Data Processing Agreement
Agreement on the processing of personal data on behalf of the controller under Art. 28 GDPR for the use of veyrisk. Last updated: September 2026. This English version is a convenience translation; in case of discrepancies, the German version prevails.
1. Parties and subject matter
This Data Processing Agreement ("DPA") is entered into between Customer as controller within the meaning of Art. 4(7) GDPR ("Controller", "Customer") and neonotu GmbH, Edelsbergstr. 8, 80686 Munich, Germany, registered with the commercial register of the Munich Local Court (Amtsgericht München) under HRB 313206, represented by its managing director, Armin Haller, as processor within the meaning of Art. 4(8) GDPR ("Processor", "veyrisk").
This DPA forms part of the contract for the use of the veyrisk platform concluded under the veyrisk Terms of Service ("Terms") (the "Main Contract"). It is concluded together with the Main Contract and specifies the parties' data protection obligations arising from the services described therein. Terms are used as defined in the GDPR.
In the event of conflict, this DPA prevails over the Main Contract with respect to the processing of personal data.
2. Subject matter, nature, and purpose of processing
The subject matter of processing is the provision of the veyrisk platform as software as a service. Processing includes in particular:
- discovering and monitoring Customer's externally reachable attack surface;
- passive checks of publicly observable information, such as subdomains, DNS, TLS, and email configuration, HTTP security headers, and reachable administration interfaces;
- port checks and vulnerability scans with OpenVAS, solely for domains for which Customer has proven control by a DNS record;
- storing, assessing, and prioritizing findings and generating reports;
- managing Customer's user accounts, including sign-in, two-factor authentication, and logging.
Nature of processing: collection, recording, storage, organization, retrieval, consultation, alignment, use, disclosure to Customer, restriction, and erasure.
The purpose of processing is the provision of the services agreed in the Main Contract.
3. Types of data and categories of data subjects
Types of personal data:
- account data of Customer's users: name, business email address, role, password (stored only as a hash), two-factor authentication key;
- sign-in and log data: timestamps, IP addresses, security-relevant actions in the audit log;
- Customer's company and contact data, to the extent it is personal data;
- domains, hostnames, and IP addresses, to the extent they can be attributed to a natural person;
- technical scan results that may incidentally contain personal data, such as names in certificates, email addresses in DNS or SPF records, or content of publicly reachable pages.
Categories of data subjects:
- employees and other users of Customer;
- persons whose data is contained in Customer's systems, certificates, or DNS records.
Special categories of personal data within the meaning of Art. 9 GDPR are not processed intentionally.
neonotu GmbH processes billing and payment data as an independent controller; the veyrisk Privacy Policy applies in this respect.
4. Duration of processing
This DPA applies for the term of the Main Contract. It ends with the Main Contract without separate termination. Obligations that by their nature survive the end of the contract, in particular regarding erasure and confidentiality, remain in effect.
5. Controller's instructions
veyrisk processes personal data only on documented instructions from Customer, unless required to do so by Union or Member State law. In such a case, veyrisk informs Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
Customer's instructions are set out conclusively in the Main Contract and this DPA. Customer's configuration of the Services, such as adding domains, starting scans, or managing users, constitutes an instruction. Customer gives further instructions in text form. Instructions beyond the agreed scope of services are treated as a change request.
veyrisk informs Customer without undue delay if, in its opinion, an instruction infringes data protection law. veyrisk may suspend the instruction until Customer confirms or changes it.
6. Confidentiality
veyrisk only uses persons for processing who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality and who have been familiarized with the relevant data protection provisions. This obligation continues after their engagement ends.
7. Technical and organizational measures
veyrisk implements all technical and organizational measures required under Art. 32 GDPR to ensure a level of security appropriate to the risk. The measures in place at the time of conclusion are described in Annex 1.
The measures are subject to technical progress. veyrisk may replace them with equivalent or better measures, provided the level of security is not reduced. Material changes are documented.
8. Sub-processors
Customer grants veyrisk general authorization to engage other processors ("Sub-processors"). The Sub-processors engaged at the time of conclusion are listed in Annex 2 and are deemed approved.
veyrisk notifies Customer by email to the address stored in the customer account at least thirty (30) days before engaging a new Sub-processor or replacing an existing one. Customer may object to the change in text form within this period on reasonable data protection grounds. If the parties cannot reach agreement, Customer may terminate the Main Contract effective on the date the new Sub-processor is engaged.
veyrisk contractually imposes on each Sub-processor substantially the same data protection obligations as set out in this DPA, in particular sufficient guarantees for appropriate technical and organizational measures. veyrisk remains liable to Customer for the Sub-processor's performance of its obligations in accordance with Art. 28(4) GDPR.
Ancillary services that veyrisk obtains from third parties purely as telecommunications or transport services, such as internet connectivity or the delivery of emails by recipients' mail servers, do not constitute sub-processing.
9. Place of processing
Processing takes place exclusively in data centers in Germany. Personal data is not transferred to a third country or an international organization. Any relocation to a third country requires Customer's prior consent in text form and may only take place if the requirements of Art. 44 et seq. GDPR are met.
10. Assistance to the controller
Taking into account the nature of the processing, veyrisk assists Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling data subject rights under Chapter III GDPR. If a data subject contacts veyrisk directly, veyrisk forwards the request to Customer without undue delay and does not respond itself unless instructed otherwise by Customer.
