Data Processing Addendum

GDPR ARTICLE 28
PROCESSOR AGREEMENT
MSA ADDENDUM

Data Processing Addendum

Effective Date: July 6, 2026

This Data Processing Addendum (“DPA”) is entered into by and between Armorstack, LLC, a Wisconsin limited liability company (“Armorstack,” “Processor,” “we,” “us,” or “our”), and the business customer identified in the applicable Master Services Agreement or Statement of Work (“Controller,” “Client,” or “you”). This DPA supplements and is incorporated into the Master Services Agreement (the “Agreement”) governing Armorstack’s provision of VERITY, CORE, SENTRY, and/or CITADEL managed services to the Controller.

This DPA reflects Armorstack’s obligations as a data Processor under the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and comparable data protection laws, to the extent Armorstack processes personal data on the Controller’s behalf in the course of delivering contracted services. In the event of a conflict between this DPA and the Agreement with respect to the processing of personal data, this DPA controls.

This document is a template addendum for reference purposes. For a countersigned copy incorporated into your specific Master Services Agreement, contact [email protected].

1. Purpose and Scope

This DPA supplements the Master Services Agreement (or applicable Statement of Work) between Armorstack, LLC and the Controller, and applies whenever Armorstack processes personal data on the Controller’s behalf in connection with the delivery of VERITY (strategic advisory and governance), CORE (IT-as-a-Service and infrastructure), SENTRY (cybersecurity and threat management), and/or CITADEL (physical security and integration) services. This DPA governs only the processing of personal data for which the Controller determines the purposes and means; it does not apply to personal data for which Armorstack acts as an independent controller (for example, Armorstack’s own website visitors, prospects, or employees, which are addressed in Armorstack’s Privacy Policy). Capitalized terms not defined here have the meaning given in the Agreement.

2. Definitions

“Controller” means the entity that determines the purposes and means of the processing of personal data — here, Armorstack’s business customer under the Agreement. “Processor” means the entity that processes personal data on behalf of the Controller — here, Armorstack, LLC. “Personal Data” means any information relating to an identified or identifiable natural person (a “Data Subject”). “Processing” means any operation performed on personal data, whether or not by automated means, including collection, storage, use, disclosure, or deletion. “Sub-processor” means any third party engaged by Armorstack to process personal data on the Controller’s behalf in furtherance of the Agreement. “Data Subject” means the identified or identifiable natural person to whom personal data relates. “Supervisory Authority” means an independent public authority established by an EU/EEA member state (or the UK Information Commissioner’s Office, or equivalent) responsible for monitoring application of applicable data protection law. These definitions are intended to align with Article 4 of the GDPR.

3. Subject Matter, Duration, Nature and Purpose of Processing

The subject matter of processing under this DPA is Armorstack’s delivery of contracted managed services to the Controller. Processing occurs for the duration of the underlying services agreement, commencing on the effective date of the applicable Statement of Work and continuing until all services are complete or the Agreement is terminated, subject to Section 12 (Term and Termination). The nature and purpose of processing is the performance of VERITY, CORE, SENTRY, and/or CITADEL managed services — including monitoring, infrastructure management, help desk support, security operations, vulnerability management, and strategic advisory — which may involve incidental access to the Controller’s systems, networks, applications, and the personal data contained within them as a necessary consequence of delivering those services. Armorstack does not process Controller personal data for any purpose other than delivering the contracted services, complying with legal obligations, or as otherwise instructed in writing by the Controller.

4. Categories of Data Subjects and Types of Personal Data

Data Subjects whose personal data Armorstack may process on the Controller’s behalf typically include the Controller’s employees, contractors, and authorized end users of the systems Armorstack supports. The types of personal data typically involved are limited to what is incidental to service delivery: names, work email addresses and business contact information, system and account identifiers (usernames, employee IDs, device IDs), and security or telemetry data generated by monitored systems (login events, network traffic metadata, endpoint activity, alert and incident data). Armorstack does not require, and will not process, special categories of personal data (health data, biometric data, genetic data, data revealing racial or ethnic origin, religious beliefs, or similar) except where a specific service scope contractually requires it — for example, engagements involving healthcare client environments subject to HIPAA — in which case additional safeguards and terms apply as documented in the applicable Statement of Work or a separate Business Associate Agreement.

5. Processor Obligations

Armorstack agrees to: (a) process personal data only on documented instructions from the Controller, including with respect to international transfers, unless required to do otherwise by law, in which case Armorstack will inform the Controller of that legal requirement before processing (unless prohibited from doing so); (b) ensure that personnel authorized to process personal data are bound by written confidentiality obligations; (c) implement appropriate technical and organizational security measures in accordance with GDPR Article 32, consistent with the security posture described in Armorstack’s Privacy Policy — role-based access control, multi-factor authentication on privileged accounts, encryption in transit (TLS 1.2+) and at rest (AES-256), continuous monitoring via Armorstack’s SENTRY Security Operations Center, vulnerability management, and documented incident response procedures aligned to NIST CSF 2.0; (d) taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures in responding to requests from Data Subjects seeking to exercise their rights; (e) assist the Controller in ensuring compliance with its obligations under GDPR Articles 32 through 36 (security of processing, breach notification, data protection impact assessments, and prior consultation with supervisory authorities), taking into account the nature of processing and information available to Armorstack; and (f) at the Controller’s choice, delete or return all personal data to the Controller after the end of the provision of services, and delete existing copies, unless applicable law requires storage of the personal data.

