Legal

Data Processing Addendum

A DPA is signed between two named parties, so it is not something we can publish as a page. Email [email protected] with your entity name and we will send one for signature. The facts your reviewer will ask for are below, so you can start the review before the document arrives.

Roles

You are the controller. Umbra is the processor, acting on your documented instructions — which in practice are the scopes you authorise and the scans you run.

Categories of data

Account and contact details for your users; technical data about the infrastructure and applications you ask us to test; credentials you choose to supply for authenticated testing, stored encrypted; and the findings and evidence produced.

Umbra is not designed to process special-category personal data, and you should not point it at systems where scan evidence would capture such data.

Location of processing

EU by default on every plan. Platform and database: Helsinki, Finland (Hetzner). Scan artifacts: Stockholm, Sweden (AWS eu-north-1).

AI analysis providers (Anthropic, DeepSeek) process scan output when you trigger a run and may do so outside the EU; those transfers rely on the providers' own transfer mechanisms. If EU-only AI processing is a requirement for you, say so before signing — it changes which capabilities are available.

Subprocessors

The full list, with purpose and region for each, is at /legal/subprocessors .

Deletion and return

On termination we delete your organisation and its data on request. Ask and we will confirm when it is done.

Breach notice

We notify you without undue delay after becoming aware of a personal data breach affecting your data, with what we know at the time and updates as we learn more.

Last reviewed: 4 September 2026.