Last updated: 2026-09-11. Governing law: Israel.
Data Processing Agreement (DPA)
This Data Processing Agreement ("DPA") forms part of the Terms of Service
(/legal/terms) between the customer ("Controller", "you") and Eyal Gabay,
trading as "EyalSec", a sole proprietor (osek murshe) registered in Israel under
no. 211868450, of Yehoshua Stampfer 39, Petah Tikva, Israel ("Processor",
"EyalSec"). It applies where EyalSec processes personal data on the Controller's
behalf in providing the EyalSec / es2 Service (the "Service"). It is intended to satisfy
Article 28 of the EU General Data Protection Regulation (GDPR) and, where applicable, the
UK GDPR.
Terms such as "personal data", "processing", "controller", "processor", "data subject", and "personal data breach" have the meanings given in the GDPR.
1. Subject-matter
The subject-matter of the processing is the provision of the Service: the ingestion, storage, and display of security events ("Events") that the Controller's deployment of an EyalSec agent (es-python, es-chromium, es-c, es-cpp, es-rust, es-node, es-solidity, es-bash or es-php) sends to EyalSec, together with related account operations.
Event Payloads (the fields where, repr, trace, location, origin) can contain
personal data and secrets drawn from the Controller's process memory. Where es-chromium is
deployed, they can additionally contain Browsing Data: the URLs of pages browsed on the
machines the Controller monitors, values present in those pages including values a person
typed, the call site in the page's own code, and an inventory of installed browser
extensions.
2. Duration
Processing continues for the term of the Controller's Subscription and until all personal data is deleted or returned in accordance with Section 10. The obligations here survive for as long as EyalSec processes personal data on the Controller's behalf.
3. Nature and purpose of processing
EyalSec processes personal data only to provide, maintain, secure, and support the Service on the Controller's documented instructions: to receive Events via the agent API, store them, aggregate and de-duplicate them, classify their severity, apply the Controller's filters and suppression rules, and make them available in the dashboard and via the API. EyalSec does not process the personal data for its own purposes, does not use the content of Event Payloads or Browsing Data to develop or train any product, and does not disclose it to any third party except as permitted by this DPA.
4. Types of personal data and categories of data subjects
- Types of personal data: as determined by the Controller's monitoring configuration. Because Event Payloads are drawn from runtime values, they may include identifiers, credentials and secrets (passwords, tokens, keys), contents of variables, file paths, network and origin information, stack traces, and, where es-chromium is deployed, page URLs, in-page values, and browser extension inventories. They may include special categories of personal data under GDPR Article 9 and criminal-offence data under Article 10, depending entirely on what the Controller chooses to monitor and on what passes through the monitored systems.
- Categories of data subjects: as determined by the Controller, for example the Controller's end users, employees, contractors, customers, and other individuals whose data passes through the monitored processes or who use the monitored browsers.
- Frequency: continuous, for as long as an agent is deployed and reporting.
5. Controller instructions and Controller warranties
5.1 Instructions
EyalSec processes personal data only on the Controller's documented instructions, including with regard to transfers, unless required by EU/Member State or other applicable law (in which case EyalSec will inform the Controller of that legal requirement before processing, unless the law prohibits it on important grounds of public interest). The Terms, this DPA, and the Controller's use of the Service's configuration constitute the Controller's complete documented instructions. EyalSec will inform the Controller if, in its opinion, an instruction infringes the GDPR or other applicable data-protection law.
5.2 Controller warranties
The Controller represents, warrants and undertakes, on a continuing basis, that:
(a) it has a valid lawful basis under Article 6, and where applicable a condition under Articles 9 and 10, for every category of personal data it routes through an agent;
(b) it has given every notice and obtained every consent, authorization or permission required by applicable law before monitoring begins, including under data-protection, employment, workplace-monitoring, wiretap, interception and communications-privacy law, and including in jurisdictions requiring the consent of all parties to a communication;
(c) it has completed any works-council, employee-representative or co-determination process, and any data protection impact assessment or prior consultation, required before systematic monitoring, and in particular before deploying es-chromium;
(d) it deploys each agent only on systems, browsers, profiles and accounts it owns or is lawfully authorized to monitor, in accordance with Section 7 of the Terms and Section 2 of the AUP;
(e) it applies data minimization to its monitoring configuration, filters and retention, and does not route personal data through the Service that it does not need for security monitoring; and
(f) its instructions to EyalSec, and the Service as configured by it, comply with applicable data-protection law.
EyalSec is not the controller of this data, does not decide what is monitored, and gives no assessment of whether a given deployment is lawful. The Controller's indemnity in Section 13 of the Terms applies to a breach of this Section 5.2.
6. Processor obligations
EyalSec shall:
(a) Documented instructions: process personal data only as set out in Section 5.1.
(b) Confidentiality: ensure that persons authorized to process the personal data are bound by confidentiality obligations.
(c) Security (Art. 32): implement appropriate technical and organizational measures
appropriate to the risk, as set out in Annex II and at /legal/security, and maintain a
process for regularly testing and assessing their effectiveness.
(d) Sub-processors: as set out in Section 8.
