Back to Mission Control

Data Processing Agreement (DPA)

Public Legal Document

1STPROTECT DATA PROCESSING AGREEMENT
Last updated: July 19, 2026 URL: https://1stprotect.ai/legal/dpa
This Data Processing Agreement (this “DPA”) supplements and forms part of the agreement between 1stProtect Corp., a Delaware corporation (“1stProtect” or “Processor”), and the customer that has executed an order or other written agreement for the 1stProtect Software Platform (the “Customer” or “Controller”) that incorporates this DPA by reference (the “Principal Agreement”).
This DPA applies to the extent that 1stProtect processes Personal Data on Customer’s behalf in connection with the Principal Agreement.

1. Definitions
1.1 Capitalized terms used and not defined in this DPA have the meanings given in the Principal Agreement or in applicable Data Protection Laws.
1.2 In this DPA:
“Applicable Data Protection Laws” means all data protection and privacy laws applicable to the processing of Personal Data under the Principal Agreement, including (as applicable) (a) the EU General Data Protection Regulation 2016/679 (“GDPR”), (b) the UK GDPR and the Data Protection Act 2018 (as amended), (c) the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (“CCPA”), (d) the Brazilian Lei Geral de Proteção de Dados (“LGPD”), and (e) any other equivalent law in any jurisdiction in which Customer is established or operates.
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing”, “Special Category Data”, and “Supervisory Authority” have the meanings given in the GDPR (or, where the GDPR does not apply, the equivalent meanings under the relevant Applicable Data Protection Law).
“Customer Personal Data” means Personal Data Processed by 1stProtect on Customer’s behalf in connection with the Principal Agreement, as further described in Annex A.
“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of Personal Data to third countries adopted by the European Commission (Decision (EU) 2021/914 of 4 June 2021), as amended.
“Subprocessor” means any third party engaged by 1stProtect to Process Customer Personal Data.
“UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner’s Office.
2. Roles and Subject Matter of Processing
2.1 In connection with the Principal Agreement, Customer is the Controller and 1stProtect is the Processor of Customer Personal Data. Where Customer is itself a Processor for an upstream Controller, 1stProtect is a sub-processor.
2.2 The subject matter, duration, nature and purpose of Processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex A (Description of Processing).
3. Customer Instructions and Compliance
3.1 1stProtect shall Process Customer Personal Data only on Customer’s documented instructions, including with regard to international transfers, except where Applicable Data Protection Laws require otherwise (in which case 1stProtect shall, where legally permitted, inform Customer of the legal requirement before Processing).
3.2 The Principal Agreement (including its Order forms, configuration choices made by Customer, and this DPA) constitutes Customer’s complete and final documented instructions to 1stProtect for the Processing of Customer Personal Data. Additional instructions may be agreed by the parties in writing.
3.3 1stProtect shall promptly notify Customer if, in 1stProtect’s opinion, an instruction infringes Applicable Data Protection Laws. 1stProtect is not obliged to determine the lawfulness of Customer’s instructions; Customer is responsible for ensuring that its instructions and the data it submits comply with Applicable Data Protection Laws.
3.4 Customer warrants that (a) it has obtained all necessary consents and provided all necessary notices to Data Subjects to enable 1stProtect’s lawful Processing under this DPA, and (b) Customer Personal Data is not Special Category Data unless Customer has informed 1stProtect in writing.
4. Confidentiality
1stProtect shall ensure that personnel authorized to Process Customer Personal Data are bound by written confidentiality obligations or are under a statutory obligation of confidentiality, and have received appropriate training in data protection.
5. Security
5.1 1stProtect shall implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to such data (“Security Measures”). The Security Measures are described in Annex B (Security Measures) and include, at a minimum:
	•	AES-256 encryption of data at rest;
	•	TLS 1.3 encryption of data in transit;
	•	role-based access controls and least-privilege provisioning;
	•	multi-factor authentication for administrative access;
	•	segregation of customer environments;
	•	logging, monitoring, and intrusion detection;
	•	personnel screening, training, and confidentiality obligations;
	•	secure software development lifecycle practices;
	•	vulnerability management and patching procedures;
	•	business continuity and disaster recovery procedures; and
	•	the controls required to maintain 1stProtect’s SOC 2 Type II attestation and ISO 27001 certification.
5.2 1stProtect shall regularly test, assess, and evaluate the effectiveness of the Security Measures and shall update them in response to evolving threats and regulatory expectations. 1stProtect may modify the Security Measures from time to time, provided that no modification materially diminishes the level of protection.
6. Subprocessors
6.1 Customer authorizes 1stProtect to engage Subprocessors to Process Customer Personal Data subject to this Section 6. 1stProtect shall enter into a written agreement with each Subprocessor that imposes data-protection obligations no less protective than those in this DPA, and 1stProtect shall remain liable for any acts or omissions of its Subprocessors as if they were 1stProtect’s own.
6.2 1stProtect maintains a current list of authorized Subprocessors at https://1stprotect.ai/legal/subprocessors and shall provide at least thirty (30) days’ prior notice (by email or by updating the list) before engaging any new Subprocessor for the Processing of Customer Personal Data.
6.3 Customers may object to a new Subprocessor on reasonable data-protection grounds within fifteen (15) days of notice. The parties shall in good faith seek a workable solution, which may include 1stProtect’s withdrawal of the proposed Subprocessor, configuration changes, or, as a last resort, Customer’s right to terminate the affected services and receive a pro-rata refund of prepaid unused fees.
