Skip to content

Legal

Data Processing Addendum

When you load your staff onto Seraph CTI, you are the data controller and we are your processor. This sets out what we may do with that data, what we must do to protect it, and what we owe you when something goes wrong. It forms part of the Terms of Service.

Version 2026-08-14 · Effective 14 August 2026

Draft, pending legal review. This document describes what the platform does today and what we intend to commit to. It has not yet been reviewed by an advocate, and items marked [TO CONFIRM] are unresolved. If you are evaluating Seraph CTI for procurement, ask us for the reviewed version rather than relying on this one.

1How this fits with the Terms

This Addendum is part of the Terms of Service and applies automatically from the moment you put personal data on the platform. You do not need to ask us to sign one, though we will sign a counterpart on request. Where this Addendum and the Terms conflict on the handling of personal data, this Addendum wins.

Terms used here — controller, processor, personal data, data subject — have the meanings given in the Data Protection Act 2019.

2Roles

You are the controller. You decide which of your staff go on the platform, what campaigns run against them, and what happens to the results. You are responsible for having a lawful basis for all of it, and for telling your staff — a simulated phishing programme that nobody was told about is a problem this Addendum cannot solve for you.

We are your processor. We process your staff’s personal data only to provide the service and only on your documented instructions, of which your configuration of the platform is the primary one.

For account administrators’ own details and for billing, we are a controller in our own right. That is covered by the Privacy Notice, not by this Addendum.

3What we process, and for how long

Subject matter: providing security awareness training, phishing simulation, reporting, and — where your package includes them — threat intelligence and breach-exposure monitoring.

Categories of data subject: your employees, contractors and other staff you place in scope, and your account administrators.

Categories of personal data: name, work email address, department or group, job title where supplied, and behavioural records — whether a simulated message was opened, clicked, or replied to, whether credentials were submitted to a simulated page, training assigned and completed, and reports submitted through the report button. Where breach monitoring is enabled, whether an address appears in a breach corpus and which field types were exposed.

No special-category data is required by the platform, and you should not load any.

Duration: for as long as your account is active, then per the retention windows in the Privacy Notice.

4Our obligations

We will:

(a) process personal data only on your instructions, and tell you if we believe an instruction breaches the Act;

(b) ensure everyone we authorise to access it is bound by confidentiality;

(c) keep the technical and organisational measures in clause 5;

(d) not engage a new sub-processor without notice to you, under clause 6;

(e) help you respond to data subjects, under clause 7;

(f) notify you of a personal data breach, under clause 8;

(g) delete or return the data when the agreement ends, under clause 9;

(h) make available what you reasonably need to demonstrate our compliance, and allow an audit under clause 10.

5Security measures

These are in place today, not planned. Our Trust & Security page describes each in more detail.

Isolation. Multi-tenant with hard boundaries. Every record is scoped to its organization and a guard layer enforces that scoping on database queries at runtime. A federated sign-in asserting an identity from another tenant is refused.

Access control. Role-based, least privilege, multi-factor authentication with lockout on repeated failure, and per-tenant SAML single sign-on on packages that include it. API keys are organization-scoped, shown once, stored hashed and individually revocable.

Encryption. TLS 1.2 and 1.3 only in transit, with a restricted modern cipher suite and HSTS. Passwords are stored only as adaptive one-way hashes.

Credential redaction. Breach monitoring reads recovered credential values only to set an exposure flag and discards them at the ingestion boundary. Recovered passwords are never written to our systems.

Auditability. Sign-ins and failures, administrative changes, MFA challenges and authorization denials are logged, tamper-evident, and exportable by your administrators.

Resilience. Database and file backups are taken on a schedule and their restoration is tested. Releases ship with tagged rollback images.

6Sub-processors

You give general authorisation for us to engage sub-processors. The current list is maintained in the Privacy Notice and today comprises Anthropic, Pesapal, Have I Been Pwned, LeakCheck, Email delivery, Hosting.

We will give you notice before a new sub-processor starts processing your data. If you reasonably object on data-protection grounds, tell us within 30 days and we will either not proceed, offer you a way to continue without it, or let you terminate the affected part of the service without penalty. Several of the sub-processors are already optional and can simply be switched off.

We remain liable to you for a sub-processor’s performance.

7Helping you answer your staff

The platform lets your administrators find, export, correct and erase an individual directly — for most requests you do not need us at all, which is the fastest way for your staff to be answered.

Erasure anonymizes the individual’s records after a 30-day grace period, so a request made in error can be recalled. Where you need help beyond what the platform does, ask and we will provide it. If a data subject contacts us directly we will not respond on your behalf; we will forward the request to you promptly and tell them we have.

8If there is a breach

We will notify you without undue delay, and in any case within 48 hours of becoming aware of a personal data breach affecting your data. The notification will describe what happened, the categories and approximate number of people and records affected, the likely consequences, and what we are doing about it — and we will keep you updated as we learn more rather than waiting until we know everything.

Notifying the Office of the Data Protection Commissioner and your staff is your decision as controller. We will give you what you need to make it.

9Deletion and return

When the agreement ends, your data stays available for export for 30 days and is then purged, including from backups as those backups age out of their rotation. We will confirm deletion in writing on request.

We keep invoices, payments and the tax records associated with them, because the law requires it. Nothing else survives.

10Audit

We will make available the information reasonably needed to show we are meeting this Addendum, and will respond to a security questionnaire once a year at no charge.

You may audit us — or appoint an independent auditor who is not a competitor of ours — on 30 days’ notice, no more than once a year unless a breach or a regulator says otherwise, during business hours, and without disrupting the service or exposing another customer’s data. Each side bears its own costs.

[TO CONFIRM: whether an independent attestation (ISO 27001, SOC 2) is being pursued, which would replace most of this clause in practice]

11Transfers out of Kenya

Some sub-processors are outside Kenya, as marked in the Privacy Notice. Where personal data is transferred out we rely on the safeguards in section 49 of the Data Protection Act, and will identify the safeguard used for a given transfer on request.

12Liability

Each side’s liability under this Addendum is subject to the limits in the Terms of Service.

Questions about any of this? Write to privacy@seraphcyber.com, or talk to us.