New: export PCI DSS v4 evidence from real browser traffic.

Legal

Data Processing Agreement - CentralCSP

Last updated: July 8, 2026

If you require a signed copy of this Data Processing Agreement (DPA), please contact us at

contact@centralcsp.com

This Data Processing Agreement ("DPA") is entered into by and between the Customer (as defined in the Principal Agreement) ("Customer" or "Controller") and CentralSaaS, operating the CentralCSP service ("CentralCSP" or "Processor") (each a "Party" and together the "Parties") and is incorporated into and forms an integral part of the Principal Agreement.

This DPA will become effective on the date the Customer electronically accepts or executes the Principal Agreement.

WHEREAS

(A) The Customer, acting as a Data Controller, has entered into an agreement for the provision of Services by the Processor (the "Principal Agreement").

(B) The provision of the Services by the Processor to the Customer involves the processing of personal data on behalf of the Customer.

(C) This DPA is intended to ensure the processing of personal data by the Processor is conducted in compliance with the requirements of applicable Data Protection Laws, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation or "GDPR").

(D) The Parties wish to lay down their respective rights and obligations concerning the processing of personal data under the Principal Agreement.

1. Definitions and Interpretation

1.1. Unless otherwise defined, capitalized terms and expressions used in this DPA shall have the following meaning:

2. Roles and Responsibilities; Processing of Personal Data

2.1. Roles of the Parties

The Parties acknowledge and agree that for the purposes of the Data Protection Laws, the Customer is the Controller and the Processor is the Processor of the Customer Data. Each Party will be responsible for its own compliance with its obligations under Data Protection Laws.

This DPA governs only the Customer Data that the Processor processes on the Customer's behalf as a processor. The Processor acts as an independent controller for the personal data it processes for its own purposes, in particular account registration and billing, which is governed by the Processor's Privacy Policy rather than this DPA.

2.2. Processor's Obligations

The Processor shall process Customer Data only on behalf of the Customer and in accordance with the Customer's documented instructions. The Customer's initial instruction to the Processor for the processing of Customer Data is the Customer's execution of the Principal Agreement and its use of the Services. The subject matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects for the processing are set forth in Annex 1 (Details of the Processing) to this DPA. The Processor shall not process Customer Data for any other purpose unless required to do so by applicable law to which the Processor is subject. In such a case, the Processor shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

2.3. Customer's Obligations

The Customer represents and warrants that it has established and will maintain a valid legal basis for the processing of Customer Data as contemplated by the Principal Agreement and this DPA. The Customer is solely responsible for the accuracy, quality, and legality of the Customer Data and the means by which it acquired the Customer Data. The Customer's instructions to the Processor for the processing of Customer Data shall comply with all Data Protection Laws.

2.4. Infringing Instructions

The Processor shall immediately inform the Customer if, in its opinion, an instruction from the Customer infringes Data Protection Laws. This obligation serves to protect both parties by ensuring that processing activities remain within the bounds of legality, reflecting the Processor's role as an expert service provider while affirming the Controller's ultimate authority over the data.

2.5. Aggregated and Anonymised Data

The Processor operates a scanner that analyses publicly accessible websites at the Customer's request. The Processor may compile aggregated and anonymised statistics derived from scans of publicly accessible websites, for example, for its periodic "State of the Web" research report. Such aggregated and anonymised data does not identify, and cannot reasonably be used to identify, any individual, and does not constitute Customer Data or Personal Data. The Processor does not use the personal data contained in the Customer's browser reports for this purpose. The Processor does not use Customer Data to train, fine-tune, or develop artificial intelligence or machine-learning models, and does not share Customer Data with any third-party AI service.

3. Security and Confidentiality

3.1. Security Measures

Taking into account the state of the art, the costs of implementation and the nature, scope, context, and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These measures are designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data. The specific technical and organizational measures implemented by the Processor are described in Annex 2 (Technical and Organizational Security Measures).

The establishment of a detailed annex for security measures, rather than a brief mention in the main body, provides a dynamic and transparent framework. It allows the Processor to update its security practices to reflect technological advancements and evolving threats without requiring an amendment to the core legal agreement. This approach demonstrates a mature commitment to state-of-the-art security, a critical factor for customers in the web security space.

3.2. Confidentiality

The Processor shall ensure that any personnel authorized to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access to Customer Data shall be strictly limited to those individuals who need such access to perform their duties in connection with the Services.

4. Sub-processing

4.1. General Authorization

The Customer provides a general written authorization to the Processor to engage Sub-processors to process Customer Data on the Customer's behalf, provided that the Processor complies with the requirements of this Section 4. This model of general authorization is a practical necessity for SaaS providers who rely on a dynamic ecosystem of underlying cloud services to deliver their product.

