Data Processing Agreement

SQUR Penetration Testing Services · Article 28 GDPR · Version 1.0, September 2026

1. Parties and purpose

This Data Processing Agreement ("DPA") is concluded between the customer that holds a SQUR account and orders penetration testing services under the SQUR Terms of Service ("Customer", the controller) and SQUR UG (haftungsbeschränkt), Hegelstrasse 7, 76356 Weingarten (Baden), Germany ("SQUR", the processor).

It sets out the obligations of both parties under Article 28 of Regulation (EU) 2016/679 ("GDPR") for personal data that SQUR processes on the Customer's behalf while providing the services. It forms part of the Terms of Service and takes effect when the Customer places its first order. Where this DPA and the Terms of Service conflict on the processing of personal data, this DPA prevails.

A countersigned copy on the Customer's own paper is available from privacy@squr.ai. The text is the same.

2. Subject matter, duration, nature and purpose

SQUR performs authorized, autonomous penetration tests against the Customer's target systems, verifies the findings and produces reports and, on a clean run, a certificate. During a test, SQUR's engine sends requests to the Customer's systems and records the responses. Those responses can contain personal data that the Customer's systems hold, for example user records returned by a vulnerable endpoint, session tokens, e-mail addresses in error messages or log lines. SQUR does not seek this data, does not need it and does not use it for any purpose other than demonstrating and verifying the vulnerability through which it surfaced.

The processing lasts for the term of the Customer's account plus the retention period in section 8. Annex 1 states the categories of data and data subjects.

3. Documented instructions

SQUR processes personal data only on the Customer's documented instructions. The instructions are: the Terms of Service, this DPA, the scope the Customer authorizes for each target inside its SQUR account, and any further written instruction sent to privacy@squr.ai. Starting a test is an instruction to test exactly the authorized scope; nothing else is tested.

If SQUR considers that an instruction infringes the GDPR or other Union or Member State data protection law, it informs the Customer without delay and may suspend the instruction until it is clarified.

SQUR does not process the data for its own purposes. The Terms of Service permit SQUR to derive aggregated, anonymized vulnerability patterns from completed tests to improve the service; such patterns contain no personal data and no information that identifies the Customer or its systems.

4. SQUR's obligations

  • Confidentiality. Every person SQUR authorizes to process the data is bound by a contractual or statutory confidentiality obligation and has access only to the extent needed to provide, support or secure the service.
  • Security. SQUR implements and maintains the technical and organisational measures in Annex 2 and reviews them at least annually. Measures may be updated, but the level of protection may not fall below Annex 2.
  • Data subject requests. Taking into account the nature of the processing, SQUR assists the Customer with appropriate technical and organisational measures in responding to requests under Chapter III GDPR. A request that reaches SQUR directly is forwarded to the Customer without delay and is not answered by SQUR on the Customer's behalf.
  • Assistance under Articles 32 to 36. SQUR assists the Customer with security, breach notification, data protection impact assessments and prior consultation, insofar as the information is available to SQUR.
  • Personal data breach. SQUR notifies the Customer of a personal data breach affecting the Customer's data without undue delay and at the latest 48 hours after becoming aware of it, with the information Article 33(3) GDPR requires as far as it is known, and supplements it as facts become available. The notice goes to the e-mail address of the account owner and to any address the Customer has registered for security notices.
  • Demonstration and audits. SQUR makes available all information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, at most once per year unless a supervisory authority requires otherwise or a breach has occurred, on 30 days' written notice, during business hours and without endangering the confidentiality of other customers' data. SQUR may first refer the Customer to the Trust Center and to existing audit reports.
  • Records. SQUR keeps the record of processing activities required by Article 30(2) GDPR.

5. Sub-processors

The Customer gives SQUR general written authorization to engage the sub-processors listed in Annex 3. SQUR imposes on each sub-processor, by contract, the same data protection obligations as in this DPA and remains fully liable to the Customer for the sub-processor's performance.

SQUR informs the Customer of any intended addition or replacement of a sub-processor at least 30 days before it takes effect, by e-mail to the account owner and by updating Annex 3 on this page. The Customer may object on reasonable data protection grounds within those 30 days. If the parties cannot resolve the objection, the Customer may terminate the affected services with immediate effect; fees for tests already delivered remain due.

6. Where the data is processed

SQUR stores and processes the Customer's data in Google Cloud's europe-west1 region (St. Ghislain, Belgium). Compute, database, object storage and backups do not leave the European Union.

One exception is stated plainly because it matters: the language models that drive the test are operated by Google. SQUR calls them through Google's AI platform, and Google may serve an inference request from a data centre outside the European Union. Those requests carry the fragments of responses the engine is reasoning about, which can include the personal data described in section 2. Google acts as SQUR's sub-processor under the Google Cloud Data Processing Addendum, and the transfer is covered by the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) incorporated in it. Google does not use the content of these requests to train its models. SQUR does not transfer the data to any other third country.

If a Customer requires inference to stay inside the EU, SQUR will say whether it can offer that for the specific order before the test starts, not after.

7. Rights and obligations of the Customer

The Customer is responsible for the lawfulness of the processing, for authorizing the test on systems it controls or is entitled to have tested, and for ensuring that its authorization covers the personal data that a test on those systems may surface. The Customer proves control of a target inside its SQUR account (a DNS TXT record with a token SQUR issues) and records the authorized scope before any test starts; SQUR does not accept authorizations given by third parties on the Customer's behalf.

