Legal
Data Processing Agreement
Last updated: 23 July 2026 · Version 1.0
When you use BreakMesh to scan a website or API you control, you (the "Customer", acting as data controller) may ask BreakMesh (the "Processor") to process personal data on your behalf — for example, personal data that happens to appear in scan evidence, or personal data about your own team members who use the platform. This Data Processing Agreement ("DPA") sets out the terms of that processing and forms part of your agreement with BreakMesh under Article 28 of the GDPR. This page is our standard DPA; enterprise customers with additional requirements may request a countersigned copy at legal@breakmesh.io.
1. Roles
| Party | Role |
|---|---|
| Customer | Data Controller — determines the purposes and means of processing personal data submitted to, or discovered by, the platform |
| BreakMesh | Data Processor — processes personal data solely to provide the scanning, reporting, and account services the Customer has configured |
2. Subject matter and duration
BreakMesh processes personal data for the duration of the Customer's subscription, plus any post-termination retention period disclosed in our Privacy Policy §7 (Data retention).
3. Nature and purpose of processing
- Running consent-gated, non-destructive security scans against Customer-verified targets.
- Storing scan findings, evidence, and generated reports.
- Operating Customer team member accounts, roles, and audit logs.
- Delivering optional integrations the Customer has explicitly configured (Jira, Slack, GitHub, webhooks).
4. Categories of data subjects
- The Customer's own team members (name, email, role).
- Individuals whose personal data may incidentally appear in scan evidence captured from the Customer's own target (e.g. names or emails visible in an exposed error page or misconfigured endpoint the scan flagged).
5. Categories of personal data
See Privacy Policy §2 for the full data inventory. In the DPA context, this is limited to identity/contact data for Customer team members and any incidental personal data captured in scan evidence.
6. Sub-processors
BreakMesh uses the following sub-processors, each engaged under a data processing agreement consistent with this DPA. This is the same register maintained in our Privacy Policy §5.
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Stripe, Inc. | Payment processing & billing | USA | Standard Contractual Clauses (SCCs) |
| Atlassian (Jira) | Issue tracking (optional integration) | Australia / USA | SCCs |
| Slack Technologies | Notifications (optional integration) | USA | SCCs |
| GitHub, Inc. | PR status checks (optional integration) | USA | SCCs |
| OpenAI / Anthropic | AI-generated remediation suggestions (optional, requires explicit org opt-in) | USA | SCCs |
| Email delivery provider | Transactional email (scan alerts, breach notifications) | USA / EU (provider-dependent) | SCCs |
| Cloud infrastructure provider | Hosting, database, storage | EU / EEA (where available) | Adequacy decision / SCCs |
We will give at least 30 days' notice before appointing a new sub-processor that will process Customer personal data, via email to the account owner and an update to this page. Customers may object on reasonable data-protection grounds within that period by contacting legal@breakmesh.io.
7. Processor obligations
- Process personal data only on documented instructions from the Customer, including regarding international transfers, unless required otherwise by law.
- Ensure persons authorized to process personal data are bound by confidentiality.
- Implement the technical and organisational security measures described in Privacy Policy §10.
- Assist the Customer, insofar as reasonably possible, in responding to data subject rights requests and in meeting Article 32–36 obligations (security, breach notification, DPIAs).
- Notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer data, consistent with our breach notification process.
- At the Customer's choice, delete or return all personal data at the end of the engagement, and delete existing copies, subject to the retention periods described in §7 of the Privacy Policy.
- Make available information necessary to demonstrate compliance with this DPA and allow for, and contribute to, audits conducted by the Customer or an auditor mandated by the Customer, on reasonable notice.
8. International transfers
Where personal data is transferred outside the European Economic Area (EEA) or UK, BreakMesh relies on Standard Contractual Clauses (SCCs) approved by the European Commission, together with supplementary technical and organisational measures where required.
9. Security incident notification
BreakMesh maintains a documented breach response process, including 72-hour supervisory
authority notification tracking for high/critical severity incidents. See our
Privacy Policy and internal
GDPR_BREACH_PROCEDURE.md for the full process.
10. Precedence
This DPA supplements, and does not replace, the Terms of Service between the Customer and BreakMesh. In the event of a conflict specifically regarding the processing of personal data, this DPA controls.
11. Contact
Data Protection queries: privacy@breakmesh.io
DPA / legal requests: legal@breakmesh.io