Legal Document
Data Processing Agreement
ThreatSabre Limited
Last updated Friday 5 June 2026
1. Introduction and Incorporation
- This Data Processing Agreement (DPA) forms part of, and is incorporated by reference into, the SaaS Terms of Use between you (the Customer) and ThreatSabre Limited (ThreatSabre, we, us or our), available at https://www.threatsabre.com/terms (the Terms). Capitalised terms not defined in this DPA have the meaning given to them in the Terms.
- This DPA applies automatically wherever ThreatSabre processes Customer Personal Data (as defined below) in the course of providing the Service. No separate signature is required for this DPA to take effect; it is effective for the duration of the Terms. A Customer that requires a counter-signed copy may request one from support+privacy@threatsabre.com.
- This DPA records the parties’ agreement in relation to the processing of personal data and is intended to satisfy the requirements of: a. Article 28 of the EU General Data Protection Regulation (Regulation (EU) 2016/679) (EU GDPR); b. Article 28 of the UK General Data Protection Regulation as incorporated into UK law by the Data Protection Act 2018 (UK GDPR); and c. the Information Privacy Principles of the New Zealand Privacy Act 2020 (NZ Privacy Act).
- In this DPA, Data Protection Law means the EU GDPR, the UK GDPR, the NZ Privacy Act, and any other data protection or privacy law applicable to a party’s processing of Customer Personal Data under the Terms.
2. Roles of the Parties
- The parties acknowledge that, for the purposes of the EU GDPR and UK GDPR and in respect of Customer Personal Data: a. the Customer is the Controller (or, where the Customer is itself a processor acting on behalf of a third-party controller, the Customer is a processor and ThreatSabre is a sub-processor — in which case the Customer warrants it has the authority of the relevant controller to engage ThreatSabre on these terms); and b. ThreatSabre is the Processor.
- For the purposes of the NZ Privacy Act, the parties acknowledge that, in collecting, holding and processing Customer Personal Data through the Service, ThreatSabre acts as the Customer’s agent (consistent with clause 6.5 of the Terms) and does not hold that information for its own purposes except as permitted under clause 7 (Analytical Data) of this DPA.
- The Customer is responsible for ensuring it has a valid lawful basis under Data Protection Law for the processing carried out by ThreatSabre on its behalf, and for providing any notices and obtaining any consents required from data subjects.
3. Definitions
In this DPA:
Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing, Special Category Data and Supervisory Authority have the meanings given to them in the EU GDPR, and (where the context requires) the equivalent meanings under the UK GDPR and NZ Privacy Act.
Customer Personal Data means any Personal Data contained within the Data that ThreatSabre processes on behalf of the Customer in the course of providing the Service, as further described in Appendix 1.
Adequacy Decision means a decision by the European Commission (or, for the UK GDPR, by the UK Secretary of State) that a country, territory or sector ensures an adequate level of protection for Personal Data.
EU SCCs means the Standard Contractual Clauses for the transfer of personal data to third countries set out in European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced from time to time.
Restricted Transfer means a transfer (or onward transfer) of Customer Personal Data from a Controller in the European Economic Area (EEA) or the United Kingdom (UK) to ThreatSabre, or onward to a Sub-processor, in a country that is not the subject of an Adequacy Decision.
Sub-processor means any third party engaged by ThreatSabre to process Customer Personal Data in connection with the Service.
UK IDTA means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, as amended or replaced from time to time.
Other capitalised terms (including Data, Service, Permitted Users, Underlying Systems and personal information) have the meanings given to them in the Terms.
4. Scope, Subject Matter and Instructions
- The subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of Data Subjects are set out in Appendix 1.
- This DPA applies for as long as ThreatSabre processes Customer Personal Data, which is the term of the Terms plus the retention period described in clause 10.
- ThreatSabre will process Customer Personal Data only: a. to provide, maintain and support the Service in accordance with the Terms; b. on the documented instructions of the Customer, including with regard to transfers (the Terms, this DPA, and the Customer’s configuration and use of the Service constitute the Customer’s complete and documented instructions); and c. as required by applicable law to which ThreatSabre is subject, in which case ThreatSabre will inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
- ThreatSabre will immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
- ThreatSabre does not require, and the Service is not designed to ingest, Special Category Data, criminal conviction data, or the personal data of children. The Customer must not submit such data through the Service except as expressly agreed in writing. The ThreatSabre agent connects read-only to the Customer’s firewalls and sensitive values are redacted at source before transmission.
