This Data Processing Agreement ("DPA") forms part of the agreement between the Customer and ValueMentor Infosec Limited for Services provided through or in connection with Secusy.ai.
1. Parties
This DPA is entered into between:
The Customer identified in the applicable Order, subscription, statement of work or other agreement incorporating this DPA ("Customer" or "Controller");
and
ValueMentor Infosec LimitedCompany number: 13545355Pepper House, Pepper RoadHazel Grove, StockportSK7 5DPUnited Kingdom("ValueMentor", "Processor", "we", "us" or "our").This DPA applies only to the extent that ValueMentor processes Personal Data on behalf of the Customer as a Processor in connection with the Services.
2. Relationship With the Main Agreement
This DPA forms part of and is incorporated into the agreement governing the Customer's use or purchase of the Services ("Agreement").
The Agreement may include the Secusy Terms and Conditions, an Order, Service Terms, statement of work or other applicable contractual documentation.
If there is a conflict between this DPA and the Agreement concerning the processing of Customer Personal Data, this DPA will prevail to the extent of that conflict.
Nothing in this DPA modifies provisions of the Agreement unrelated to data protection.
3. Definitions
For this DPA:
Applicable Data Protection Law means applicable laws governing the processing of Personal Data under this DPA, including, where applicable, the UK GDPR and Data Protection Act 2018, each as amended or replaced from time to time.
Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing and Supervisory Authority have the meanings given to them under Applicable Data Protection Law.
Customer Personal Data means Personal Data processed by ValueMentor on behalf of the Customer in connection with the Services.
Subprocessor means a third party engaged by ValueMentor to process Customer Personal Data on behalf of the Customer.
UK GDPR means the United Kingdom General Data Protection Regulation as it forms part of UK law, as amended from time to time.
4. Roles of the Parties
The Customer is the Controller of Customer Personal Data and ValueMentor is the Processor except where the circumstances require a different classification under Applicable Data Protection Law.
The Customer determines the purposes and essential means of processing Customer Personal Data.
ValueMentor processes Customer Personal Data on behalf of the Customer and according to the Customer's documented instructions.
ValueMentor may separately act as a Controller for Personal Data it processes for its own legitimate purposes, including account administration, billing, fraud prevention, Platform security, legal compliance and its own business administration.
Such Controller processing is governed by the Secusy Privacy Policy and does not fall within this DPA.
5. Customer Instructions
ValueMentor will process Customer Personal Data only on documented instructions from the Customer, including with respect to international transfers, unless processing is required by applicable law.
The Agreement, applicable Order, Service configuration, Customer's use of the Services and written instructions consistent with the Agreement constitute the Customer's documented instructions.
The Customer may provide additional reasonable documented instructions where necessary to comply with Applicable Data Protection Law.
If applicable law requires ValueMentor to process Customer Personal Data other than according to Customer instructions, ValueMentor will inform the Customer of that legal requirement before processing unless applicable law prohibits such notification.
ValueMentor will promptly inform the Customer if, in ValueMentor's reasonable opinion, an instruction infringes Applicable Data Protection Law.
ValueMentor is not required to comply with an instruction that would require ValueMentor to violate applicable law.
6. Customer Responsibilities
The Customer is responsible for ensuring that:
- its processing of Personal Data complies with Applicable Data Protection Law;
- it has an appropriate lawful basis for processing Customer Personal Data;
- it has provided required privacy information to Data Subjects;
- it has the right to provide Customer Personal Data to ValueMentor;
- its instructions to ValueMentor are lawful;
- it does not provide Personal Data that is unnecessary for the relevant Service; and
- the scope and configuration of the Services are appropriate for its processing requirements.
The Customer is responsible for determining whether the Services meet any sector-specific, regulatory, localisation or other requirements applicable to the Customer unless ValueMentor expressly agrees otherwise in writing.
7. Details of Processing
The subject matter, duration, nature and purpose of processing, categories of Data Subjects and types of Personal Data are described in Schedule 1.
The Customer may provide additional documented instructions through the applicable Order or Service configuration.
8. Confidentiality
ValueMentor will ensure that persons authorised to process Customer Personal Data:
- are subject to appropriate confidentiality obligations;
- receive access only where reasonably necessary for their responsibilities; and
- process Customer Personal Data only in accordance with this DPA and applicable instructions.
