CANIMA, INC.
DATA PROCESSING ADDENDUM
This Data Processing Addendum ("DPA") forms part of the Master Subscription Agreement ("MSA") between Canima, Inc. ("Company" or "Processor") and the Customer entity identified in the applicable Order Form ("Customer" or "Controller"). This DPA applies to the extent that Company processes Personal Data on behalf of Customer in connection with the provision of the Service.
This DPA is incorporated by reference into the MSA and is accepted by Customer upon execution of an Order Form that references the MSA. No separate signature on this DPA is required. This DPA is effective as of the date Customer executes an Order Form, or if later, the date Customer begins using Services that involve the processing of Personal Data. The current version of this DPA is available at https://canima.com/legal/dpa.
1. DEFINITIONS
1.1 "Data Protection Laws". means all applicable laws and regulations relating to the processing, privacy, and use of Personal Data, including: (i) the EU General Data Protection Regulation 2016/679 ("GDPR"); (ii) the UK Data Protection Act 2018 and UK GDPR; (iii) the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"); (iv) any other applicable U.S. state privacy laws; and (v) any laws implementing or supplementing the foregoing.
1.2 "Data Subject". means the identified or identifiable natural person to whom Personal Data relates.
1.3 "Personal Data". means any information that relates to an identified or identifiable natural person that is processed by Company on behalf of Customer in connection with the Service, as further described in Annex 1.
1.4 "Personal Data Breach". means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed by Company.
1.5 "Sub-processor". means any third party engaged by Company to process Personal Data on behalf of Customer.
All other capitalized terms not defined herein shall have the meanings set forth in the MSA or in applicable Data Protection Laws.
2. SCOPE AND ROLES
2.1 Roles. For the purposes of this DPA, Customer is the Controller (or Business, as applicable under CCPA) and Company is the Processor (or Service Provider, as applicable under CCPA) with respect to Personal Data processed in connection with the Service.
2.2 Processing Details. The subject matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects are described in Annex 1 to this DPA.
3. OBLIGATIONS OF COMPANY
3.1 Processing Instructions. Company shall process Personal Data only on documented instructions from Customer (including as set forth in the MSA and this DPA), unless required to do so by applicable law, in which case Company shall inform Customer of that legal requirement before processing (unless prohibited by law from doing so).
3.2 Confidentiality. Company shall ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.3 Security Measures. Company shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including, as appropriate: (i) the pseudonymization and encryption of Personal Data; (ii) the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services; (iii) the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident; and (iv) a process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures. Company’s current security measures are described in Annex 2.
3.4 Sub-processors. Customer provides general authorization for Company to engage Sub-processors. Company shall: (i) maintain a current list of Sub-processors, available upon request; (ii) notify Customer of any intended changes concerning the addition or replacement of Sub-processors, giving Customer the opportunity to object within thirty (30) days; (iii) ensure that each Sub-processor is bound by data protection obligations no less protective than those set forth in this DPA; and (iv) remain fully liable for the performance of each Sub-processor’s obligations.
3.5 Data Subject Rights. Company shall, taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures in fulfilling Customer’s obligation to respond to requests from Data Subjects exercising their rights under Data Protection Laws.
3.6 Personal Data Breach Notification. Company shall notify Customer without undue delay (and in any event within seventy-two (72) hours) after becoming aware of a Personal Data Breach. Such notification shall include: (i) a description of the nature of the breach; (ii) the categories and approximate number of Data Subjects and records concerned; (iii) the likely consequences of the breach; and (iv) the measures taken or proposed to be taken to address the breach.
3.7 Deletion and Return. Upon termination of the MSA or upon Customer’s written request, Company shall, at Customer’s election, delete or return all Personal Data to Customer and delete existing copies, unless applicable law requires storage of the Personal Data. Company shall certify in writing that it has complied with this requirement upon Customer’s request.
3.8 Audits and Inspections. Company shall make available to Customer all information necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by Customer or a third-party auditor mandated by Customer, subject to reasonable notice and confidentiality requirements. Company may satisfy this obligation by providing Customer with: (i) SOC 2 Type II reports or equivalent certifications; (ii) results of penetration tests or vulnerability assessments conducted by qualified third parties; or (iii) other relevant audit reports or certifications.
