Data Processing Agreement
This DPA supplements our Terms of Service and governs the processing of personal data by EchelonGraph on your behalf.
Version: September 24, 2026 · What changed in this version
1. Definitions
Controller: You, the customer, who determines the purposes and means of processing personal data through the Service.
Processor: EchelonGraph, Inc., a United States C-corporation, which processes personal data on behalf of the Controller.
Personal Data: Any information relating to an identified or identifiable natural person as defined in GDPR Article 4(1).
Processing: Any operation performed on personal data, including collection, storage, use, disclosure, and deletion.
2. Categories of Data Processed
| Category | Data Types | Lawful Basis |
|---|---|---|
| Account Data | Name, email, organization, role, auth credentials (hashed) | Contract performance |
| Cloud Configuration | IAM policies, security groups, VPC configs, resource metadata | Contract performance |
| Vulnerability Data | CVE IDs, CVSS scores, affected resources, remediation states | Contract performance |
| Compliance Data | Framework scores, control results, evidence artifacts | Contract performance |
| Usage Data | API calls, page views, feature usage (anonymized) | Legitimate interest |
| Log Data | IP addresses, access timestamps, user agent, request metadata | Legitimate interest / Security |
3. Processing Obligations
EchelonGraph shall: (a) process personal data only on documented instructions from the Controller; (b) ensure that persons authorized to process personal data have committed themselves to confidentiality; (c) implement appropriate technical and organizational security measures; (d) respect the conditions for engaging sub-processors; (e) assist the Controller in responding to data subject requests; (f) assist the Controller in ensuring compliance with GDPR Articles 32-36; (g) delete or return all personal data upon termination; (h) make available to the Controller all information necessary to demonstrate compliance.
4. Sub-Processors
We use the following sub-processors. You will be notified 30 days before adding new sub-processors.
| Provider | Purpose | Location | SCCs |
|---|---|---|---|
| Google Cloud Platform | Infrastructure hosting, compute, storage | United States (databases and backups); operational logs: global | ✅ |
| Stripe | Payment processing | United States | ✅ |
| SendGrid (Twilio) | Transactional email delivery | United States | ✅ |
| Cloudflare | CDN, DDoS protection, DNS | Global (edge) | ✅ |
| Anthropic | AI remediation guidance and AI copilot answers (Claude models) | United States (at rest); inference may run in any geography Anthropic makes available | ✅ Incorporated in Anthropic's Data Processing Addendum |
| Google Gemini API | AI copilot chat and AI remediation guidance (Gemini models) | Any country where Google or its agents maintain facilities (Google does not commit to a region for the Gemini API) | ✅ Incorporated in Google's Data Processing Addendum, which applies to paid Gemini API use |
5. Technical & Organizational Measures
Encryption at Rest
AES-256-GCM for all data stores (PostgreSQL, Neo4j, ClickHouse, Redis)
Encryption in Transit
TLS 1.3 for all inter-service communication and external APIs
Access Control
RBAC with 5 roles, 18 permissions, least-privilege principle
Authentication
RS256 JWT, TOTP MFA, SAML/OIDC/LDAP SSO, session management
Tenant Isolation
PostgreSQL RLS, Neo4j label isolation, ClickHouse partition isolation
Audit Logging
All admin actions logged with user ID, timestamp, IP, and action detail
Vulnerability Management
Automated CVE scanning of infrastructure, 24h critical patch SLA
Incident Response
24/7 on-call, 4-hour initial response for P1 incidents, documented runbooks
Backup & Recovery
Automated daily backups, 30-day retention, tested quarterly disaster recovery
6. Data Subject Rights
EchelonGraph will assist the Controller in fulfilling its obligations to respond to data subject requests under GDPR Articles 15-22 (access, rectification, erasure, restriction, portability, objection). Requests should be directed to [email protected] and will be processed within 30 days.
7. International Transfers
When personal data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses (Module 2: Controller-to-Processor) as a legal transfer mechanism. We also implement supplementary measures including encryption, access controls, and pseudonymization to ensure adequate protection.
8. Data Breach Notification
EchelonGraph will notify the Controller without undue delay (within 72 hours) after becoming aware of a personal data breach. The notification will include: the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to mitigate the breach.
9. Audit Rights
To demonstrate compliance with Article 28 GDPR, EchelonGraph will make available to the Controller, on reasonable written request, the information necessary to evidence its data-protection obligations — including current security documentation, certifications, and third-party assessment reports as they become available. Where the Controller reasonably requires a further audit, it may — no more than once per twelve months (unless required by a supervisory authority or following a personal-data breach) — conduct an audit on at least 30 days' written notice, during business hours, subject to confidentiality, in a manner that does not access other customers' data or compromise platform security, and at the Controller's expense. EchelonGraph will provide reasonable cooperation.
10. Term, Return & Deletion
This DPA takes effect when you accept the Terms of Service or first use the Service, and remains in force for as long as EchelonGraph processes personal data on your behalf. To the extent of any conflict regarding the processing of personal data, this DPA prevails over the Terms of Service. On termination, EchelonGraph will, at the Controller's choice, return or delete all personal data within 30 days, except where retention is required by applicable law; residual copies in encrypted backups are purged on their normal 30-day rotation.
11. California Consumer Privacy (CCPA / CPRA)
Where EchelonGraph processes the personal information of California residents on the Controller's behalf, it acts as a Service Provider under the CCPA/CPRA. EchelonGraph does not sell or share personal information; does not retain, use, or disclose it for any purpose other than performing the Service (or as otherwise permitted by the CCPA); and does not combine it with personal information from other sources except as permitted. EchelonGraph certifies that it understands and will comply with these restrictions.
Changes in this version (September 24, 2026)
This version corrects the sub-processor table in Section 4 in two ways. No other term of this DPA changed, and no data is handled differently because of these corrections.
Google Cloud Platform: location corrected. The row said “United States”. Databases are in Google Cloud's us-central1 region and their backups in its US multi-region, both in the United States, but operational logs, which can include IP addresses and email addresses, are stored in Google Cloud Logging's global location, which is not limited to the United States. The row now reads “United States (databases and backups); operational logs: global”.
Anthropic and the Google Gemini API: added. Since April 15, 2026 for the Google Gemini API, and since June 30, 2026 for Anthropic, the AI copilot and AI remediation features of the hosted service have sent these providers what they need to answer whenever the features were used: your questions and the earlier turns of the conversation, and details of your findings and assets, such as resource identifiers, asset names, severities, attack paths and compliance scores. This table did not name either provider. Section 4 promises notice 30 days before a new sub-processor is added. Because neither provider was listed, that notice was never given, so the promise was not met for these two. Both are now listed with their purpose, location and transfer terms.
An earlier change, not dated at the time. On May 31, 2026, Sections 9 (Audit Rights), 10 (Term, Return & Deletion) and 11 (California Consumer Privacy) were added. This page did not show a version or a date then; it is recorded here so the history is complete.
The same corrections are recorded in Section 12 of our Privacy Policy.
Execute This DPA
Enterprise customers can request a countersigned DPA by emailing [email protected] with your company name and authorized signatory details. Our standard DPA is provided at no additional cost.
Request DPA Copy