The Customer informs SQUR without delay if it discovers errors or irregularities in the processing, and provides SQUR with the information SQUR needs to comply with this DPA.

8. Retention, return and deletion

SQUR keeps the Customer's target configuration, findings, test artefacts and reports for three years after the end of the calendar year in which the respective test was completed, and deletes them at the end of that period. The period mirrors the regular limitation period under German law and exists so that both parties can evidence what was tested, what was found and what was certified.

The Customer may at any time request earlier deletion of a specific test, a specific target or the whole account by written request to privacy@squr.ai from the account owner's address. SQUR completes the deletion within 30 days of the request and confirms it in writing. Before deleting, SQUR gives the Customer the opportunity to download its reports.

When the Customer's account is terminated, SQUR deletes the account's data at the Customer's choice either immediately after the termination takes effect or at the end of the retention period above. Absent a choice, the retention period applies.

Deletion covers the production database records and the object storage that holds the test's artefacts. Backup copies are overwritten in the normal backup cycle, which retains a copy for at most 7 days; a deleted record can therefore exist in a backup for up to 7 further days and is not restored from it. SQUR may retain what Union or Member State law requires it to retain, in particular invoicing records, for the statutory period and for no other purpose.

9. Liability, term, law

Liability between the parties is governed by the Terms of Service; nothing in this DPA limits the liability either party has towards data subjects under Article 82 GDPR. This DPA applies for as long as SQUR processes personal data on the Customer's behalf, and sections 4, 8 and 9 survive its end. German law applies. Where this DPA is silent, the GDPR applies directly.

Annex 1. Details of the processing

  • Subject matter: autonomous penetration testing of the target systems the Customer authorizes, verification of findings, reporting and certification.
  • Nature of the processing: sending requests to the target systems, recording responses, storing artefacts that evidence a vulnerability, generating reports, and storing the Customer's account and target configuration.
  • Categories of data subjects: the Customer's account users; and, only where a vulnerability exposes them, the users, customers, employees and contacts whose data the target systems hold.
  • Categories of personal data: account data (name, e-mail address, organisation, role); target configuration (host names, URLs, test credentials the Customer supplies); and, only where a vulnerability exposes them, any category the target systems hold, including identifiers, contact details, credentials and session data. Special categories of data under Article 9 GDPR are processed only if a target system exposes them through a vulnerability; SQUR does not test systems that are designated as holding such data unless the Customer has confirmed in writing that its authorization covers them.
  • Duration: the term of the account plus the retention period in section 8.

Annex 2. Technical and organisational measures

  • Data residency: all storage and compute in Google Cloud europe-west1 (Belgium); Google's EU contracting entity is Google Ireland Limited.
  • Encryption: TLS 1.2 or higher on every connection; AES-256 encryption at rest using Google-managed keys (Cloud KMS).
  • Authorization before testing: the Customer proves control of a target by a DNS TXT record carrying a token SQUR issues, and records the authorized scope in its account; the engine tests only that scope, and out-of-scope hosts discovered during a test are recorded but not tested.
  • Isolation: each test runs in its own container with its own short-lived service account and its own storage location that no other test can read; egress from the test environment is guarded and attributed.
  • Access control: customer accounts authenticate through an identity provider hosted in the EU with multi-factor authentication available; access within an organisation is role-based; SQUR staff access to customer data is limited to named operators, requires the same identity provider, and is logged.
  • Credentials: test credentials the Customer supplies are stored separately from report data and are never written into reports.
  • Logging and monitoring: platform and engine actions are logged with the run they belong to; logs are stored in the EU.
  • Development and change: code changes require review and passing automated tests before deployment; dependency updates are checked weekly; production deploys are attributable to a commit.
  • Deletion: documented procedure for deleting a test, a target or an account on request, with written confirmation; backups overwritten within 7 days.
  • Incident response: a security contact at security@squr.ai, a published vulnerability disclosure policy, and customer notification of a personal data breach within 48 hours of awareness.

Annex 3. Sub-processors

Current as of September 2026. Changes are announced under section 5.

Sub-processorPurposeDataLocation
Google Ireland Limited (Google Cloud)Hosting: compute, database, object storage, backups, loggingAll service dataeurope-west1, Belgium
Google Ireland Limited (Google AI platform)Language-model inference that drives the test engineFragments of target responses the engine reasons about, which can include exposed personal dataGoogle data centres, possibly outside the EU; SCCs under the Google Cloud Data Processing Addendum
Okta, Inc. (Auth0)Identity and login for the SQUR applicationAccount data of the Customer's usersEU tenant
Stripe Payments Europe, Ltd.Payment processing and invoicingBilling contact and payment data; no test dataEU; Stripe's own transfer mechanisms for card networks
PostHog Inc. (EU Cloud)Product usage analytics inside the applicationPseudonymous usage events of account users; no test dataBrussels, Belgium
Google Ireland Limited (Google Workspace)Transactional e-mail from the platform (invitations, notifications, verification)Recipient address and notification contentEU, under the Google Workspace Data Processing Addendum

Contact

SQUR UG (haftungsbeschränkt)
Hegelstrasse 7, 76356 Weingarten (Baden), Germany
Managing Director: Adam Lundqvist
Commercial register: Amtsgericht Mannheim, HRB 753863
VAT ID: DE 453660591
Data protection: privacy@squr.ai