6. Sub-processors

The Controller authorizes Armorstack to engage sub-processors in furtherance of service delivery, subject to the obligations in this section. Armorstack’s general sub-processors supporting service infrastructure include cloud and hosting infrastructure providers engaged to deliver contracted services. Armorstack’s own website uses MonsterInsights (Google Analytics 4) for website-visitor analytics — a tool that processes data about visitors to armorstack.ai and is separate and distinct from Client Service Data processed under a Master Services Agreement; it is not used to process personal data within the scope of contracted managed services unless a specific engagement’s Statement of Work states otherwise. Engagement-specific sub-processors — for example, monitoring platforms, ticketing systems, or remote access tools used to deliver a particular client’s VERITY, CORE, SENTRY, or CITADEL services — are documented in the applicable Statement of Work. Armorstack will provide the Controller with notice of any intended addition or replacement of a sub-processor that will process Controller personal data, and the Controller may object to such a change on reasonable data-protection grounds within a reasonable period following notice. Armorstack remains responsible for its sub-processors’ performance of their data protection obligations under written agreements imposing terms no less protective than those in this DPA.

7. International Transfers

Armorstack is a U.S.-based company and primarily processes and stores personal data in the United States. Where personal data subject to this DPA is transferred outside the European Economic Area, United Kingdom, or Switzerland, Armorstack will rely on Standard Contractual Clauses (SCCs) approved by the European Commission, the UK International Data Transfer Addendum, or another valid transfer mechanism recognized under applicable law, and will implement supplementary measures as reasonably necessary given the circumstances of the transfer. Controllers requiring the execution of SCCs or equivalent transfer documentation as part of this DPA should contact [email protected] to arrange the appropriate module and annexes for their engagement.

8. Data Breach Notification

Armorstack will notify the Controller without undue delay, and in any event targeting within 72 hours of becoming aware, upon confirming a personal data breach affecting personal data processed on the Controller’s behalf, consistent with GDPR Article 33. Notification will describe, to the extent then known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Armorstack will cooperate with the Controller and provide reasonably requested information to support the Controller’s own notification obligations to supervisory authorities and affected Data Subjects. Armorstack’s Incident Response function operates 24/7 through its SENTRY Security Operations Center.

9. Audit Rights

The Controller may request evidence of Armorstack’s compliance with this DPA, including relevant security certifications, audit summaries, or attestation reports (such as a SOC 2 Type II report, where available) then held by Armorstack. Upon reasonable advance written notice, and no more than once per 12-month period absent a reasonable basis to believe a breach has occurred, the Controller (or its independent third-party auditor, subject to confidentiality obligations at least as protective as those in the Agreement) may conduct or commission an audit of Armorstack’s relevant processing activities and controls. Audits will be scheduled to minimize disruption to Armorstack’s operations and other clients, conducted during normal business hours, and subject to the confidentiality provisions of the Agreement. Armorstack may satisfy an audit request by providing existing third-party audit reports and certifications where those reasonably address the Controller’s inquiry.

10. Regulator Contacts

Data Subjects have the right under GDPR Article 77 to lodge a complaint with a supervisory authority, in particular in the EU/EEA member state of their habitual residence, place of work, or place of the alleged infringement. Armorstack, LLC is a United States entity without an establishment in the European Union and does not maintain a designated EU representative or Data Protection Officer at this time. Data Subjects seeking to identify their applicable supervisory authority may reference the European Data Protection Board’s list of member authorities at edpb.europa.eu/about-edpb/about-edpb/members_en. Inquiries relating to this DPA, GDPR compliance, or requests for referral to the appropriate authority may also be directed to [email protected], and Armorstack will assist in good faith to route the inquiry appropriately.

11. Signature/Execution

This DPA is incorporated by reference into the Master Services Agreement for Controllers who require it as a condition of engaging Armorstack’s services. Publication of this DPA on Armorstack’s website does not by itself constitute execution; it is made available for reference and to describe the terms Armorstack will offer. To request a signed, client-specific copy of this DPA for your records — including any applicable Standard Contractual Clauses, engagement-specific sub-processor listings, or negotiated variations — contact [email protected] with your company name and Master Services Agreement reference. A countersigned DPA, once executed, supersedes this reference version as between Armorstack and that Controller.

12. Term and Termination

This DPA remains in effect for as long as Armorstack processes personal data on the Controller’s behalf under the Agreement, and terminates automatically upon expiration or termination of the Agreement, except that the obligations in this DPA relating to confidentiality, data deletion or return, and any post-termination assistance obligations survive termination until fully performed. Upon termination, Armorstack will, at the Controller’s choice, delete or return all personal data processed under this DPA and delete existing copies, unless applicable law requires Armorstack to retain some or all of the personal data, in which case Armorstack will continue to protect that data in accordance with this DPA for as long as it is retained.

Armorstack — The Standard of Truth in Technology.

Unifying security for a resilient future.

Need a Client-Specific DPA?

Request a signed, engagement-specific Data Processing Addendum — including Standard Contractual Clauses and sub-processor listings for your Statement of Work.

Contact Legal