Data Processing Agreement

Version 1.0 — Effective: July 25, 2026

This DPA forms part of the agreement between WireZTNA (Processor) and the subscribing Partner (Controller). It is automatically effective upon subscription — no separate signature required. For a countersigned copy, email legal@wireztna.com.

1. Parties and Scope

This Data Processing Agreement ("DPA") is entered into between:

  • Data Controller ("Controller"): The Partner organization subscribing to WireZTNA services
  • Data Processor ("Processor"): WireZTNA

This DPA governs the processing of personal data by the Processor on behalf of the Controller in connection with the WireZTNA platform services, as required by Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").

2. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person processed through the Service
  • "Processing" means any operation performed on Personal Data (collection, storage, use, transmission, deletion)
  • "Sub-processor" means any third party engaged by the Processor to process Personal Data
  • "Data Subjects" means the end users and administrators whose data is processed

3. Subject Matter and Duration

ElementDescription
Subject matterProvision of Zero Trust Network Access services
DurationDuration of the service agreement + 30 days for data deletion
Nature of processingStorage, routing, authentication, access control, logging
PurposeEnabling secure remote access for Controller's end users

4. Categories of Data Subjects and Personal Data

4.1 Data Subjects

  • End users (employees/contractors of the Controller's clients)
  • System administrators of the Controller

4.2 Categories of Personal Data

CategoryData ElementsSensitivity
Identity dataEmail address, display nameStandard
Authentication dataPassword hash (bcrypt), TOTP secret (encrypted)Standard
Network identityWireGuard public key, overlay IP addressStandard
Connection metadataSession timestamps, handshake age, bytes transferredStandard
Access logsLogin events, group changes, resource access timestampsStandard

Not processed: Traffic payload content, DNS query contents, private keys, special categories of data (Art. 9 GDPR).

5. Processor Obligations

The Processor shall:

  1. Process Personal Data only on documented instructions from the Controller (this DPA and the service configuration constitute such instructions)
  2. Ensure that persons authorized to process Personal Data are bound by confidentiality obligations
  3. Implement appropriate technical and organizational security measures (see Section 8)
  4. Not engage Sub-processors without prior written authorization (see Section 6)
  5. Assist the Controller in responding to Data Subject rights requests
  6. Assist the Controller with data protection impact assessments where required
  7. Delete or return all Personal Data upon termination (Controller's choice)
  8. Make available all information necessary to demonstrate compliance and allow audits

6. Sub-processors

The Controller provides general authorization for the Processor to engage the following Sub-processors:

Sub-processorPurposeLocationDPA in place
Amazon Web Services EMEA SARLInfrastructure hosting (compute, storage)EU (Frankfurt, DE)Yes (AWS DPA)
Cloudflare Inc.CDN, DDoS protection, DNS, edge computeEU edge nodes (data localization enabled)Yes (Cloudflare DPA)
Mailjet SAS (Sinch)Transactional email delivery (OTP codes, notifications)EUYes (Mailjet DPA)
Better Stack Inc.Uptime monitoring (checks only — no personal data transferred)EUYes

The Processor shall inform the Controller of any intended addition or replacement of Sub-processors at least 30 days before the change, giving the Controller the opportunity to object. If the Controller objects on reasonable grounds and no resolution is found within 15 days, the Controller may terminate the affected service component.

7. International Transfers

All processing occurs within the European Economic Area (EEA). No Personal Data is transferred to third countries unless:

  • The Controller explicitly configures publishers in non-EEA regions
  • A Sub-processor has limited processing in countries with an EU adequacy decision
  • Standard Contractual Clauses (SCCs) per Commission Implementing Decision (EU) 2021/914 are in place

As of this version, no routine international transfers occur.

8. Security Measures

The Processor implements the following technical and organizational measures:

8.1 Encryption

  • Data in transit: WireGuard (Curve25519 + ChaCha20-Poly1305) for all tunnel traffic; TLS 1.3 for API/web
  • Data at rest: Encrypted EBS volumes (AES-256) for all storage
  • Key management: Private keys generated on-device, never transmitted to or stored by the Processor

8.2 Access Control

  • Role-based access control (admin / user) enforced at API level
  • Network-level isolation per tenant (dedicated broker instance, no shared data plane)
  • nftables kernel-level enforcement of per-user access policies
  • Infrastructure access restricted to authorized personnel with MFA

8.3 Availability and Resilience

  • Automated health monitoring with 15-second check intervals
  • Self-healing reconciliation loop (convergent infrastructure)
  • Regular encrypted backups with tested restore procedures
  • DDoS protection via Cloudflare (enterprise-grade)

8.4 Personnel

  • All personnel with access to Personal Data are bound by NDAs
  • Principle of least privilege enforced for infrastructure access
  • Security awareness and GDPR training

9. Data Breach Notification

In the event of a Personal Data breach, the Processor shall:

  1. Notify the Controller without undue delay and in any event within 48 hours of becoming aware of the breach
  2. Provide the following information:
    • Nature of the breach (categories and approximate number of Data Subjects affected)
    • Likely consequences of the breach
    • Measures taken or proposed to mitigate the breach
    • Contact point for further information
  3. Cooperate with the Controller in notifying supervisory authorities and Data Subjects where required
  4. Document all breaches including facts, effects, and remedial actions taken

10. Data Subject Rights

The Processor shall assist the Controller in fulfilling obligations to respond to Data Subject requests (Articles 15–22 GDPR):

  • Access and portability: Export functionality via API and admin panel
  • Rectification: Admin panel allows editing all user data
  • Erasure: Account deletion removes all associated personal data within 30 days
  • Restriction: Account suspension stops all processing while retaining data

The Processor will respond to Controller assistance requests within 10 business days.

11. Audit Rights

The Controller has the right to conduct audits (or appoint an independent auditor) to verify the Processor's compliance with this DPA. Audits shall be:

  • Requested with at least 30 days written notice
  • Conducted during business hours with minimal disruption
  • Limited to once per 12-month period (unless triggered by a breach or regulatory requirement)
  • Subject to reasonable confidentiality obligations on the auditor

The Processor may provide SOC 2 Type II reports, penetration test summaries, or equivalent certifications as alternative evidence of compliance.

12. Data Deletion and Return

Upon termination of the service agreement:

  • The Controller may request data export (JSON format via API) for 30 days post-termination
  • After the 30-day period, the Processor shall permanently delete all Personal Data from active systems
  • Backup copies are overwritten within 90 days through normal backup rotation
  • The Processor shall provide written confirmation of deletion upon request

13. Liability

Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. The Processor is liable for damages caused by processing that does not comply with GDPR obligations specifically directed to processors, or where it has acted outside of or contrary to the Controller's lawful instructions.

14. Governing Law

This DPA is governed by the laws of Spain and the GDPR. For disputes, the provisions in the Terms of Service (Section 13) apply.

15. Contact

For DPA-related inquiries, requests for countersigned copies, or to exercise audit rights: