[{"data":1,"prerenderedAt":197},["ShallowReactive",2],{"i-lucide:chevron-down":3,"i-lucide:menu":8,"legal-\u002Flegal\u002Fdpa":10,"i-lucide:chevron-right":195},{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":7},0,24,false,"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"m6 9l6 6l6-6\"\u002F>",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":9},"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M4 5h16M4 12h16M4 19h16\"\u002F>",{"id":11,"title":12,"body":13,"description":166,"effectiveFrom":184,"extension":185,"lastUpdated":184,"meta":186,"navigation":187,"order":188,"path":189,"seo":190,"stem":191,"summary":192,"version":193,"__hash__":194},"legal_en\u002Flegal\u002Fdpa.md","Data processing",{"type":14,"value":15,"toc":165},"minimark",[16,21,30,40,44,47,51,54,58,61,65,68,72,75,79,82,107,110,114,117,121,124,128,131,135,138,142,145,149,152,156],[17,18,20],"h2",{"id":19},"when-we-are-a-processor","When we are a processor",[22,23,24,25,29],"p",{},"For a ",[26,27,28],"strong",{},"self-hosted deployment",", the Customer operates the Platform on its own infrastructure and FluenceSecurity does not process the Customer's telemetry at all, other than incidentally during support with the Customer's authorisation. No data processing agreement is needed for the software licence alone.",[22,31,24,32,35,36,39],{},[26,33,34],{},"hosted tenant"," or the ",[26,37,38],{},"managed service",", FluenceSecurity processes personal data contained in telemetry, alerts and cases on the Customer's behalf. The Customer is the controller; FluenceSecurity is the processor within the meaning of art. 28 GDPR. In that case the parties sign a data processing agreement (\"DPA\"). This page summarises its content. The signed DPA prevails over this summary.",[17,41,43],{"id":42},"subject-matter-and-duration","Subject matter and duration",[22,45,46],{},"The processing concerns security telemetry from the Customer's endpoints, networks, identity providers and other configured sources, together with alerts, cases, reports and tickets derived from it. It lasts for the term of the hosted tenant or managed service agreement and the deletion period that follows.",[17,48,50],{"id":49},"nature-and-purpose","Nature and purpose",[22,52,53],{},"Collection, normalisation, storage, search, correlation, detection, automated enrichment, advisory AI analysis if configured by the Customer, case management, reporting and, for the managed service, human analysis and response by FluenceSecurity's analysts under the Customer's instructions.",[17,55,57],{"id":56},"categories-of-data-and-data-subjects","Categories of data and data subjects",[22,59,60],{},"Data subjects are the Customer's employees, contractors and, incidentally, third parties whose identifiers appear in telemetry, such as senders of email or sources of network connections. Data categories include usernames and email addresses, device identifiers and hostnames, IP addresses, process and file metadata, authentication events and, where the Customer sends them, the contents of log lines. The Customer is responsible for not sending special categories of data to the Platform unless the DPA expressly covers them.",[17,62,64],{"id":63},"instructions","Instructions",[22,66,67],{},"FluenceSecurity processes personal data only on documented instructions from the Customer, which include the agreement, the Platform configuration the Customer controls, and, for the managed service, the response policy the Customer signs off. FluenceSecurity informs the Customer if it believes an instruction infringes data protection law.",[17,69,71],{"id":70},"confidentiality-and-personnel","Confidentiality and personnel",[22,73,74],{},"Analysts and engineers with access to Customer data are bound by confidentiality obligations and receive security and data protection training. Access is limited to what the role requires and every action is recorded in the Platform's audit trail.",[17,76,78],{"id":77},"security-measures","Security measures",[22,80,81],{},"The technical and organisational measures include, at minimum:",[83,84,85,89,92,95,98,101,104],"ul",{},[86,87,88],"li",{},"encryption of data in transit for all telemetry and console traffic;",[86,90,91],{},"dedicated tenants with isolated database identities and least-privilege service accounts;",[86,93,94],{},"role-based access with per-organisation scoping enforced on the server;",[86,96,97],{},"an immutable-by-convention audit trail retained for 365 days;",[86,99,100],{},"per-agent credentials, signed agent updates and no inbound listener on endpoints;",[86,102,103],{},"scripted, tested backups and a documented restore procedure;",[86,105,106],{},"vulnerability management with a public disclosure policy.",[22,108,109],{},"The full list is an annex to the DPA and is updated as the measures evolve.",[17,111,113],{"id":112},"sub-processors","Sub-processors",[22,115,116],{},"FluenceSecurity uses the sub-processors listed on the subprocessors page. The Customer is informed of intended additions or replacements at least 30 days in advance and may object on reasonable data protection grounds; if the objection cannot be resolved, the Customer may terminate the affected service.",[17,118,120],{"id":119},"assistance","Assistance",[22,122,123],{},"FluenceSecurity assists the Customer, taking into account the nature of the processing, with responding to data subject requests, with security of processing, with personal data breach notifications, and with data protection impact assessments and prior consultations.",[17,125,127],{"id":126},"personal-data-breaches","Personal data breaches",[22,129,130],{},"FluenceSecurity notifies the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the Customer's data, and provides the information the Customer needs to meet its own notification obligations.",[17,132,134],{"id":133},"deletion-and-return","Deletion and return",[22,136,137],{},"At the end of the service FluenceSecurity returns the Customer's data in the documented export formats on request and deletes it from the tenant and from backups within the period stated in the DPA, unless EU or Polish law requires storage.",[17,139,141],{"id":140},"audits","Audits",[22,143,144],{},"FluenceSecurity makes available the information necessary to demonstrate compliance with art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, on reasonable notice and no more than once a year unless a supervisory authority or a breach requires otherwise.",[17,146,148],{"id":147},"transfers","Transfers",[22,150,151],{},"Customer data in hosted tenants is stored in the European Union. Any transfer outside the EEA, for example through a sub-processor, takes place only with appropriate safeguards under Chapter V GDPR and is listed on the subprocessors page.",[17,153,155],{"id":154},"requesting-the-dpa","Requesting the DPA",[22,157,158,159,164],{},"To receive the full DPA for signature, use the contact form and select \"Request the DPA\", or write to ",[160,161,163],"a",{"href":162},"mailto:legal@fluencesecurity.com","legal@fluencesecurity.com",". We accept the Customer's own DPA template for review where it does not conflict with the way the Platform is operated.",{"title":166,"searchDepth":167,"depth":167,"links":168},"",3,[169,171,172,173,174,175,176,177,178,179,180,181,182,183],{"id":19,"depth":170,"text":20},2,{"id":42,"depth":170,"text":43},{"id":49,"depth":170,"text":50},{"id":56,"depth":170,"text":57},{"id":63,"depth":170,"text":64},{"id":70,"depth":170,"text":71},{"id":77,"depth":170,"text":78},{"id":112,"depth":170,"text":113},{"id":119,"depth":170,"text":120},{"id":126,"depth":170,"text":127},{"id":133,"depth":170,"text":134},{"id":140,"depth":170,"text":141},{"id":147,"depth":170,"text":148},{"id":154,"depth":170,"text":155},"2026-09-15","md",{},true,50,"\u002Flegal\u002Fdpa",{"title":12,"description":166},"legal\u002Fdpa","How FluenceSecurity acts as a processor when it hosts a tenant or operates the managed service, and how to request the full data processing agreement.","1.0","SL9BQkuyaQVigZKfLE4OK__1i3-6Mo0CX0R5l9sii8Q",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":196},"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"m9 18l6-6l-6-6\"\u002F>",1789936661759]