When we are a processor
For a self-hosted deployment, the Customer operates the Platform on its own infrastructure and FluenceSecurity does not process the Customer's telemetry at all, other than incidentally during support with the Customer's authorisation. No data processing agreement is needed for the software licence alone.
For a hosted tenant or the managed service, FluenceSecurity processes personal data contained in telemetry, alerts and cases on the Customer's behalf. The Customer is the controller; FluenceSecurity is the processor within the meaning of art. 28 GDPR. In that case the parties sign a data processing agreement ("DPA"). This page summarises its content. The signed DPA prevails over this summary.
Subject matter and duration
The processing concerns security telemetry from the Customer's endpoints, networks, identity providers and other configured sources, together with alerts, cases, reports and tickets derived from it. It lasts for the term of the hosted tenant or managed service agreement and the deletion period that follows.
Nature and purpose
Collection, normalisation, storage, search, correlation, detection, automated enrichment, advisory AI analysis if configured by the Customer, case management, reporting and, for the managed service, human analysis and response by FluenceSecurity's analysts under the Customer's instructions.
Categories of data and data subjects
Data subjects are the Customer's employees, contractors and, incidentally, third parties whose identifiers appear in telemetry, such as senders of email or sources of network connections. Data categories include usernames and email addresses, device identifiers and hostnames, IP addresses, process and file metadata, authentication events and, where the Customer sends them, the contents of log lines. The Customer is responsible for not sending special categories of data to the Platform unless the DPA expressly covers them.
Instructions
FluenceSecurity processes personal data only on documented instructions from the Customer, which include the agreement, the Platform configuration the Customer controls, and, for the managed service, the response policy the Customer signs off. FluenceSecurity informs the Customer if it believes an instruction infringes data protection law.
Confidentiality and personnel
Analysts and engineers with access to Customer data are bound by confidentiality obligations and receive security and data protection training. Access is limited to what the role requires and every action is recorded in the Platform's audit trail.
Security measures
The technical and organisational measures include, at minimum:
- encryption of data in transit for all telemetry and console traffic;
- dedicated tenants with isolated database identities and least-privilege service accounts;
- role-based access with per-organisation scoping enforced on the server;
- an immutable-by-convention audit trail retained for 365 days;
- per-agent credentials, signed agent updates and no inbound listener on endpoints;
- scripted, tested backups and a documented restore procedure;
- vulnerability management with a public disclosure policy.
The full list is an annex to the DPA and is updated as the measures evolve.
Sub-processors
FluenceSecurity uses the sub-processors listed on the subprocessors page. The Customer is informed of intended additions or replacements at least 30 days in advance and may object on reasonable data protection grounds; if the objection cannot be resolved, the Customer may terminate the affected service.
Assistance
FluenceSecurity assists the Customer, taking into account the nature of the processing, with responding to data subject requests, with security of processing, with personal data breach notifications, and with data protection impact assessments and prior consultations.
Personal data breaches
FluenceSecurity notifies the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the Customer's data, and provides the information the Customer needs to meet its own notification obligations.
Deletion and return
At the end of the service FluenceSecurity returns the Customer's data in the documented export formats on request and deletes it from the tenant and from backups within the period stated in the DPA, unless EU or Polish law requires storage.
Audits
FluenceSecurity makes available the information necessary to demonstrate compliance with art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, on reasonable notice and no more than once a year unless a supervisory authority or a breach requires otherwise.
Transfers
Customer data in hosted tenants is stored in the European Union. Any transfer outside the EEA, for example through a sub-processor, takes place only with appropriate safeguards under Chapter V GDPR and is listed on the subprocessors page.
Requesting the DPA
To receive the full DPA for signature, use the contact form and select "Request the DPA", or write to legal@fluencesecurity.com. We accept the Customer's own DPA template for review where it does not conflict with the way the Platform is operated.