Data Processing Agreement
This DPA applies where we process personal data on your behalf, and forms part of the Terms of Service. It takes effect when you accept the Terms — you do not need to sign or return anything. If your procurement process needs a countersigned copy, ask and we will send one.
1. Scope and roles
- This DPA is between you ("Controller") and File Master LLC, Serena app., office C13, Golden Sands, Varna 9007, Bulgaria, VAT 180842207 ("Processor").
- It covers personal data of visitors to your sites, which we receive through the snippet and your gateway and process to produce verdicts.
- It does not cover your own account data — your name, email, team and billing. For that we are a controller in our own right and the Privacy Policy applies.
- You confirm that you are the controller of the visitor data, or that you act with the authority of the controller, and that you have a lawful basis for the processing you instruct.
2. Subject matter of the processing
Set out in Annex 1. In summary: we receive signals about sessions on your sites, score each session, return a verdict, and retain the record for the period in Annex 1 so that you can investigate a disputed decision.
3. Processing on instructions
- We process personal data only on your documented instructions. Your instructions are: this DPA, the Terms, and the configuration of your account — the sites you add, the capture rules you write, the lists you maintain, and the switches you set.
- Changing your configuration changes your instruction. Enabling value-mode field capture on a selector instructs us to receive whatever that field contains. We cannot evaluate a selector for you.
- If we believe an instruction infringes the GDPR or another applicable data protection law, we will tell you and may suspend that processing until it is resolved.
- If we are required by law to process beyond your instructions, we will inform you first unless that law forbids it on important grounds of public interest.
- We do not sell personal data, use it for our own advertising, or use it to build profiles of identified individuals. The one use beyond producing your verdicts is clause 13.
4. Confidentiality
Everyone we authorise to process personal data is bound by confidentiality obligations that survive the end of their engagement, and access is limited to those who need it for a defined purpose.
5. Security measures
We implement the measures in Annex 2, appropriate to the risk under Article 32. We may change them, provided the level of protection is not reduced.
6. Sub-processors
- You give general authorisation to engage sub-processors.
- Those engaged at the effective date are listed in Annex 3.
- We will give at least 30 days' notice by email before adding or replacing one. You may object on reasonable data-protection grounds within that period; if we cannot resolve the objection, you may terminate the affected part of the service and receive a pro-rata refund of the unused prepaid term.
- We impose data-protection obligations on each sub-processor no less protective than this DPA, and remain fully liable to you for their performance.
7. Assisting with data-subject rights
- The panel lets you look up, export and delete records for a given address or session yourself, which will answer most requests without involving us.
- Where it will not, we assist you by appropriate technical and organisational measures, taking into account the nature of the processing.
- If a visitor contacts us directly, we will not act on their request. We will tell them to contact you, and pass the request on if they identify the site.
8. Assisting with security and impact assessments
We assist you, on request and taking into account the information available to us, with your obligations under Articles 32 to 36 — security, breach notification, data protection impact assessments and prior consultation. Annexes 1 and 2 are written to be usable directly in a DPIA.
9. Personal data breaches
- We notify you without undue delay after becoming aware of a personal data breach affecting data processed under this DPA.
- The notification describes the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. Where we cannot provide all of it at once, we provide it in phases without further undue delay.
- Notifying your supervisory authority and the affected individuals is your responsibility as controller. We do not do it on your behalf, and we will not make a public statement identifying you without your agreement unless the law requires it.
10. Return and deletion
- You can export your data from the panel at any time during the subscription.
- On termination we delete personal data processed under this DPA within 30 days, unless law requires us to keep it — billing records, for instance.
- Backups are on a rolling cycle and are overwritten within 90 days. Data in a backup is not restored to production except to recover from an incident.
- Clause 13(4) states the one exception: observations already aggregated into the shared pool. Read it before you decide whether to leave contribution on.
11. Audits and information
- We make available the information needed to demonstrate compliance with Article 28, starting with this DPA and its annexes.
- You may audit no more than once in any 12 months, on 30 days' written notice, at your cost, during business hours, without unreasonable disruption, and subject to confidentiality. A more frequent audit is permitted after a breach affecting your data or where a supervisory authority requires it.
- Where an auditor is a competitor of ours, we may reasonably require a different one.
12. International transfers
- Processing and storage of verdict data take place in the European Union.
- Where a sub-processor in Annex 3 is outside the EEA, the transfer relies on an adequacy decision or on the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Three (processor to sub-processor), which are incorporated here by reference. Annexes 1 to 3 of this DPA populate the corresponding annexes of those Clauses, and the docking clause applies.
- For the United Kingdom, the UK International Data Transfer Addendum applies to those Clauses. For Switzerland, references to the GDPR are read as references to the FADP.
13. The shared reputation pool
This clause describes personal data leaving your tenant. It is the part of Karma most likely to need a decision from your data protection officer, so it is stated plainly.
