Legal and compliance
Data Processing Addendum
Last updated: September 11, 2026
This is an Article 28-style processing template for review when SecurityOla or AppCare processes customer-site personal data on a customer’s documented instructions. It is not a signed agreement and does not claim GDPR compliance by itself.
1. Roles and documented instructions
The SecurityOla/AppCare customer is the controller for customer-site personal data. SecurityOla acts as processor only when it processes that data on the customer’s documented instructions to provide the contracted scan, monitoring, backup, reporting or bounded operational service. SecurityOla acts as an independent controller for its own account, entitlement, billing-support and security-abuse records.
2. Subject matter and duration
Processing is limited to delivering the purchased service, maintaining security and reliability, supporting the customer and complying with law. Processing lasts for the service term and any strictly necessary transition, deletion, security or legal-retention period. Exact schedules remain pending verification in the production retention controls.
3. Data categories and data subjects
Depending on the customer’s site and instructions, data can include site identifiers, user/account records, database and options evidence, uploaded-file metadata, security findings, logs, support records and technical identifiers. Data subjects may include the customer’s staff, site users, subscribers and other people whose information is present on the authorized site. Customers must not instruct processing beyond their lawful scope.
4. Processor obligations
- Process customer-site data only on documented instructions and for the stated services.
- Require confidentiality from people with access and apply access control, secret separation, bounded logging and least-privilege operational practices.
- Use appropriate technical and organizational measures for the risk; no absolute security guarantee is made.
- Assist, where reasonably available, with data-subject requests, security incidents, impact assessments and regulator inquiries.
- Notify the customer through the agreed support/incident path of a confirmed processor-side personal-data breach without undue delay after awareness.
5. Subprocessors and transfers
The current evidence-backed inventory is published at /subprocessors. No AI/model provider is authorized by this page to receive scanned customer files or databases; none was observed in the current SecurityOla API/site paths. Provider locations and transfer mechanisms require owner/operator review before this template is treated as a final executed DPA.
6. Return and deletion
At the end of the service, SecurityOla should return or delete customer-site personal data on the customer’s documented instruction unless retention is required by law or a narrowly defined security/backup transition. The customer must specify any required export or deletion instruction through support; the current deployment does not claim a universal deletion deadline.
7. Audit and evidence
SecurityOla can provide reasonable information about the safeguards and service scope recorded in its operational documentation. Any audit must be proportionate, protect other customers’ information and not require disclosure of secrets, raw unrelated customer content or provider credentials.
8. Review status
This page is a public engineering template, not legal advice and not a signed DPA. Owner/legal review of identity, provider contracts, transfer mechanisms, retention schedules and final contractual wording is required before relying on it as an Article 28 agreement.