Confidentiality obligations will continue after the relevant person's involvement in processing ends.
9. Security
Taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of processing, as well as risks to individuals, ValueMentor will implement appropriate technical and organisational measures designed to protect Customer Personal Data.
Such measures are intended to provide a level of security appropriate to the risk and may include, where appropriate:
- access controls;
- identity and authentication controls;
- least-privilege access;
- encryption in transit and, where appropriate, at rest;
- network and infrastructure security;
- logging and monitoring;
- vulnerability management;
- endpoint security;
- backup and recovery measures;
- incident-management procedures;
- secure development practices;
- personnel security;
- confidentiality requirements;
- security awareness and training;
- supplier security management; and
- processes for testing and evaluating security measures.
Further information is provided in Schedule 3 – Technical and Organisational Measures.
ValueMentor may update its security measures over time, provided that such updates do not materially reduce the overall level of protection for Customer Personal Data during the applicable Service term.
10. Personal Data Breaches
ValueMentor will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
To the extent reasonably available, the notification will include information necessary to assist the Customer in meeting applicable breach-notification obligations, which may include:
- the nature of the breach;
- categories of affected Data Subjects;
- categories of affected Personal Data;
- likely consequences;
- measures taken or proposed to address the breach; and
- relevant contact information.
Where all information is not immediately available, ValueMentor may provide information in phases as it becomes available.
ValueMentor will take reasonable steps to contain, investigate and mitigate the effects of a Personal Data Breach.
Notification of a Personal Data Breach does not constitute an admission of fault or liability.
The Customer is responsible for determining whether notification to a Supervisory Authority, affected Data Subjects or another party is legally required, unless applicable law assigns that obligation directly to ValueMentor.
11. Data Subject Requests
Taking into account the nature of the processing, ValueMentor will provide reasonable assistance through appropriate technical and organisational measures to enable the Customer to respond to requests by Data Subjects exercising their rights under Applicable Data Protection Law.
If ValueMentor receives a request directly from a Data Subject relating to Customer Personal Data, ValueMentor will, where reasonably identifiable and legally permitted:
- notify the Customer; and
- direct the Data Subject to the Customer or otherwise act according to the Customer's lawful instructions.
ValueMentor will not independently respond to such a request except where required by law or authorised by the Customer.
12. Assistance With Compliance
Taking into account the nature of processing and information available to ValueMentor, ValueMentor will provide reasonable assistance to the Customer with its applicable obligations relating to:
- security of processing;
- Personal Data Breach assessment and notification;
- Data Protection Impact Assessments;
- prior consultation with Supervisory Authorities where required; and
- other Processor assistance expressly required by Applicable Data Protection Law.
Assistance that materially exceeds the ordinary functionality or support included in the Services may be subject to reasonable additional charges where permitted by law, provided such charges are communicated to the Customer in advance.
13. Subprocessors
The Customer provides general written authorisation for ValueMentor to engage Subprocessors to process Customer Personal Data.
ValueMentor maintains information about its subprocessors and technology providers at:
The providers actually used may depend upon the Service, functionality, hosting environment, integrations and Customer requirements.
ValueMentor will ensure that each Subprocessor processing Customer Personal Data is bound by written obligations providing a level of data protection appropriate to the processing and meeting applicable requirements for subprocessors.
ValueMentor remains responsible to the Customer for the performance of its Subprocessors' data-protection obligations to the extent required by Applicable Data Protection Law.
Changes to Subprocessors
ValueMentor may add or replace Subprocessors.
Where required under Applicable Data Protection Law or this DPA, ValueMentor will provide reasonable advance notice of a material new Subprocessor that will process Customer Personal Data.
The Customer may object on reasonable data-protection grounds by contacting privacy@valuementor.com within the period stated in the notification.
The parties will work in good faith to address a valid objection.
Where a reasonable alternative cannot be provided and the parties cannot resolve the objection, either party may terminate the affected Service without penalty for the unused portion of a prepaid Service, subject to the circumstances and applicable Agreement.
An objection must relate to genuine data-protection concerns and must not be used solely to avoid contractual obligations.
