Data Processing Agreement
Document version: 1.0
Last updated: August 22, 2026
Between: the Client (as identified in the contract or subscription account, "Data Controller") and LudiSec ("Data Processor", "LudiSec").
This Data Processing Agreement ("DPA") implements art. 28 GDPR and is incorporated by reference into the Terms of Service accepted by the Client when contracting the Platform. Acceptance via checkbox during account signup carries the same validity as a handwritten signature, per art. 28.9 GDPR, which allows electronic form.
1. Subject matter and duration
The Processor will process personal data on behalf of the Controller exclusively to provide the LudiSec service (cybersecurity training, phishing simulations, human-risk indicators), for the duration of the contractual relationship and, after termination, for the period set out in clause 8.
2. Nature and purpose of processing
Hosting, processing, and analysis of data required for: End User account management, training progress and gamification, execution of phishing simulations, generation of risk indicators (including the global classifier described in clause 5), and multi-tenant administration features where the Client acts as a Reseller.
3. Data types and categories of data subjects
| Data category | Data subject categories |
|---|---|
| Identification and contact data | Client's employees/End Users |
| Platform usage data | Client's employees/End Users |
| Phishing simulation interaction data | Client's employees/End Users |
| Technical data (IP, browser, security logs) | End Users and administrators |
No special categories of data (art. 9 GDPR) are processed unless the Client mistakenly enters them, in which case it must notify admin.ludisec@gmail.com immediately.
4. Controller's instructions
The Processor will process data only on documented instructions from the Controller, including those resulting from the Client's own configuration of the Platform (e.g., scope of simulation campaigns). If the Processor believes an instruction infringes GDPR or other data protection law, it will inform the Controller before carrying it out.
5. Global classifier and aggregated data
The Controller authorizes the Processor to use data derived from End Users' use of the Platform, in aggregated and pseudonymized form, to train the global human-risk classifier (Naive Bayes) described in the Privacy Policy, in order to improve risk-pattern detection for the benefit of all Clients. This aggregated processing does not allow individual identification of other Clients' End Users and is deemed necessary to provide and improve the service.
6. Confidentiality
The Processor ensures that persons authorized to process the data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
7. Security measures (art. 32 GDPR)
Including: encryption in transit (TLS) and at rest; role-based access control; SSO/Keycloak authentication; hash-chained compliance event logging to ensure record integrity and traceability; periodic backups; segregation of development and production environments; infrastructure monitoring (Grafana Alloy).
8. Sub-processors
The Client gives general authorization for the Processor to engage the following sub-processors, bound by obligations equivalent to this DPA:
| Sub-processor | Service |
|---|---|
| Amazon Web Services (EC2, RDS, S3) | Cloud infrastructure and storage |
| Amazon SES | Transactional and simulation email delivery |
| Stripe | Payment processing |
| Odoo (SaaS) | Billing and Verifactu compliance |
| Bunny Stream | Training video delivery |
The Processor will notify the Controller of any intended change to this list at least 15 days in advance; the Controller may object on reasonable data-protection grounds.
9. Assistance to the Controller
The Processor will assist the Controller, to a reasonable extent given the nature of processing, with: (a) responding to data subject rights requests; (b) carrying out Data Protection Impact Assessments where required; (c) notifying security breaches per clause 10.
10. Personal data breach notification
The Processor will notify the Controller of any personal data breach without undue delay and, in any event, within 48 hours of becoming aware of it, providing the information available under art. 33 GDPR so the Controller can meet its 72-hour notification obligation to the supervisory authority.
11. International transfers
Where a sub-processor is located outside the European Economic Area, the Processor ensures Standard Contractual Clauses approved by the European Commission, or another appropriate transfer mechanism under Chapter V GDPR, are in place.
12. Deletion or return of data
On termination of the service, the Processor will, at the Controller's choice, delete or return all personal data and delete existing copies, unless applicable law requires retention (e.g., tax or NIS2/DORA traceability obligations), in which case data will be retained only for the legally required period with restricted access.
13. Audits
The Processor will make available to the Controller the information necessary to demonstrate compliance with art. 28 GDPR obligations and will allow reasonable audits, with at least 30 days' notice and in a manner that does not disproportionately interfere with service delivery to other Clients.
14. Liability
Each party is liable for damages caused by its own breach of GDPR and this DPA, per art. 82 GDPR and the general Terms of Service.
15. Acceptance
This DPA is accepted by checking the corresponding box during account signup or update. This acceptance is recorded immutably (user, date, time, IP, and document version/hash) in LudiSec's compliance traceability system, available to the Client upon request.
16. Governing law
This DPA is governed by Spanish law and the GDPR, and subject to the Courts of Barcelona.
17. Contact
admin.ludisec@gmail.com