1.Parties & Roles
This Data Processing Agreement (“DPA”) is entered into between:
- Customer, acting as the Data Controller to the extent it determines the purposes and means of processing of the personal data submitted to the services, under applicable law (LGPD, GDPR, CCPA).
- WASViking LLC, acting as the Data Processor (Processor or Operador) to the extent it processes personal data on the Customer’s behalf and under its documented instructions.
Where the Customer uses the services on behalf of its own clients, for example as a managed security service provider, the Customer’s client is the controller of that client’s data, the Customer acts as a processor (operador) on behalf of its client to the extent it processes that data through the services, and WASViking acts as a subprocessor (suboperador) engaged by the Customer. In that case, the Customer warrants that it has the authority and instructions from its client needed to engage WASViking under this DPA, and references to “Controller” apply to the party that holds that role for the data concerned. A partner or provider may also act as an independent controller of the personal data it processes for its own purposes, such as billing, support, and its commercial relationship with its clients; this DPA does not govern that independent processing.
2. Definitions
- Controller, Processor, Personal Data, Processing per LGPD/GDPR/CCPA.
- Subprocessor: third party authorized by WASViking to process data (e.g., AWS, Cloudflare, MongoDB).
- Applicable Data Protection Law includes LGPD, GDPR, CCPA, and relevant privacy laws.
3. Scope & Purpose
WASViking will process Personal Data only to provide the services as described in the Terms of Service and Privacy Policy, including technical analysis of systems, domains, headers, certificates, and related assets.
4. Processor Obligations
WASViking commits to:
- Process data only on Controller’s instructions.
- Implement technical & organizational measures (see section 8).
- Maintain confidentiality of data and authorize only trained personnel.
- Assist the Controller with data subject requests (access, deletion, portability).
- Notify of data breaches without undue delay.
- Provide audit documents, logs, or evidence upon request.
5. Subprocessors
- WASViking may appoint subprocessors (e.g., AWS, Cloudflare, MongoDB, OpenAI).
- Must sign a written agreement ensuring at least equivalent data protection.
- Customer is notified 30 days before any new subprocessor is added and may object within 10 days on reasonable grounds.
WASViking maintains an up-to-date list of subprocessors, available at the WASViking Trust Center Subprocessors page or upon request.
6. International Data Transfers
WASViking LLC is based in the United States and may process Personal Data in the United States and in other locations in which WASViking or its authorized subprocessors operate.
6.1 European Economic Area
Where Personal Data subject to the GDPR is transferred from the European Economic Area to a country that does not benefit from an applicable adequacy decision, WASViking will rely on an applicable transfer mechanism recognized under European data protection law, which may include the European Commission Standard Contractual Clauses or another lawful mechanism.
Where applicable, participation by an eligible recipient in the EU-U.S. Data Privacy Framework may also constitute the applicable transfer mechanism.
6.2 Brazil
Where Personal Data subject to the Brazilian General Data Protection Law (LGPD) is transferred internationally, WASViking will conduct the transfer in accordance with Article 33 of Law No. 13,709/2018 and the applicable regulations issued by the Brazilian National Data Protection Authority (ANPD), including Resolution CD/ANPD No. 19/2024.
Where the Standard Contractual Clauses issued by the ANPD are used as the applicable transfer mechanism, those clauses must be incorporated in accordance with the requirements of Resolution CD/ANPD No. 19/2024.
European Standard Contractual Clauses or participation in the EU-U.S. Data Privacy Framework do not, by themselves, satisfy Brazilian international-transfer requirements and are not represented as doing so.
6.3 Other jurisdictions
Where another data protection law applies to an international transfer, WASViking will apply the transfer mechanism required by the applicable jurisdiction, which may include, where applicable, participation by an eligible recipient in the Swiss-U.S. Data Privacy Framework.
6.4 Subprocessors
International transfers involving authorized subprocessors remain subject to the applicable transfer requirements and to the safeguards described in this DPA and in the WASViking Subprocessors list.
WASViking's services are designed to process technical and security data. Certain features, such as Exposure Intelligence and AI Guardian, may surface personal data elements (for example, email addresses, usernames, or credential indicators) connected to a security event. WASViking applies data minimization by design to these features, including masking by default and metadata-first collection, as described in the Security Data Handling page of the Trust Center.
7. Security Measures
WASViking will maintain appropriate technical and organizational security measures, including:
- Infrastructure hosted on AWS behind Cloudflare (WAF, TLS, DNS), with network segmentation and least-privilege access.
- Customer data stored in Amazon RDS and MongoDB Atlas is encrypted at rest. Managed backups and encrypted snapshots are configured for both database platforms, with recovery capabilities available when restoration is required. Connectivity between the WASViking AWS environment and MongoDB Atlas uses private network connectivity through AWS PrivateLink.
- Data in transit is protected using TLS 1.2 or higher. Stored credentials, tokens, and secrets receive an additional layer of application-level encryption.
- Access controls: additional authentication controls for customer and partner environments, which may include an email security code at sign-in, authenticator-based two-factor authentication, or authentication through an approved identity provider; role-based access control (RBAC); and tenant isolation.
- Tenant-scoped audit logging of security-relevant actions, with tamper-evident integrity protection for selected high-sensitivity events.
- Secure development practices, including code review, dependency vulnerability monitoring, and use of the WASViking platform to test our own services.
- Incident response procedures in place.
8. Data Retention & Deletion
Upon termination of the services or upon the Customer's verified written request, WASViking deletes the personal data it processes on the Customer's behalf from active systems in accordance with its documented deletion procedures. Limited records may be retained where reasonably necessary for security, fraud prevention, audit integrity, legal compliance, or the establishment, exercise, or defense of legal claims. Retained records remain protected and access-restricted and are deleted or de-identified when no longer required. Residual copies may remain in encrypted backups until they expire through the normal backup retention cycle. For Customers contracting WASViking directly, deletion upon termination may be exercised through the self-service account closure in the portal: the Customer may export its data from the portal during a 60-day reversible window and may request a full export from WASViking; when the window ends, Customer Data is erased from active systems and a completion record is issued. Copies held in encrypted backups expire within 7 days on the rotation schedule; if a backup is restored for disaster recovery within that window, the erased data is deleted again from the restored system. The procedure is documented at docs.wasviking.com/security/account-closure-and-data-erasure/.
9. Audit Rights
- Controller may review compliance by requesting logs, documentation, or evidence.
- Audits must be reasonable, on-site only if essential and after prior notice.
- Processor remains responsible for subcontractors and their compliance.
10. Data Subject Rights
WASViking will:
- Notify Controller of any data subject request received.
- Assist with requests (access, correction, deletion, portability).
- Act only per Controller’s instruction.
11. Breach Notification
Processor must notify Controller without undue delay upon detection of any incident potentially affecting personal data, including details and remediation plans.
12. Liability & Responsibility
- WASViking remains responsible for its actions and those of its subprocessors.
- Controller is responsible for ensuring lawfulness and scope of data processing.
- Processor will not use data for its own purposes nor retain it after termination.
13. Term & Termination
- This DPA remains in effect while WASViking processes data for Customer.
- Confidentiality and data protection obligations survive the DPA termination.
14. Governing Law
This DPA shall be governed by and construed in accordance with the laws of the State of Florida, USA, excluding its conflict of laws provisions. This is without prejudice to any mandatory data protection rights under LGPD, GDPR, or other applicable legislation.
15. Contact Information
For DPA requests, subprocessors, logs, audits, or privacy matters:
WASViking LLC
Orlando, FL, USA
[email protected]