14. International Transfers
ValueMentor may process or permit processing of Customer Personal Data outside the United Kingdom where necessary to provide the Services.
ValueMentor will ensure that restricted international transfers are made using a lawful transfer mechanism where required under Applicable Data Protection Law.
Depending upon the transfer, this may include:
- applicable UK adequacy regulations;
- the UK International Data Transfer Agreement ("IDTA");
- the UK Addendum to approved EU Standard Contractual Clauses;
- another recognised Article 46 safeguard; or
- another lawful transfer mechanism.
Where required, ValueMentor will take reasonable steps to assess whether the transfer mechanism provides the required protection and implement appropriate supplementary measures.
UK International Transfer Terms
Where a restricted transfer of Customer Personal Data from the United Kingdom requires the UK IDTA or UK Addendum, the parties agree to cooperate in completing and entering into the applicable approved transfer mechanism.
Where legally permitted and appropriate, the relevant approved transfer terms may be incorporated into the Agreement by reference.
If the ICO replaces or updates an approved transfer mechanism, the parties agree that the updated or replacement mechanism may apply where necessary to maintain a lawful transfer, subject to applicable law.
15. Data Location
Customer Personal Data may be hosted or processed using different infrastructure depending upon the applicable Service.
Potential infrastructure providers may include AWS, Microsoft Azure, Google Cloud, DigitalOcean, Vercel and other approved providers identified on the Secusy Subprocessor & Technology Providers page.
The presence of a provider on that list does not mean Customer Personal Data is processed by every listed provider.
Where the applicable Order or Service Terms expressly specify a hosting region, in-country hosting arrangement or other data-residency commitment, ValueMentor will provide the affected Service in accordance with that commitment.
16. AI and Machine-Learning Providers
Where an AI-enabled Service or feature requires processing Customer Personal Data through a third-party AI provider, such provider will be treated in accordance with the Subprocessor requirements of this DPA where it acts as a Subprocessor.
Potential AI providers are identified on the Secusy Subprocessor & Technology Providers page.
ValueMentor will not use Customer Personal Data containing identifiable personal information, credentials, identifiable confidential documents or identifiable Customer-specific security findings to train general-purpose AI models unless separately agreed with the Customer.
This restriction does not prevent ValueMentor from using information that has been effectively anonymised so that it no longer constitutes Customer Personal Data or identifies the Customer, subject to the confidentiality provisions of the Agreement.
17. Return and Deletion of Customer Personal Data
Upon termination or expiry of the affected Services, and at the Customer's choice where required by Applicable Data Protection Law, ValueMentor will delete or return Customer Personal Data and delete remaining copies, unless applicable law requires continued retention.
The Customer should export or retrieve Customer Personal Data and deliverables before termination where functionality is available to do so.
Deletion may occur according to ValueMentor's standard deletion and backup-retention processes.
Customer Personal Data contained in backups may remain for a limited period until overwritten or deleted in the ordinary backup lifecycle, provided that it remains protected and is not restored except where necessary for disaster recovery, legal requirements or legitimate security purposes.
Where applicable law requires ValueMentor to retain particular Customer Personal Data, ValueMentor may retain such information for the required period and will continue to protect it under this DPA.
18. Audits and Compliance Information
ValueMentor will make available information reasonably necessary to demonstrate compliance with its obligations under this DPA and applicable Article 28 requirements.
Where appropriate, ValueMentor may satisfy reasonable audit requests initially through:
- security documentation;
- policies;
- certifications or independent assurance reports, where available;
- completed security questionnaires;
- summaries of relevant controls; and
- other appropriate compliance information.
If this information is reasonably insufficient to demonstrate compliance, the Customer may request an audit.
Audits must:
- relate to processing of Customer Personal Data;
- be conducted on reasonable advance written notice;
- occur during normal business hours;
- avoid unreasonable disruption;
- be subject to appropriate confidentiality and security requirements; and
- normally occur no more than once in any twelve-month period unless a Personal Data Breach, regulatory requirement or reasonable evidence of material non-compliance justifies an additional audit.
The Customer may use an independent auditor that is not a competitor of ValueMentor and that is subject to appropriate confidentiality obligations.
The Customer will bear its own audit costs.
