// DPA
Data Processing Addendum
Last updated:
This baseline DPA explains how Loki handles customer-provided operational and personal data during authorized security testing. A signed DPA or customer procurement document can replace or extend it.
1. Purpose
This Data Processing Addendum sets baseline handling rules for personal data processed by Loki Intelligence during authorized security testing, onboarding, report delivery, customer support, and related operational communication.
2. Roles
Unless a signed agreement says otherwise, the customer is the controller for customer-provided personal data and Loki Intelligence acts as processor for the limited purpose of delivering the requested security service.
3. Categories of data
Data may include contact details, company details, submitted scope information, test-account metadata, logs, report evidence, remediation communication, payment references, and limited technical identifiers needed to validate findings.
4. Processing instructions
Loki processes customer data only to deliver, secure, support, document, and improve the authorized service, or to comply with legal obligations. Loki does not use submitted customer data to train public models.
5. Security measures
Loki applies access controls, least-privilege handling, evidence minimization, report access controls, operational logging, and credential redaction in notifications. Customers should avoid sharing unnecessary secrets and should rotate temporary credentials after testing.
6. Subprocessors and deletion
Service delivery may rely on hosting, email, payment, calendar, authentication, logging, and storage providers. Retention and deletion periods can be agreed per engagement; security evidence is kept only as long as needed for delivery, support, audit, and legal protection.