(e) Data-subject requests: taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures, insofar as possible, to respond to requests to exercise data-subject rights under GDPR Chapter III. Where a data subject contacts EyalSec directly about Controller data, EyalSec will refer them to the Controller and will not respond substantively.
(f) Personal data breach (Arts 33-34): notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data, providing the information available to EyalSec, including the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, and the measures taken or proposed. EyalSec will provide further information as it becomes available and will assist the Controller with its own notification obligations. EyalSec will not notify a supervisory authority or data subjects on the Controller's behalf unless instructed.
(g) Assistance with Arts 32-36: assist the Controller in ensuring compliance with security (Art. 32), breach notification (Arts 33-34), data protection impact assessments (Art. 35), and prior consultation (Art. 36), taking into account the nature of processing and the information available to EyalSec.
(h) Deletion or return: at the Controller's choice, delete or return all personal data after the end of the provision of services, and delete existing copies unless applicable law requires storage (Section 10).
(i) Audits and information: make available to the Controller all information necessary to demonstrate compliance with Art. 28, and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, on at least thirty (30) days' prior written notice, during business hours, subject to confidentiality and to EyalSec's security policies, and not more than once per twelve-month period except where required by a supervisory authority or following a personal data breach affecting the Controller. An audit must not compromise the confidentiality, security or availability of another customer's data, and must not require disclosure of EyalSec's proprietary detection logic or source code. EyalSec may satisfy audit obligations by providing the measures at Annex II, responses to a reasonable security questionnaire, and any relevant certifications or third-party reports it holds. The Controller bears its own and EyalSec's reasonable costs of an on-site audit.
7. Government and law-enforcement requests
If EyalSec receives a legally binding request from a public authority for the Controller's personal data, EyalSec will, unless legally prohibited: notify the Controller without undue delay; ask the authority to seek the data from the Controller directly; challenge a request that appears unlawful, overbroad or invalid; and disclose only the minimum required. EyalSec will keep a record of such requests and make it available to the Controller on request, to the extent lawful.
8. Sub-processors
The Controller provides a general authorization for EyalSec to engage sub-processors.
EyalSec's current sub-processors are listed at /legal/subprocessors and reproduced at
Annex III. EyalSec will:
(a) impose data-protection obligations on each sub-processor that are substantially the same as those in this DPA, in particular providing sufficient guarantees under Art. 28(4);
(b) remain fully liable to the Controller for the performance of each sub-processor's obligations; and
(c) give the Controller at least thirty (30) days' prior notice of any intended addition or replacement of a sub-processor, and an opportunity to object on reasonable data-protection grounds. The parties will discuss a reasonable objection in good faith; if it cannot be resolved, the Controller may terminate the affected Service without penalty and receive a pro-rata refund of prepaid fees for the unused period.
To subscribe to sub-processor change notices, contact eyal@eyalsec.com.
9. International transfers and the SCCs
The Service is hosted by EyalSec in the il-central-1 (Israel) AWS region. Israel benefits from an EU adequacy decision, so a transfer of personal data from the EEA to EyalSec in Israel does not, at the date of this DPA, require additional safeguards.
Where and to the extent processing involves a transfer of personal data out of the EEA or the UK to a country without an adequacy decision (including if Israel's adequacy status is suspended, repealed or amended), the parties incorporate by reference the European Commission's Standard Contractual Clauses (Module Two: Controller-to-Processor) adopted under Commission Implementing Decision (EU) 2021/914, and, for UK transfers, the UK International Data Transfer Addendum issued by the ICO. For those clauses:
- the Controller is the data exporter and EyalSec the data importer;
- the optional docking clause (Clause 7) applies;
- for Clause 9, Option 2 (general written authorization) applies, with the notice period in Section 8(c);
- for Clause 11, the optional independent-dispute-resolution body does not apply;
- for Clause 17, the governing law is the law of Ireland; for Clause 18(b), the forum is the courts of Ireland;
- Annexes I, II and III below populate the SCC annexes; and
- the SCCs prevail over conflicting terms of this DPA to the extent of the conflict.
10. Deletion or return
On termination or expiry of the Service, or earlier on the Controller's written request, EyalSec will, at the Controller's election, delete or return the Controller's personal data and delete existing copies, unless retention is required by applicable law. The Controller's self-serve account deletion in Settings cascade-deletes the Controller's machines, Events and filters. A retrieval period applies as set out in Section 17 of the Terms. Backups are purged on EyalSec's standard rotation cycle, so data may persist in encrypted backups for a short period after deletion.
11. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms (including the liability cap and its carve-outs), to the maximum extent permitted by applicable law. Nothing in this DPA limits a data subject's rights under the GDPR or the SCCs, or either party's liability that cannot be excluded by law. The Controller's indemnity at Section 13 of the Terms applies to claims arising from the Controller's breach of Section 5.2 of this DPA.
12. Order of precedence
In case of conflict: the SCCs prevail over this DPA; this DPA prevails over the rest of the Terms with respect to the processing of personal data on the Controller's behalf.
