Agreement on the processing of personal data on behalf of a controller pursuant to Art. 28 GDPR between you as the customer (controller, "client") and [set legal.name in config.php] (processor, "contractor").
Subject matter and duration
The contractor processes personal data contained in the client's content exclusively to provide the ZeroFlaw service under the terms (main contract). The term corresponds to the term of the main contract.
Nature, purpose and data subjects
- Nature and purpose: automated security checks of uploaded or imported source code and of verified websites, storage and display of the results, creation of reports, notifications and, on explicit request, the AI explanation of individual findings.
- Types of data: data contained in source code, configurations, database dumps, log files or on the checked websites, for example names, e-mail addresses, credentials, IP addresses or form contents; also data in support attachments.
- Data subjects: employees, customers, users and website visitors of the client.
Instructions
The contractor processes the data only on documented instructions from the client. Instructions are this agreement, the main contract and the settings the client makes in the dashboard (for example starting, scheduling and deleting scans). If the contractor considers an instruction to be unlawful, it informs the client without delay. Processing required by law remains unaffected; the contractor informs the client about it where the law permits.
Confidentiality
The contractor ensures that all persons with access to the data are bound to confidentiality or are subject to a statutory obligation of secrecy. Access to the client's content only takes place where necessary for operation, support or investigating faults; every access by administrators to scan results is logged.
Security of processing
The contractor takes the technical and organizational measures described in Annex 1 (Art. 32 GDPR). It may develop them further as long as the level of protection is not reduced.
Sub-processors
The client authorizes the sub-processors listed in Annex 2. The contractor informs the client of intended changes at least four weeks in advance in text form; the client may object for an important reason under data protection law and in this case terminate the main contract for cause. The contractor imposes the same data protection obligations on sub-processors as set out in this agreement.
Assistance to the client
Within reason, the contractor assists the client in responding to requests from data subjects (Art. 12 to 23 GDPR) and with the obligations under Art. 32 to 36 GDPR. The client can exercise many rights directly in the dashboard, for example by exporting and deleting scans.
Notification of breaches
The contractor notifies the client of a personal data breach without undue delay, if possible within 48 hours of becoming aware of it, with the information under Art. 33 (3) GDPR insofar as it is available.
Deletion and return
Uploaded source code is deleted right after the respective scan is finished. The client can export and delete results at any time. When the account is deleted or the main contract ends, the contractor deletes all of the client's data unless there is a legal obligation to retain it. Security-relevant log entries are pseudonymized in the process.
Evidence and audits
On request, the contractor provides the client with the information needed to demonstrate compliance with the obligations under this agreement. It allows audits, including inspections, with at least 14 days' notice during normal business hours and without disrupting operations; the client bears the costs unless the audit reveals a breach by the contractor.
Third countries, liability, final provisions
Data is only transferred to countries outside the EU under the conditions of Chapter V GDPR. Liability is governed by Art. 82 GDPR and otherwise by § 9 of the terms. In the event of conflict, the provisions of this agreement take precedence over the terms insofar as the protection of personal data is concerned.
Annex 1: Technical and organizational measures
Confidentiality
- Physical access: operation in the data centers of the hosting provider (Annex 2) with its physical security measures.
- System access: server access only for authorized administrators. Customer accounts with Argon2id-hashed passwords, lockouts after failed attempts and optional two-factor sign-in; two-factor sign-in is mandatory for administrators, and admin sessions end after 30 minutes of inactivity.
- Data access: role and permission concept; every record belongs to an account and is only visible to that account or its team. Sensitive admin actions require re-confirmation and are logged.
- Separation: logical tenant separation in the database; scans run in separate, short-lived working directories or containers.
- Encryption: finding descriptions, code snippets, notes, AI answers, two-factor secrets and login cookies for scans are stored encrypted with AES-256-GCM; session, API and invitation tokens only as hashes.
Integrity
- Transfer: transmission only via TLS, HSTS, strict Content Security Policy, protection against CSRF and clickjacking.
- Input control: logging of security-relevant events with time, account and IP address.
Availability and resilience
- Service monitoring with a public status page, load limitation through quotas and queues, reassignment of scans after a scan server fails.
- Uploaded content is checked for size, type and dangerous paths before it is processed.
Regular review
- Automated tests of the application, regular software updates and checks of our own application with ZeroFlaw.
- Privacy-friendly defaults: deletion of source code after the scan, masking of found secrets, no tracking or analytics services.
Annex 2: Sub-processors
| Company | Service | Location |
|---|---|---|
| [set legal.hoster in config.php] | Hosting of the application, the database and the scan servers | as stated by the hosting provider |
| Anthropic, PBC, San Francisco, USA | AI explanation of individual findings, only on explicit request in the dashboard | USA (EU standard contractual clauses) |