1. Parties and Application
This Data Processing Agreement ("DPA") applies when incorporated into an accepted engagement between the customer identified in that engagement and Enigma Labs OÜ for processing personal data on the customer's behalf.
| Processor information | Details |
|---|---|
| Legal name | Enigma Labs OÜ |
| Legal form | Osaühing (Estonian private limited company) |
| Registry code | 17166408 |
| VAT number | EE102825316 |
| Registered address | Harju maakond, Tallinn, Kesklinna linnaosa, Juhkentali tn 8, 10132, Estonia |
| Data-protection and incident contact | hello@enigmalab.io |
The customer is the controller and Enigma Labs OÜ is the processor, unless the customer is itself a processor, in which case Enigma Labs OÜ acts as its sub-processor. In that case, the customer must obtain the controller's required authorisation and convey its applicable instructions. "Personal data", "processing", "controller", "processor", "personal data breach" and "supervisory authority" have their GDPR meanings.
Applicable data-protection law includes Regulation (EU) 2016/679 (GDPR) and Estonia's Personal Data Protection Act (Isikuandmete kaitse seadus), together with other laws applicable to the processing. This DPA implements Article 28(3) GDPR. It is not formed simply by browsing the website or submitting an enquiry. The customer and Enigma Labs OÜ must incorporate it, or agree another compliant DPA, before processing customer personal data.
Business contact, enquiry and billing data that Enigma Labs OÜ processes for its own purposes are governed by the Privacy Policy, rather than treated as processor data solely because the person represents a customer.
2. Description of Processing
The accepted order, statement of work and documented instructions identify the customer, authorised systems, service scope, contacts and any additional processing restrictions. The following schedule applies only to data necessary for those agreed services; it does not authorise access to unrelated systems or data.
| Article 28 requirement | Agreed scope |
|---|---|
| Subject matter | Personal data encountered or provided in the customer's authorised security audit, penetration test, incident-response, security-engineering or application-development engagement |
| Duration | The engagement period and the limited period necessary for return or deletion under Section 9 |
| Nature of processing | Authorised access, collection, organisation, examination, analysis, testing, storage, retrieval, report preparation, secure transfer to the customer, and return or deletion as necessary for the agreed service |
| Purpose | Assess and improve security, investigate and remediate incidents, or build and test agreed applications on the customer's documented instructions |
| Data subjects | The customer's personnel, contractors, users, customers, suppliers and other individuals whose data is present in authorised systems or materials |
| Personal-data categories | Names and business contact details, user/account identifiers, IP addresses, device and network identifiers, access and event logs, security findings, and relevant records or evidence in the agreed systems |
| Special categories and criminal-offence data | Excluded from the agreed processing: the customer must not intentionally supply special-category data under Article 9 GDPR or criminal-conviction and offence data under Article 10 GDPR. Any exceptional processing requires a separate written agreement identifying a lawful basis, instructions and additional safeguards before it begins |
| Frequency | As needed for the agreed project; continuous or recurring access only where expressly included in the order |
Use synthetic or anonymised test data where feasible. If sensitive or out-of-scope data is incidentally encountered, we will restrict access, notify the customer as appropriate, and obtain instructions for secure handling, minimisation or deletion. The customer must ensure its instructions, collection, disclosures and legal bases comply with applicable law and provide required notices to individuals.
3. Documented Instructions and Confidentiality
We will process personal data only on documented instructions from the customer, including instructions concerning transfers, unless EU or Member State law requires processing. Where such a legal requirement applies, we will inform the customer before processing unless that law prohibits notification on important grounds of public interest.
The engagement, this DPA and subsequent written instructions from authorised contacts constitute documented instructions. We will immediately inform the customer if, in our opinion, an instruction infringes the GDPR or other applicable EU or Member State data-protection law, and suspend the affected processing while seeking lawful instructions.
We will not sell customer personal data, use it for advertising, or train general-purpose AI models on it. We will limit access to people who need it for the engagement and ensure that authorised persons are bound by confidentiality obligations or an appropriate statutory duty of confidentiality.
If the customer gives instructions that change the agreed service, the parties may agree reasonable scope and fee changes. This does not justify delaying mandatory protection, incident notification or other obligations under applicable law.
4. Technical and Organisational Security Measures
Account security: All accounts used by Enigma Labs for the services enforce multi-factor authentication (MFA) and access restrictions.
Taking account of the state of the art, implementation costs, and the nature, scope, context, purposes and risks of processing, we will implement measures appropriate under Article 32 GDPR. In addition to the account controls above, the following are contractual requirements for each engagement, as appropriate to the actual processing:
- Access control: individual authorisation, least-privilege access, enforcement of MFA and access restrictions on all accounts, and timely removal of access no longer needed.