5. ThreatSabre’s Obligations as Processor
ThreatSabre will:
- Confidentiality — ensure that personnel authorised to process Customer Personal Data are subject to binding obligations of confidentiality and have received appropriate data protection training.
- Security — implement and maintain the technical and organisational measures set out in Appendix 3, appropriate to the risk, in accordance with Article 32 of the EU/UK GDPR.
- Assistance with Data Subject rights — taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights under Data Protection Law (see clause 8).
- Assistance with compliance — assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the EU/UK GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of processing and the information available to ThreatSabre.
- Breach notification — notify the Customer of a Personal Data Breach in accordance with clause 9.
- Return or deletion — at the Customer’s choice, delete or return Customer Personal Data on termination in accordance with clause 10.
- Records and demonstration of compliance — make available to the Customer the information reasonably necessary to demonstrate compliance with Article 28 of the EU/UK GDPR, in accordance with the audit provisions in clause 11.
6. Sub-processors
- The Customer provides general authorisation for ThreatSabre to engage the Sub-processors listed in Appendix 2 to process Customer Personal Data in connection with the Service. An up-to-date list of Sub-processors is set out in Appendix 2 and maintained at https://www.threatsabre.com/sub-processors.
- ThreatSabre will notify the Customer of any intended changes concerning the addition or replacement of a Sub-processor, giving the Customer the opportunity to review the change. Customers may subscribe to change notifications via support+privacy@threatsabre.com.
- Where a Customer has a reasonable, data-protection-based objection to a new Sub-processor, the parties will work together in good faith to resolve it. If the parties cannot reach a resolution, the Customer may, as its sole remedy, terminate the affected part of the Service in accordance with the Terms.
- ThreatSabre will impose on each Sub-processor, by written contract, data protection obligations that are substantially equivalent to those set out in this DPA, and remains fully liable to the Customer for the performance of each Sub-processor’s obligations.
7. ThreatSabre’s Own Use of Data
To the extent permitted by clause 6.3 of the Terms, ThreatSabre may generate anonymised and aggregated statistical and analytical data (Analytical Data) from the Data and use it for its internal research and product development. Analytical Data does not identify the Customer or any Data Subject and is not Customer Personal Data. Where data is anonymised such that no individual is identifiable, it falls outside the scope of this DPA.
8. Data Subject Rights
- ThreatSabre will, to the extent legally permitted, promptly notify the Customer if it receives a request from a Data Subject to exercise rights of access, rectification, erasure, restriction, portability, or objection (under the EU/UK GDPR), or access and correction (under NZ Privacy Act Information Privacy Principles 6 and 7), in respect of Customer Personal Data. ThreatSabre will not respond to such a request itself except on the documented instructions of the Customer or as required by applicable law.
- ThreatSabre will provide self-service tooling within the Service, and reasonable assistance, to enable the Customer to respond to such requests. Data Subject and privacy enquiries directed to ThreatSabre will be routed to support+privacy@threatsabre.com.
9. Personal Data Breach
- ThreatSabre will notify the Customer without undue delay, and in any event where feasible within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
- The notification will, to the extent known and available, describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address it.
- ThreatSabre will take reasonable steps to contain, mitigate and remediate the breach, and will cooperate with the Customer so that the Customer can meet its own notification obligations to Supervisory Authorities and Data Subjects (EU/UK GDPR Articles 33 and 34) and to the Office of the Privacy Commissioner and affected individuals in respect of notifiable privacy breaches under Part 6 of the NZ Privacy Act.
- ThreatSabre’s notification is not, and will not be construed as, an acknowledgement of fault or liability.
10. Return and Deletion of Data
- On termination or expiry of the Terms, ThreatSabre will, at the Customer’s choice, delete or return Customer Personal Data, save to the extent that retention is required by applicable law.
- Consistent with clause 12.9 of the Terms and ThreatSabre’s retention schedule, Customer Personal Data is retained for the duration of the subscription plus three (3) months, after which it is deleted by automated processes (database purge, object-storage lifecycle rules, and backup expiry). Sub-processor-held data is deleted within the relevant Sub-processor’s deletion window (for example, transactional email data within the email provider’s agreement-plus-90-day window).
- ThreatSabre will provide written confirmation of deletion on the Customer’s request.
11. Audit and Demonstration of Compliance
- ThreatSabre will make available to the Customer, on reasonable written request and no more than once per year (except where required following a Personal Data Breach or by a Supervisory Authority), information reasonably necessary to demonstrate compliance with this DPA. This will ordinarily be satisfied by providing: a. ThreatSabre’s then-current SOC 2 report (available under NDA); and b. responses to a reasonable security or data protection questionnaire.
