Legal
Data Processing Agreement - CentralCSP
Last updated: August 9, 2026Effective: September 13, 2026
This Data Processing Agreement ("DPA") is entered into by and between the Customer (as defined in the Principal Agreement) ("Customer" or "Controller") and CentralSaaS, a société par actions simplifiée incorporated under the laws of France, registered office at 1 Allée des Frênes, 38240 Meylan, France, registered with the Registre du Commerce et des Sociétés of Grenoble under number 927 890 756, operating the CentralCSP service ("CentralCSP" or "Processor") (each a "Party" and together the "Parties") and is incorporated into and forms an integral part of the Principal Agreement.
This DPA will become effective on the date the Customer electronically accepts or executes the Principal Agreement.
WHEREAS
(A) The Customer, acting as a Data Controller, has entered into an agreement for the provision of Services by the Processor (the "Principal Agreement").
(B) The provision of the Services by the Processor to the Customer involves the processing of personal data on behalf of the Customer.
(C) This DPA is intended to ensure the processing of personal data by the Processor is conducted in compliance with the requirements of applicable Data Protection Laws, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation or "GDPR").
(D) The Parties wish to lay down their respective rights and obligations concerning the processing of personal data under the Principal Agreement.
1. Definitions and Interpretation
1.1. Unless otherwise defined, capitalized terms and expressions used in this DPA shall have the following meaning:
- 1.1.1. Customer Data means any data, including Personal Data, that the Customer or its End-Users submit to, or that is generated in relation to the Customer's use of, the Services for processing by the Processor on behalf of the Customer.
- 1.1.2. Data Protection Laws means all applicable laws and regulations relating to the processing of personal data and privacy, including but not limited to the GDPR and any national implementing laws, regulations, and secondary legislation.
- 1.1.3. End-User means a natural person (Data Subject) who accesses or uses the Customer's websites, applications, or online services that are monitored or protected by the Services.
- 1.1.4. EEA means the European Economic Area.
- 1.1.5. Principal Agreement means the Terms of Service, Master Services Agreement, or other written or electronic agreement between the Processor and the Customer for the provision of the Services.
- 1.1.6. Services means the provision of web security and compliance services by the Processor, including but not limited to the collection and analysis of all browser Reporting-API report types via a reporting endpoint, event-based alerting, script inventory and vulnerability (CVE) detection, PCI DSS evidence generation, on-demand website security scanning, CSP scanning and evaluation, automated CSP policy building, and the API and MCP integrations, as more fully described in the Principal Agreement and in Annex 1.
- 1.1.7. Standard Contractual Clauses or SCCs means the standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as adopted by the European Commission.
- 1.1.8. Sub-processor means any third-party processor engaged by the Processor to process Customer Data.
- 1.1.9. Customer-Directed Destination means any product, service, endpoint, or recipient outside the Processor's infrastructure to which the Customer configures the Services to transmit Customer Data, including alert delivery channels (for example Slack, Microsoft Teams, PagerDuty, an email address, or a webhook endpoint) and any AI assistant or agent connected through the API or the MCP integration.
- 1.2. The terms Controller, Data Subject, Personal Data, Personal Data Breach, Processing, and Supervisory Authority shall have the same meaning as in the GDPR, and their cognate terms shall be construed accordingly.
- 1.3. In the event of any conflict or inconsistency between this DPA and the Principal Agreement, the terms of this DPA shall prevail with regard to the processing of Personal Data. In the event of any conflict between this DPA and an Order Form executed by both Parties, the Order Form prevails, except that no Order Form may reduce the Processor's obligations below what Data Protection Laws require.
2. Roles and Responsibilities; Processing of Personal Data
2.1. Roles of the Parties
The Parties acknowledge and agree that for the purposes of the Data Protection Laws, the Customer is the Controller and the Processor is the Processor of the Customer Data. Each Party will be responsible for its own compliance with its obligations under Data Protection Laws.
This DPA governs only the Customer Data that the Processor processes on the Customer's behalf as a processor. The Processor acts as an independent controller for the personal data it processes for its own purposes, in particular account registration and billing, which is governed by the Processor's Privacy Policy rather than this DPA.
2.2. Processor's Obligations
The Processor shall process Customer Data only on behalf of the Customer and in accordance with the Customer's documented instructions. The Customer's initial instruction to the Processor for the processing of Customer Data is the Customer's execution of the Principal Agreement and its use of the Services. The subject matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects for the processing are set forth in Annex 1 (Details of the Processing) to this DPA. The Processor shall not process Customer Data for any other purpose unless required to do so by applicable law to which the Processor is subject. In such a case, the Processor shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
2.3. Customer's Obligations
The Customer represents and warrants that it has established and will maintain a valid legal basis for the processing of Customer Data as contemplated by the Principal Agreement and this DPA. The Customer is solely responsible for the accuracy, quality, and legality of the Customer Data and the means by which it acquired the Customer Data. The Customer's instructions to the Processor for the processing of Customer Data shall comply with all Data Protection Laws.
