Data Processing Agreement
Last updated: 2026-07-01
This Data Processing Agreement describes how MB XThreat processes personal data on behalf of its customers under Article 28 of the GDPR. It is incorporated into the Terms of Service.
1. Scope of This Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between MB XThreat and the Customer and applies wherever MB XThreat processes personal data on the Customer’s behalf in connection with the XThreat security-awareness training platform.
It sets out the parties’ respective obligations under Article 28 of the GDPR. In the event of a conflict on data-protection matters, this DPA prevails over the Terms of Service.
2. Parties and Roles
This DPA governs the processing of personal data carried out by the Processor on behalf of the Controller in connection with the XThreat security-awareness training platform.
- Controller: the Customer — the organisation that subscribes to and administers the XThreat platform for its personnel.
- Processor: MB XThreat, company code 307258262, Narėpų g. 40, Narėpų k., LT-54470 Kauno r., Lithuania, info@xthreat.eu.
- This DPA is incorporated into and subject to the Terms of Service. In the event of a conflict on data-protection matters, this DPA prevails.
3. Definitions
"GDPR" means Regulation (EU) 2016/679. "Controller", "Processor", "Personal Data", "Processing", "Data Subject", "Personal Data Breach" and "Sub-processor" have the meanings given in the GDPR.
"Applicable Data Protection Law" means the GDPR and the data-protection laws of the Republic of Lithuania, together with any other laws applicable to the processing.
4. Subject Matter, Duration, Nature and Purpose
The Processor processes personal data only to provide the contracted services:
- Subject matter: provision of the XThreat security-awareness training platform.
- Duration: for the term of the Customer’s subscription, plus the deletion or return period in the section "Deletion or Return of Data".
- Nature and purpose: hosting and operating the platform, account and access management, delivering training and lessons, recording quiz results, course completion and phishing-simulation interactions, and providing support.
5. Categories of Data Subjects and Personal Data
On the Controller’s instructions, the Processor processes the following:
- Data subjects: the Controller’s employees and authorised users, including managers and administrators.
- Personal data: name, work email address, job title and organisation; authentication data (passwords are stored only in hashed form; login is primarily by one-time email code); usage and technical data (IP address, device and browser information, activity); training performance data (quiz results, completion status, phishing-simulation interactions); and support communications.
- Special categories of data: none. The platform is neither intended for nor configured to process special-category data (Article 9 GDPR), and the Controller must not upload such data to the platform.
6. Processor Obligations (Article 28(3))
The Processor shall:
- process the personal data only on the Controller’s documented instructions, including for transfers, unless required by law (in which case it informs the Controller unless the law prohibits this);
- ensure that persons authorised to process the personal data are bound by confidentiality;
- implement the technical and organisational measures described in the "Security Measures" section;
- respect the conditions for engaging Sub-processors set out below;
- assist the Controller as described in "Assistance to the Controller";
- delete or return the personal data as set out in "Deletion or Return of Data"; and
- make available the information necessary to demonstrate compliance and allow for audits as set out below.
7. Confidentiality
The Processor ensures that all personnel authorised to process the Controller’s personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to those who need it to deliver the services.
8. Security Measures (Article 32)
Taking into account the state of the art and the risks, the Processor maintains appropriate technical and organisational measures, which include:
- encryption of personal data in transit (TLS) and at rest;
- access controls on a least-privilege, need-to-know basis, enforced at the database layer through row-level security;
- multi-factor authentication for administrative access to the Processor’s infrastructure;
- logging and monitoring of access to systems and data;
- regular, protected backups of the production database;
- secure software-development and change-management practices using version control; and
- a documented incident-response process.
9. Sub-processors (Article 28(2), (4))
The Controller grants a general authorisation for the Processor to engage Sub-processors. The Processor imposes data-protection obligations equivalent to this DPA on each Sub-processor, remains responsible for their performance, and will inform the Controller of intended changes, giving the Controller the opportunity to object. The current Sub-processors are (with processing locations and transfer safeguards recorded in Annex III):
- Supabase — database, authentication and file hosting;
- Stripe — payment processing;
- Resend — transactional and notification email delivery;
- Vercel — application hosting and content delivery (CDN);
- Sentry — application error monitoring and performance diagnostics (EU/Frankfurt region).
10. International Transfers
Where a Sub-processor processes personal data outside the EU/EEA, such transfers are made only under appropriate safeguards pursuant to Chapter V of the GDPR — principally the EU Standard Contractual Clauses (SCCs), which are incorporated into each Sub-processor’s data-processing terms (Supabase, Stripe, Resend and Vercel each make SCCs and a DPA available). The safeguard relied on for each Sub-processor is recorded in Annex III.
11. Assistance to the Controller
Taking into account the nature of the processing, the Processor assists the Controller by:
- providing reasonable measures to help the Controller respond to data-subject requests under Articles 15–22, insofar as possible;
- assisting with data-protection impact assessments and prior consultations (Articles 35–36); and
- assisting with the Controller’s obligations to secure processing and to handle personal data breaches (Articles 32–34).
12. Personal Data Breach (Article 33)
The Processor notifies the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Controller’s personal data, and provides the information reasonably available to help the Controller meet its own notification obligations under Articles 33–34. Breach notifications and security queries should be directed to info@xthreat.eu.
13. Deletion or Return of Data (Article 28(3)(g))
On termination of the services, at the Controller’s choice, the Processor deletes or returns all personal data processed on the Controller’s behalf and deletes existing copies within 30 days of termination, unless retention is required by law. The Controller may request an export of its data within this period.
14. Audits and Inspections (Article 28(3)(h))
The Processor makes available to the Controller the information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates — subject to at least 30 days’ prior written notice, no more than once per year (save where required by a supervisory authority or following a personal data breach), and appropriate confidentiality. Where available, the Processor may satisfy such requests through relevant third-party reports or certifications.
15. Liability and Governing Law
This DPA is governed by the law of the Republic of Lithuania and is subject to the jurisdiction and the limitations of liability set out in the Terms of Service, which are incorporated by reference.
16. Annexes
The following annexes form part of this DPA:
- Annex I — Details of processing (parties, categories of data subjects and personal data, nature, purpose and duration): as set out in the sections "Parties and Roles", "Subject Matter, Duration, Nature and Purpose" and "Categories of Data Subjects and Personal Data" above.
- Annex II — Technical and organisational security measures: as set out in the "Security Measures" section above.
- Annex III — Approved Sub-processors, with purpose and processing location: Supabase (database, authentication and file hosting), Stripe (payment processing), Resend (transactional email), Vercel (application hosting/CDN) and Sentry (error monitoring and diagnostics, EU/Frankfurt region). The processing location and transfer safeguard for each are those set out in that Sub-processor’s current published sub-processor list and DPA.
17. Contact and Execution
For DPA requests, or to put in place a signed copy of this agreement, contact:
MB XThreat
Email: info@xthreat.eu
Data Protection inquiries: info@xthreat.eu
Address: Narėpų g. 40, Narėpų k., LT-54470 Kauno r., Lithuania
A countersigned copy of this DPA is available to Customers on request; email info@xthreat.eu to execute a signed version.