Legal

Data Processing Addendum

Last updated: July 16, 2026

This Data Processing Addendum (DPA) forms part of the agreement between RedStrike and a customer and describes how we process personal data on the customer's behalf when acting as a processor. It reflects the requirements of the GDPR, the UK GDPR, and comparable data protection laws.

Definitions

Capitalized terms not defined here have the meaning given in the agreement or in applicable data protection law. In this DPA:

  • Controller, Processor, Data Subject, Personal Data, and Processing have the meanings given in the GDPR.
  • Customer Personal Data means personal data contained in the content the customer submits to or generates through the service.
  • Subprocessor means a third party engaged by RedStrike to process Customer Personal Data.
  • Data Protection Laws means all laws applicable to the processing of personal data under the agreement, including the GDPR, UK GDPR, and U.S. state privacy laws.

Roles of the parties

As between the parties, the customer is the Controller (or a Processor acting on behalf of a third-party Controller) of Customer Personal Data, and Encyfr Technologies Private Limited is the Processor. The customer is responsible for the lawfulness of the data it provides and of the instructions it gives us.

RedStrike will process Customer Personal Data only on the customer’s documented instructions, including as set out in the agreement, this DPA, and the configuration choices the customer makes in the platform, unless required to act otherwise by law — in which case we will inform the customer where permitted.

Scope & nature of processing

The subject matter of processing is the provision of the RedStrike platform. We process Customer Personal Data for the duration of the agreement, for the purpose of delivering continuous security testing and cloud posture management and related support.

  • Categories of data subjects: the customer’s authorized users and any individuals whose personal data appears in scan targets or findings.
  • Categories of personal data: account and contact details, authentication data, and any personal data incidentally present in assessed systems, logs, or reports.
  • Nature of processing: collection, storage, analysis, verification, reporting, and deletion as necessary to provide the service.

Subprocessors

The customer authorizes RedStrike to engage Subprocessors to process Customer Personal Data in support of the service, including cloud infrastructure, monitoring, and communications providers. We impose data protection obligations on each Subprocessor that are no less protective than those in this DPA.

We maintain a current list of Subprocessors, available on request, and will give the customer notice of any intended addition or replacement so the customer has an opportunity to object on reasonable data-protection grounds. RedStrike remains responsible for its Subprocessors’ performance.

Security measures

RedStrike implements and maintains appropriate technical and organizational measures to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. These measures include:

  • Encryption of data in transit and at rest.
  • Role-based, least-privilege access controls and strong authentication.
  • Network segmentation, logging, and continuous monitoring.
  • Secure software development, testing, and change-management practices.
  • Personnel confidentiality obligations and security training.

Details of our program and certifications are described on our Trust & security page.

Data subject requests

Taking into account the nature of the processing, RedStrike will assist the customer with appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights under Data Protection Laws.

If we receive a request directly from a data subject relating to Customer Personal Data, we will, unless legally prohibited, promptly notify the customer and direct the individual to the customer rather than respond on the customer’s behalf.

Breach notification

RedStrike will notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Our notice will describe the nature of the breach, the likely consequences, and the measures taken or proposed to address it, to the extent known.

We will cooperate with the customer and take reasonable steps to mitigate the effects of the breach. Our notification is not an acknowledgment of fault or liability. Report suspected issues to security@encyfr.ai.

International transfers & SCCs

Where RedStrike processes Customer Personal Data originating from the EEA, the UK, or Switzerland in a country that has not received an adequacy decision, the parties agree that the European Commission’s Standard Contractual Clauses (SCCs) are incorporated into this DPA by reference and apply to that transfer.

For transfers of UK data, the UK International Data Transfer Addendum to the SCCs applies. We supplement these mechanisms with technical and organizational measures, including encryption and access controls, to protect data during transfer.

Audits

RedStrike will make available to the customer information reasonably necessary to demonstrate compliance with this DPA, including relevant third-party audit reports and certifications, which will ordinarily satisfy the customer’s audit rights.

Where Data Protection Laws require a further audit, the customer may request one no more than once per year, on reasonable prior notice, during business hours, subject to confidentiality, and in a manner that does not disrupt our operations or the security of other customers’ data.

Return & deletion of data

Upon termination or expiry of the agreement, RedStrike will, at the customer’s choice, delete or return Customer Personal Data and delete existing copies, unless retention is required by law. We provide a limited export window before deletion so the customer can retrieve its data.

Residual copies present in routine backups are deleted or overwritten in the ordinary course within our standard retention window, during which they remain protected by the security measures described above.

Contact us

To request an executed copy of this DPA, our Subprocessor list, or our data-protection documentation, contact Encyfr Technologies Private Limited at hello@encyfr.ai. See also our Privacy Policy.

Questions about our policies?

Our team is happy to walk security and legal reviewers through how RedStrike handles data.