Annex I: Description of the processing
A. List of parties
| | Data exporter | Data importer | |---|---|---| | Name | The Controller (the customer identified in the account and any signed order) | Eyal Gabay, trading as EyalSec, sole proprietor (osek murshe) no. 211868450 | | Address | As held in the account record | Yehoshua Stampfer 39, Petah Tikva, Israel | | Contact | The account's administrative contact | eyal@eyalsec.com | | Activities | Deploys EyalSec agents on its own authorized systems and uses the dashboard | Provides the hosted security-event monitoring and reporting Service | | Role | Controller | Processor |
B. Description of transfer
| Item | Detail | |------|--------| | Categories of data subjects | As determined by the Controller: its end users, employees, contractors, customers, and other individuals whose data passes through the monitored systems or who use the monitored browsers. | | Categories of personal data | As determined by the Controller's monitoring configuration: identifiers, credentials and secrets, contents of variables, file paths, network and origin information, stack traces, and, for es-chromium, page URLs, in-page values including values a person typed, and browser extension inventories. Plus account data: username, email, hashed password, authentication settings, billing records. | | Special-category data | Possible but not intended. The Controller determines whether any is routed through the Service, and is responsible for the additional restrictions and safeguards that apply to it. | | Frequency | Continuous, for as long as an agent is deployed and reporting. | | Nature of processing | Collection via the agent API, transmission, storage, aggregation and de-duplication, severity classification, filtering and suppression, display in the dashboard, export via the API, deletion. | | Purpose | Provision of the security-event monitoring and reporting Service to the Controller. | | Retention | Per the Controller's configuration and Section 7 of the Privacy Policy; deleted or returned per Section 10 of this DPA. | | Sub-processor processing | As set out in Annex III, for the duration of the Service. |
C. Competent supervisory authority
The supervisory authority of the EEA Member State in which the data exporter is established, or, where the exporter is not established in the EEA, the authority of the Member State in which its EU Article 27 representative is established or in which the relevant data subjects are located.
Annex II: Technical and organizational measures
The measures EyalSec applies under GDPR Article 32 and Clause 8.6 of the SCCs are set out in
full at /legal/security, which is incorporated into this DPA as Annex II. In summary:
| Area | Measure |
|------|---------|
| Encryption in transit | TLS for every connection to the dashboard, the API and the agent ingestion endpoint. |
| Encryption at rest | Encryption of the underlying storage holding the database, artifacts and backups; encrypted off-box backups. |
| Pseudonymisation and minimization | Per-customer scoping of all event data; filters and suppression the Controller configures to limit what is captured; deleting a machine or the account deletes its events; an optional service-wide event retention window. |
| Access control | Role-separated dashboard access; per-user capabilities enforced server-side; per-machine agent credentials with no shared master key; revocable credentials; optional two-factor authentication; API keys stored only as hashes; passwords stored with bcrypt. |
| Network control | Optional IP access-control list restricting which addresses may reach the dashboard and API; rate limiting and admission control on ingestion. |
| System hardening | Unprivileged service account, sandboxed service, least-privilege database roles with the runtime role restricted to data operations only, root-owned binaries, no source code or build toolchain on the production host, and verification of the hardening on every deployment. |
| Availability and resilience | Encrypted automated backups on a rotation cycle; health and uptime monitoring; error capture and review. |
| Testing and assurance | Automated security and dependency scanning as a release gate; a coordinated vulnerability disclosure policy at /legal/vulnerability-disclosure. |
| Personnel | Confidentiality obligations for anyone authorized to process personal data; least-privilege administrative access. |
| Sub-processor governance | Contractual data-protection obligations substantially the same as this DPA; published sub-processor list with advance notice of changes. |
Annex III: Sub-processors
The authoritative and current list is at /legal/subprocessors. At the date of this DPA:
| Sub-processor | Purpose | Location | |---------------|---------|----------| | Amazon Web Services (AWS) | Cloud hosting: the compute instance, its encrypted storage, the database and artifacts. All Service data, including account data and Event Payloads, is stored and processed here. | il-central-1 (Israel) | | Amazon SES | Transactional email: password-reset codes, invitations, service notices. Processes recipient email addresses and message content. | eu-central-1 (Germany, EU) | | MaxMind | Optional GeoIP enrichment for self-hosted analytics, used only if the operator enables a GeoIP database. The lookup runs against a database file on EyalSec's own server and sends no data to MaxMind. Not engaged for Event Payloads. | As applicable to the database used |
Signature blocks
Execution is not required for this DPA to apply: it forms part of the Terms of Service and binds both parties on the Controller's acceptance of those Terms. The blocks below are provided for Controllers whose procurement process requires a signed copy.
Controller (Customer)
- Legal name: ______________________________
- Registered address: ______________________________
- Signatory name / title: ______________________________
- Signature: ______________________________
- Date: ______________________________
Processor (EyalSec)
- Legal name: Eyal Gabay, trading as EyalSec
- Status: sole proprietor (osek murshe), registration no. 211868450, Israel
- Registered address: Yehoshua Stampfer 39, Petah Tikva, Israel
- Signatory name / title: ______________________________
- Signature: ______________________________
- Date: ______________________________