Passbolt Cloud Data Processing Agreement

1. Definitions and Interpretation

2. Description of the Processing

3. Instructions and purpose

3.1 Processor

3.2. Documented instructions

3.3 Controller's obligations

3.4 Compliance with Data Protection Laws

4. Security

5. Subprocessing

5.1 Controller's authorisation

5.2 Contract with Contracted Processor

6. Data Subject rights requests

7. Personal Data Breach

8. Other assistance to the Controller

9. Documentation, compliance and audit rights

10. Data Transfer

11. Confidentiality

12. Non-compliance with this DPA and termination

13. Miscellaneous

14. Governing Law and Jurisdiction

Date of Last Update

[email protected]

Schedule 1 – Details of Processing

Subject matter and nature of the Processing

Duration of the Processing

Types of Personal Data

Categories of Data Subjects

Schedule 2 – Technical and Organization Security Measures (TOM)

Organizational Security

Information Security Program

Third-Party Penetration Testing

Roles and Responsibilities

Confidentiality

Background Checks

Product security

Development best practice

Change management

Security whitepaper

Cloud Security

Cloud Infrastructure Security

Data Hosting Security

Encryption at Rest

Encryption in Transit

Vulnerability Scanning

Logging and Monitoring

Business Continuity and Disaster Recovery

Incident Response

Access Security

Permissions and Authentication

Least Privilege Access Control

Quarterly Access Reviews

Endpoint Security

Password Requirements

Password Managers

Physical Security

Vendor and Risk Management

Annual Risk Assessments

Vendor Risk Management

Schedule 3 – Approved Contracted Processors

  • Aikido

    Processor activities
    Type of personal data
    Headquarters location
    Safeguards & data transfer
  • Amazon Web Services

    Processor activities
    Type of personal data
    Headquarters location
    Safeguards & data transfer
  • Chargebee

    Processor activities
    Type of personal data
    Headquarters location
    Safeguards & data transfer
  • Chartmogul

    Processor activities
    Type of personal data
    Headquarters location
    Safeguards & data transfer
  • CloudFlare

    Processor activities
    Type of personal data
    Headquarters location
    Safeguards & data transfer
  • Google Cloud Platform (GCP)

    Processor activities
    Type of personal data
    Headquarters location
    Safeguards & data transfer
  • Hubspot

    Processor activities
    Type of personal data
    Headquarters location
    Safeguards & data transfer
  • n8n

    Processor activities
    Type of personal data
    Headquarters location
    Safeguards & data transfer
  • New relic

    Processor activities
    Type of personal data
    Headquarters location
    Safeguards & data transfer
  • Odoo

    Processor activities
    Type of personal data
    Headquarters location
    Safeguards & data transfer
  • Slack

    Processor activities
    Type of personal data
    Headquarters location
    Safeguards & data transfer
  • Stripe

    Processor activities
    Type of personal data
    Headquarters location
    Safeguards & data transfer
  • Thales Cyber Solutions Luxembourg

    Processor activities
    Type of personal data
    Headquarters location
    Safeguards & data transfer
  • Zoho

    Processor activities
    Type of personal data
    Headquarters location
    Safeguards & data transfer
Flag of European UnionMade in Europe. Privacy by default.