COMPLIANCE LAYER
  • Domain MonitoringCompliance ReportsExternal Risk API
  • MSP & MSSPCompliance TeamsCyber InsuranceCompliance FrameworksInsurance Audit Mapping
  • Pricing
  • Documentation
  • Integrations
  • Tools
  • Blog
Free Scan →Verify ReportSign inSign up

Legal

Data Processing Addendum

Last updated: August 4, 2026

This Data Processing Addendum ("DPA") forms part of the ComplianceLayer Terms of Service between ComplianceLayer, Inc. ("ComplianceLayer," the "Processor") and the customer identified in the applicable account ("Customer," the "Controller"). It applies whenever ComplianceLayer processes Personal Data on Customer's behalf in the course of providing the service, and automatically binds both parties without further signature. A countersigned copy is available on request from privacy@compliancelayer.net.

1. Definitions

"Data Protection Laws" means all laws applicable to the processing of Personal Data under this DPA, including the EU/UK General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act as amended ("CCPA"). "Personal Data," "processing," "controller," "processor," "data subject," and "personal data breach" have the meanings given in the applicable Data Protection Laws. "Customer Personal Data" means Personal Data that Customer submits to the service or that the service collects on Customer's behalf, as described in Annex A.

2. Roles and Scope

Customer is the controller (or a processor acting on behalf of another controller) of Customer Personal Data; ComplianceLayer is Customer's processor (or subprocessor). ComplianceLayer acts as an independent controller for Customer's own account, billing, and website usage data, which is governed by the Privacy Policy rather than this DPA. The subject matter, nature, purpose, and duration of processing, and the categories of data subjects and Personal Data, are set out in Annex A.

3. Processing Instructions

ComplianceLayer processes Customer Personal Data only on Customer's documented instructions — the Terms of Service, this DPA, and Customer's use of the service's features constitute those instructions — unless required to do otherwise by law, in which case ComplianceLayer will inform Customer of that legal requirement before processing unless the law prohibits doing so. ComplianceLayer will inform Customer if, in its opinion, an instruction infringes Data Protection Laws.

4. Confidentiality

ComplianceLayer ensures that persons authorized to process Customer Personal Data are bound by confidentiality obligations, whether contractual or statutory.

5. Security

Taking into account the state of the art and the risks presented by the processing, ComplianceLayer implements appropriate technical and organizational measures to protect Customer Personal Data, including: encryption in transit (TLS 1.2+), encryption at rest, hashing and encryption of API credentials, role-based access controls, network isolation of production infrastructure, and logging and monitoring of production systems. ComplianceLayer will not materially decrease the overall security of the service during a subscription term.

6. Subprocessors

Customer grants ComplianceLayer general authorization to engage the subprocessors listed in Annex B. ComplianceLayer will provide at least 30 days' notice of any intended addition or replacement of a subprocessor (via email to the account owner or a notice on this page), during which Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection, Customer may terminate the affected subscription and receive a pro-rated refund of prepaid fees. ComplianceLayer imposes data-protection obligations on each subprocessor no less protective than those in this DPA and remains liable for its subprocessors' performance.

7. Assistance

Taking into account the nature of the processing, ComplianceLayer will assist Customer, by appropriate technical and organizational measures and insofar as reasonably possible, in fulfilling Customer's obligations to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection) and, taking into account the information available to it, in Customer's obligations regarding security, breach notification, and data-protection impact assessments. If a data subject contacts ComplianceLayer directly about Customer Personal Data, ComplianceLayer will redirect the request to Customer without responding substantively, unless legally required.

8. Personal Data Breach

ComplianceLayer will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and in any event within 72 hours of awareness, providing the information reasonably available to it about the nature of the breach, the categories and approximate numbers of data subjects and records affected, the likely consequences, and the measures taken or proposed.

9. Deletion and Return

Upon termination of the service, ComplianceLayer will, at Customer's choice, delete or return all Customer Personal Data, and delete existing copies, unless retention is required by law (e.g., billing records). Customer may export scan history from the dashboard at any time before termination; deletion requests are processed as described in the Privacy Policy.

10. Audits

ComplianceLayer will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including responses to reasonable written security questionnaires (no more than once per 12-month period). Where Data Protection Laws grant Customer a mandatory audit right that cannot be satisfied by documentation, Customer may conduct an audit no more than once per 12-month period, on at least 30 days' notice, during business hours, without disrupting the service, at Customer's expense, and subject to reasonable confidentiality obligations.

