Data Processing Agreement

Governs BITS Blackrock IT Solutions LLC's processing of personal data on behalf of the Customer under GDPR Art. 28 and equivalent PDPL provisions. Forms part of the Terms of Service.

BITS Blackrock IT Solutions LLC · Last updated 2026-07-17

1.Roles

The Customer is the controller of personal data it enters into SekuRad. BITS Blackrock IT Solutions LLC is the processor, acting only on the Customer’s documented instructions — which include operating the Service as configured.

2.Scope of processing

  • Subject matter: provision of the SekuRad security-operations platform.
  • Duration: the term of the subscription, plus the deletion window.
  • Nature & purpose: hosting, storing, and processing operational security data as directed.
  • Data types: account identifiers, personnel and site records, incidents, assessments, documents, and related metadata.
  • Data subjects: the Customer’s staff, officers, visitors, and other individuals recorded by its users.

3.Our obligations

  • Process personal data only on the Customer's documented instructions.
  • Ensure persons authorised to process the data are bound by confidentiality.
  • Implement appropriate technical and organisational security measures (Section 5).
  • Assist the Customer with data-subject requests and with its own security/DPIA obligations, taking into account the information available to us.
  • Make available information necessary to demonstrate compliance and allow for reasonable audits.

4.Sub-processors

The Customer authorises the use of the sub-processors listed below. We impose data-protection obligations on each that are no less protective than this DPA, and remain responsible for their performance. We will give reasonable notice of any intended change, and the Customer may object on reasonable data-protection grounds.

Sub-processorPurposeLocation
Hetzner Online GmbHApplication hosting & deliveryGermany (EU)
Supabase (PostgreSQL)Primary database & file storageEU
Clerk Inc.Authentication & identityUSA (SCCs)
OpenAIAI assistant (Keva) — features you opt intoUSA (SCCs, no training on your data)
AnthropicAI assistant (Keva) — features you opt intoUSA (SCCs, no training on your data)
ResendTransactional & alert emailUSA (SCCs)
LemonSqueezyBilling & payment processingUSA (SCCs)
Sentry (Functional Software, Inc.)Error & performance monitoring (PII disabled)USA (SCCs)

5.Security measures

  • Tenant isolation enforced at the database level (PostgreSQL row-level security), not application code alone.
  • Encryption of data in transit (TLS) and at rest.
  • Role-based access control scoped to region, country, and site; least-privilege internal access.
  • Full audit logging of security-relevant actions.
  • Authentication delegated to a dedicated identity provider with MFA support.

Full detail is on our Security & Trust page.

6.International transfers

Where personal data is transferred outside the Customer’s region, the transfer is covered by Standard Contractual Clauses or an equivalent approved safeguard, as reflected in the sub-processor table.

7.Personal data breach

We will notify the Customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer data, with the information reasonably available to support the Customer’s own obligations.

8.Return & deletion

On termination, and at the Customer’s choice, we will return or delete Customer personal data within 30 days, except where retention is required by law.

9.Signing this DPA

A countersigned copy is available on request at legal@sekurad.com. Accepting the Terms of Service incorporates this DPA where the Customer is a controller under GDPR or PDPL.