// legal · data processing addendum

Data Processing Addendum (DPA)

Template form · effective 2026-05-25 · Article 28 GDPR · language: EN

This is a template. The executed DPA is co-signed by Customer and Kotav and forms part of the Master Services Agreement. To request the current signed copy, or to negotiate customer-specific deviations, email global@kotav.org.

Standard processing fits this template without modification for the vast majority of customers; bespoke changes are accommodated within the spirit of Article 28 GDPR.

1. Parties and definitions

This Addendum is entered into between [Customer Legal Name] ("Controller") and Kotav International — business and assets, Lda. ("Processor"), and forms part of the Master Services Agreement between them (the "MSA"). Terms used herein have the meaning given in Regulation (EU) 2016/679 (the "GDPR").

2. Subject matter, duration, nature and purpose of processing

Processor processes personal data only to provide the Service set out in the MSA and on documented instructions from Controller. Duration of processing equals the term of the MSA plus any post-termination data-export window.

Categories of data subjects: Controller's employees, contractors, end-users, and any third-party data present in scan targets authorised by Controller. Categories of personal data: identifiers (name, work email, IP address), service-usage metadata, and any incidental personal data present in scan evidence.

3. Controller and Processor obligations

Controller warrants that it has obtained all consents and provided all notices required for Processor to process personal data on its behalf, and that scanning targets are within Controller's lawful authority.

Processor shall:

  • process personal data only on Controller's documented instructions;
  • ensure persons authorised to process are bound by confidentiality obligations;
  • implement the technical and organisational measures described in Annex II;
  • assist Controller in fulfilling its obligations to respond to data-subject requests;
  • assist Controller with DPIAs and prior consultations under Articles 35–36;
  • notify Controller without undue delay (and in any event within 72 hours) on becoming aware of a personal-data breach;
  • on termination, at Controller's choice, delete or return all personal data, subject to any legal-retention obligations on Processor.

4. Subprocessors

Controller authorises Processor to engage the subprocessors listed in Annex III. Processor will give Controller 30 days' prior written notice of any addition or replacement, during which Controller may object on reasonable grounds; if Controller objects, the parties shall negotiate in good faith for a workable solution.

Processor shall impose data-protection obligations on each subprocessor that are no less protective than those in this DPA, and remains liable for the acts and omissions of its subprocessors as if they were its own.

5. International transfers

Transfers of personal data outside the EEA are made under the European Commission's Standard Contractual Clauses (Module 1 or Module 2 as appropriate, 2021 version), which are incorporated by reference into this DPA. Supplementary measures include encryption in transit (TLS 1.2+) and at rest (AES-256), pseudonymisation where feasible, and contractual restrictions on government access.

6. Audit

Once per calendar year, on 30 days' written notice and at Controller's expense, Controller may audit Processor's compliance with this DPA, conducted in a manner that does not unreasonably disrupt Processor's operations. Processor's most recent independent attestations (e.g. SOC 2 Type II once available; SOC 2 Type I planned 2026) are accepted in lieu where applicable.

7. Liability and term

Liability under this DPA is governed by the limitations in the MSA. This DPA takes effect on the same date as the MSA and remains in force for as long as Processor processes personal data on Controller's behalf.

Annex I — description of processing

  • Subject matter: provision of the Kotav Labs platform and argus penetration-testing service.
  • Duration: term of the MSA plus 30-day post-termination export window.
  • Nature and purpose: hosting, scanning, finding generation, audit logging, billing, support.
  • Categories of personal data: identifiers, service usage, scan evidence (which may incidentally contain personal data of third parties present in targets authorised by Controller).
  • Categories of data subjects: Controller's authorised users; end-users of Controller's systems present in scan evidence.
  • Special categories: none routinely; any incidental special categories handled as special categories.

Annex II — technical and organisational measures

  • TLS 1.2+ in transit; AES-256 at rest for primary datastore.
  • Role-based access controls, JWT short-lived sessions, mandatory MFA for Kotav staff.
  • Audit logging of all administrative actions; tamper-evident audit log of scan actions (git-versioned).
  • Vulnerability scanning of own infrastructure (dogfood) at least monthly.
  • Incident-response plan with named on-call; 72-hour breach notification commitment.
  • Background checks for personnel with production access; confidentiality agreements for all staff.
  • Hetzner DE (Germany) for infrastructure; physical security and certifications as published by Hetzner.
  • Annual penetration test of the platform by an independent third party (planned, in addition to dogfood).

Annex III — list of subprocessors (as of 2026-05-25)

  • Hetzner Online GmbH (Germany) — infrastructure hosting
  • Anthropic PBC (USA, with EU region options) — LLM inference for argus
  • Stripe Payments Europe Ltd (Ireland) — payment processing
  • Postmark / Resend — transactional email
  • Google Workspace — internal email and document collaboration

Up-to-date list available on request from global@kotav.org. Material additions notified 30 days in advance.

Plano de Recuperação e Resiliência, República Portuguesa e Financiado pela União Europeia — NextGenerationEU