7. International Data Transfers
7.1 1stProtect may Process Customer Personal Data outside the country in which it was collected, including in the United States. Where Customer Personal Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country that does not provide an adequate level of protection (as determined by the relevant authority), the parties agree that:
	•	for transfers from the EEA, the EU SCCs (Module 2 — Controller to Processor, or Module 3 — Processor to Processor, as applicable) are incorporated into this DPA by reference, with the parties’ details and elections set out in Annex C (SCC Annex);
	•	for transfers from the United Kingdom, the UK Addendum is incorporated into this DPA by reference, with the parties’ details and elections set out in Annex C; and
	•	for transfers from Switzerland, the EU SCCs apply with such adaptations as are required under Swiss law.
7.2 The parties shall comply with the requirements of the SCCs and UK Addendum as incorporated. To the extent of any conflict between this DPA and the SCCs or UK Addendum, the SCCs or UK Addendum prevail.
7.3 Where required by law, 1stProtect has carried out a transfer impact assessment and shall make it available to Customer on reasonable request.
8. Data Subject Requests
8.1 1stProtect shall, taking into account the nature of the Processing, assist Customer by appropriate technical and organizational measures (insofar as possible) for the fulfilment of Customer’s obligations to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Laws (including rights of access, rectification, erasure, restriction, portability, and objection).
8.2 If 1stProtect receives a Data Subject request directly, 1stProtect shall promptly forward it to Customer and shall not respond to the Data Subject except to acknowledge receipt and refer the Data Subject to Customer.
9. Personal Data Breach
9.1 1stProtect shall notify Customer without undue delay (and in any event within seventy-two (72) hours) after becoming aware of a Personal Data Breach affecting Customer Personal Data in 1stProtect’s custody.
9.2 The notification shall, to the extent then known, include (a) the nature of the Personal Data Breach, (b) the categories and approximate number of Data Subjects and records affected, (c) the likely consequences, and (d) the measures taken or proposed to address the Personal Data Breach.
9.3 1stProtect shall provide reasonable cooperation and information to assist Customer in meeting its own breach-notification obligations to Supervisory Authorities and Data Subjects.
10. Data Protection Impact Assessments and Consultation
1stProtect shall, taking into account the nature of the Processing and the information available to 1stProtect, provide reasonable assistance to Customer in carrying out data protection impact assessments and prior consultations with Supervisory Authorities as required under Applicable Data Protection Laws.
11. Audits
11.1 1stProtect shall make available to Customer, on reasonable written request, information necessary to demonstrate compliance with this DPA, including by providing copies of its most recent SOC 2 Type II report and ISO 27001 certificate (subject to applicable confidentiality obligations).
11.2 Customer (or its independent auditor, subject to reasonable confidentiality terms) may, on at least thirty (30) days’ prior written notice and not more than once per calendar year (except in the case of a Personal Data Breach or a documented regulatory requirement), conduct an audit of 1stProtect’s compliance with this DPA. Audits shall be conducted during regular business hours, in a manner that does not unreasonably interfere with 1stProtect’s operations, and shall be limited to information and systems relevant to the Processing of Customer Personal Data. Each party bears its own costs.
12. Return and Deletion of Customer Personal Data
12.1 Upon termination of the Principal Agreement (or earlier on Customer’s written request, where the request relates to Customer’s compliance with Applicable Data Protection Laws), 1stProtect shall, at Customer’s election, return to Customer or delete all Customer Personal Data in 1stProtect’s possession or control, except to the extent that 1stProtect is required by law to retain some or all of the Customer Personal Data.
12.2 1stProtect may retain Customer Personal Data in routine backups for the period required by its standard backup-retention schedule, provided that retained Personal Data remains subject to this DPA and is deleted at the expiry of the retention period.
13. CCPA Specific Terms
13.1 To the extent 1stProtect Processes Personal Information (as defined in the CCPA) of California residents on Customer’s behalf, the parties acknowledge that 1stProtect is a “service provider” under the CCPA.
13.2 1stProtect shall not (a) sell or share Personal Information, (b) retain, use, or disclose Personal Information for any purpose other than for the specific purpose of performing the services specified in the Principal Agreement, or as otherwise permitted by the CCPA, (c) retain, use, or disclose Personal Information outside the direct business relationship with Customer, or (d) combine Personal Information received from Customer with Personal Information received from another source, except to the extent permitted by the CCPA.
13.3 1stProtect certifies that it understands the restrictions in this Section 13 and will comply with them.
14. Term, Conflict, and Termination
14.1 This DPA is effective on the effective date of the Principal Agreement and continues for so long as 1stProtect Processes Customer Personal Data on Customer’s behalf.
14.2 In the event of any conflict between this DPA and the Principal Agreement with respect to the Processing of Personal Data, this DPA prevails. In the event of any conflict between this DPA and the SCCs or UK Addendum, the SCCs or UK Addendum prevail.
14.3 Termination of this DPA does not relieve either party of obligations that, by their nature, survive termination, including obligations relating to confidentiality, data deletion, and audit cooperation.