Where an audit imposes material additional costs on ValueMentor beyond ordinary compliance assistance, ValueMentor may charge reasonable costs where legally permitted and agreed in advance.
Nothing in this section limits audit rights that cannot lawfully be restricted.
19. Regulatory Enquiries
Where legally permitted, ValueMentor will notify the Customer of a binding request from a Supervisory Authority or governmental authority specifically concerning Customer Personal Data.
ValueMentor will provide reasonable cooperation where required under Applicable Data Protection Law.
Nothing in this DPA requires either party to waive legal privilege or disclose information where disclosure is prohibited by law.
20. Records
ValueMentor will maintain records of processing activities as required by Applicable Data Protection Law.
Each party will provide information reasonably required by the other party to demonstrate compliance with obligations applicable to that party under this DPA.
21. Liability
The liability of each party arising from this DPA is subject to the liability provisions of the Agreement, except to the extent such limitation is prohibited by Applicable Data Protection Law.
Nothing in this DPA relieves either party of liabilities imposed directly upon it by Applicable Data Protection Law.
22. Term
This DPA begins when ValueMentor first processes Customer Personal Data on behalf of the Customer and continues for as long as ValueMentor processes Customer Personal Data subject to this DPA.
Provisions that by their nature should continue following termination, including confidentiality, deletion, audit and applicable international-transfer obligations, will survive for as long as necessary.
23. Governing Law
Unless an applicable mandatory data-protection requirement provides otherwise, this DPA is governed by the governing-law and jurisdiction provisions of the Agreement.
Where the Secusy Terms and Conditions apply, the DPA is governed by the laws of England and Wales and the courts of England and Wales have jurisdiction.
24. Contact
Data-protection enquiries relating to this DPA should be sent to:
ValueMentor Infosec LimitedCompany number: 13545355Pepper House, Pepper RoadHazel Grove, StockportSK7 5DPUnited KingdomSchedule 1 — Details of Processing
1. Subject Matter
Processing of Customer Personal Data as necessary to provide cybersecurity, compliance, assurance, testing, consulting, managed security, Platform and other Services purchased or used by the Customer through or in connection with Secusy.
2. Duration
For the duration of the applicable Service and for any limited period thereafter necessary for deletion, return, backup expiry, legal requirements or other obligations under the Agreement and Applicable Data Protection Law.
3. Nature of Processing
Processing may include, depending upon the Service:
- collection;
- receipt;
- access;
- hosting;
- storage;
- organisation;
- structuring;
- analysis;
- scanning;
- assessment;
- comparison;
- classification;
- transmission;
- retrieval;
- consultation;
- reporting;
- remediation tracking;
- security monitoring;
- deletion; and
- other processing reasonably necessary to provide the applicable Service.
4. Purpose of Processing
To provide the Services purchased or configured by the Customer, including where applicable:
- cybersecurity assessments;
- vulnerability management;
- penetration testing;
- security scanning;
- compliance assessments;
- compliance-management functionality;
- GRC functionality;
- evidence review;
- audit support;
- managed security services;
- security monitoring;
- reporting;
- customer support;
- Platform functionality; and
- related Service delivery.
5. Categories of Data Subjects
Depending upon Customer Content and the Service, Data Subjects may include:
- Customer employees;
- directors and officers;
- contractors;
- consultants;
- temporary personnel;
- Customer users;
- end users;
- customers of the Customer;
- suppliers;
- business partners;
- website or application users; and
- other individuals whose Personal Data is contained within Customer systems, evidence, logs or information supplied for the Service.
6. Types of Personal Data
Depending upon the Service, Customer Personal Data may include:
- names;
- business contact details;
- usernames and user identifiers;
- IP addresses;
- device identifiers;
- system and application identifiers;
- account information;
- authentication and access information;
- logs;
- security events;
- vulnerability information;
- configuration information;
- compliance evidence;
- policy and procedure information;
- audit evidence;
- application information;
- communications;
- employment-related business information; and
- other Personal Data contained in Customer Content.
7. Special Category and Highly Sensitive Data
The Services are not generally designed to require Customers to provide special-category Personal Data unless necessary for a specifically agreed Service.
Customers should avoid providing special-category Personal Data, financial credentials, government identifiers, health information or other highly sensitive Personal Data unless it is necessary for the Service and appropriate safeguards have been agreed where required.