- Where the information in clause 11.1 is insufficient to demonstrate compliance, or where an audit is required by a Supervisory Authority or by mandatory Data Protection Law, ThreatSabre will permit and contribute to an audit, including an inspection by the Customer or an independent third-party auditor appointed by the Customer (and reasonably acceptable to ThreatSabre, and bound by confidentiality), subject to reasonable advance written notice (not less than 30 days, except for-cause or where a shorter period is legally required), conducted during business hours, in a manner that does not compromise the security or confidentiality of other customers’ data, and at the Customer’s cost.
12. International Transfers
- ThreatSabre stores and processes Customer Personal Data in the hosting region applicable to the Customer’s account. Where the Customer is able to select a hosting region, the selected region is recorded in Appendix 4. The current default hosting region for customer platform data is AWS Asia Pacific (Sydney,
ap-southeast-2), with disaster-recovery backups in AWS Asia Pacific (Melbourne,ap-southeast-4) — both located in Australia. - Where ThreatSabre processes Customer Personal Data in a country that is the subject of an Adequacy Decision (for example, New Zealand, which benefits from an EU Adequacy Decision), no additional transfer mechanism is required for that transfer.
- To the extent any processing of Customer Personal Data under this DPA constitutes a Restricted Transfer: a. for transfers subject to the EU GDPR, the EU SCCs are incorporated into this DPA by reference and apply, with Module Two (Controller to Processor) completed as set out in Appendix 4, the Customer (or its relevant controller) acting as data exporter and ThreatSabre as data importer; and b. for transfers subject to the UK GDPR, the UK IDTA is incorporated into this DPA by reference and applies, completed as set out in Appendix 4.
- In the event of any conflict between the EU SCCs or UK IDTA and the other terms of this DPA or the Terms, the EU SCCs or UK IDTA prevail in respect of the relevant Restricted Transfer.
- Transfer impact (Australia hosting). ThreatSabre has assessed the laws and practices of the current default hosting country (Australia) relevant to the protection of Customer Personal Data, including any government access regimes (such as the Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018). ThreatSabre is not subject to FISA 702 or the US CLOUD Act in respect of data hosted in Australia, has received no government access requests for Customer Personal Data, and considers that the technical and organisational measures in Appendix 3 (including encryption in transit and at rest, access controls and source-side redaction of sensitive values) provide appropriate supplementary protection. ThreatSabre will notify the Customer if it can no longer comply with the transfer safeguards, and will challenge any government access request that is unlawful or overbroad.
- Transfer impact (United States sub-processors). Certain Sub-processors listed in Appendix 2 are located in the United States. Of these, only Resend processes Customer Personal Data — limited to the notification content the Customer configures for email alerts; GitHub, Tailscale and PostHog do not process customer firewall or posture data. Transfers to these Sub-processors are made under the EU-U.S. Data Privacy Framework and/or the EU SCCs (with the UK Addendum where applicable), as recorded in Appendix 2. Taking into account the limited and low-sensitivity nature of the data transferred (posture-summary notification content, not firewall configuration), encryption in transit, the measures in Appendix 3, and the contractual commitments of the relevant Sub-processors, ThreatSabre considers that the transfers provide an appropriate level of protection notwithstanding United States government-access regimes (including FISA 702 and the US CLOUD Act). A Customer that does not wish notification content to be processed in the United States may configure webhook-only notification delivery to an endpoint of its choice.
- New Zealand Privacy Act (IPP 12). For Customers and Data Subjects subject to the NZ Privacy Act, ThreatSabre’s hosting of Customer Personal Data in Australia is a cross-border disclosure for the purposes of Information Privacy Principle 12. ThreatSabre relies on IPP 12(1) on the basis that the Australian hosting environment, together with the contractual obligations in this DPA and the technical and organisational measures in Appendix 3, ensures that the Customer Personal Data is subject to safeguards that are comparable to those under the NZ Privacy Act.
13. Liability
The liability of each party under or in connection with this DPA is subject to the exclusions and limitations of liability set out in clause 11 of the Terms.
14. General
- This DPA is governed by the laws of New Zealand and the parties submit to the non-exclusive jurisdiction of the New Zealand courts, except that the EU SCCs and UK IDTA are governed by, and subject to the forum specified in, those instruments (as completed in Appendix 4) in respect of the relevant Restricted Transfer.
