Skip to content
xenXDRby FluenceSecurity
PricingDocs
EN·PL
Sign inBook a demo
  1. XenXDR
  2. Legal
  3. Data processing

Data processing

How FluenceSecurity acts as a processor when it hosts a tenant or operates the managed service, and how to request the full data processing agreement.

Version 1.0Last updated 2026-09-15Effective from 2026-09-15

On this page

  1. 1When we are a processor
  2. 2Subject matter and duration
  3. 3Nature and purpose
  4. 4Categories of data and data subjects
  5. 5Instructions
  6. 6Confidentiality and personnel
  7. 7Security measures
  8. 8Sub-processors
  9. 9Assistance
  10. 10Personal data breaches
  11. 11Deletion and return
  12. 12Audits
  13. 13Transfers
  14. 14Requesting the DPA

When we are a processor

For a self-hosted deployment, the Customer operates the Platform on its own infrastructure and FluenceSecurity does not process the Customer's telemetry at all, other than incidentally during support with the Customer's authorisation. No data processing agreement is needed for the software licence alone.

For a hosted tenant or the managed service, FluenceSecurity processes personal data contained in telemetry, alerts and cases on the Customer's behalf. The Customer is the controller; FluenceSecurity is the processor within the meaning of art. 28 GDPR. In that case the parties sign a data processing agreement ("DPA"). This page summarises its content. The signed DPA prevails over this summary.

Subject matter and duration

The processing concerns security telemetry from the Customer's endpoints, networks, identity providers and other configured sources, together with alerts, cases, reports and tickets derived from it. It lasts for the term of the hosted tenant or managed service agreement and the deletion period that follows.

Nature and purpose

Collection, normalisation, storage, search, correlation, detection, automated enrichment, advisory AI analysis if configured by the Customer, case management, reporting and, for the managed service, human analysis and response by FluenceSecurity's analysts under the Customer's instructions.

Categories of data and data subjects

Data subjects are the Customer's employees, contractors and, incidentally, third parties whose identifiers appear in telemetry, such as senders of email or sources of network connections. Data categories include usernames and email addresses, device identifiers and hostnames, IP addresses, process and file metadata, authentication events and, where the Customer sends them, the contents of log lines. The Customer is responsible for not sending special categories of data to the Platform unless the DPA expressly covers them.

Instructions

FluenceSecurity processes personal data only on documented instructions from the Customer, which include the agreement, the Platform configuration the Customer controls, and, for the managed service, the response policy the Customer signs off. FluenceSecurity informs the Customer if it believes an instruction infringes data protection law.

Confidentiality and personnel

Analysts and engineers with access to Customer data are bound by confidentiality obligations and receive security and data protection training. Access is limited to what the role requires and every action is recorded in the Platform's audit trail.

Security measures

The technical and organisational measures include, at minimum:

  • encryption of data in transit for all telemetry and console traffic;
  • dedicated tenants with isolated database identities and least-privilege service accounts;
  • role-based access with per-organisation scoping enforced on the server;
  • an immutable-by-convention audit trail retained for 365 days;
  • per-agent credentials, signed agent updates and no inbound listener on endpoints;
  • scripted, tested backups and a documented restore procedure;
  • vulnerability management with a public disclosure policy.

The full list is an annex to the DPA and is updated as the measures evolve.

Sub-processors

FluenceSecurity uses the sub-processors listed on the subprocessors page. The Customer is informed of intended additions or replacements at least 30 days in advance and may object on reasonable data protection grounds; if the objection cannot be resolved, the Customer may terminate the affected service.

Assistance

FluenceSecurity assists the Customer, taking into account the nature of the processing, with responding to data subject requests, with security of processing, with personal data breach notifications, and with data protection impact assessments and prior consultations.

Personal data breaches

FluenceSecurity notifies the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the Customer's data, and provides the information the Customer needs to meet its own notification obligations.

Deletion and return

At the end of the service FluenceSecurity returns the Customer's data in the documented export formats on request and deletes it from the tenant and from backups within the period stated in the DPA, unless EU or Polish law requires storage.

Audits

FluenceSecurity makes available the information necessary to demonstrate compliance with art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, on reasonable notice and no more than once a year unless a supervisory authority or a breach requires otherwise.

Transfers

Customer data in hosted tenants is stored in the European Union. Any transfer outside the EEA, for example through a sub-processor, takes place only with appropriate safeguards under Chapter V GDPR and is listed on the subprocessors page.

Requesting the DPA

To receive the full DPA for signature, use the contact form and select "Request the DPA", or write to legal@fluencesecurity.com. We accept the Customer's own DPA template for review where it does not conflict with the way the Platform is operated.

Questions about this document?

Write to legal@fluencesecurity.com or privacy@fluencesecurity.com for privacy matters.

xenXDRby FluenceSecurity

A FluenceSecurity product
Made in Gdańsk, Poland

  • GitHub
  • LinkedIn
  • X

Platform

  • Platform overview
  • SIEM and search
  • Endpoint agent
  • Detections
  • AI triage
  • Playbooks and response
  • Alerts, cases and reports
  • Multi-tenancy and access
  • Customer portal
  • Integrations

Solutions

  • For security teams
  • For MSSPs
  • Managed SOC by FluenceSecurity

Resources

  • Documentation
  • Why XenXDR
  • Security and trust
  • Changelog
  • Pricing

Company

  • fluencesecurity.com
  • About FluenceSecurity
  • MDR service
  • Blog
  • Contact

Legal

  • Privacy policy
  • Cookie policy
  • Website terms
  • Software licence terms
  • Data processing
  • Service levels
  • Company details
  • Accessibility
  • Vulnerability disclosure
  • Subprocessors
© 2026 FluenceSecurity. All rights reserved.Sigma, Splunk, Okta, Microsoft, Fortinet and other marks belong to their respective owners.
EN·PL