Legal
Data Processing
How we handle data processing when engaged as a service provider, including sub-processors, security measures, and how to request a signed DPA.
1 min readLast reviewed July 18, 2026Threat ResQ Technologies
1. Our role: processor, not controller
When engaged for a paid service — VAPT, compliance consulting, digital forensics, incident response, security awareness training, or a managed platform like TRISA, getTRAC, or SOC+ — Threat ResQ typically acts as a Data Processor under GDPR, or the equivalent vendor role under India's DPDP Act, processing personal data on your documented instructions as the Data Controller / Data Fiduciary. This page describes that relationship; it is not a substitute for a signed Data Processing Agreement, which we're happy to execute per §5 below.
2. Processing commitments
- We process personal data only on your documented instructions, unless required otherwise by law;
- Staff with access are bound by confidentiality obligations;
- We implement appropriate technical and organizational security measures — encryption in transit, access controls, least-privilege, and logging;
- We do not engage a sub-processor without your prior authorization (general or specific, as agreed in the underlying contract);
- We assist you in responding to data subject requests and regulatory inquiries relating to the processing we carry out on your behalf;
- At the end of the engagement, we delete or return personal data per your instructions and the retention terms in the underlying agreement;
- We make available information reasonably necessary to demonstrate compliance with these commitments.
3. Breach notification
If we become aware of a confirmed personal data breach affecting data we process on your behalf, we will notify you without undue delay, with the information reasonably available at the time, so you can meet your own regulatory notification obligations (72 hours under GDPR; the timelines prescribed under the DPDP Act and its rules for India-regulated data).
4. International transfers
Where delivering a service requires transferring personal data across borders — for example between our India delivery team and a client's EU or UAE operations — we rely on Standard Contractual Clauses or another legally recognized transfer mechanism appropriate to the jurisdictions involved.
5. Requesting a signed DPA
If your organization requires a signed Data Processing Agreement — your own template or ours, including Standard Contractual Clauses where applicable — contact your Threat ResQ engagement lead or email legal@threatresq.com. For general privacy questions unrelated to an active engagement, see our Privacy Policy instead.