Data Processing Agreement (DPA)
For customers whose use of LaunchSafe involves processing personal data. Covers roles, security measures, sub-processors, and international transfers.
This Data Processing Agreement applies where your use of LaunchSafe involves processing personal data subject to the GDPR, the UK GDPR, the Swiss FADP or US state privacy law. It forms part of the Terms of Service. Terms such as controller, processor, personal data and processing carry the meaning given in the applicable law.
If your procurement process needs a countersigned copy, email hello@launchsafe.com.
Roles
You are the controller, or a processor acting for your own controller, of the personal data within Customer Data. LaunchSafe is the processor and processes it only on your documented instructions; your use of the Service and this DPA are those instructions. Where we act as a business or service provider under US state law, we do not sell or share personal data and do not retain, use or disclose it for any purpose other than performing the Service.
What is processed
- Subject matter: provision of the LaunchSafe security-testing platform.
- Duration: your subscription term, plus the deletion period below.
- Nature and purpose: hosting, scanning, analysis, reporting and support.
- Data subjects: your personnel, contractors and users, and any individuals whose personal data appears incidentally in code, configuration, logs or findings you send us.
- Types of data: names, work contact details, user identifiers and authentication metadata, plus incidental personal data present in Customer Data. We ask you not to send special-category data.
Our obligations
- Process personal data only on your instructions, and tell you if we believe an instruction breaches data protection law.
- Ensure everyone we authorise to process it is under a duty of confidence.
- Implement the technical and organisational measures described in the Security Overview, which we may update provided protection is not reduced.
- Help you respond to data-subject requests and to your own obligations on security, breach notification and impact assessments, taking into account the nature of the processing.
- Make available the information needed to demonstrate compliance.
Sub-processors
You give general authorisation for us to engage sub-processors. Each is bound by written terms no less protective than this DPA, and we remain liable for their performance. Our current sub-processors:
- DigitalOcean — application hosting and managed Postgres (United States, European Union).
- Anthropic — model inference, under zero data-retention terms (United States).
- Cloudflare — DNS, CDN and edge protection (global).
- Google Workspace — business email and document collaboration (United States).
- Stripe — payment processing (United States).
We give at least 30 days' notice before adding or replacing a sub-processor. Email hello@launchsafe.com to receive those notices. If you reasonably object on data-protection grounds we will work with you on an alternative, and if none can be found you may terminate the affected part of the Service without penalty.
International transfers
Where personal data leaves the UK, EEA or Switzerland we rely on the European Commission's Standard Contractual Clauses (Module Two controller-to-processor, or Module Three where you are a processor), the UK International Data Transfer Addendum, and the Swiss amendments, each incorporated here by reference and completed with the details above. We carry out and document transfer risk assessments. Enterprise customers may pin processing to a single region or deploy into their own VPC.
Security incidents
We will notify you without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting your data. The notice will describe what we know, the likely consequences, and the steps taken. We will not delay notice in order to finish an investigation.
Data-subject requests
If a request reaches us directly from one of your data subjects we will not answer it substantively. We will pass it to you promptly and help you respond.
Audits
Once a year, or following a security incident affecting your data, you may request our current third-party audit reports and penetration-test summaries under NDA. Where that genuinely does not demonstrate compliance, you may audit us on 30 days' notice, at your cost, during business hours, with reasonable scope, and without access to other customers' data.
Return and deletion
On termination we delete Customer Data, including personal data, within 30 days, and you may export it during that window. Backups age out on their normal rotation within 90 days and stay encrypted and inaccessible until then. We keep data longer only where the law requires it.
Precedence
Where this DPA conflicts with the Terms of Service on the processing of personal data, this DPA wins.