As of: September 2026
This data processing agreement (DPA) is concluded between Rheono, owner Samir Abis, Daimlerstr. 5E, 76669 Bad Schönborn, Germany (hereinafter "Processor"), and the Customer as Controller (hereinafter "Client"), for the security testing agreed in the contract. It governs the processing of personal data by the Processor under Art. 28 GDPR. It prevails over the Terms & Conditions in respect of the subject matter it covers.
The subject of the mandate is the processing of personal data arising in the course of the agreed security testing on the Client's external web and API surface. The Processor processes such data exclusively to deliver the agreed service and on the basis of the Client's instructions.
The Processor performs a continuous, autonomous vulnerability assessment (external, non-mutating), verifies each finding manually by proof of concept, and issues signed reports with CVSS rating and mapping to NIS2 and ISO 27001 evidence. Processing comprises the capture, testing, documentation, storage and, after the retention period, deletion of findings, proofs of concept and related metadata.
Data subjects may be: end users of the systems under test (e.g. within a finding), the Client's employees (e.g. as contact person) and third parties whose systems are touched by a finding.
Personal data that is unavoidably captured in a finding or in communication, in particular: names, email addresses, IP addresses, role/context data in the context of a vulnerability finding, and technically unavoidable telemetry. The Processor avoids accessing personal data where technically reasonable and limits processing to what is necessary (data minimisation, Art. 5 GDPR). Reports and PoCs contain only the data required for the respective finding.
Processing lasts for the term of the respective contract (the respective authorisation) plus the agreed retention period. The retention period the Client sets in the customer portal (30 days to 100 years) applies to test data and unreported findings. Reports and signed snapshots are subject to a statutory retention of 10 years.
The Processor processes the Client's data exclusively in a data centre located in the European Union. It implements the technical and organisational measures appropriate under Art. 32 GDPR, in particular: encryption in transit and at rest, access control (least privilege), a separated production environment, logging of signing-relevant events (append-only) and secure destruction.
The Processor processes the personal data only on documented instructions from the Client, unless required to do so by Union or national law. The Client's instructions are the written authorisation, the rules of engagement and the settings made separately in the customer portal. On instructions that contravene the GDPR, the Processor informs the Client without delay.
The Processor engages only sub-processors that assume the equivalent obligations under Art. 28 GDPR, and is liable towards the Client for the selection, direction and supervision of the sub-processor as for its own fault. The Client may object to the engagement of a sub-processor if the Processor cannot offer a technical or organisational alternative without substantially degrading the service.
The Client provides all information, access, test accounts and approvals required for performance in a timely and usable form, and warrants that, as Controller, it is authorised to include the systems to be tested in the mandate.
Taking into account the nature of the processing, the Processor assists the Client in fulfilling its obligations under Arts. 32 to 36 GDPR, in particular regarding security, notifying the supervisory authority and data subjects of a personal data breach, and data protection impact assessments and prior consultations.
The Processor informs the Client without delay, and at the latest within 24 hours, of any breach that has become known and affects the Client's personal data, and assists the Client in fulfilling its obligations under Art. 33 GDPR and in the technical and organisational follow-up.
The Processor makes available to the Client all information necessary to demonstrate compliance and permits audits, including inspections, carried out by the Client or another auditor mandated by the Client.
After the termination of the contract or the completion of the individual service, the Processor, at the Client's choice, returns or deletes (including all copies) all personal data, unless a statutory retention obligation (in particular tax, commercial or procedural) applies; in that case the data is limited to the statutory retention purpose.
The Processor's liability towards the Client is governed by clause 14 of the Terms & Conditions, unless expressly provided otherwise in this agreement.
The laws of the Federal Republic of Germany apply to this agreement. In case of conflict the German version prevails. Amendments require text form.
Note: This DPA is part of the respective contract for security services (AGB §13) and applies as soon as personal data is processed in the course of the service. It prevails over the T&Cs in respect of the subject matter it covers.