Data Processing Agreement

Version v1.0 · Last updated 11 July 2026

UK GDPR / EU GDPR Article 28 processing terms, written to be reviewed as-is by an MSP’s auditor before sign-up. The authorised third-party list is maintained in our sub-processor register, which is incorporated into this DPA by reference.

1. Scope and roles

This Data Processing Agreement (“DPA”) forms part of the agreement between the subscribing MSP (the “Controller”) and Tidehawk (the “Processor”) and applies wherever Tidehawk processes personal data on the MSP’s behalf under UK GDPR / EU GDPR Article 28. It is accepted electronically at signup and the acceptance is timestamped and versioned against your account.

2. Subject matter and duration

Processing covers the personal data the Controller submits to the service — typically end-client organisation names, contact details for alert recipients, monitored hostnames, and associated certificate/domain metadata — for the duration of the subscription plus the 30-day post-cancellation retention window.

3. Processor obligations

  • Process personal data only on the Controller’s documented instructions.
  • Ensure personnel with access are bound by confidentiality.
  • Apply appropriate technical and organisational measures (Article 32): AES-256-GCM encryption of sensitive values at rest, TLS 1.2+ in transit, PostgreSQL Row-Level Security for tenant isolation, mandatory multi-factor authentication, least-privilege database roles, and a tamper-evident audit chain of administrative access.
  • Assist the Controller with data-subject requests and Articles 32–36 obligations.
  • Engage sub-processors only under written terms no less protective than this DPA (§5).
  • Delete or return personal data at the end of the engagement (§7).
  • Make available the information necessary to demonstrate compliance, and allow for audits.

4. Data residency

All storage and primary processing takes place in the United Kingdom / EU: hosting and the primary database on DigitalOcean LON1 (London), transactional email via AWS SES eu-west-2 (London), file storage on Wasabi eu-west-1 (London), and error monitoring on self-hosted GlitchTip within our own LON1 infrastructure. No personal data is stored outside the UK/EU.

5. Authorised sub-processors

The Controller authorises the sub-processors listed in the sub-processor register (DigitalOcean, AWS, Wasabi, Stripe, Cloudflare, and the public certificate/domain look-up sources Certspotter, Censys, crt.sh and RDAP/WHOIS), each engaged under a data processing agreement. We will give at least 30 days’ notice before adding or replacing a sub-processor, during which the Controller may object on reasonable grounds.

6. International transfers

No personal data is stored outside the UK/EU. Where a transfer arises from a public look-up query (domain name only) or billing, it is safeguarded by UK↔EU adequacy, the UK–US / EU–US Data Privacy Framework and/or Standard Contractual Clauses with the UK International Data Transfer Addendum, together with data minimisation. Per-provider mechanisms are set out in the register.

Certificate-transparency look-ups

Certificate-transparency look-ups transmit the domain name only and are performed by the sub-processors listed in the register. A per-workspace in-region-only discovery option is not currently available; the Processor will notify the Controller under the register’s change-notice mechanism before making one available.

7. Personal data breach

We will notify the Controller without undue delay, and in any event within 48 hoursof becoming aware of a personal data breach affecting the Controller’s data, providing the information the Controller needs for its own UK GDPR obligations. We operate an automated 72-hour breach-deadline watchdog to support timely regulator notification.

8. Erasure and export

Account owners can trigger a full erasure or a complete data export from within the application (Settings → Account). Erasure runs through an auditable pipeline — removing certificates, domains, registration records, logs, and stored files — and completes with a signed, verifiable erasure certificate. On request we will provide a countersigned copy of this DPA: email hello@tidehawk.co.