Data Processing Agreement

Last updated: 2026-04-29. Forms part of the Terms of Service.

1. Roles

The Customer ("you") acts as Controller. Vritah Technologies ("we") acts as Processor when processing personal data on your instructions through the CRA Toolkit Service.

2. Subject matter, nature & purpose

Provision of a SaaS platform for EU Cyber Resilience Act compliance — including assessments, document generation, AI assistance, and account management.

3. Duration

For the duration of the underlying subscription. Personal data is returned or deleted on termination per Section 9.

4. Categories of data subjects

  • Customer's authorised users (account holders)
  • Customer's team members invited to a workspace
  • End-users whose data is voluntarily entered into the platform (e.g., a contact in a generated technical file)

5. Types of personal data

  • Identification: name, email, company name
  • Authentication: hashed password, session tokens
  • Usage: IP address, request metadata, AI prompt content
  • Billing: address, VAT ID (handled by Paddle as Merchant of Record / separate Controller)

6. Processor obligations

  • Process personal data only on documented instructions from the Customer.
  • Ensure persons authorised to process the data are bound by confidentiality.
  • Implement appropriate technical and organisational measures (Annex A).
  • Engage sub-processors only with general written authorisation (see Sub-processors); notify Customer at least 30 days before adding or replacing a sub-processor.
  • Assist the Customer in responding to data subject requests (Articles 12-23 GDPR).
  • Assist the Customer with security, breach notification, and DPIA obligations (Articles 32-36 GDPR).
  • Notify the Customer without undue delay (and within 72 hours) of becoming aware of a personal data breach.
  • Make available all information necessary to demonstrate compliance and allow audits, including inspections, conducted by the Customer or an auditor mandated by it.

7. International transfers

Where personal data is transferred outside the EEA, the parties incorporate the European Commission's Standard Contractual Clauses (Module 2: Controller to Processor, Decision (EU) 2021/914) by reference. Supplementary measures include encryption in transit (TLS 1.2+) and at rest (AES-256).

8. Sub-processors

The Customer authorises us to engage the sub-processors listed at /sub-processors. The Customer may object to a new sub-processor on reasonable grounds (data protection-related) within 14 days of notice; in that case the Customer may terminate the affected service for convenience.

9. Return / deletion of data

On termination, and at the Customer's choice, we will return or delete all personal data processed on its behalf within 30 days, unless retention is required by EU or Member State law. Deletion is logged.

10. Liability

Liability under this DPA is governed by the limitations in the Terms of Service, subject to mandatory liability under Art. 82 GDPR.

Annex A — Technical & organisational measures (summary)

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access control with Postgres row-level security
  • Webhook signature verification (HMAC-SHA256) and rate limiting
  • Secrets stored in platform secret managers, never in source control
  • Audit logging of authentication and admin actions
  • Regular security updates and dependency scanning
  • Backups with restoration testing
  • Incident response plan with 72-hour breach notification SLA

For a counter-signed copy of this DPA, contact support@cra-toolkit.com.