4.2. List of Sub-processors

The Processor shall maintain a list of its current Sub-processors, as set out in Annex 3 (Authorized Sub-processors), and shall make this list available to the Customer. This list shall include the identities of the Sub-processors, their location, and the purpose of the sub-processing activities.

4.3. Notification of New Sub-processors

The Processor shall inform the Customer of any intended changes concerning the addition or replacement of Sub-processors. The Processor will provide such notification by a reasonable mechanism (e.g., via email or through the service portal) at least thirty (30) days in advance of the new Sub-processor beginning to process Customer Data. This notification period provides the Customer with a meaningful opportunity to assess the proposed change.

4.4. Right to Object

The Customer may object to the appointment of a new Sub-processor within fourteen (14) days of receiving the notification from the Processor, provided such objection is based on reasonable grounds relating to data protection. If the Customer objects, the Parties will work together in good faith to find a commercially reasonable solution. If no such solution can be found, either Party may terminate the Principal Agreement. This objection mechanism is a critical control for the Customer, reinforcing their role as the Data Controller and ensuring they retain ultimate authority over where and by whom their data is processed.

4.5. Sub-processor Obligations

The Processor shall enter into a written agreement with each Sub-processor that imposes on the Sub-processor data protection obligations that are no less protective than those imposed on the Processor under this DPA. The Processor shall remain fully liable to the Customer for the performance of that Sub-processor's data protection obligations.

5. Data Subject Rights

Taking into account the nature of the Processing, the Processor shall assist the Customer by implementing appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Customer's obligation to respond to requests for exercising the Data Subject's rights laid down in Chapter III of the GDPR. The Processor shall promptly notify the Customer if it receives a request from a Data Subject. The Processor shall not respond to any such request itself, except on the documented instructions of the Customer or as required by applicable law. Given the nature of the Services, where Customer Data primarily consists of technical violation reports, the Processor may not be able to directly identify an End-User from the data it processes. Therefore, the responsibility to verify and respond to the Data Subject remains with the Customer, with the Processor providing necessary assistance.

6. Personal Data Breach

The Processor shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data. The Processor shall provide the Customer with sufficient information to allow the Customer to meet its obligations to report the breach to the Supervisory Authority and/or inform Data Subjects. Such notification shall, at a minimum:

The Processor shall cooperate with the Customer and take such reasonable commercial steps as are directed by the Customer to assist in the investigation, mitigation, and remediation of each such Personal Data Breach.

7. Data Protection Impact Assessment and Prior Consultation

The Processor shall provide reasonable assistance to the Customer with any data protection impact assessments and prior consultations with Supervisory Authorities which the Customer reasonably considers to be required under Articles 35 and 36 of the GDPR or equivalent provisions of any other Data Protection Law. Such assistance shall be provided solely in relation to the processing of Customer Data by the Processor and taking into account the nature of the processing and the information available to the Processor.

8. Retention, Return and Deletion of Data

During the term of the Principal Agreement, browser reports are retained for a rolling period of ninety (90) days, after which they are deleted or irreversibly aggregated into anonymised statistics. Scan results have no automatic expiry and are retained until the Customer deletes the corresponding website or workspace in the dashboard, which also deletes the associated browser reports.

Upon termination of the Principal Agreement, the Processor shall, at the choice of the Customer, delete or return all Customer Data to the Customer. The Processor shall delete all existing copies of Customer Data within ninety (90) days of the termination date, unless applicable law requires storage of the Personal Data. A 90-day retention period is a practical timeframe for a SaaS provider, allowing for orderly data deletion from complex, multi-layered storage and backup systems.

9. Audit Rights

The Processor shall make available to the Customer, upon request, all information necessary to demonstrate compliance with its obligations under this DPA. To satisfy this requirement, the Processor may provide the Customer with copies of relevant third-party audit reports and certifications (e.g., PCI DSS SAQ A). This approach is standard for multi-tenant cloud environments, as it provides robust assurance of compliance without exposing the Processor's infrastructure or the data of other customers to the risks associated with direct, on-site audits by every customer.

The Processor does not collect, process, or store cardholder data, including primary account numbers (PAN); all payment card processing is performed by Stripe. The Processor maintains PCI DSS SAQ A compliance.

10. International Transfers

The Processor hosts and processes all Customer Data within the European Union / EEA, and in the ordinary course of providing the Services it does not transfer Customer Data to any country outside the EEA. Where a Sub-processor engaged by the Processor may make an onward transfer of limited data outside the EEA (for example, a payment processor transferring billing data to an affiliated entity in the United States), such transfers are governed by that Sub-processor's own appropriate safeguards under Chapter V of the GDPR, namely the Standard Contractual Clauses and/or certification under the EU-US Data Privacy Framework. Should the Processor itself transfer Customer Data outside the EEA in the future, it shall do so only subject to an appropriate transfer mechanism, the Standard Contractual Clauses, which shall be deemed incorporated into this DPA by reference, and, where required, a documented transfer impact assessment.

