GDPR-Compliant DPA for Enterprise Customers
Last updated: October 9, 2025
This Data Processing Agreement ("DPA") governs the processing of personal data by DfenAI on behalf of our enterprise customers. It forms part of the DfenAI Terms of Service and ensures compliance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
The DPA incorporates the EU Standard Contractual Clauses (SCCs) adopted by Commission Implementing Decision 2021/914 and provides comprehensive data protection safeguards for international data transfers.
📋 For Enterprise Customers: Download the full DPA template above to execute with your legal team. Contact legal@dfen.ai for executed copies or customization requests.
Controller: Your organization (the Customer) who determines the purposes and means of processing personal data.
Processor: DfenAI, who processes personal data on behalf of the Controller.
Personal Data: Any information relating to an identified or identifiable natural person as defined in GDPR.
Sub-processor: Third parties appointed by DfenAI to process personal data on behalf of the Controller.
DfenAI processes personal data to provide cybersecurity threat intelligence services, including:
DfenAI implements comprehensive technical and organizational measures to ensure data security:
DfenAI engages the following sub-processors with equivalent data protection obligations:
Sub-processor | Purpose | Location |
---|---|---|
Amazon Web Services | Infrastructure hosting, database | EU / US |
Mailgun | Transactional emails | EU (Ireland) |
Stripe | Payment processing | EU / US |
Cloudflare | CDN, DDoS protection | Global |
📢 Sub-processor Changes: Customers will be notified 30 days in advance of any changes to sub-processors. You may object on reasonable data protection grounds within this period.
For detailed sub-processor information including DPAs and safeguards, see Sub-processors List.
DfenAI may transfer personal data to countries outside the European Economic Area (EEA) where sub-processors are located. We ensure appropriate safeguards:
In the event of government access requests, DfenAI will challenge unlawful requests and notify customers unless legally prohibited.
DfenAI provides technical capabilities to assist customers in fulfilling data subject rights:
Response Time: DfenAI aims to respond to data subject requests within 10 business days (up to 30 days for complex requests).
DfenAI shall notify customers without undue delay (within 72 hours) after becoming aware of a personal data breach. The notification will include:
Customers may request compliance documentation and audits to verify DfenAI's adherence to this DPA:
Contact legal@dfen.ai to request audit documentation or schedule an audit.
DfenAI retains personal data only as long as necessary to provide services or as required by law:
Upon request, DfenAI will provide written certification of data deletion.
For questions about this DPA or data protection inquiries:
Data Protection Officer: dpo@dfen.ai
Legal Inquiries: legal@dfen.ai
Website: https://dfen.ai
Company: DfenAI ApS (Denmark)
📄 Execute DPA: Download the template above and contact legal@dfen.ai to execute a signed DPA for your organization. Typically completed within 5 business days.