- In the event of any conflict between this DPA and the Terms in relation to the processing of Customer Personal Data, this DPA prevails. Subject to clause 12.4, the EU SCCs and UK IDTA prevail over this DPA in respect of a Restricted Transfer.
- Except as amended by this DPA, the Terms remain in full force and effect. ThreatSabre may update this DPA in accordance with the change provisions of the Terms, provided that no update will materially reduce the protections afforded to Customer Personal Data.
- No signature is required: this DPA takes effect on the Customer’s acceptance of, or continued use of the Service under, the Terms.
Appendix 1 — Details of Processing (EU SCCs Annex I)
A. List of Parties
Data exporter: the Customer, as identified in the Terms / Customer’s account (the Controller of the Customer Personal Data). Contact: the account administrator identified in the Customer’s account.
Data importer: ThreatSabre Limited (Company Number 9363459), a New Zealand company. Role: Processor. Contact: Tim Morris, Privacy Lead, tim.morris@threatsabre.com; privacy enquiries support+privacy@threatsabre.com.
B. Description of Transfer
| Item | Detail |
|---|---|
| Categories of Data Subjects | Platform users — employees and authorised personnel of the Customer who access the ThreatSabre platform. In addition, individuals identified within the Customer’s firewall configuration — for example firewall administrators and user accounts configured on the Customer’s devices — where such identifiers appear in the configuration data analysed by the Service |
| Categories of Personal Data | Email address; username / display name; user ID (kp_* identifiers issued by the authentication provider); IP address; browser metadata / User-Agent; organisation name; authentication tokens; notification content. Firewall configuration data analysed by the Service may also contain limited identifiers used in firewall administration — for example administrator usernames, firewall-user account names, and email addresses referenced in authentication / LDAP / RADIUS configuration — which are processed solely to deliver security posture analysis |
| Special category data | None. The Service is not designed to process special category, criminal, or children’s data. Fortinet-encrypted (ENC) values in firewall configuration data are redacted at source before transmission |
| Nature and purpose of processing | Delivery of the ThreatSabre network security posture management platform: ingesting firewall configuration/posture data via an agent, analysing it, and presenting findings via the web application, PDF reports, email alerts, and webhook alerts; authentication, access control, audit logging, and notification routing |
| Frequency of transfer | Continuous, on an ongoing basis for the duration of the subscription |
| Duration / retention | Duration of the subscription plus three (3) months (see clause 10) |
| Subject matter and duration | As set out in clause 4 of this DPA |
C. Competent Supervisory Authority
For EU SCC purposes, the competent Supervisory Authority is determined in accordance with Clause 13 of the EU SCCs — that is, the Supervisory Authority of the EEA member state in which the data exporter (Customer) is established or, where the exporter is not established in the EEA, the Supervisory Authority of the member state in which the exporter’s EU representative is appointed or in which the relevant Data Subjects are located. For UK transfers, the competent authority is the UK Information Commissioner’s Office (ICO).
Appendix 2 — Sub-processors
The following Sub-processors are authorised to process Customer Personal Data in connection with the Service. The current list is maintained at https://www.threatsabre.com/sub-processors.
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| AWS | Cloud infrastructure (compute, database, storage) | Australia (Sydney; Melbourne for backups) | AWS DPA + SCCs |
| Kinde | Authentication and identity | Australia | AU data residency |
| Cloudflare | CDN, DNS, WAF, DDoS and bot protection | Global edge network | DPA + EU SCCs, UK Addendum, EU-U.S. DPF |
| Resend | Transactional email delivery | United States | EU-U.S. DPF + SCCs |
| PostHog | Website analytics (anonymised, no PII) | United States | DPA + SCCs |
| Microsoft 365 | Corporate email and collaboration | New Zealand | DPA + EU SCCs + EU-U.S. DPF |
| Zoho | CRM, customer support, demo bookings | Australia | AU data residency |
Note: not all Sub-processors process all categories of Customer Personal Data. AWS hosts the platform and therefore processes the full set of Customer Personal Data; others process only the data necessary for their stated purpose.
Appendix 3 — Technical and Organisational Measures (EU SCCs Annex II)
ThreatSabre maintains the following measures, appropriate to the risk, in accordance with Article 32 of the EU/UK GDPR. A fuller description is published in ThreatSabre’s Security Posture Overview.
Encryption
- In transit: TLS 1.2 or higher, enforced on all public endpoints via Cloudflare and the application load balancer.
