Our standard Article 28 terms, published so your legal and privacy teams can review them before you contact us. We will also work under your own DPA.
This Data Processing Agreement (“DPA”) forms part of the agreement between Cetonix (“Processor”) and the client (“Controller”) for penetration testing, security assessment, GRC and certification coordination services.
Version 1.0 · Effective 1 October 2025. Request a signable copy as PDF or Word.
If you have your own DPA, send it. We would rather sign your paper than argue about ours. This document exists so that you can assess us before that conversation, and so that clients without a template have one to start from.
The Controller determines the purposes and means of processing. Cetonix acts as Processor and processes personal data only on the Controller’s documented instructions, which are given by the signed statement of work and the agreed rules of engagement.
A note specific to security testing. In a penetration test, Cetonix does not receive a dataset to process. Personal data is encountered incidentally, inside systems the Controller has authorised us to test. Our obligation is therefore to minimise what we access at all, not merely to protect what we are given. Section 6 sets out how.
| Subject matter | Security testing, assessment and reporting, or coordination of certification, as described in the statement of work. |
| Duration | The engagement term plus the agreed retest window. See section 9. |
| Nature and purpose | Identifying and evidencing security vulnerabilities in systems the Controller owns or is authorised to test. |
| Categories of data subject | Controller personnel whose test accounts are supplied; and, incidentally, any data subject whose records exist in the systems under test — which may include customers, end users, employees and, where applicable, minors. |
| Types of personal data | Test account credentials and contact details supplied by the Controller. Incidentally: identifiers, contact data, images, and any other category present in the systems under test. |
| Special category data | Not processed by design. Where special category data, children’s data or financial data is present in the environment, testing is designed to avoid retrieval and section 6 applies. |
Cetonix shall:
All engagement material — findings, evidence, credentials, screenshots, network captures and reports — is treated as the Controller’s confidential information. Access is restricted to the assigned engagement team on a least-privilege basis and is logged. Every member of the team signs an individual confidentiality undertaking in addition to the company-level NDA. These obligations survive termination.
Cetonix will not use engagement material as a case study, marketing example or training material without the Controller’s specific written permission.
Cetonix maintains at least the following technical and organisational measures:
This section is the practical heart of the agreement for a testing engagement, and we hold ourselves to it in every report we issue:
Penetration testing and security assessment are delivered by Cetonix’s own employed team. No sub-processor is engaged for the testing itself.
Cetonix uses a limited number of sub-processors for supporting infrastructure — hosting, email and file transfer. A current list is available on request and is provided before contracting. Cetonix will give the Controller at least 30 days’ notice before adding or replacing a sub-processor, during which the Controller may object on reasonable data protection grounds; if the objection cannot be resolved, either party may terminate the affected services without penalty.
Cetonix imposes on every sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Controller for the sub-processor’s performance.
Where Cetonix coordinates certification, the appointed conformity assessment body is an independent controller of the audit records it creates, not a Cetonix sub-processor.
Cetonix will notify the Controller without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting the Controller’s data, and will provide the information reasonably required for the Controller to meet its own notification obligations, including the nature of the breach, categories and approximate number of records affected, likely consequences and remedial measures taken.
Cetonix will not notify a supervisory authority or data subject on the Controller’s behalf unless instructed to, and will not make public statements identifying the Controller without written consent.
Cetonix retains no copy except where required by law, in which case the data remains subject to this DPA for as long as it is held.
Cetonix will make available the information necessary to demonstrate compliance with this DPA, and will respond to reasonable security questionnaires. The Controller may audit Cetonix’s compliance no more than once in any twelve-month period, on 30 days’ written notice, during business hours, subject to confidentiality undertakings and without access to other clients’ data. Additional audits may be conducted following a personal data breach affecting the Controller.
Cetonix is established in India and processes engagement data in India. We state this plainly because it is material to your assessment.
For personal data originating in the EEA, the UK or Switzerland, the parties enter into the European Commission’s Standard Contractual Clauses (Module Two, controller to processor), which are incorporated into this DPA by reference, together with the UK International Data Transfer Addendum where applicable. Cetonix will complete a transfer impact assessment on request and applies supplementary technical measures including encryption at rest and in transit and strict access control.
Where an engagement requires that data remain in a specific jurisdiction, raise it at scoping. Depending on the engagement we may be able to operate entirely within infrastructure the Controller provides and controls, so that no engagement data leaves the Controller’s own environment. We will confirm in writing what is achievable before contracting rather than after.
Where the Controller is subject to the California Consumer Privacy Act as amended by the CPRA, or to a comparable US state privacy law, Cetonix acts as a service provider (or processor) and:
Where the systems under test contain student education records or the personal information of children, the Controller remains responsible for its own obligations under FERPA, COPPA and equivalent laws. Cetonix will support those obligations through the minimisation practices in section 6 and will not knowingly retrieve, retain or transmit children’s personal data beyond the minimum required to evidence a finding.
Liability under this DPA is subject to the limitations in the master services agreement or statement of work, except where applicable law prevents such limitation. Liability for breach of confidentiality, and liability arising from wilful misconduct or fraud, is not limited by those provisions.
This DPA takes effect on signature of the statement of work and continues until all engagement data has been deleted or returned. Where this DPA conflicts with the master services agreement on the processing of personal data, this DPA prevails. Where the Controller’s own DPA is executed, that document prevails over this one.
Please have this reviewed by your own counsel before signature. It is a template drafted for common engagement types, not legal advice, and it does not account for sector-specific obligations that may apply to you.
Related: Privacy policy · Security practices and vulnerability disclosure · Terms of service