Summary: This Data Processing Agreement sets out the terms on which Certiva ApS processes personal data on your behalf as a customer, pursuant to Art. 28 GDPR. These are our standard terms; the agreement can be signed as a standalone addendum. Need adjustments? Write to mail@trustctrl.com.

1. The parties

This Data Processing Agreement (the "Agreement") is entered into between:

  • The Customer — the legal entity using TrustCtrl, acting as the data controller ("the Controller").
  • Certiva ApS, company reg. (CVR) 46450965, Denmark — provider of TrustCtrl and data processor ("the Processor", "we", "us").

The Agreement is ancillary to the agreement between the parties for the use of TrustCtrl — currently the Terms of Service (the "Main Agreement") — and governs the Processor's processing of personal data on behalf of the Controller. In the event of conflict between the Agreement and the Main Agreement regarding the processing of personal data, the Agreement prevails.

2. Definitions

The terms "personal data", "processing", "controller", "processor", "sub-processor", "data subject" and "personal data breach" have the meaning given to them in the General Data Protection Regulation (EU) 2016/679 ("GDPR"). "Data Protection Law" means the GDPR and the Danish Data Protection Act and associated rules.

3. Subject matter, duration, nature and purpose

  • Subject matter: Processing of personal data in connection with the provision of TrustCtrl — a digital trust monitoring platform covering TLS certificates, uptime and service health, website quality and security, brand impersonation and email security for the domains the Controller adds.
  • Duration: Processing continues for as long as the Main Agreement is in force, and until data is deleted or returned under section 11.
  • Nature and purpose: Collection, recording, storage, organisation, display, analysis and deletion of the data listed in Appendix A, solely for the purpose of providing and operating the service for the Controller.

The specific categories of data subjects and personal data are set out in Appendix A.

4. The Controller's instructions

The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers to third countries, unless required to do otherwise by EU or Danish law. The Main Agreement, this Agreement and the Controller's use of the service's features — including which domains the Controller adds and verifies — constitute the complete documented instructions. If, in the Processor's assessment, an instruction infringes Data Protection Law, the Processor shall inform the Controller.

5. Confidentiality

The Processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access to customer data is limited to staff with a work-related need.

6. Security of processing (Art. 32)

The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The specific measures are set out in Appendix C and include, among others:

  • Tenant separation — customer data is logically separated per organisation, and access within an organisation is governed by fine-grained role-based access control (RBAC) with per-product permissions.
  • Encryption in transit via TLS (HTTPS), and encryption of stored secrets at rest with AES-256-GCM.
  • Access control — authenticated sessions, bcrypt-hashed passwords, CSRF protection, and two-factor authentication (TOTP) that can be enforced organisation-wide.
  • Hardened scanning infrastructure — including protection against SSRF and DNS-rebinding attacks in the components that connect to monitored domains.

7. Sub-processors (Art. 28(2) and (4))

The Controller hereby grants the Processor a general prior authorisation to engage sub-processors for the provision of the service. The current categories of sub-processors are listed in Appendix B; the specific, named list is available on request.

The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors with reasonable notice, giving the Controller the opportunity to object before the change takes effect. The Processor imposes on each sub-processor the same data protection obligations as those set out in this Agreement and remains fully liable to the Controller for the sub-processor's performance thereof.

8. Assistance to the Controller

Taking into account the nature of the processing and insofar as possible, the Processor assists the Controller with:

  • fulfilling requests from data subjects exercising their rights (access, rectification, erasure, restriction, data portability and objection);
  • complying with the obligations under Art. 32-36 GDPR (security of processing, breach notification, impact assessments and prior consultation), taking into account the information available to the Processor.

9. Personal data breach (Art. 33(2))

The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting personal data processed on behalf of the Controller. The notification shall contain the information reasonably available, so that the Controller can meet its own notification obligation (if any) to the supervisory authority (per Art. 33(1)) within 72 hours.

10. Transfers to third countries

The personal data is hosted and processed within the EU/EEA. Data is not transferred to countries outside the EU/EEA as part of normal operations. Should a transfer exceptionally become necessary, it will only take place on the Controller's instructions and on a valid transfer basis under Chapter V GDPR (e.g. the European Commission's Standard Contractual Clauses, SCCs).

11. Deletion or return on termination

On termination of the Main Agreement, the Processor shall, at the Controller's choice, delete or return all personal data processed on the Controller's behalf and delete existing copies, unless EU or Danish law requires continued storage. Residual copies in backups expire with the applicable backup retention period.

12. Audits and inspections (Art. 28(3)(h))

The Processor makes available to the Controller all information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. Audits are announced with reasonable notice, carried out during normal business hours and must not unduly disrupt the Processor's operations. The Processor may satisfy part of this obligation by providing documentation of its security measures and answering security questionnaires.

13. Liability, term and governing law

The parties' liability is governed by the Main Agreement. The Agreement applies for as long as the Processor processes personal data on behalf of the Controller. The Agreement is governed by Danish law, and any dispute shall be settled by the Danish courts, per the venue clause of the Main Agreement.

Appendix A — Details of the processing

Categories of data subjects: The Controller's users (account holders), and any individuals whose personal data appears incidentally in monitoring data — for example contact details in domain registration (RDAP) records, subject fields in TLS certificates, or sending-source information in DMARC aggregate reports.

Categories of personal data:

  • Account data: name, email address, company affiliation and password (bcrypt-hashed).
  • Monitoring data: domains and hostnames added by the Controller, certificate metadata, DNS records, scan results, website content collected during crawls, and email-authentication reports.
  • Usage and log data: IP addresses, session identifiers and security-relevant logs of actions in the service.

Special categories (sensitive data): Not processed. The service is not intended for processing special categories of personal data under Art. 9 GDPR.

Appendix B — Sub-processors

Sub-processor Purpose Location
EU-based hosting provider Hosting and infrastructure EU data centre

The specific, named sub-processor list is maintained by the Processor and provided to the Controller on request via mail@trustctrl.com. Changes are notified under section 7.

Appendix C — Technical and organisational measures

  • EU hosting: data is hosted on infrastructure located within the EU. Data does not leave the EU/EEA during normal operations.
  • Tenant separation: logical separation of customer data per organisation, with fine-grained role-based access control and per-product permissions inside each organisation.
  • Encryption: TLS/HTTPS in transit; stored secrets encrypted at rest with AES-256-GCM.
  • Access control: authenticated sessions, bcrypt-hashed passwords, CSRF protection, and two-factor authentication (TOTP) with optional organisation-wide enforcement.
  • Domain ownership verification: full scanning of a domain requires proof of control via a DNS record, preventing the platform from being pointed at third-party infrastructure.
  • Hardening: scanning components are protected against SSRF and DNS-rebinding attacks.

Contact

For questions about this Data Processing Agreement or to have it drawn up for signature:
Certiva ApS (CVR: 46450965)
Denmark
Email: mail@trustctrl.com
Web: trustctrl.com/contact