2.4. Infringing Instructions
The Processor shall immediately inform the Customer if, in its opinion, an instruction from the Customer infringes Data Protection Laws. The Processor may suspend performance of the affected instruction until the Customer confirms, modifies, or withdraws it.
2.5. Aggregated and Anonymised Data; Artificial Intelligence
The Processor operates a scanner that analyses publicly accessible websites at the Customer's request. The Processor may compile aggregated and anonymised statistics derived from scans of publicly accessible websites, for example for its periodic "State of the Web" research report. Such aggregated and anonymised data does not identify, and cannot reasonably be used to identify, any individual, and does not constitute Customer Data or Personal Data. The Processor does not use the personal data contained in the Customer's browser reports for this purpose.
The Processor does not use Customer Data to train, fine-tune, or develop artificial intelligence or machine-learning models.
This commitment concerns the Processor's own processing. Where the Customer connects the Services to a Customer-Directed Destination, including an AI assistant or agent connected through the API or the MCP integration, the Customer initiates and directs that transmission in its capacity as Controller. Such a transmission is not a disclosure or a sub-processing by the Processor, is outside the scope of this DPA once the data leaves the Processor's systems, and the Customer is solely responsible for it, including for establishing a legal basis, for the recipient's processing (such as whether the data is used for model training), and for any transfer outside the EEA that results.
3. Security and Confidentiality
3.1. Security Measures
Taking into account the state of the art, the costs of implementation and the nature, scope, context, and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These measures are designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data. The specific technical and organizational measures implemented by the Processor are described in Annex 2 (Technical and Organizational Security Measures).
The Processor may update the measures described in Annex 2 to reflect technological developments and evolving threats, provided that no update materially reduces the overall level of security of the Customer Data.
3.2. Confidentiality
The Processor shall ensure that any personnel authorized to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access to Customer Data shall be strictly limited to those individuals who need such access to perform their duties in connection with the Services.
4. Sub-processing
4.1. General Authorization
The Customer provides a general written authorization to the Processor to engage Sub-processors to process Customer Data on the Customer's behalf, provided that the Processor complies with the requirements of this Section 4.
4.2. List of Sub-processors
The Processor shall maintain a list of its current Sub-processors, as set out in Annex 3 (Authorized Sub-processors), and shall make this list available to the Customer. This list shall include the identities of the Sub-processors, their location, and the purpose of the sub-processing activities.
A Customer-Directed Destination is not a Sub-processor of the Processor. Where the Customer routes Customer Data to such a destination, the Customer engages that recipient directly and is responsible for the corresponding contractual arrangements.
4.3. Notification of New Sub-processors
The Processor shall inform the Customer of any intended changes concerning the addition or replacement of Sub-processors. The Processor will provide such notification by a reasonable mechanism (for example by email or through the service portal) at least thirty (30) days in advance of the new Sub-processor beginning to process Customer Data.
4.4. Right to Object
The Customer may object to the appointment of a new Sub-processor within fourteen (14) days of receiving the notification from the Processor, provided such objection is based on reasonable grounds relating to data protection. If the Customer objects, the Parties will work together in good faith to find a commercially reasonable solution.
If no such solution is found within thirty (30) days of the objection, the Customer may terminate the affected Services by written notice, and the Processor shall refund, on a pro-rata basis, any prepaid fees covering the period after the effective date of that termination. Termination under this Section is without penalty for the Customer.
4.5. Sub-processor Obligations and Liability
In accordance with Article 28(4) of the GDPR, the Processor shall impose on each Sub-processor, by way of a written contract, data protection obligations that are the same in substance as those set out in this DPA, in particular the obligation to provide sufficient guarantees to implement appropriate technical and organizational measures so that the processing meets the requirements of the GDPR. Where a Sub-processor fails to fulfil its data protection obligations, the Processor remains fully liable to the Customer for the performance of that Sub-processor's obligations.
