Data Processing Addendum

Last updated: July 18, 2026

This Data Processing Addendum ("DPA") is incorporated into and forms part of the Soviron Terms of Service between Soviron LLC ("Soviron") and the Customer. It applies where Soviron processes personal data on the Customer's behalf. No signature is required; it takes effect when the Customer accepts the Terms or uses the Service to process such data. For a signed copy, contact legal@soviron.com.

Contents

  1. Definitions and roles
  2. Scope and instructions
  3. Confidentiality
  4. Security measures
  5. Subprocessors
  6. Incident notification
  7. Assistance with requests
  8. Deletion
  9. Audit and compliance information
  10. Customer responsibilities
  11. US state privacy terms
  12. International transfers
  13. General

1. Definitions and roles

Terms such as "controller," "processor," "personal data," and "processing" have the meanings given under applicable data protection law. For personal data contained in a Connected Environment and the Monitoring Data derived from it (together, "Customer Personal Data"), the Customer is the controller, or a processor acting on behalf of an End Client, and Soviron acts as the Customer's processor or subprocessor, as applicable. For Soviron's own account administration, billing, security, and legal compliance, Soviron acts as an independent controller under its Privacy Policy, and that processing is outside this DPA. Capitalized terms not defined here have the meaning given in the Terms.

2. Scope and instructions

Soviron processes Customer Personal Data only to provide the Service and on the Customer's documented instructions, which include the Terms, this DPA, the Customer's configuration of the Service, and the read-only monitoring the Customer enables. The subject matter is security posture monitoring; the duration is the term of the Terms plus the retention periods in the Privacy Policy; the nature and purpose is read-only detection, alerting, and reporting; the types of data may include user display names, user principal names / email addresses, license and MFA status, and administrator-role membership within a connected Microsoft 365 tenant; and the categories of data subjects are the Customer's and its End Clients' users. Soviron will tell the Customer if it believes an instruction violates applicable law.

3. Confidentiality

Soviron keeps Customer Personal Data confidential and ensures that personnel authorized to process it are bound by confidentiality obligations and access it only as needed to provide the Service.

4. Security measures

Soviron maintains technical and organizational measures appropriate to the risk, including: strictly read-only, least-privilege access to monitored Microsoft 365 environments, limited to the permissions required for the enabled checks; authentication credentials and access tokens protected using access controls and secure server-side storage appropriate to their type, with measures to keep them out of application logs; passwords stored only as salted hashes; encryption in transit (TLS); encrypted off-site backups; access controls and account isolation; and monitoring of service and backup liveness. These measures may be updated as the Service evolves, provided protection is not materially reduced.

5. Subprocessors

The Customer authorizes Soviron to engage the subprocessors listed at the Subprocessor List to process Customer Personal Data. Soviron will enter into data protection terms with its subprocessors as required by applicable law, and will remain responsible for subprocessor processing to the extent required under applicable law. Soviron will post material additions or replacements of subprocessors to the Subprocessor List; a Customer who reasonably objects to a new subprocessor on data protection grounds may notify legal@soviron.com, and if the objection cannot be resolved, may terminate the affected integration or, where that is not feasible, the subscription.

6. Incident notification

Soviron will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to help the Customer meet its own notification obligations. Notice is not an acknowledgment of fault.

7. Assistance with requests

Taking into account the nature of the processing, Soviron will provide reasonable assistance to help the Customer respond to requests from data subjects to exercise their rights, and to meet the Customer's obligations regarding security, breach notification, and, where applicable, data protection impact assessments. Because Soviron acts on the Customer's instructions, requests received directly by Soviron from a data subject will be referred to the Customer.

8. Deletion

On termination, and on Customer request, Soviron will delete or de-identify Customer Personal Data in accordance with the retention approach in the Privacy Policy, within a reasonable period and subject to technical, security, and legal retention requirements; residual copies age out of the normal backup rotation. Disconnecting a monitored environment stops further collection and active monitoring of that environment; previously collected data remains subject to the retention approach in the Privacy Policy. The Service does not currently provide a data-export function; while the account is active, the Customer can access and generate reports through the Service's standard features.

9. Audit and compliance information

Soviron will make available information reasonably necessary to demonstrate compliance with this DPA, and will respond to reasonable written questions from the Customer about its processing and security, no more than once per year absent a specific regulatory or breach reason. Given Soviron's size and single-operator structure, this is satisfied through written information rather than on-site audits, unless applicable law requires otherwise.

10. Customer responsibilities

The Customer is responsible for the lawfulness of the personal data it causes the Service to process, including having a lawful basis and any authority or consents needed to connect an environment (including an End Client's), and for its own configuration and use of the Service.

11. US state privacy terms

To the extent the CCPA/CPRA or similar US state laws apply, Soviron acts as a "service provider" or "processor." Soviron will not sell or share Customer Personal Data, will not retain, use, or disclose it except to provide the Service or as permitted by law, will not combine it with data from other sources except as permitted, and will not process it outside the direct business relationship. Soviron certifies that it understands and will comply with these restrictions.

The specific business purposes are the read-only security posture monitoring, detection, alerting, reporting, support, security, and abuse-prevention activities described in this DPA. Soviron will provide the level of privacy protection required by applicable law, notify the Customer if Soviron determines it can no longer meet these obligations, and permit the Customer, on reasonable notice, to take reasonable and appropriate steps to verify compliance and to stop and remediate any unauthorized use of Customer Personal Data. Soviron will assist the Customer with applicable consumer requests as described in Section 7.

12. International transfers

The Service is intended for US business customers and is hosted in the United States. Soviron does not offer transfer mechanisms such as the EU Standard Contractual Clauses at this time. Customers subject to the EU or UK GDPR should not use the Service to process personal data of individuals in the EEA or UK without a separate written arrangement with Soviron addressing those requirements.

13. General

If any conflict exists between this DPA and the Terms or Privacy Policy regarding the processing of Customer Personal Data, this DPA controls for that processing. All other terms of the Terms remain in effect. Questions: legal@soviron.com.