If the nature of a Service is expected to involve systematic processing of special-category or other particularly sensitive Personal Data, the parties may document additional safeguards in the applicable Order.
8. Frequency
Processing may be continuous, periodic, event-driven or one-time depending upon the applicable Service.
Schedule 2 — Approved Subprocessors
The Customer provides general authorisation for ValueMentor to use Subprocessors in accordance with Section 13.
The current list of subprocessors and technology providers is maintained at:
Providers may include, depending upon the applicable Service and configuration:
- Vercel;
- Amazon Web Services;
- Microsoft Azure;
- Google Cloud;
- DigitalOcean;
- Clerk;
- Microsoft 365;
- Zoho;
- Anthropic;
- OpenAI; and
- Google.
Stripe, Google Analytics, Hotjar and other providers may also process Personal Data in connection with Secusy, but their precise legal role may vary depending upon the processing activity. Their inclusion as technology providers does not by itself mean they act as a Subprocessor for all Customer Personal Data.
The live Subprocessor page should be consulted for the current provider information.
Schedule 3 — Technical and Organisational Measures
ValueMentor maintains technical and organisational measures appropriate to the Services and risks associated with processing.
Depending upon the applicable system and Service, these measures may include:
Governance and Personnel
- documented information-security responsibilities;
- confidentiality obligations;
- security awareness and training;
- role-based responsibilities;
- appropriate personnel access procedures; and
- security policies and procedures.
Identity and Access Management
- unique user accounts;
- role-based access controls;
- least-privilege principles;
- authentication controls;
- multifactor authentication where appropriate;
- privileged-access restrictions; and
- periodic access review where appropriate.
Encryption and Data Protection
- encryption of network communications using appropriate cryptographic protocols;
- encryption at rest where appropriate to the applicable system and risk;
- secure handling of credentials and secrets;
- data minimisation; and
- logical separation of information where appropriate.
Infrastructure and Network Security
- cloud and infrastructure security controls;
- network restrictions and segmentation where appropriate;
- firewalls and related security controls;
- secure configuration;
- monitoring and logging; and
- protection of production environments.
Vulnerability and Security Management
- vulnerability identification and management;
- security patching processes;
- endpoint protection where appropriate;
- security testing;
- remediation processes; and
- monitoring of relevant security threats.
Application Security
- secure development practices;
- source-code and change-management controls;
- testing before material production changes where appropriate;
- dependency and vulnerability management; and
- restricted production access.
Logging and Monitoring
- security and operational logging;
- monitoring of relevant systems;
- alerting where appropriate;
- investigation of security events; and
- retention of logs appropriate to operational and security requirements.
Business Continuity
- backup arrangements appropriate to the relevant systems;
- recovery procedures;
- infrastructure resilience where appropriate; and
- incident and continuity planning.
Incident Management
- documented incident-management processes;
- investigation and containment;
- escalation procedures;
- breach-assessment procedures;
- remediation and lessons learned; and
- Customer notification procedures as required by this DPA.
Supplier Management
- assessment of relevant service providers;
- contractual data-protection obligations;
- confidentiality requirements;
- Subprocessor management; and
- review of relevant security and privacy considerations.
Data Lifecycle
- retention controls;
- Customer data return or export where applicable;
- deletion procedures;
- backup expiry processes; and
- secure disposal where appropriate.
The specific controls applicable to a particular Service may vary according to its architecture, risk profile and hosting environment.
Schedule 4 — International Transfers
Where ValueMentor makes a restricted international transfer of Customer Personal Data, it will use a lawful transfer mechanism as required by Applicable Data Protection Law.
Where applicable, this may include:
- an applicable UK adequacy regulation;
- the UK International Data Transfer Agreement;
- the UK Addendum to approved EU Standard Contractual Clauses; or
- another legally recognised transfer safeguard.
Where a transfer mechanism requires additional information concerning the parties, categories of data, purpose, security measures or recipient, the relevant information in this DPA, the applicable Order and the Subprocessor & Technology Providers page may be used to complete the applicable transfer documentation to the extent legally permitted.
The parties will reasonably cooperate to execute additional transfer documentation where required to maintain lawful processing.