DPA (Art. 28 GDPR) — Version 2.3, June 2026

Pre-signed by RevealMyRisk. Download, complete the Controller block, done.

Download DPA (PDF)

Version 2.3 · June 2026

Data Processing Agreement

How it applies

Processor: RevealMyRisk — Herr Godfrey Mwasanje c/o Block Services Stuttgarter Straße 106 70736 Fellbach Deutschland Email: contact@revealmyrisk.com

Where you use RevealMyRisk to monitor your organisation's domains and assets, we process personal data on your behalf. For that processing you are the data controller and RevealMyRisk is your data processor under Article 28 GDPR. Our Data Processing Agreement (DPA) governs it.

The DPA is incorporated into our Terms of Service by reference and applies automatically to every customer. It is binding without a separate signature, so you do not need to contact us to put it in place. Pre-signed by RevealMyRisk.

Need a counter-signed copy?

The PDF above is already signed on our side. If your procurement process requires a counter-signed copy, download it, complete and sign the Controller block, and keep it for your records; it is then fully executed without any action on our part. If you must have us sign your own paper template instead, email contact@revealmyrisk.com.

Roles

You are the controller; we are your processor for account and monitoring data. Separately, we are an independent controller for the breach datasets we index or license from public sources, which fall outside this DPA.

Sub-processors

Listed in Annex 2 of the DPA. We give at least 30 days' notice before adding or replacing one, and you may object on reasonable data-protection grounds.

International transfers

Core account and monitoring data is hosted in the EU/EEA. For sub-processors outside the EEA, an adequacy decision (including the EU-U.S. Data Privacy Framework) or Standard Contractual Clauses apply.

Breach notification

We notify you of a personal data breach affecting your data within 24 hours of becoming aware, with a substantive Article 33(3) update within a further 48 hours.

Return and deletion

On termination we delete or anonymise your account and monitoring data within 90 days and provide a written deletion certificate, except for records we must keep by law (such as billing).

Audit

You may audit compliance once per twelve-month period (and after a breach) on reasonable notice; we may satisfy requests with existing documentation where available.

Security

Our technical and organisational measures are set out in Annex 3 of the DPA and summarised on the Security Measures page.

Device binding of authorised users

Access by your authorised users can be bound to a single approved device. At sign-in the browser reads stable technical characteristics — user agent, browser language settings, processor cores and reported device memory, screen resolution, colour depth and pixel ratio, time zone and UTC offset, and the rendering signature of a small canvas drawing — and hashes them with SHA-256 into one non-reversible token. Only that pseudonymous token is transmitted and stored in our device register alongside the user account; the underlying characteristics are not stored and cannot be derived from it.

For device-locked accounts each login is checked against the registered devices: unknown fingerprints are refused and unapproved devices stay blocked until an administrator approves them. This is a security measure under Article 32 GDPR to prevent credential sharing and unauthorised access; it uses no cookies, advertising identifiers or client-installed software and is never used for profiling. As controller you can request the list, reset or deletion of your users' device entries at contact@revealmyrisk.com; all entries are deleted with the account.