Legal

Data Processing Agreement

Effective 2026-09-16 (subject to change on legal review) · Version dpa-draft-2026-09-16

DRAFT - pending legal review. Not a binding agreement. The text below is the document prepared for legal review. It does not create, and must not be relied on as, a binding agreement. A reviewed version will supersede this draft under a new version id once review is complete. Breachr OÜ's registry code and registered address are placeholders (shown underlined) while company registration is with our lawyers. They are not the filed values.

Our Data Processing Agreement gives effect to Article 28 of the GDPR and governs the personal data we process on your behalf when you run security tests through breachr.

It is not published here. The DPA describes our processing architecture in detail, so we release it to customers under a non-disclosure agreement rather than to anyone who visits the site. The text is unchanged from customer to customer.

How to obtain it

Hold a paid plan
The DPA is issued to customers on a paid plan. If you are evaluating breachr and need it before you commit, contact us and we will handle it directly.
Request it from your dashboard
Sign in and open Settings → Data Processing Agreement. The request records who asked and when.
Sign our NDA, or send us yours
You can accept our standard NDA in the portal, or upload your own for us to review. Either route satisfies the same requirement.
Our DPO releases it
A founder reviews the request and our Data Protection Officer releases the document. You then download it from the same screen, over a private, expiring link.

What is public: our Privacy Policy, our sub-processor register naming every third party that touches your data and where each one processes it, and our Permission to Penetrate. A DPO can assess us from those without an NDA.

← Back to home