Last updated: July 2026. This Data Processing Agreement ("DPA") forms part of, and is subject to, the Terms of Service between Vulny SIA ("Vulny", "Processor", "we") and the customer ("Customer", "Controller", "you"). It applies whenever Vulny processes personal data on your behalf in the course of providing the Vulny scanning service, and reflects the requirements of Article 28 of the EU General Data Protection Regulation (GDPR).
For personal data that Vulny processes on your behalf to deliver the service (for example, personal data contained in the targets you submit, in scan findings, or in your account and support records), you act as the controller and Vulny acts as the processor. For data Vulny processes for its own purposes (such as account administration, billing and platform security), Vulny is an independent controller, as described in our Privacy Policy. Where you are yourself a processor for a third party, you appoint Vulny as a sub-processor and confirm you have the necessary authority to do so.
The subject matter is the processing of personal data necessary to provide the vulnerability, SEO and AI-search scanning service and related support. Processing continues for the duration of your subscription or use of the service and until deletion or return of the data under Section 9. The nature and purpose of processing is the automated scanning of the assets you designate, the generation and storage of findings and reports, authentication, and support.
The personal data processed on your behalf may include:
Categories of data subjects may include your personnel, contractors, and the operators or users of the assets you are authorised to scan. You are responsible for ensuring you have a lawful basis to submit such data for scanning.
Vulny will:
You give Vulny general authorisation to engage sub-processors to provide the service. Our current sub-processors and their locations are listed in our Privacy Policy. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. We will inform you of intended changes to our sub-processors so you have the opportunity to object on reasonable data-protection grounds.
Vulny maintains technical and organisational measures appropriate to the risk, including encryption in transit, encrypted storage of secrets, hashed credentials, role-based access control, tenant isolation, and audit logging. A fuller description is in the Security section of our Privacy Policy.
Our platform and data are hosted within the EU. Where a sub-processor processes personal data outside the EU/EEA, the transfer is made under an adequacy decision or the EU Standard Contractual Clauses, which are incorporated into this DPA by reference and take precedence in the event of conflict on transfer matters.
If we receive a request from a data subject relating to data we process on your behalf, we will, where legally permitted, direct them to you and assist you in responding, rather than responding directly.
On termination of the service, or at your request, Vulny will delete or return the personal data processed on your behalf and delete existing copies, unless EU or Member State law requires storage (for example, invoicing and tax records kept for the statutory period).
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. In the event of a conflict between this DPA and the Terms of Service on the subject of personal data processing, this DPA prevails.
Data protection queries: support@vulny.app. Vulny SIA, registration number 40203753831, Kazaru street 4-59, Saurieši, LV-2118, Latvia. Registry: info.ur.gov.lv.