info@cetonix.com +91 (966) 512-1196 Mon–Fri, 09:30–18:00 IST
HomeData Processing Agreement

Data Processing Agreement

Our standard Article 28 terms, published so your legal and privacy teams can review them before you contact us. We will also work under your own DPA.

This Data Processing Agreement (“DPA”) forms part of the agreement between Cetonix (“Processor”) and the client (“Controller”) for penetration testing, security assessment, GRC and certification coordination services.

Version 1.0 · Effective 1 October 2025. Request a signable copy as PDF or Word.

If you have your own DPA, send it. We would rather sign your paper than argue about ours. This document exists so that you can assess us before that conversation, and so that clients without a template have one to start from.

1. Roles and scope

The Controller determines the purposes and means of processing. Cetonix acts as Processor and processes personal data only on the Controller’s documented instructions, which are given by the signed statement of work and the agreed rules of engagement.

A note specific to security testing. In a penetration test, Cetonix does not receive a dataset to process. Personal data is encountered incidentally, inside systems the Controller has authorised us to test. Our obligation is therefore to minimise what we access at all, not merely to protect what we are given. Section 6 sets out how.

2. Details of processing

Subject matterSecurity testing, assessment and reporting, or coordination of certification, as described in the statement of work.
DurationThe engagement term plus the agreed retest window. See section 9.
Nature and purposeIdentifying and evidencing security vulnerabilities in systems the Controller owns or is authorised to test.
Categories of data subjectController personnel whose test accounts are supplied; and, incidentally, any data subject whose records exist in the systems under test — which may include customers, end users, employees and, where applicable, minors.
Types of personal dataTest account credentials and contact details supplied by the Controller. Incidentally: identifiers, contact data, images, and any other category present in the systems under test.
Special category dataNot processed by design. Where special category data, children’s data or financial data is present in the environment, testing is designed to avoid retrieval and section 6 applies.

3. Processor obligations

Cetonix shall:

  • Process personal data only on the Controller’s documented instructions, including on international transfers, unless required otherwise by law — in which case Cetonix will inform the Controller before processing, unless legally prohibited.
  • Ensure that every person authorised to process personal data is under an appropriate obligation of confidentiality, whether contractual or statutory.
  • Implement the technical and organisational measures set out in section 5.
  • Respect the conditions in section 7 for engaging any sub-processor.
  • Assist the Controller, by appropriate measures, in fulfilling its obligation to respond to data subject requests.
  • Assist the Controller in complying with its obligations on security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of processing and the information available to Cetonix.
  • Delete or return personal data at the Controller’s election at the end of the engagement, in accordance with section 9.
  • Make available all information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, in accordance with section 10.
  • Immediately inform the Controller if, in its opinion, an instruction infringes applicable data protection law.

4. Confidentiality

All engagement material — findings, evidence, credentials, screenshots, network captures and reports — is treated as the Controller’s confidential information. Access is restricted to the assigned engagement team on a least-privilege basis and is logged. Every member of the team signs an individual confidentiality undertaking in addition to the company-level NDA. These obligations survive termination.

Cetonix will not use engagement material as a case study, marketing example or training material without the Controller’s specific written permission.

5. Security measures

Cetonix maintains at least the following technical and organisational measures:

  • Encryption. Personal data and engagement evidence encrypted at rest and in transit. Reports delivered over an encrypted channel, never as an unprotected email attachment.
  • Access control. Least privilege, individual named accounts, multi-factor authentication on systems holding engagement data, and logged access.
  • Segregation. Each engagement’s data is held separately; testers are granted access only to the engagements they are assigned to.
  • Endpoint controls. Full-disk encryption on testing devices, and no engagement data retained on personal devices.
  • Personnel. Background verification appropriate to the engagement, confidentiality undertakings, and defined disciplinary consequences for breach.
  • Restrictions on third-party services. No client data is submitted to any artificial intelligence or machine learning service under any circumstances — not source code, configuration, traffic captures, credentials, findings or report content. Where AI tooling is used for internal work unrelated to client engagements, it is on enterprise tiers with model training disabled and zero data retention. Cetonix accepts this as a contractual term including subcontractor flow-down.
  • Resilience and recovery. Backups of engagement data are encrypted and subject to the same retention and destruction rules as the primary copy.
  • Testing of measures. These measures are reviewed at least annually and after any material change.

