Legal
Controller–processor terms for Customer Personal Data processed when you use AtRisk. Accepted with our Terms of Service unless a separately signed DPA controls.
Last updated: September 9, 2026 · Effective: September 9, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between AtRisk ("Processor") and the customer entity that subscribes to the Services ("Controller") under our Terms of Service (the "Agreement"). It applies where, and to the extent that, AtRisk processes Personal Data on behalf of the Controller in the course of providing the Services. Capitalized terms not defined here have the meaning given in the EU GDPR, UK GDPR, or analogous law, as applicable.
By accepting the Agreement, the Controller accepts this DPA. Where a separately negotiated data-processing agreement has been signed, that agreement controls in the event of conflict.
For Personal Data about website visitors and account holders that AtRisk decides how to process (for example marketing-site leads we control), AtRisk acts as an independent controller as described in the Privacy Policy. This DPA covers Customer Personal Data processed on the Controller's documented instructions.
The duration of processing is the term of the Agreement plus any post-termination period required to return or delete Customer Personal Data. The nature of processing is operation of an automated security-assurance service (URL scanning, monitors, repository analysis, Findings, fix prompts, MCP/CI features, and related workflows). The purpose is to deliver the functionalities the Controller configures.
Depending on the Controller's use, data subjects may include:
Categories of Personal Data may include:
The Services are not intended to process special-category data under Art. 9 GDPR. The Controller agrees not to deliberately submit such data without prior written agreement and additional safeguards.
AtRisk ensures that persons authorized to process Customer Personal Data are bound by confidentiality obligations and process the data only on the Controller's instructions and as required by law.
AtRisk implements and maintains appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, including: TLS in transit; access controls and least-privilege practices; managed auth and database hosting; secrets in platform secret stores; rate limiting and SSRF protections on scan endpoints; logging and monitoring; vendor risk awareness; and secure development practices. A plain-language summary is on our Trust Center. Additional detail is available on reasonable request to contact@atrisk.dev.
The Controller authorizes AtRisk to engage the subprocessors listed at /subprocessors and to add or replace subprocessors as needed, subject to reasonable prior notice (generally at least thirty (30) days for material additions, unless urgent for security or legal reasons). AtRisk will impose data-protection obligations on each subprocessor consistent with this DPA and remains liable to the Controller for subprocessors' acts and omissions within the scope of this DPA.
The Controller may object in writing, on reasonable data-protection grounds, to a new subprocessor within fifteen (15) days of notice. If the parties cannot resolve the objection, the Controller may terminate the affected portion of the Services for convenience.
Where processing involves a transfer of Customer Personal Data to a country outside the EEA, UK, or Switzerland that lacks an adequacy decision, the parties enter into the European Commission's Standard Contractual Clauses (Module 2: Controller-to-Processor) and, where applicable, the UK International Data Transfer Addendum, each incorporated by reference into this DPA and completed with the information in the Annexes below. Where a recipient is certified under the EU-U.S. Data Privacy Framework (or UK/Swiss extensions), reliance on the framework may apply in addition to or instead of the SCCs.
Taking into account the nature of the processing, AtRisk will assist the Controller, by appropriate technical and organizational measures, in fulfilling obligations to respond to data-subject requests under Chapter III GDPR (or analogous law). Where legally permissible, AtRisk will promptly notify the Controller of any data-subject request it receives directly that relates to the Controller's data and will not respond except on the Controller's documented instructions or as required by law.
AtRisk will notify the Controller without undue delay (and in any event within seventy-two (72) hours where feasible) after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will include information reasonably available to allow the Controller to meet Arts. 33 and 34 GDPR (or analogous) obligations.
Where required by Art. 35 or 36 GDPR (or analogous law), AtRisk will provide reasonable assistance to the Controller for Data Protection Impact Assessments and prior consultations with supervisory authorities, taking into account the nature of processing and information available to AtRisk.
On termination or expiry of the Agreement, AtRisk will, at the Controller's choice and within a reasonable period (generally not more than thirty (30) days), delete or return Customer Personal Data and delete existing copies, except where retention is required by law, audit, dispute, or security purposes. Backups are overwritten in the ordinary course of operations.
AtRisk will make available to the Controller, on reasonable written request and no more than once per year (or more frequently after a documented Personal Data Breach involving the Controller's data, or where required by a supervisory authority), information reasonably necessary to demonstrate compliance with this DPA, including summary security and privacy program information. If an on-site audit is required by mandatory law, the parties will agree scope, timing, and conduct in advance; the audit will be by an independent auditor bound by confidentiality, will not unreasonably interfere with operations, and will be at the Controller's expense unless material non-compliance is found.
Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement. Liability under this DPA does not increase the aggregate cap in the Agreement.
On data-protection matters, this DPA controls over the Agreement. If this DPA conflicts with SCCs incorporated by reference, the SCCs control. This DPA is governed by the law set out in the Agreement except where mandatory data-protection law requires otherwise.
Controller: the customer entity that subscribes to the Services. Processor: AtRisk (operator of atrisk.dev / app.atrisk.dev).
Categories of data subjects and Personal Data, sensitive data (if any), frequency, nature, purpose, and retention are as set out in Sections 2–3 of this DPA and the Privacy Policy. Transfers occur on a continuous basis for the duration of the Agreement. Onward transfers to subprocessors are made on the same basis.
Where the Controller has a Lead Supervisory Authority under the GDPR, that authority; otherwise as determined under applicable law. Controllers may also contact their local authority (for example the UK ICO for UK GDPR matters).
The measures in Section 5 and the Trust Center constitute Annex II to the SCCs. Additional detail is available on request to contact@atrisk.dev.
The list at /subprocessors constitutes Annex III to the SCCs.