11. International Transfers

ComplianceLayer processes Customer Personal Data in the United States. Where Customer Personal Data originating in the EEA, UK, or Switzerland is transferred to ComplianceLayer, the parties incorporate by reference the European Commission's Standard Contractual Clauses (Decision 2021/914, Module Two: controller to processor, with the UK Addendum where applicable), with Customer as data exporter and ComplianceLayer as data importer; Annex A of this DPA serves as Annex I of the Clauses and Section 5 as Annex II. In the event of a conflict, the Standard Contractual Clauses prevail over this DPA.

12. CCPA

To the extent the CCPA applies, ComplianceLayer acts as Customer's "service provider," processes Customer Personal Data only for the business purposes described in Annex A, and will not sell or share Customer Personal Data, retain, use, or disclose it outside the direct business relationship with Customer, or combine it with personal information from other sources except as permitted by the CCPA. ComplianceLayer certifies that it understands these restrictions.

13. Liability and Precedence

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service, except where Data Protection Laws do not permit such limitation. In case of conflict between this DPA and the Terms of Service regarding the processing of Personal Data, this DPA prevails.

Annex A — Details of Processing

  • Subject matter and nature: Hosting, storage, and display of data Customer submits to the external security scanning service, and delivery of scan results, reports, and notifications.
  • Purpose: Providing external security assessments, monitoring, alerting, reporting, and related account features.
  • Duration: The subscription term, plus the deletion/return period in Section 9.
  • Categories of data subjects: Customer's personnel and end clients whose contact details Customer stores in the service (e.g., client portfolio records, alert recipients, webhook and integration recipients).
  • Categories of Personal Data: Names, business email addresses, company affiliations, domain names, and notification/delivery metadata. The service is not intended for special categories of data, and Customer agrees not to submit them.

Annex B — Authorized Subprocessors

All subprocessors below are located in the United States. We notify account owners at least 30 days before adding or replacing one, as described in Section 6.

Infrastructure and platform

  • Vultr (The Constant Company, LLC) — cloud infrastructure hosting; all Customer Personal Data at rest
  • Cloudflare, Inc. — DNS, CDN and TLS termination; all inbound traffic, including request metadata and IP addresses
  • Stripe, Inc. — payment processing; billing identity and payment metadata
  • MXRoute — transactional email delivery; recipient addresses and message content
  • Functional Software, Inc. (Sentry) — application error monitoring; diagnostic data (configured to exclude personal data by default)
  • Google LLC (Google Analytics) — website usage measurement on our marketing pages only, and only for visitors who accept analytics cookies. Not used inside the authenticated application.

Scan data sources

These receive the domain name or server IP address being assessedin order to return public information about it. They do not receive account credentials, contact records, or billing data.

  • Shodan (InternetDB) — exposed-service data for the assessed host
  • ip-api.com — geolocation and network operator for the assessed host
  • Have I Been Pwned — public breach catalogue lookup by domain
  • crt.sh (Sectigo) and HackerTarget — Certificate Transparency and passive DNS lookups for subdomain discovery
  • Google Safe Browsing and VirusTotal (Google LLC) — domain reputation lookups

Optional integrations — enabled only if Customer connects them

  • Slack Technologies, LLC — scan notifications to a workspace the Customer authorizes
  • Microsoft Corporation — scan notifications to Microsoft Teams
  • Zapier, Inc. — scan events to a Customer-configured Zap
  • RapidAPI (Rakuten) — applies only where Customer accesses the API through the RapidAPI marketplace

Contact

Questions about this DPA, objections to subprocessor changes, or requests for a countersigned copy: privacy@compliancelayer.net

Product
ToolsFree scanVerify ReportIntegrationsDocumentationRapidAPI
Solutions
MSP & MSSPCompliance TeamsCyber InsuranceInsurance Audit MappingCompliance Frameworks
Company
AboutPartnersCompareChangelogContact
Resources
StatusSecurity practicesReport a vulnerability
Legal
PrivacyTermsAUPRefundsDPAAbout our scanningRescans & disputes
© 2026 ComplianceLayer, Inc. All rights reserved. ·
System status