will delete or return all personal data and delete existing copies, unless retention is required by law. Retention behaviour: Scan data, reports, findings, projects and agents are retained until you delete them (individually, in bulk, or by deleting the parent project or agent), which removes them and their associated results. Account and organisation data are retained for the life of your account and are deleted upon account closure or on request, subject to any mandatory legal retention obligations. Aegvale does not apply a fixed automatic deletion period..
10. Audits
The Processor will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or a mandated auditor, subject to reasonable notice and confidentiality.
11. International transfers
Where personal data is transferred outside the EEA, such transfers are made on the basis of an adequacy decision or appropriate safeguards (e.g. EU Standard Contractual Clauses).
12. Governing law
This DPA is governed by the law of Germany, with jurisdiction as set out in the Terms of Service.
Signatures
Processor
Aegvale
Controller (Customer)
This DPA is provided as a template and should be reviewed by your legal counsel before use.