1 Min. Lesezeit
Dieser Inhalt ist derzeit nur auf Englisch verfügbar.
Our role
During penetration testing, monitoring and incident response we may access data in our customers’ systems. In that case the customer is the data controller and Logflare is the processor, handling data only on the customer’s instructions.
Principles
- Data is processed only for the purpose and scope defined in the contract.
- Only the minimum data needed to demonstrate a finding is kept as evidence; personal data is masked where possible.
- Data is stored in encrypted environments and accessed only by the assigned team.
- Using a sub-processor requires the customer’s prior written approval.
- Any data breach is reported to the customer without undue delay.
- At the end of the contract data is returned or securely destroyed.
Details are set out in the data processing agreement (DPA) signed with each customer. For a sample DPA contact [email protected].