11. General Provisions

12. Governing Law and Jurisdiction

Annex 1: Details of the Processing

This Annex forms part of the DPA and describes the processing of Personal Data performed by the Processor on behalf of the Controller. The inclusion of this detailed annex is a direct requirement of GDPR Article 28(3) and is fundamental to a compliant DPA. It translates the technical functions of the CentralCSP service into the precise legal language required by data protection regulations, providing clarity and transparency to both the customer and any supervisory authorities.

SpecificationDetails
Subject-matter of the ProcessingThe processing of browser-generated security telemetry, reports delivered through the browser Reporting API (including Content Security Policy (CSP), Network Error Logging (NEL), deprecation, intervention, crash, COOP/COEP, Document-Policy, Certificate Transparency, and integrity reports), together with website security scan data and script inventory data generated by, or in relation to, the Customer's websites, applications, and online services.
Duration of the ProcessingFor the term of the Principal Agreement between the Customer and the Processor, and until all Customer Data is deleted in accordance with Section 8 of the DPA.
Nature and Purpose of the ProcessingTo provide web security and compliance services to the Customer, including:
  • Collecting, storing, and analysing all supported browser Reporting-API report types via a dedicated reporting endpoint to identify security threats and misconfigurations.
  • Generating alerts on security-relevant events (e.g., new scripts, new origins, hash changes, violation spikes) through the Customer's chosen channels.
  • Maintaining an inventory of the scripts loaded on the Customer's pages and detecting known vulnerabilities (CVEs) affecting them.
  • Producing auditor-ready PCI DSS v4 evidence (e.g., requirements 6.4.3 and 11.6.1) from real browser traffic.
  • Scanning and evaluating a website page requested by the Customer to analyse its security configuration and identify vulnerabilities, misconfigurations, and compliance gaps.
  • Using aggregated report data to help the Customer automatically generate and optimise secure CSP policies via a policy builder tool.
Type of Personal Data ProcessedThe Services are designed to process technical security telemetry rather than personal data, and the personal data processed is limited and largely incidental. It is contained within the browser reports and scan data, and may include:
  • Technical and navigational data: the URL of the page where an event occurred (document-uri), a blocked or referenced resource (blocked-uri), the referrer URL (referrer), the violated and effective CSP directives, error details, the browser user-agent string, and the operating system.
  • Online identifiers: an IP address may appear where a URL, referrer, or blocked resource is itself an IP address, and other identifiers may appear where they are embedded in a URL or query string.
The Processor does not process special categories of personal data and does not process cardholder data.
Categories of Data SubjectsThe Personal Data processed relates to End-Users of the Customer's websites, applications, and online services.

Annex 2: Technical and Organizational Security Measures

This Annex describes the technical and organizational security measures (TOMs) implemented by the Processor to protect Customer Data. As a security-focused company, CentralCSP's customers will have high expectations for these measures. This detailed list demonstrates a robust security posture aligned with industry best practices and provides the assurance required by security professionals and IT directors.

1. Access Control

2. Encryption

3. System Security and Resilience

4. Incident Response and Management

5. Personnel Security

6. Data Deletion

7. Physical Security

8. Data Residency and Minimisation

Annex 3: Authorized Sub-processors

This Annex lists the Sub-processors authorized by the Customer to process Customer Data. Transparency regarding sub-processors is a key requirement of the GDPR and a critical component of customer due diligence. This list allows customers to understand the complete data processing chain and conduct their own risk assessments.

As of the Effective Date of this DPA, the Processor engages the following Sub-processors:

Sub-ProcessorPurposeTypes of Data ProcessedLocation
OVHcloudCloud hosting and infrastructure provider for all core platform services and data.All Customer Data, account data, service configuration, backups.France (EU)
Bunny.netContent delivery network (CDN) for static assets and edge caching.IP address, browser/device information, requested URLs.European Union
ScalewayTransactional and notification email delivery.Name, email address, email content, engagement data.France (EU)
StripePayment processing for subscriptions and billing.Name, email, payment method, billing address, transaction details.Ireland (contracting entity); transfers outside the EU (US) possible, governed by DPF + SCC

The Processor stores all Customer Data within the European Union. Bunny.net processing is restricted to European points of presence. The Processor's contracting entity for payments is Stripe Payments Europe, Ltd. (Ireland); any onward transfer of billing data to Stripe, Inc. (United States) is governed by Stripe's Standard Contractual Clauses and its certification under the EU-US Data Privacy Framework. Bot and abuse protection on public forms is provided by a CAPTCHA that the Processor self-hosts on its own EU infrastructure; it is therefore not a Sub-processor and no CAPTCHA data is shared with any third party.