Taking into account the information available to it, veyrisk assists Customer in complying with its obligations under Art. 32 to 36 GDPR, in particular regarding security of processing, notification of personal data breaches, data protection impact assessments, and prior consultation with the supervisory authority.
For assistance beyond the provision of the Services and existing documentation that is not caused by a breach by veyrisk, veyrisk may charge reasonable fees based on effort.
11. Personal data breaches
veyrisk notifies Customer of any personal data breach affecting data processed on behalf of Customer without undue delay and in any event within forty-eight (48) hours after becoming aware of it, by email to the address stored in the customer account.
To the extent known, the notification contains the information under Art. 33(3) GDPR, in particular a description of the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Information not available immediately is provided in phases.
veyrisk takes the necessary measures without undue delay to secure the data and to mitigate possible adverse effects and coordinates them with Customer. Notifications to supervisory authorities and data subjects are Customer's responsibility.
12. Evidence and audits
veyrisk makes available to Customer on request all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR. Evidence is provided primarily through current certificates, reports or extracts from independent auditors, and the documentation of technical and organizational measures. neonotu GmbH is certified under ISO/IEC 27001 and ISO 9001; the veyrisk services are within the scope of these certifications.
If this evidence is insufficient in an individual case, Customer may conduct audits, including on-site inspections, itself or through an auditor bound to confidentiality who is not a competitor of veyrisk. Inspections must be announced at least thirty (30) days in advance, take place during normal business hours, must not disproportionately disrupt operations, and must not compromise the confidentiality of other customers' data.
On-site inspections are permitted at most once per calendar year, unless a personal data breach affecting Customer's data has occurred or a supervisory authority requires the audit. Customer bears the costs of the audit; veyrisk may charge reasonable fees for its effort unless the audit reveals a material breach of this DPA by veyrisk.
13. Erasure and return after termination
After termination of the Main Contract, veyrisk erases all personal data processed on behalf of Customer within thirty (30) days, unless Union or Member State law requires storage. Before the contract ends, Customer can export its findings and reports through the Services; any further return is provided on request in a common format.
Backups are deleted in the course of regular rotation, no later than ninety (90) days after the end of the contract. Until then, they are protected against access and not actively processed.
neonotu GmbH, as an independent controller, retains billing records in accordance with commercial and tax law, generally for ten (10) years.
On request, veyrisk confirms erasure in text form.
14. Customer's obligations
Customer is responsible for the lawfulness of processing and for safeguarding data subject rights. In particular, Customer ensures that it is authorized to have the specified systems checked and that it has a legal basis for processing its users' data.
Customer informs veyrisk without undue delay if it detects errors or irregularities regarding data protection provisions when reviewing the results.
15. Liability and final provisions
The parties' liability is governed by Art. 82 GDPR. Otherwise, the liability provisions of the Main Contract apply, unless mandatory law provides otherwise.
Amendments and supplements to this DPA require text form. veyrisk may amend this DPA following the procedure for changes to the Terms where required by changes in legal requirements or the further development of the Services, provided the level of protection is not reduced.
If individual provisions of this DPA are invalid, the validity of the remaining provisions is not affected. German law applies. To the extent permitted, the place of jurisdiction is Munich.
Contact for data protection matters: neonotu GmbH, Edelsbergstr. 8, 80686 Munich, Germany, email: contact@veyrisk.com.
Annex 1: Technical and organizational measures
Confidentiality (Art. 32(1)(b) GDPR)
- Physical access control: operation exclusively in ISO/IEC 27001 certified data centers in Germany with access control, video surveillance, and security staff.
- System access control: two-factor authentication mandatory for all users; passwords stored only as scrypt hashes; sessions expire after eight (8) hours of inactivity; administrative server access only via SSH with keys, password login disabled.
- Data access control: role model with owner, admin, and member; strict tenant separation, every query is scoped to the respective customer; two-factor authentication keys stored encrypted (AES-256-GCM).
- Separation control: logical separation of data per customer; separation of production and development environments.
- Staff confidentiality: written confidentiality commitment of all persons involved in processing.
Integrity (Art. 32(1)(b) GDPR)
- Transfer control: all connections encrypted with TLS 1.2 or higher.
- Input control: audit log of security-relevant actions, such as sign-ins, role changes, invitations, and domain verifications.
- Scanner protection: SSRF protection preventing connections to internal or reserved addresses; active checks only after proof of control via DNS record.
Availability and resilience (Art. 32(1)(b) and (c) GDPR)
- Encrypted backups retained for no more than ninety (90) days.
- Automatic installation of security updates.
- Data centers with redundant power and network connectivity, climate control, and fire protection.
Data minimization and erasure
- Requests submitted via the free scan on the website are deleted automatically after ninety (90) days.
- Server logs are deleted after fourteen (14) days.
- Customer data is erased within thirty (30) days after the end of the contract.
Procedures for regular review (Art. 32(1)(d) GDPR)
- Information security management system under ISO/IEC 27001 and quality management under ISO 9001 with regular internal and external audits.
- Processor control: selection and contractual commitment of Sub-processors under Art. 28 GDPR.
Annex 2: Sub-processors
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Service: server hosting. Location: data centers in Nuremberg and Falkenstein, Germany.
- Email delivery: email is sent via neonotu GmbH's own mail server or the service named in this list.
Not Sub-processors:
- Mollie B.V., Amsterdam, Netherlands: processes payment data for billing as an independent controller, not on behalf of Customer.
- Public certificate transparency sources (crt.sh, Cert Spotter): only domain names are queried to discover subdomains. In this context they are not personal data; no other data is transmitted.