Data Processing Addendum

Effective June 2026

About this addendum

This Data Processing Addendum (DPA) forms part of the agreement between you (the customer) and Uvy, and applies where Uvy processes personal data on your behalf in providing the service. Where it conflicts with the rest of the agreement on data protection, this DPA controls. Each party's liability under this addendum is subject to the limitations and exclusions of liability in the Terms. This addendum remains in effect while Uvy processes personal data on your behalf, and the confidentiality, return-and-deletion, and audit obligations survive termination. Enterprise customers may request a signed copy by contacting [email protected].

Roles

For the personal data in your applications and in the engagement data we process to deliver assessments, you are the controller and Uvy is the processor (under CCPA/CPRA, you are the business and Uvy is a service provider). Uvy processes that data only on your documented instructions, which include this DPA and your use of the product, and does not sell or share it, or retain, use, or disclose it for any purpose other than providing the service. Uvy certifies that it understands and will comply with these restrictions. The parties acknowledge that no monetary or other valuable consideration is exchanged for personal data, and that no ‘sale’ or ‘sharing’ (as defined under applicable US state privacy law) occurs under the agreement.

What we process

Subject matter: delivery of AI-native penetration testing. Duration: the term of your engagement plus the retention described in our privacy policy. Nature and purpose: discovering, proving, and reporting security vulnerabilities in the targets you authorize. Categories of data: the contents of the targets you test and the resulting findings (which may incidentally include personal data present in those systems), plus account and contact details. Data subjects: your users and personnel whose data appears in the tested systems, and your authorized account users.

Subprocessors

You authorize Uvy to engage subprocessors to provide the service. Our current named subprocessors and their locations are published on our security page. Each is bound by data-protection terms no less protective than this DPA. We will give notice of a new subprocessor before it begins processing, and you may object on reasonable data-protection grounds. If you object on reasonable grounds and we cannot accommodate the objection, you may terminate the affected service and receive a pro-rata refund of prepaid fees for the unused term.

Security

Uvy maintains technical and organizational measures appropriate to the risk: each assessment runs in an isolated, single-use environment that is decommissioned and its data deleted after the engagement completes; data is encrypted in transit, and at rest in our managed data stores; access is restricted on a need-to-know basis; and AI inference runs under contractual no-training and zero-data-retention terms. We do not pool your data across customers or use it to train shared models.

Confidentiality and personnel

Personnel authorized to process your data are bound by confidentiality obligations and access data only as needed to provide and support the service.

Assistance and data-subject requests

Taking into account the nature of the processing, Uvy will assist you by appropriate measures in responding to data-subject requests and in meeting your obligations around security, breach notification, and data-protection impact assessments. If a data subject contacts us directly about your data, we will refer them to you.

Breach notification

Uvy will notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information you reasonably need to meet your own notification obligations.

International transfers

Uvy is operated from the United States and our subprocessors process data in the United States. Where personal data is transferred from a region that requires a transfer mechanism, the parties rely on an appropriate safeguard, such as the Standard Contractual Clauses, incorporated by reference where applicable.

Return and deletion

At the end of the engagement, or on your request, Uvy will delete or return the personal data it processes on your behalf, except where retention is required by law (for example, invoicing records). The single-use infrastructure used to run an assessment is decommissioned after the engagement.

Audit

On reasonable request and subject to confidentiality, Uvy will make available the information needed to demonstrate compliance with this DPA, including relevant third-party reports where available, or a response to a reasonable security questionnaire.

Contact

Data-protection questions or requests under this DPA: [email protected].