Data Processing Agreement
Version 1.0 — Effective: July 25, 2026
This DPA forms part of the agreement between WireZTNA (Processor) and the subscribing Partner (Controller). It is automatically effective upon subscription — no separate signature required. For a countersigned copy, email legal@wireztna.com.
1. Parties and Scope
This Data Processing Agreement ("DPA") is entered into between:
- Data Controller ("Controller"): The Partner organization subscribing to WireZTNA services
- Data Processor ("Processor"): WireZTNA
This DPA governs the processing of personal data by the Processor on behalf of the Controller in connection with the WireZTNA platform services, as required by Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").
2. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person processed through the Service
- "Processing" means any operation performed on Personal Data (collection, storage, use, transmission, deletion)
- "Sub-processor" means any third party engaged by the Processor to process Personal Data
- "Data Subjects" means the end users and administrators whose data is processed
3. Subject Matter and Duration
| Element | Description |
|---|---|
| Subject matter | Provision of Zero Trust Network Access services |
| Duration | Duration of the service agreement + 30 days for data deletion |
| Nature of processing | Storage, routing, authentication, access control, logging |
| Purpose | Enabling secure remote access for Controller's end users |
4. Categories of Data Subjects and Personal Data
4.1 Data Subjects
- End users (employees/contractors of the Controller's clients)
- System administrators of the Controller
4.2 Categories of Personal Data
| Category | Data Elements | Sensitivity |
|---|---|---|
| Identity data | Email address, display name | Standard |
| Authentication data | Password hash (bcrypt), TOTP secret (encrypted) | Standard |
| Network identity | WireGuard public key, overlay IP address | Standard |
| Connection metadata | Session timestamps, handshake age, bytes transferred | Standard |
| Access logs | Login events, group changes, resource access timestamps | Standard |
Not processed: Traffic payload content, DNS query contents, private keys, special categories of data (Art. 9 GDPR).
5. Processor Obligations
The Processor shall:
- Process Personal Data only on documented instructions from the Controller (this DPA and the service configuration constitute such instructions)
- Ensure that persons authorized to process Personal Data are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures (see Section 8)
- Not engage Sub-processors without prior written authorization (see Section 6)
- Assist the Controller in responding to Data Subject rights requests
- Assist the Controller with data protection impact assessments where required
- Delete or return all Personal Data upon termination (Controller's choice)
- Make available all information necessary to demonstrate compliance and allow audits
6. Sub-processors
The Controller provides general authorization for the Processor to engage the following Sub-processors:
| Sub-processor | Purpose | Location | DPA in place |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Infrastructure hosting (compute, storage) | EU (Frankfurt, DE) | Yes (AWS DPA) |
| Cloudflare Inc. | CDN, DDoS protection, DNS, edge compute | EU edge nodes (data localization enabled) | Yes (Cloudflare DPA) |
| Mailjet SAS (Sinch) | Transactional email delivery (OTP codes, notifications) | EU | Yes (Mailjet DPA) |
| Better Stack Inc. | Uptime monitoring (checks only — no personal data transferred) | EU | Yes |
The Processor shall inform the Controller of any intended addition or replacement of Sub-processors at least 30 days before the change, giving the Controller the opportunity to object. If the Controller objects on reasonable grounds and no resolution is found within 15 days, the Controller may terminate the affected service component.
7. International Transfers
All processing occurs within the European Economic Area (EEA). No Personal Data is transferred to third countries unless:
- The Controller explicitly configures publishers in non-EEA regions
- A Sub-processor has limited processing in countries with an EU adequacy decision
- Standard Contractual Clauses (SCCs) per Commission Implementing Decision (EU) 2021/914 are in place
As of this version, no routine international transfers occur.
8. Security Measures
The Processor implements the following technical and organizational measures:
8.1 Encryption
- Data in transit: WireGuard (Curve25519 + ChaCha20-Poly1305) for all tunnel traffic; TLS 1.3 for API/web
- Data at rest: Encrypted EBS volumes (AES-256) for all storage
- Key management: Private keys generated on-device, never transmitted to or stored by the Processor
8.2 Access Control
- Role-based access control (admin / user) enforced at API level
- Network-level isolation per tenant (dedicated broker instance, no shared data plane)
- nftables kernel-level enforcement of per-user access policies
- Infrastructure access restricted to authorized personnel with MFA
8.3 Availability and Resilience
- Automated health monitoring with 15-second check intervals
- Self-healing reconciliation loop (convergent infrastructure)
- Regular encrypted backups with tested restore procedures
- DDoS protection via Cloudflare (enterprise-grade)
8.4 Personnel
- All personnel with access to Personal Data are bound by NDAs
- Principle of least privilege enforced for infrastructure access
- Security awareness and GDPR training
9. Data Breach Notification
In the event of a Personal Data breach, the Processor shall:
- Notify the Controller without undue delay and in any event within 48 hours of becoming aware of the breach
- Provide the following information:
- Nature of the breach (categories and approximate number of Data Subjects affected)
- Likely consequences of the breach
- Measures taken or proposed to mitigate the breach
- Contact point for further information
- Cooperate with the Controller in notifying supervisory authorities and Data Subjects where required
- Document all breaches including facts, effects, and remedial actions taken
10. Data Subject Rights
The Processor shall assist the Controller in fulfilling obligations to respond to Data Subject requests (Articles 15–22 GDPR):
- Access and portability: Export functionality via API and admin panel
- Rectification: Admin panel allows editing all user data
- Erasure: Account deletion removes all associated personal data within 30 days
- Restriction: Account suspension stops all processing while retaining data
The Processor will respond to Controller assistance requests within 10 business days.
11. Audit Rights
The Controller has the right to conduct audits (or appoint an independent auditor) to verify the Processor's compliance with this DPA. Audits shall be:
- Requested with at least 30 days written notice
- Conducted during business hours with minimal disruption
- Limited to once per 12-month period (unless triggered by a breach or regulatory requirement)
- Subject to reasonable confidentiality obligations on the auditor
The Processor may provide SOC 2 Type II reports, penetration test summaries, or equivalent certifications as alternative evidence of compliance.
12. Data Deletion and Return
Upon termination of the service agreement:
- The Controller may request data export (JSON format via API) for 30 days post-termination
- After the 30-day period, the Processor shall permanently delete all Personal Data from active systems
- Backup copies are overwritten within 90 days through normal backup rotation
- The Processor shall provide written confirmation of deletion upon request
13. Liability
Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. The Processor is liable for damages caused by processing that does not comply with GDPR obligations specifically directed to processors, or where it has acted outside of or contrary to the Controller's lawful instructions.
14. Governing Law
This DPA is governed by the laws of Spain and the GDPR. For disputes, the provisions in the Terms of Service (Section 13) apply.
15. Contact
For DPA-related inquiries, requests for countersigned copies, or to exercise audit rights:
- Email: legal@wireztna.com
- Privacy inquiries: privacy@wireztna.com