Annex A — Description of Processing
Subject matter and duration of Processing: Provision of the 1stProtect Software Platform pursuant to the Principal Agreement, for the duration of the Subscription Term and any post-termination retention period required by law.
Nature and purpose of Processing: Storage, transmission, analysis, and security monitoring of telemetry generated by Sensors deployed in Customer’s IT environment; provision of dashboard, alerting, and forensic functionality; aggregated threat-intelligence improvement; provision of customer support.
Types of Personal Data: - Authentication and authorization data: usernames, account identifiers, hashed credentials, authentication events - Endpoint metadata: device names, IP addresses, host names, OS information - Activity telemetry: process execution data, system call chains, network connection metadata, file system events - Security event data: detection alerts, policy enforcement actions, forensic snapshots - Customer portal user data: names, business email addresses, role assignments - Support correspondence
Special Category Data: None, unless explicitly configured by Customer for DLP inspection of specific data streams. The customer is responsible for advising 1stProtect in writing if such configuration is intended.
Categories of Data Subjects: - Customer’s employees, contractors, and other authorized users of Endpoints on which Sensors are deployed - Customer’s authorized portal users - Persons identified incidentally in security event data (e.g., a perpetrator of a credential-theft attempt)
Frequency of transfer: Continuous (real-time telemetry streaming and on-demand dashboard access).
Retention: Telemetry is retained for the period selected in Customer’s configuration, with a default of ninety (90) days for raw event data and twelve (12) months for aggregated security-event metadata.