5. Data Subject Rights
Taking into account the nature of the Processing, the Processor shall assist the Customer by implementing appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Customer's obligation to respond to requests for exercising the Data Subject's rights laid down in Chapter III of the GDPR. The Processor shall promptly notify the Customer if it receives a request from a Data Subject. The Processor shall not respond to any such request itself, except on the documented instructions of the Customer or as required by applicable law. Given the nature of the Services, where Customer Data primarily consists of technical violation reports, the Processor may not be able to directly identify an End-User from the data it processes. The responsibility to verify and respond to the Data Subject therefore remains with the Customer, with the Processor providing necessary assistance.
6. Personal Data Breach
The Processor shall notify the Customer without undue delay and in any event within seventy-two (72) hours after becoming aware of a Personal Data Breach affecting Customer Data. The Processor shall provide the Customer with sufficient information to allow the Customer to meet its obligations to report the breach to the Supervisory Authority and/or inform Data Subjects. Such notification shall, at a minimum:
- (a) describe the nature of the Personal Data Breach, including, where possible, the categories and approximate number of Data Subjects and Personal Data records concerned.
- (b) communicate the name and contact details of the data protection contact or other contact point where more information can be obtained (see Section 11.5).
- (c) describe the likely consequences of the Personal Data Breach.
- (d) describe the measures taken or proposed to be taken by the Processor to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.
The Processor shall cooperate with the Customer and take such reasonable commercial steps as are directed by the Customer to assist in the investigation, mitigation, and remediation of each such Personal Data Breach.
7. Data Protection Impact Assessment and Prior Consultation
The Processor shall provide reasonable assistance to the Customer with any data protection impact assessments and prior consultations with Supervisory Authorities which the Customer reasonably considers to be required under Articles 35 and 36 of the GDPR or equivalent provisions of any other Data Protection Law. Such assistance shall be provided solely in relation to the processing of Customer Data by the Processor and taking into account the nature of the processing and the information available to the Processor.
8. Retention, Return and Deletion of Data
During the term of the Principal Agreement, browser reports are retained for a rolling period of ninety (90) days, after which they are deleted or irreversibly aggregated into anonymised statistics. Deleting a website or workspace in the dashboard deletes the browser reports associated with it. Scan results are designed to describe the publicly accessible configuration of a website; they are retained indefinitely or aggregated into statistics, and where a scan result incidentally contains personal data (for example an identifier embedded in a URL), the Processor deletes or redacts it on the Customer's request. Free-tool submissions are not retained as individual records; they are aggregated into anonymised statistics. Anonymised statistics derived from browser reports and free-tool submissions contain no personal data and are retained indefinitely.
Upon termination of the Principal Agreement, the Customer has a period of thirty (30) days during which it may export Customer Data through the Services or request its return in a structured, commonly used, machine-readable format, as provided in the Principal Agreement. The Processor shall then, at the choice of the Customer, delete or return all Customer Data, and shall delete all existing copies within ninety (90) days of the termination date, unless applicable law requires continued storage. Scan results are excepted from this deletion obligation and are retained as described above, subject to the same deletion or redaction of incidental personal data on request. Backup copies are deleted on the expiry of the ordinary backup rotation cycle, which does not exceed ninety (90) days. Where the Customer makes no choice within the export window, the Processor will delete the Customer Data.
9. Audit Rights
The Processor shall make available to the Customer, upon request, all information necessary to demonstrate compliance with its obligations under this DPA. In the first instance, the Processor may provide the Customer with copies of relevant third-party audit reports and certifications (e.g., PCI DSS SAQ A). This approach is standard for multi-tenant cloud environments, as it provides robust assurance of compliance without exposing the Processor's infrastructure or the data of other customers to the risks associated with direct, on-site audits by every customer.
Where the information and reports so provided are not reasonably sufficient to demonstrate compliance with this DPA, or where an audit is required by a Supervisory Authority or by mandatory Data Protection Law, the Processor shall, in accordance with Article 28(3)(h) of the GDPR, allow for and contribute to an audit, including an inspection, conducted by the Customer or an independent auditor mandated by the Customer (which may not be a competitor of the Processor), subject to the following conditions: (a) no more than one audit in any twelve (12) month period, except following a Personal Data Breach affecting Customer Data or where required by a Supervisory Authority; (b) at least thirty (30) days' prior written notice; (c) the execution of a confidentiality agreement covering the audit; (d) the audit being conducted during normal business hours, with minimal disruption to the Processor's operations; (e) no access being given to the data of other customers or to systems not relevant to the processing of Customer Data; and (f) each party bearing its own costs, the Customer reimbursing the Processor's reasonable costs of contribution for any audit exceeding one (1) business day.