- Confidentiality and separation: confidentiality commitments, instructions to personnel, separation of customer materials, and restricted access to sensitive evidence and reports.
- Secure transfer and storage: encrypted transfer channels; encryption of stored customer data where appropriate to risk; controlled handling of encryption keys and credentials; agreed secure exchange methods.
- Data minimisation: limiting collection to the authorised scope, avoiding unnecessary copies, using synthetic or anonymised test data where possible, and controlling exports and temporary files.
- Operational security: timely security updates, secure configurations, relevant access/activity records, vulnerability handling and procedures to detect and respond to incidents.
- Availability and resilience: appropriate backup, recovery and restoration arrangements for systems under our control that hold customer data, with periodic checks appropriate to the engagement.
- Testing and review: assessment of the effectiveness of applicable safeguards and remediation of identified material weaknesses.
- Lifecycle control: retention restrictions and secure return or deletion, including controlled backup expiry, under Section 9.
The parties will record any additional measures needed for the engagement, including sensitive data, production access or elevated threats, before the relevant processing. We will provide information about applicable measures on request and will not materially reduce the agreed level of protection during the engagement. This schedule states contractual requirements; it is not a claim of a particular certification or an assurance that every engagement uses the same infrastructure.
5. Sub-processors
The following infrastructure providers form the sub-processor schedule incorporated into this DPA. When the customer accepts an engagement incorporating this DPA, it gives general written authorisation to use these providers to the extent needed for that engagement, subject to its documented instructions and Section 6:
| Provider | Service and processing purpose | Geographic scope |
|---|---|---|
| Vercel | Application hosting and delivery for the agreed services, including associated processing and storage of customer data | Global: all regions offered by the provider, subject to Section 6 |
| Amazon Web Services (AWS) | Cloud infrastructure, compute and storage for the agreed services and customer data | Global: all regions offered by the provider, subject to Section 6 |
| Microsoft Azure | Cloud infrastructure, compute and storage for the agreed services and customer data | Global: all regions offered by the provider, subject to Section 6 |
The provider names above identify the services used. The applicable provider contracting entity and any participating affiliates are identified in the service agreement and provider data-processing terms for the account used in the engagement. Before processing begins, we will disclose to the customer the applicable legal entities, actual processing countries or regions, and relevant transfer safeguards. Provider terms do not override our obligations to the customer under this DPA.
The schedule permits global infrastructure use; it does not promise that customer data remains in Estonia or the EEA. Any customer-specific residency restriction must be recorded in the engagement and followed. Global geographic scope does not dispense with the authorisation, transparency or transfer-safeguard requirements in this DPA. An unlisted provider is not authorised to receive customer personal data unless added through the procedure below.
We will give at least thirty days' advance written notice of an intended addition or replacement, allowing the customer to object on reasonable data-protection grounds. We will discuss an alternative or other reasonable resolution. If no resolution is available, the affected processing must not be transferred to that provider and either party may terminate the affected service with an appropriate refund of unused prepaid fees.
Each sub-processor must be bound by a written agreement imposing materially the same applicable data-protection obligations, including sufficient guarantees of appropriate technical and organisational measures. Enigma Labs OÜ remains fully liable to the customer for the performance of its sub-processors' data-protection obligations under Article 28(4) GDPR.
Other marketing-website providers listed in the Privacy Policy are not automatically authorised to receive customer incident evidence or other processor data. If an engagement requires one of those providers to handle that data, it must be added to this schedule through the authorisation procedure above.
6. International Transfers
Personnel access locations: Enigma Labs personnel may access customer data from the European Economic Area (EEA), Canada, the United Arab Emirates and Singapore. These access locations are separate from the global infrastructure regions in Section 5. Any access must comply with the customer's documented instructions, account security controls and applicable data-protection law. Provider personnel and onward processing locations must be disclosed as part of the provider information required by Section 5.
We will not transfer personal data outside the EEA, including by remote access where it constitutes a transfer, without documented customer instructions and a lawful mechanism under Chapter V GDPR. Actual processing locations and onward transfers must be disclosed before the affected processing begins. A provider's global availability or the inclusion of a country in this DPA is not itself a transfer safeguard.
For Canadian recipients, an adequacy decision may be relied on only where the recipient and processing fall within its scope; Canada's adequacy coverage is limited to commercial organisations subject to the Personal Information Protection and Electronic Documents Act (PIPEDA). Transfers to recipients in the United Arab Emirates, Singapore or any other country that are not covered by an applicable adequacy decision require appropriate safeguards, such as applicable Standard Contractual Clauses, a transfer assessment and any necessary supplementary measures. Access within the same legal entity must also comply with the GDPR's security and accountability requirements, even where it does not constitute a Chapter V transfer.
