[ Legal ]
Data processing addendum
Effective 28 July 2026. This addendum forms part of the agreement between RootXLabs (processor) and the customer (controller) wherever an engagement involves personal data.
1. Subject matter and roles
You are the controller of the personal data in your systems. We are your processor for any personal data we encounter while testing the scope you authorize. We process it only on your documented instructions, of which the engagement scope is one.
2. Nature of the processing
| Purpose | Demonstrating and remediating security vulnerabilities in the authorized scope. |
|---|---|
| Duration | The engagement term, plus the retention period below. |
| Data subjects | Whoever appears in the tested systems — typically your users, staff and customers. Not selected by us. |
| Data types | Whatever the tested system holds. Testing routinely surfaces credentials, tokens, session identifiers and record extracts. We take the minimum needed to prove a finding. |
Because we test live systems, we cannot know in advance which personal data a successful exploit will expose. That is inherent to the service, which is why the minimisation and deletion commitments below matter.
3. Minimisation
When a finding requires proof, we capture the smallest evidence that establishes it — a single record rather than a table, a redacted screenshot rather than a dump, a truncated token rather than a working one, wherever that still proves the issue. We do not bulk-extract data to demonstrate that bulk extraction is possible unless you ask us to in writing.
4. Confidentiality
Everyone with access to your data is bound by written confidentiality obligations that survive the engagement.
5. Security measures
- Encryption in transit for all data, and at rest for stored evidence.
- Access to engagement evidence restricted to the assigned team on a need-to-know basis.
- Multi-factor authentication on the systems that hold it.
- Evidence held in a per-engagement store that is destroyed as a unit at the end of retention.
6. Subprocessors
We use subprocessors for hosting, model inference and communications. The current list is available on request from privacy@rootxlabs.ai. Each is bound by terms no less protective than these. We will give you notice before adding a new subprocessor that will handle your data, and you may object on reasonable data-protection grounds.
Model providers. Where an engagement involves sending material to a third-party model provider, we use configurations that exclude your data from provider-side training and retention. Where you require that no third-party model sees your data at all, say so before the engagement starts — it changes how we run it.
7. International transfers
Where personal data leaves the EEA or UK we rely on the European Commission's Standard Contractual Clauses, together with the UK Addendum where applicable, and we carry out a transfer risk assessment.
8. Assistance
We will help you respond to data subject requests, and with data protection impact assessments and regulator consultations, taking account of the nature of the processing and the information available to us. If a data subject contacts us directly about your data, we will refer them to you rather than answer.
9. Breach notification
We will notify you without undue delay and within 48 hours of becoming aware of a personal data breach affecting your data, with what we know at the time and updates as we learn more. We will not wait for a complete picture before telling you.
10. Return and deletion
At the end of the engagement we delete the material recovered from your scope within 30 days, or sooner on written request, except where law requires us to keep it. The finding write-ups themselves — the descriptions, not the extracted data — are retained for 24 months so we can support your remediation and re-test, unless you ask us to delete those too.
Deletion is confirmed in writing on request.
11. Audit
We will make available the information needed to demonstrate compliance with this addendum, and will allow an audit by you or an independent auditor you appoint, on reasonable notice, no more than once a year unless a regulator or a breach requires otherwise.
12. Signing this
If your procurement process needs a countersigned copy, or you need your own DPA reviewed instead of this one, email legal@rootxlabs.ai.