9.1. Payment card data
The Processor does not collect, process, or store cardholder data, including primary account numbers (PAN); all payment card processing is performed by Stripe. The Processor maintains PCI DSS SAQ A compliance, which is a self-assessment concerning that outsourcing of cardholder data handling and does not evidence the security of the browser telemetry processed under this DPA. Compliance with this DPA is evidenced by the measures in Annex 2 and the audit rights in this Section.
10. International Transfers
The Processor hosts and processes all Customer Data within the European Union / EEA, and in the ordinary course of providing the Services it does not transfer Customer Data to any country outside the EEA.
Where a Sub-processor engaged by the Processor may make an onward transfer of limited data outside the EEA (for example, a payment processor transferring billing data to an affiliated entity in the United States), such transfers are governed by that Sub-processor's own appropriate safeguards under Chapter V of the GDPR, namely the Standard Contractual Clauses and/or certification under the EU-US Data Privacy Framework. Should the Processor itself transfer Customer Data outside the EEA in the future, it shall do so only subject to an appropriate transfer mechanism, the Standard Contractual Clauses, which shall be deemed incorporated into this DPA by reference, and, where required, a documented transfer impact assessment.
The Processor's data residency commitment covers the data it holds on its own infrastructure and that of its Sub-processors. It does not cover Customer-Directed Destinations. Where the Customer configures the Services to transmit Customer Data outside the EEA (for example by routing alerts to a channel hosted in a third country, or by connecting an AI assistant through the API or the MCP integration), that transfer is made on the Customer's instruction and in its capacity as Controller. The Customer is solely responsible for identifying and putting in place the appropriate Chapter V transfer mechanism for it, and for carrying out any required transfer impact assessment.
11. General Provisions
- 11.1. Liability. Each Party's liability arising out of or related to this DPA shall be subject to the limitations of liability set forth in the Principal Agreement.
- 11.2. Confidentiality. The Parties agree that this DPA and any information exchanged in connection with it are confidential and shall be handled in accordance with the confidentiality provisions of the Principal Agreement.
- 11.3. Notices. All notices and communications given under this DPA must be in writing and will be delivered in accordance with the notice provisions of the Principal Agreement.
- 11.4. Severability. If any provision of this DPA is found by any court or administrative body of competent jurisdiction to be invalid, unenforceable, or illegal, that provision shall be modified to the minimum extent necessary to make it valid and enforceable, or, failing that, severed, and the other provisions shall remain in force.
- 11.5. Data Protection Contact. Questions, requests, or notices relating to data protection or this DPA may be addressed to the Processor's data protection contact at contact@centralcsp.com.
- 11.6. No waiver. No failure or delay by either Party in exercising any right under this DPA operates as a waiver of it, and a waiver is effective only if given in writing.
- 11.7. Language. This DPA is drafted in English, which is the authoritative and legally binding version. Any translation is provided for convenience only, and in the event of any conflict or divergence between the English version and a translated version, the English version prevails.
12. Governing Law and Jurisdiction
- 12.1. This DPA and any dispute or claim arising out of or in connection with it or its subject matter or formation shall be governed by and construed in accordance with the laws of France.
- 12.2. The Parties irrevocably agree that the Tribunal de commerce de Grenoble (France) shall have exclusive jurisdiction to settle any dispute or claim that arises out of or in connection with this DPA, in accordance with the dispute resolution provisions of the Principal Agreement.
Annex 1: Details of the Processing
This Annex forms part of the DPA and describes the processing of Personal Data performed by the Processor on behalf of the Controller, as required by Article 28(3) of the GDPR.
| Specification | Details |
|---|---|
| Subject-matter of the Processing | The processing of browser-generated security telemetry, reports delivered through the browser Reporting API (including Content Security Policy (CSP), Network Error Logging (NEL), deprecation, intervention, crash, COOP/COEP, Document-Policy, Certificate Transparency, and integrity reports), together with website security scan data and script inventory data generated by, or in relation to, the Customer's websites, applications, and online services. |
| Duration of the Processing | For the term of the Principal Agreement between the Customer and the Processor, and until all Customer Data is deleted in accordance with Section 8 of the DPA. |
| Nature and Purpose of the Processing | To provide web security and compliance services to the Customer, including:
|
| Type of Personal Data Processed | The Services are designed to process technical security telemetry rather than personal data, and the personal data processed is limited and largely incidental. It is contained within the browser reports and scan data, and may include:
|
| Categories of Data Subjects | The Personal Data processed relates to End-Users of the Customer's websites, applications, and online services. |
Annex 2: Technical and Organizational Security Measures
This Annex describes the technical and organizational security measures implemented by the Processor to protect Customer Data.
1. Access Control
- Personnel Access: Access to systems processing Customer Data is granted on a need-to-know basis according to the principle of least privilege. Access rights are reviewed periodically and revoked upon termination of employment or change in job function.