- At rest: AES-256 — AWS RDS (PostgreSQL) database encryption and AWS S3 server-side encryption (SSE-S3), with object versioning enabled.
- Secrets: application secrets, API keys, and database credentials held in AWS Secrets Manager.
Access control and authentication
- Role-based access control (RBAC) scopes what each user can see and do within the platform; data is scoped to the Customer’s organisation account.
- Authentication via Kinde using OAuth 2.0 / OIDC, with MFA supported.
- AWS IAM follows least-privilege; administrative access to production is restricted to authorised personnel over an encrypted WireGuard mesh (Tailscale) and is logged.
- Internal corporate access (Microsoft 365) is governed by Entra ID with MFA and Conditional Access.
Network security
- All public traffic is routed through Cloudflare, with DDoS mitigation active at the edge and a Web Application Firewall (Cloudflare managed rules and the OWASP Core Ruleset) deployed in active blocking mode.
- Databases and internal services sit in private VPC subnets with no direct internet access; security groups enforce minimal inbound rules.
Data minimisation
- The agent connects read-only to Customer firewalls over outbound HTTPS only; no inbound access to the Customer’s network is required, and sensitive values are redacted at source before transmission.
Logging and monitoring
- AWS CloudWatch and CloudTrail for application and infrastructure logs; Cloudflare analytics at the edge.
- Microsoft 365 Unified Audit Log and Entra ID sign-in/audit logs for corporate activity; Microsoft Defender for Endpoint for endpoint threat detection on managed devices.
- Alerting configured for security-relevant events.
Secure development
- Peer-reviewed pull requests before merge; dependency and vulnerability scanning in the CI/CD pipeline; infrastructure defined as code with separate development, staging, and production environments; secrets never committed to source control.
Incident response and resilience
- Documented incident response process (detection and triage, containment, eradication and recovery, post-incident review).
- Multi-AZ deployment in Sydney, automated database backups with point-in-time recovery, cross-region backups in Melbourne, and infrastructure reproducible from infrastructure-as-code.
Measures for sub-processor engagement
- Sub-processors are engaged under written contracts imposing data protection obligations substantially equivalent to this DPA, and their security posture is reviewed (see clause 6 and Appendix 2).
Appendix 4 — Transfer Mechanism
This Appendix completes the EU SCCs and UK IDTA where a Restricted Transfer arises under clause 12.
Hosting region for this Customer: Default — AWS Asia Pacific (Sydney, ap-southeast-2), backups in AWS Asia Pacific (Melbourne, ap-southeast-4), both in Australia. Where region selection is available, the Customer’s selected region (as recorded at sign-up or in the applicable order documentation) governs, and the transfer analysis in clause 12 applies to that region.
EU SCCs — Module Two (Controller to Processor) selections
| Clause | Selection |
|---|---|
| Module | Module Two (Controller to Processor) |
| Clause 7 (Docking clause) | Included |
| Clause 9 (Sub-processors) | Option 2 — General written authorisation. ThreatSabre will inform the Customer of intended changes to Sub-processors as set out in clause 6 of this DPA |
| Clause 11 (Redress) | Optional independent dispute resolution language not included |
| Clause 17 (Governing law) | The law of the EEA member state in which the data exporter (Customer) is established; where the exporter is not established in an EEA member state, the law of Ireland |
| Clause 18 (Choice of forum and jurisdiction) | The courts of the EEA member state whose law governs under Clause 17; where that is Ireland, the courts of Ireland |
| Annex I.A (List of Parties) | As set out in Appendix 1.A |
| Annex I.B (Description of transfer) | As set out in Appendix 1.B |
| Annex I.C (Competent Supervisory Authority) | As set out in Appendix 1.C |
| Annex II (Technical and organisational measures) | As set out in Appendix 3 |
| Annex III (Sub-processors) | As set out in Appendix 2 |
UK IDTA
For transfers subject to the UK GDPR, the UK International Data Transfer Addendum applies, with the following Tables completed:
| IDTA Table | Completion |
|---|---|
| Table 1 (Parties) | As set out in Appendix 1.A |
| Table 2 (Selected SCCs, Modules and Clauses) | The EU SCCs Module Two, completed as set out above |
| Table 3 (Appendix Information) | Annexes I, II and III completed as set out in Appendices 1, 3 and 2 respectively |
| Table 4 (Ending the Addendum when the Approved Addendum changes) | The data importer (ThreatSabre) may end the Addendum as set out in Section 19 of the Approved Addendum |