6. Data minimisation during testing

This section is the practical heart of the agreement for a testing engagement, and we hold ourselves to it in every report we issue:

  • Where a vulnerability exposes personal data, records are counted and classified, never copied. Sampling stops at the minimum needed to evidence the finding.
  • Live credential material recovered during testing is recorded as recovered, and the value itself is masked in every copy of the report, including the Controller’s own copy.
  • Payment card data is never retrieved by design; where a payment reference is returned it is recorded as a token, not a primary account number.
  • Children’s personal data and images are masked in every copy of the report, including the Controller’s own.
  • Reports issued for onward distribution — to auditors, assessors or prospective customers — carry a documented redaction key stating exactly what has been masked and what the Controller’s copy contains in its place.

7. Sub-processors

Penetration testing and security assessment are delivered by Cetonix’s own employed team. No sub-processor is engaged for the testing itself.

Cetonix uses a limited number of sub-processors for supporting infrastructure — hosting, email and file transfer. A current list is available on request and is provided before contracting. Cetonix will give the Controller at least 30 days’ notice before adding or replacing a sub-processor, during which the Controller may object on reasonable data protection grounds; if the objection cannot be resolved, either party may terminate the affected services without penalty.

Cetonix imposes on every sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Controller for the sub-processor’s performance.

Where Cetonix coordinates certification, the appointed conformity assessment body is an independent controller of the audit records it creates, not a Cetonix sub-processor.

8. Personal data breach

Cetonix will notify the Controller without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting the Controller’s data, and will provide the information reasonably required for the Controller to meet its own notification obligations, including the nature of the breach, categories and approximate number of records affected, likely consequences and remedial measures taken.

Cetonix will not notify a supervisory authority or data subject on the Controller’s behalf unless instructed to, and will not make public statements identifying the Controller without written consent.

9. Retention, return and deletion

  • Credentials supplied for testing are destroyed on completion of testing. The Controller should also revoke them.
  • Evidence and findings are retained only until the end of the agreed retest window, then destroyed.
  • Final reports are retained only where the Controller asks Cetonix to retain them; otherwise they are destroyed with the evidence.
  • Earlier destruction on the Controller’s written request, at any time.
  • Written confirmation of destruction is provided in every case, identifying what was destroyed and when.

Cetonix retains no copy except where required by law, in which case the data remains subject to this DPA for as long as it is held.

10. Audits

Cetonix will make available the information necessary to demonstrate compliance with this DPA, and will respond to reasonable security questionnaires. The Controller may audit Cetonix’s compliance no more than once in any twelve-month period, on 30 days’ written notice, during business hours, subject to confidentiality undertakings and without access to other clients’ data. Additional audits may be conducted following a personal data breach affecting the Controller.

11. International transfers

Cetonix is established in India and processes engagement data in India. We state this plainly because it is material to your assessment.

For personal data originating in the EEA, the UK or Switzerland, the parties enter into the European Commission’s Standard Contractual Clauses (Module Two, controller to processor), which are incorporated into this DPA by reference, together with the UK International Data Transfer Addendum where applicable. Cetonix will complete a transfer impact assessment on request and applies supplementary technical measures including encryption at rest and in transit and strict access control.

Where an engagement requires that data remain in a specific jurisdiction, raise it at scoping. Depending on the engagement we may be able to operate entirely within infrastructure the Controller provides and controls, so that no engagement data leaves the Controller’s own environment. We will confirm in writing what is achievable before contracting rather than after.

12. United States privacy laws

Where the Controller is subject to the California Consumer Privacy Act as amended by the CPRA, or to a comparable US state privacy law, Cetonix acts as a service provider (or processor) and:

  • Processes personal information solely to perform the services specified in the statement of work.
  • Does not sell or share personal information, as those terms are defined in the applicable law.
  • Does not retain, use or disclose personal information for any purpose other than performing the services, or outside the direct business relationship with the Controller.
  • Does not combine personal information received from the Controller with personal information from any other source, except as permitted by law.
  • Will notify the Controller if it determines it can no longer meet these obligations.

Where the systems under test contain student education records or the personal information of children, the Controller remains responsible for its own obligations under FERPA, COPPA and equivalent laws. Cetonix will support those obligations through the minimisation practices in section 6 and will not knowingly retrieve, retain or transmit children’s personal data beyond the minimum required to evidence a finding.

13. Liability

Liability under this DPA is subject to the limitations in the master services agreement or statement of work, except where applicable law prevents such limitation. Liability for breach of confidentiality, and liability arising from wilful misconduct or fraud, is not limited by those provisions.

14. Term and precedence

This DPA takes effect on signature of the statement of work and continues until all engagement data has been deleted or returned. Where this DPA conflicts with the master services agreement on the processing of personal data, this DPA prevails. Where the Controller’s own DPA is executed, that document prevails over this one.


Please have this reviewed by your own counsel before signature. It is a template drafted for common engagement types, not legal advice, and it does not account for sector-specific obligations that may apply to you.

Related: Privacy policy · Security practices and vulnerability disclosure · Terms of service