- Authentication: All personnel access to production environments requires multi-factor authentication (MFA).
- Logging: Access to production systems is logged and monitored for unauthorized activity.
2. Encryption
- In Transit: All Customer Data transmitted over public networks (e.g., from an End-User's browser to the reporting endpoint, or between the Processor's internal services) is encrypted using strong, industry-standard protocols (e.g., TLS 1.2 or higher).
- At Rest: All Customer Data stored on the Processor's systems, including backups, is encrypted at rest using AES-256.
3. System Security and Resilience
- Vulnerability Management: The Processor conducts regular vulnerability scans of its systems and applications. Critical security patches are applied in a timely manner.
- Network Security: The Processor employs firewalls, network segmentation, and other measures to protect its network from unauthorized access.
- Availability and Resilience: The Processor utilizes redundant, fault-tolerant infrastructure hosted with leading cloud providers to ensure the ongoing availability and resilience of the Services. Regular backups of Customer Data are performed to enable timely restoration in the event of a physical or technical incident.
4. Incident Response and Management
- Incident Response: The Processor detects, contains, investigates, and remediates security incidents.
- Breach Notification: The Processor has established procedures to ensure timely and effective notification to Customers in the event of a Personal Data Breach, in accordance with Section 6 of the DPA.
5. Personnel Security
- Training: All personnel undergo regular security and data privacy awareness training.
- Confidentiality: All personnel are subject to binding confidentiality obligations as a condition of their employment.
6. Data Deletion
- Secure Disposal: The Processor utilizes secure data disposal methods to ensure that Customer Data is permanently and irretrievably deleted from its systems upon the expiration of the retention period defined in Section 8 of the DPA.
7. Physical Security
- Data Centers: The Processor utilizes data centers provided by major cloud infrastructure providers that maintain high standards of physical security. These data centers are protected by measures including 24/7 security personnel, video surveillance, and strict physical access controls.
- Certifications: The Processor's infrastructure provider, OVHcloud, holds third-party certifications including SOC 2 and ISO 27001 covering the data centers and infrastructure services it supplies. These are the provider's certifications, attesting to the controls of the underlying infrastructure. CentralCSP does not itself currently hold SOC 2 or ISO 27001 certification. CentralCSP's own controls are those described in this Annex and are subject to the audit rights in Section 9 of the DPA.
8. Data Residency and Minimisation
- Data Residency: All Customer Data is stored and backed up exclusively within the European Union (OVHcloud, France). Website scans requested by the Customer are performed from within the European Union (France). This commitment covers the Processor's own infrastructure and that of its Sub-processors. It does not cover Customer-Directed Destinations: where the Customer configures the Services to send data to a recipient it selects, the location of that recipient is determined by the Customer, and Section 10 of the DPA applies.
- Data Minimisation: The Services are designed to process technical security telemetry; the Processor does not deliberately collect End-User identifiers beyond what is incidentally contained in browser reports and scan data.
Annex 3: Authorized Sub-processors
This Annex lists the Sub-processors authorized by the Customer to process Customer Data.
As of the Effective Date of this DPA, the Processor engages the following Sub-processors:
| Sub-Processor | Purpose | Types of Data Processed | Location |
|---|---|---|---|
| OVHcloud | Cloud hosting and infrastructure provider for all core platform services and data. | All Customer Data, account data, service configuration, backups. | France (EU) |
| Bunny.net | Content delivery network (CDN) and edge layer, including in front of the reporting endpoint, and delivery of static assets. | IP address, browser/device information, requested URLs, and browser reports in transit through the reporting endpoint edge. | European Union |
| Scaleway | Transactional and notification email delivery. | Name, email address, email content, engagement data. | France (EU) |
The Processor stores all Customer Data within the European Union. Bunny.net processing is restricted to European points of presence. Payment processing (Stripe) is not listed in this Annex: billing is processing that the Processor carries out for its own purposes as an independent controller (see Section 2.1), governed by the Processor's Privacy Policy, and Stripe is therefore not a Sub-processor of Customer Data under this DPA. Bot and abuse protection on public forms is provided by a CAPTCHA that the Processor self-hosts on its own EU infrastructure; it is therefore not a Sub-processor and no CAPTCHA data is shared with any third party.
Destinations the Customer configures itself (alert delivery channels and AI assistants or agents connected through the API or the MCP integration) are not listed here. They are Customer-Directed Destinations engaged by the Customer, not Sub-processors of the Processor, and Sections 2.5, 4.2, and 10 of this DPA apply to them.