Annex B — Security Measures
The Security Measures referenced in Section 5 of this DPA include the following:
A. Organizational Measures - Written information security policy reviewed annually by senior management - Designated security and privacy officers - Personnel screening (background checks where permitted by law) - Security awareness training for all personnel; role-based training for technical staff - Confidentiality obligations in all employment and contractor agreements - Incident response policy and trained incident response team - Vendor risk management program for Subprocessors
B. Access Controls - Role-based access control with least-privilege provisioning - Multi-factor authentication required for all administrative access - Centralized identity management - Quarterly access reviews - Logging of administrative access; tamper-evident audit logs - Prompt revocation of access on personnel changes
C. Encryption - AES-256 encryption of Customer Personal Data at rest in production environments - TLS 1.3 encryption of Customer Personal Data in transit between 1stProtect systems and Customer endpoints/users - Encryption key management consistent with industry standards (NIST SP 800-57)
D. Network and Infrastructure Security - Production environments hosted in SOC 2- and ISO 27001-certified facilities - Network segmentation; firewall and intrusion detection at perimeter and internal trust boundaries - Anti-DDoS and web application firewall protection at internet-facing surfaces - Regular vulnerability scanning and penetration testing (at least annually, and after significant changes) - Patch management with risk-based remediation timelines
E. Application Security - Secure software development lifecycle (SSDLC), including threat modeling, secure code review, and static and dynamic application security testing - Coordinated vulnerability disclosure program - Code signing for binary releases - Pre-release security review
F. Physical Security - Production data is hosted in cloud facilities with physical access controls including biometric or card-based access, video surveillance, and 24x7 onsite security personnel (per cloud provider attestations) - 1stProtect office facilities employ commercially reasonable physical access controls
G. Business Continuity and Disaster Recovery - Geographically redundant production architecture - Documented and regularly tested business continuity and disaster recovery procedures - Daily backups; backup integrity testing
H. Compliance and Audit - SOC 2 Type II attestation (annual) - ISO 27001 certification - Privacy impact assessment program - Internal audit function

Annex C — Standard Contractual Clauses Annex
This Annex is completed where the EU SCCs and/or UK Addendum apply.
Module: Module 2 (Controller-to-Processor) for direct-controller customers; Module 3 (Processor-to-Processor) where Customer is itself a Processor.
Data Exporter: Customer (as identified in the Principal Agreement).
Data Importer: 1stProtect Corp., a Delaware corporation with its principal place of business in San Francisco, California, USA. Contact: legal@1stprotect.ai. Data protection contact: privacy@1stprotect.ai.
Description of Transfer: As set out in Annex A above.
Competent Supervisory Authority (Clause 13): The Supervisory Authority of the EU/EEA Member State in which the Data Exporter has its main establishment or, if the Data Exporter is not established in the EU/EEA, the Supervisory Authority of the Member State whose data subjects are most affected.
Optional Clauses: - Clause 7 (Docking Clause): Adopted. - Clause 11(a) (Independent dispute resolution body): Not adopted. - Clause 17 (Governing law): The law of the Republic of Ireland. - Clause 18 (Choice of forum): The courts of Ireland.
UK Addendum elections: - Table 1 (Parties): As set out above. - Table 2 (Selected SCCs): The EU SCCs incorporated in this DPA. - Table 3 (Appendix Information): Annexes A, B, and this Annex C. - Table 4 (Termination of UK Addendum): Either party may end the UK Addendum as set out in Section 19 of the UK Addendum.

Contact: privacy@1stprotect.ai
For Data Subject inquiries: privacy@1stprotect.ai