Last updated: September 5, 2026 · Version 2.0
This Data Processing Agreement ("DPA") governs the Processing of Personal Data by Antanox ("Processor") on behalf of the Customer ("Controller") in connection with the Orithos AI Security Scanning Platform. It forms part of the Terms of Service and, where executed, the Master Subscription Agreement. On conflict concerning data protection, this DPA prevails.
"Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Personal Data Breach" have the meanings in the EU GDPR; equivalent terms in the UK GDPR and India's DPDP Act 2023 apply in their territories. "Data Protection Law" means all applicable data-protection regimes, including EU GDPR, UK GDPR, India DPDP Act 2023, and US state privacy laws (including CCPA/CPRA) to the extent applicable.
The Customer determines the purposes and means of Processing Customer Personal Data submitted through agent configurations and scan traffic (Controller). Antanox Processes it solely to provide the Service, as documented in this DPA and the Customer's configured instructions (scan settings, retention mode, API calls).
Antanox engages the following subprocessors. The Customer gives general authorisation; Antanox will notify the Customer of intended changes at least 30 days in advance, and the Customer may object on reasonable data-protection grounds, in which case the parties will work in good faith to recommend an alternative or the Customer may terminate the affected services:
Primary hosting is in the European Union; Antanox operates from India; some subprocessors process data in the United States. Where EU/UK GDPR applies, transfers outside the EEA/UK rely on an adequacy decision or the EU Standard Contractual Clauses (2021/914, Module 2) with the UK Addendum, plus transfer risk assessments. Equivalent safeguards apply under India DPDP Act transfer rules and other regimes as applicable.
Antanox will notify the Controller without undue delay and no later than 72 hours after becoming aware of a Personal Data Breach affecting Customer Personal Data, with the nature, categories and approximate numbers affected, likely consequences, and mitigation measures — updated as investigation proceeds. The Controller remains responsible for notifications to authorities and Data Subjects.
Antanox will make available information necessary to demonstrate compliance and allow audits: a written security summary and questionnaire responses annually on request; targeted remote audits for substantiated concerns; on-site audits for Enterprise customers with 30 days' notice, during business hours, at Customer expense, no more than once per year absent a breach.
During the term, the Customer can export scan data at any time (evidence packs, CSV). Within 30 days after termination, Antanox deletes Customer Personal Data and existing copies, except where law requires retention (in which case it is isolated and protected until lawful deletion). Expiry-based deletion follows the configured retention schedule automatically.
Liability under this DPA is subject to the Master Subscription Agreement or, absent one, the Terms of Service liability provisions. This DPA takes effect on first Processing and survives termination for as long as Customer Personal Data is retained.
Data protection questions: [email protected]. Privacy requests: [email protected]. This page is the authoritative text; a countersigned PDF is available on request for Enterprise customers.