// DPA
Data Processing Addendum
Last updated:
This page is a public review baseline, not a signed Data Processing Addendum and not proof that every listed engagement detail has already been agreed. Where Loki will process personal data for a customer, the parties complete and sign engagement-specific data terms before testing. Those signed terms and the fully executed agreement containing the applicable scope and Rules of Engagement take priority over this public baseline where they are more specific.
1. Status, parties and roles
The signed data terms identify the customer, Loki Intelligence B.V., their contact details and signatures, the effective date, and whether each party acts as controller, processor or independently for a particular activity. The usual baseline is that the customer is controller and Loki is processor for customer personal data handled only to deliver the authorized service. This public page does not itself appoint Loki as processor or authorize testing.
2. Subject, duration, nature and purpose
The signed schedule records the particular assessment, processing purpose, permitted operations, systems, test accounts, evidence types and support activities, together with the processing start, duration and end conditions. Processing is limited to scoping, safely performing and documenting the authorized assessment, human review, delivery, remediation support, the agreed retest and closure.
3. Data subjects and categories
The engagement schedule identifies the relevant data subjects and data categories before work. Depending on the agreed scope, these can include customer staff, authorized test users, business contacts or limited application-user records, and contact details, account identifiers, test-account metadata, scope records, technical identifiers, logs, redacted requests and responses, screenshots, finding evidence, remediation communication and report content. Special-category data, secrets and live customer records are excluded unless specifically necessary, documented and protected in the signed terms.
4. Documented instructions and purpose limits
Loki processes customer personal data only on documented customer instructions contained in the signed data terms and fully executed agreement, including its applicable scope and Rules of Engagement and any instruction about a transfer. If law requires other processing, Loki will inform the customer before processing unless the law prohibits that notice. Customer data is not used for advertising, unrelated analytics, model training or other secondary purposes unless the customer gives a separate, explicit written instruction and the parties first document the legal and security conditions. Loki will notify the customer if an instruction appears to breach applicable data-protection law.
5. Confidentiality and authorized personnel
People allowed to handle customer personal data are limited to those who need it for the authorized work, are subject to confidentiality obligations and receive instructions appropriate to their role. The signed engagement identifies any customer restrictions on access. Findings, credentials, evidence, reports and non-public system information are treated as confidential.
6. Security measures
The engagement-specific security schedule records measures appropriate to the scoped data and risk. The public baseline includes least-privilege access, evidence minimization, separation of test and customer context where practical, report access controls, operational logging, redaction of credentials in notifications, controlled evidence release and a human publication decision. This list is a baseline, not a claim that one unchanged control set is sufficient for every engagement.
7. Assistance and personal-data incidents
Taking account of the processing and information available to it, Loki will provide reasonable assistance with data-subject requests, security obligations, incident assessment, regulatory consultation and impact assessments that concern the service. Loki will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data, provide available facts and updates, and support the customer's response. The signed terms set contacts, channels, responsibilities and any measurable notification target; this public baseline does not invent a fixed SLA.
8. Subprocessors and change notice
Potential service-provider categories include hosting, authentication, email, security, logging, storage, calendar and payment services. Before an engagement that requires processor terms, the signed schedule or referenced register identifies the providers actually relevant to customer data, their function and processing location, and records the agreed authorization method. It also sets advance notice for intended additions or replacements, a reasonable objection path and the requirement that downstream providers accept materially equivalent data-protection obligations.
9. International transfers
The parties identify expected processing locations before the engagement. Customer personal data is not intentionally transferred outside the agreed locations unless the signed terms record the instruction, destination, recipient and applicable transfer mechanism or safeguard. The final arrangement may use an adequacy decision, approved contractual safeguards or another lawful mechanism where required; this baseline does not assert that a particular mechanism applies before the provider map is known.
10. Return, deletion and retention
At the end of the service, Loki will return or delete customer personal data as the customer chooses and as the signed schedule specifies, unless applicable law requires retention. The schedule records the delivery and retest period, evidence-retention window, deletion or return method, treatment of backups and any legal or security hold. Customer-provided temporary credentials should be revoked or rotated at closure.
11. Information and audits
Loki will make information reasonably necessary to demonstrate compliance with the signed processor terms available to the customer. The signed terms define a practical sequence such as documentation or questionnaire review first, followed where justified by a scoped independent or customer audit, while protecting other customers, confidential information and system security. Loki will cooperate with competent supervisory authorities as required.
12. Details completed before testing
Before processing begins, the signed pack must complete the parties and roles; service and processing duration; purposes and operations; data-subject and data categories; documented instructions; security schedule; approved subprocessors, locations, change notice and transfers; assistance and incident contacts; return, deletion and backup handling; audit process; liability or commercial terms; and signatures. If those details are unresolved, testing does not start.