4. INTERNATIONAL DATA TRANSFERS
4.1 Transfer Mechanisms. To the extent that Company processes Personal Data originating from the European Economic Area ("EEA"), United Kingdom, or Switzerland in a country not recognized as providing an adequate level of data protection, the parties agree that such transfers shall be governed by the Standard Contractual Clauses ("SCCs") adopted by the European Commission, as incorporated by reference into this DPA.
4.2 Supplementary Measures. Company shall implement supplementary technical and organizational measures as may be necessary to ensure that Personal Data transferred internationally receives an essentially equivalent level of protection as it would in the EEA.
5. CCPA-SPECIFIC PROVISIONS
5.1 Service Provider Obligations. To the extent that Company processes Personal Information (as defined under CCPA) on behalf of Customer, Company shall: (i) not sell or share such Personal Information; (ii) not retain, use, or disclose such Personal Information for any purpose other than the business purposes specified in the MSA; (iii) not retain, use, or disclose such Personal Information outside of the direct business relationship between Company and Customer; and (iv) comply with applicable obligations under the CCPA.
5.2 Certification. Company certifies that it understands the restrictions set forth in this Section 5 and will comply with them.
6. GENERAL
6.1 Precedence. In the event of any conflict between this DPA and the MSA, this DPA shall prevail with respect to the processing of Personal Data.
6.2 Liability. Each party’s liability under this DPA shall be subject to the limitations of liability set forth in the MSA.
6.3 Governing Law. This DPA shall be governed by the laws specified in the MSA, except where Data Protection Laws require application of the laws of another jurisdiction.
ANNEX 1: DETAILS OF PROCESSING
Subject Matter | Provision of AI-powered penetration testing services, including external, internal, and web application security testing. |
Duration | For the duration of the MSA and any Order Form(s), plus such additional period as may be necessary for deletion/return of Personal Data. |
Nature and Purpose | Processing is necessary to provide the Service, including: scanning and testing of Customer networks, applications, and systems; generating vulnerability reports and Findings; providing platform access and user management; and communicating with Authorized Users. |
Types of Personal Data | Contact information (names, email addresses, phone numbers); IP addresses; user account credentials (hashed); network identifiers and hostnames; domain registration data; application user data discovered during testing; and any Personal Data incidentally encountered during authorized penetration testing activities. |
Categories of Data Subjects | Customer employees and Authorized Users; Customer’s end users whose data may be incidentally encountered during penetration testing; system administrators and IT personnel. |
ANNEX 2: TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES
Company implements and maintains the following categories of security measures to protect Personal Data:
Encryption: Data in transit is protected using TLS 1.2 or higher. Data at rest is encrypted using AES-256 or equivalent industry-standard encryption.
Access Controls: Role-based access control (RBAC) is enforced across all systems. Multi-factor authentication (MFA) is required for all employee and administrative access. Access is granted on a least-privilege basis and reviewed quarterly.
Infrastructure Security: The Service is hosted on enterprise-grade cloud infrastructure with SOC 2 Type II certification. Network segmentation, intrusion detection systems, and regular vulnerability assessments are employed.
Data Isolation: Customer data is logically isolated from other customers’ data. Multi-tenant architecture employs strict access controls to prevent cross-tenant data access.
Personnel Security: All Company employees undergo background checks and sign confidentiality agreements. Regular security awareness training is provided.
Incident Response: Company maintains a documented incident response plan that is tested and updated regularly. Breach notification procedures comply with applicable Data Protection Laws.
Business Continuity: Regular data backups are performed with geographically distributed redundancy. Disaster recovery plans are maintained and tested.
Audit and Compliance: Company undergoes regular third-party security assessments and maintains relevant compliance certifications.
ACCEPTANCE
This DPA does not require a separate signature. Customer’s execution of an Order Form that references the MSA constitutes Customer’s acceptance of this DPA as published at https://canima.com/legal/dpa as of the date of such execution.
Last Updated: 05/06/2026