Where an adequacy decision applies, it must cover the recipient and processing concerned. Otherwise, appropriate safeguards must be in place before transfer. Where the European Commission's Standard Contractual Clauses under Implementing Decision (EU) 2021/914 are used, the parties must select the appropriate module and complete the required annexes for the actual transfer, including parties, processing, competent supervisory authority, security measures and sub-processors.
The applicable module is normally Module Two for a controller-to-processor transfer or Module Three for a processor-to-processor transfer. The competent supervisory authority is determined under Clause 13, rather than automatically assigned by this website's domain. Where the SCCs permit selection, Estonian law applies under Clause 17 and the courts of Estonia under Clause 18, without restricting data subjects' rights under those clauses.
We will cooperate with required transfer assessments, supplementary measures and responses to public-authority access requests. If a lawful transfer mechanism is unavailable or can no longer be complied with, the affected transfer must be suspended until remedied or the data returned or deleted as required. The SCCs prevail over conflicting contractual terms.
7. Assistance, Rights Requests and Breaches
Taking account of the nature of processing, we will assist the customer by appropriate technical and organisational measures, insofar as possible, in responding to requests under Chapter III GDPR. If a request concerning customer-controlled data comes directly to us, we will notify the customer without undue delay and will not respond substantively except on its instructions or as legally required.
Taking account of the processing and information available to us, we will assist with compliance under Articles 32–36 GDPR, including security, breach assessment and notification, data-protection impact assessments and prior consultation with supervisory authorities.
We will notify the customer's designated incident contact without undue delay after becoming aware of a personal data breach affecting customer data. Notification will not be deferred until a full investigation or confirmation of every detail. As information becomes available, we will provide:
- The nature of the breach, including, where possible, categories and approximate numbers of affected individuals and records.
- A contact for further information.
- Likely consequences and the measures taken or proposed to address the breach and mitigate its effects.
- Updates, relevant evidence and reasonable assistance with the customer's notification and documentation obligations.
The customer is responsible for controller notifications to authorities and individuals unless applicable law requires otherwise. We will cooperate in containment and remediation and preserve relevant evidence. Any agreed fee for assistance must not delay breach notification or mandatory compliance action.
8. Compliance Information and Audits
We will make available information necessary to demonstrate compliance with Article 28 GDPR and this DPA, and allow and contribute to audits, including inspections, conducted by the customer or its mandated auditor.
Routine audits should use reasonable advance notice and safeguards for security, confidentiality and other customers' data. Existing reports may be used where sufficient. These arrangements must not prevent an audit needed to verify compliance, delay an urgent investigation, or restrict a supervisory authority's powers. We will cooperate with competent supervisory authorities and address identified material deficiencies without undue delay.
9. Return and Deletion
At the customer's choice, we will return or delete personal data after the end of the services relating to processing and delete existing copies, unless EU or Member State law requires storage. The customer may communicate its choice before or at termination. Unless a different lawful period is agreed in writing, return or deletion of active copies will be completed within thirty days after the end of the relevant service.
Any residual backup copies must be isolated from ordinary use, protected by this DPA, and deleted through the applicable backup cycle, no later than ninety days after service end unless law requires otherwise. If restored for disaster recovery before expiry, deletion instructions must be reapplied. Legally retained data must be restricted to the required purpose and deleted when the obligation ends.
We will confirm completion on request and require applicable sub-processors to comply. A payment dispute does not authorise retention of personal data contrary to this DPA or applicable law.
10. Law, Precedence and Contact
This DPA continues for as long as we hold personal data on the customer's behalf. It prevails over conflicting commercial terms on personal-data matters, and applicable SCCs prevail over this DPA. No contractual liability limit restricts data subjects' GDPR compensation rights, third-party beneficiary rights under the SCCs, or supervisory-authority powers. Between the parties, any allocation of liability remains subject to the GDPR and mandatory law.
Estonian law and applicable EU law govern this DPA. Business-to-business disputes are subject to the courts of Estonia, with Harju County Court (Harju Maakohus) in Tallinn as the court of first instance where legally permitted. This does not restrict mandatory jurisdiction, SCC forum requirements or individuals' rights to lodge a complaint or bring proceedings under the GDPR.
Andmekaitse Inspektsioon (AKI) is the Estonian Data Protection Inspectorate: https://www.aki.ee. Another authority may be competent for a particular processing activity or transfer under the GDPR. Data subjects may complain to an authority in their habitual residence, place of work or the alleged infringement as provided by Article 77.
Changes to an accepted DPA require written agreement and must comply with applicable law. Publishing a revised website version alone does not amend an existing engagement.
For DPA enquiries or incident communications, contact hello@enigmalab.io, identifying Enigma Labs OÜ and the customer engagement. Postal address: Harju maakond, Tallinn, Kesklinna linnaosa, Juhkentali tn 8, 10132, Estonia. Registry code: 17166408. VAT number: EE102825316.