- Contribution is enabled by default. Observations about network addresses seen on your sites — the address, signal-level facts about its behaviour, and the time — are added to a pool shared across accounts. You may disable contribution at any time in your Karma settings, on any plan including the free one, and detection on your own account does not degrade if you do.
- Reading the pool is a separate switch, off by default, available from the Protect+ plan. The two switches are independent in both directions.
- Contributed: network addresses and signal-level behavioural facts. Never contributed: your URLs or content, which of your pages an address visited, anything captured by field-capture rules, your customers' identities or form contents, and any indication that an observation came from you.
- Aggregation is one-way. Once an observation is merged into the pool it cannot be attributed to you or extracted on your behalf. A deletion request under clause 10 therefore covers your own tenant's records; it cannot unwind the pool's aggregate state. If that is unacceptable for your assessment, disable contribution before you begin — not after.
- For contributions we act as a controller of the pooled dataset, on the basis of legitimate interests in preventing automated abuse across the service (Article 6(1)(f), Recital 49). As the controller of the source data, you need your own basis for the disclosure.
14. Liability and precedence
- The liability limits in the Terms apply to this DPA, save where the GDPR forbids it.
- On the processing of personal data, this DPA prevails over the Terms if they conflict; the Standard Contractual Clauses prevail over this DPA.
- This DPA is governed by the law of Bulgaria, except that the Standard Contractual Clauses are governed by the law they specify.
Annex 1 — Details of processing
| Subject matter | Reputation-based detection of automated traffic on the Controller's websites. |
|---|---|
| Duration | The term of the subscription, plus the deletion period in clause 10. |
| Nature and purpose | Receiving session signals; deriving network, operator and country from the address; scoring the session; producing and storing a verdict with its explanation; making the verdict available to the Controller's gateway. |
| Categories of data subject | Visitors to the Controller's websites — including its customers, prospective customers, and any other person whose browser or tooling reaches those sites. |
| Categories of personal data | Network address, port and protocol version; TLS and HTTP/2 transport fingerprints (JA3/JA3N, settings frame); request headers including user agent, languages and referrer; the requested path; behavioural interaction signals recorded as statistical properties; derived autonomous system, operator and country; timestamps; the verdict and the signals behind it. Where the Controller enables field capture: the presence or value of the form fields it selects. |
| Special-category data | None. The service is not designed for it and the Controller must not instruct its collection — including indirectly, by pointing a capture rule at a field that holds it. |
| Frequency | Continuous for the duration of the subscription. |
| Retention | Raw events, verdicts and captured values: 180 days. Then as clause 10. |
| Data never received | Passwords (never transmitted by the snippet); payment card numbers (Luhn-matching values are replaced with a redaction marker before storage); page content; the Controller's databases or application logs. No cookie or persistent identifier is set in the visitor's browser. |
Annex 2 — Technical and organisational measures
| Area | Measure |
|---|---|
| Encryption in transit | TLS on every path. The snippet refuses to send signals over plain HTTP. |
| Encryption at rest | Full-disk encryption on servers holding personal data; encrypted backups. |
| Tenant isolation | Row-level security in the database, so a query scoped to one account cannot return another's rows even if application code is wrong. |
| Credentials | Argon2id password hashing; API keys stored hashed and displayed once; short-lived access tokens with rotating refresh tokens. |
| Data minimisation | Field capture off by default and per-selector; passwords never transmitted; card-shaped values redacted before storage; behavioural signals stored as statistical properties rather than an interaction replay. |
| Access control | Production access limited to staff who need it, individually attributable, with administrative actions written to an audit log. |
| Availability | Verdicts cached at the gateway so a collector outage degrades to fail-open rather than to an outage of the Controller's site; encrypted backups with tested restores. |
| Resilience | Rate limiting and quota enforcement on ingest; cache eviction bounded to prevent memory exhaustion. |
| Deletion | Automated retention enforcement at 180 days; account deletion within 30 days; backups overwritten within 90. |
| Sub-processor governance | Written terms no less protective than this DPA, with 30 days' notice before any change. |
| Change management | Version control, code review and automated tests before deployment. |
Annex 3 — Approved sub-processors
Sub-processors of visitor data, as at the effective date:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hosting provider (collector, panel, databases) | Infrastructure on which the processing runs | European Union |
No other sub-processor receives visitor data. The payment providers, OAuth providers, analytics and email delivery listed in section 12 of the Privacy Policy handle your account and billing data, not your visitors' — and are therefore outside this annex.
The autonomous-system dataset used to derive network and country is the public iptoasn data (CC0), downloaded to our own infrastructure. No address is sent to a third party to be looked up, so no geolocation service is a sub-processor here.
Contact
File Master LLC · Serena app., office C13, Golden Sands, Varna 9007, Bulgaria · VAT
180842207
Email: tech.support@recoverytoolbox.com
Karma