Skip to content

Data Processing Addendum

Version 2026-07-31.1

Effective date: 31 July 2026 — Version 2026-07-31.1

This Data Processing Addendum (DPA) forms part of the Business Terms of Service between Customer and Codelynx, LLC. It applies when Codelynx processes Personal Data on Customer's behalf to perform a security audit.

1. Roles and instructions

Customer is the controller or a processor acting for another controller. Codelynx is Customer's processor or subprocessor. Customer instructs Codelynx to process Personal Data only to verify the authorized scope, test the application, prove findings, deliver reports, secure the service and comply with documented instructions consistent with the contract.

Codelynx will inform Customer if an instruction appears to violate applicable data-protection law and may suspend that instruction. Customer is responsible for the lawfulness of its instructions, notices, legal basis and authority over the data and systems.

2. Processing details

  • Subject: authorized manual security testing and report delivery.
  • Duration: from signed authorization until deletion or return under the contract; contract evidence is retained separately as controller data.
  • Operations: access, consultation, testing, minimum reproduction, organization, masking, storage, transmission in reports and deletion.
  • Data subjects: Customer users, workforce, contractors, customers and other people whose data is lawfully present in the authorized application.
  • Data: account identifiers, contact details, tenant and authorization data, application records, logs, tokens and other data incidentally encountered.
  • Sensitive data: not intentionally requested. Customer must identify unavoidable sensitive or regulated data before signature so enhanced controls or exclusion can be agreed.

3. Confidentiality and personnel

Codelynx limits access to personnel who need it for the audit and who are bound by confidentiality obligations. Personal Data is not used for advertising, sale, unrelated product development or public case studies.

4. Security measures

Codelynx maintains measures appropriate to the risk, including least-privilege access; MFA where supported; TLS; provider encryption at rest; private report storage and signed URLs; separated Customer organizations; bounded evidence collection; masking in reports where feasible; logging; secure development and dependency controls; incident procedures; backup and recovery controls; and deletion of test secrets when no longer needed.

Customer must issue dedicated low-privilege accounts, avoid production secrets where possible, maintain backups and promptly revoke access.

5. Subprocessors

Customer gives general written authorization for the subprocessors on the current list. Codelynx will impose materially equivalent data-protection duties and remains responsible for their processing to the extent required by law.

Material additions will be posted at least 15 days before the new provider processes audit Personal Data where reasonably possible. Customer may object on reasonable data-protection grounds during that period. The parties will seek a practical solution; if none exists, Customer may terminate the affected unsigned service. A signed or completed audit cannot be unwound where the provider is necessary and the data has already been lawfully processed.

6. Data-subject requests and compliance assistance

Taking into account the nature of processing, Codelynx will reasonably assist Customer with data-subject requests, security obligations, data-protection impact assessments and regulator consultations. Requests received directly about Customer-controlled data will be referred to Customer unless law requires otherwise.

7. Security incidents

Codelynx will notify Customer without undue delay and, where feasible, within 24 hours after confirming a Personal Data Breach affecting Customer Personal Data. Notice will include available information about nature, scope, likely consequences, containment and contact details, and may be updated in phases. Notification is not an admission of fault.

Customer remains responsible for determining whether notification to an authority or individual is required.

8. Return and deletion

At Customer's choice and subject to technical feasibility, Codelynx will return report data or delete Customer Personal Data at the end of the service. Test secrets are deleted under the Privacy Policy. Data may remain in isolated rolling backups until overwritten and may be retained where law requires, solely for that legal purpose.

9. Audit information

On reasonable written request, Codelynx will provide information necessary to demonstrate compliance. No more than once annually, unless an incident or authority requires otherwise, Customer may request a proportionate remote audit at its cost, subject to confidentiality, security and protection of other customers.

10. International transfers

For restricted transfers from the EEA, the 2021 European Commission Standard Contractual Clauses are incorporated by reference. Module Two applies where Customer is controller and Codelynx is processor; Module Three applies where both are processors. The optional docking clause applies, Option 2 general authorization applies for Clause 9, and Delaware law applies to the extent the SCCs permit. The competent authority is determined under Clause 13.

For the UK, the then-current UK International Data Transfer Addendum applies. For Switzerland, references are adapted to the Swiss FADP where required. An applicable adequacy decision or Data Privacy Framework certification may take precedence where legally available.

Exporter: Customer, at the contact and address supplied with the order.
Importer: Codelynx, LLC, 8 The Green STE B, Dover, Delaware 19901, United States; melvyn@melvynx.com.
Transfer: continuous only as needed during the authorized audit; categories, purpose and safeguards are described in Sections 2 and 4.
Subprocessors: listed at /legal/subprocessors.

11. Liability, precedence and termination

Liability under this DPA is subject to the Terms except where applicable law or the SCCs prohibit that limitation. If this DPA conflicts with the Terms on Personal Data, this DPA controls; the SCCs control over both for a restricted transfer. This DPA ends when Codelynx no longer processes Customer Personal Data, while surviving duties continue for retained data.