Last updated: September 28, 2026
This Data Processing Addendum ("DPA") forms part of the Pistos Terms and Conditions, or any other written agreement between ITG Security LLC dba Pistos Trust Labs ("Pistos") and the Customer governing use of the Services (the "Agreement"). It applies to the extent Pistos processes Customer Personal Data on behalf of Customer while providing the Services.
Customer accepts this DPA by accepting the Agreement. A Customer that needs a countersigned copy may sign below and send it to privacy@pistos.io. If this DPA conflicts with the Agreement, this DPA controls on matters relating to the processing of personal data. If this DPA conflicts with the Standard Contractual Clauses, the Standard Contractual Clauses control.
Capitalized terms not defined in this DPA have the meanings given in the Agreement.
1. Definitions
- "Data Protection Laws" means all data protection and privacy laws that apply to the processing of Customer Personal Data under the Agreement, including, as applicable: the EU General Data Protection Regulation 2016/679 ("GDPR"); the GDPR as incorporated into UK law and the UK Data Protection Act 2018 ("UK GDPR"); the Swiss Federal Act on Data Protection ("FADP"); the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and its regulations ("CCPA"); and other U.S. state comprehensive privacy laws.
- "Customer Personal Data" means any personal data within Customer Data that Pistos processes on behalf of Customer under the Agreement.
- "Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Supervisory Authority" have the meanings given in the GDPR. The terms "Business", "Service Provider", "Sell", and "Share" have the meanings given in the CCPA.
- "Security Incident" means a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data transmitted, stored, or otherwise processed by Pistos or its Subprocessors.
- "Subprocessor" means any third party engaged by Pistos to process Customer Personal Data.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914.
- "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the UK Data Protection Act 2018.
- "Restricted Transfer" means a transfer of Customer Personal Data from the EEA, UK, or Switzerland to a country that has not been recognized as providing an adequate level of protection under the applicable Data Protection Laws.
2. Roles and Scope
2.1 Roles. For Customer Personal Data, Customer is the Controller (or, where Customer acts on behalf of its own Clients or affiliates, a Processor acting for those Controllers), and Pistos is the Processor (or Subprocessor). Where Customer is itself a Processor, Customer warrants that its instructions, including the appointment of Pistos, have been authorized by the relevant Controller.
2.2 Partners. Where Customer is a Partner using the Services on behalf of its Clients, Customer is responsible for entering into appropriate data processing terms with each Client, and for passing on to its Clients any notices Pistos gives under this DPA.
2.3 Details of processing. The subject matter, duration, nature, and purpose of the processing, and the types of Customer Personal Data and categories of Data Subjects, are set out in Annex 1.
2.4 Out of scope. This DPA does not apply to personal data for which Pistos is a Controller, such as account administration, billing, and marketing data. Pistos's Privacy Policy at pistos.io/privacy governs that data.
3. Customer Obligations
Customer will:
(a) comply with Data Protection Laws when using the Services and when giving processing instructions to Pistos;
(b) ensure it has a lawful basis and has given all notices and obtained all consents needed for Pistos to process Customer Personal Data as described in the Agreement, including for personal data of Respondents, Clients, and Trust Center visitors;
(c) not submit special categories of personal data (as defined in Article 9 GDPR), criminal offense data, or other sensitive data to the Services unless Pistos has agreed in writing that the Services support that data; and
(d) be responsible for the accuracy, quality, and legality of Customer Personal Data and for how it was obtained.
4. Pistos Obligations
4.1 Instructions. Pistos will process Customer Personal Data only on Customer's documented instructions, unless Union, Member State, or other applicable law requires otherwise. In that case, Pistos will inform Customer of that legal requirement before processing, unless the law prohibits doing so. The Agreement, this DPA, and Customer's configuration and use of the Services are Customer's complete instructions. Additional instructions require the parties' written agreement. Pistos will tell Customer promptly if it believes an instruction infringes Data Protection Laws.
4.2 Confidentiality of personnel. Pistos will ensure that people authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and receive training appropriate to their role.
4.3 Security. Pistos will implement and maintain the technical and organizational measures described in Annex 2. These measures are designed to ensure a level of security appropriate to the risk, as required by Article 32 GDPR. Pistos may update these measures over time, provided the updates do not materially reduce the overall level of protection.
4.4 Assistance. Taking into account the nature of the processing and the information available to Pistos, Pistos will provide reasonable assistance to Customer with:
- responding to Data Subject requests (Section 7);
- Customer's obligations regarding security, Security Incident notification, data protection impact assessments, and prior consultation with Supervisory Authorities under Articles 32 to 36 GDPR.
Pistos may charge reasonable fees for assistance that goes beyond the standard functionality of the Services, except where the assistance is needed because of Pistos's breach of this DPA.
5. Subprocessors
5.1 General authorization. Customer gives Pistos general authorization to engage Subprocessors. The current list of Subprocessors is set out in Annex 3 and at pistos.io/dpa#annex-3-subprocessors.
5.2 Subprocessor obligations. Pistos will enter into a written agreement with each Subprocessor that imposes data protection obligations no less protective than those in this DPA, as far as they apply to the services the Subprocessor provides. Pistos remains liable to Customer for each Subprocessor's performance of its obligations.
5.3 Changes. Pistos will notify Customer of any new or replacement Subprocessor at least 30 days before allowing it to process Customer Personal Data. Pistos will do this by updating the Subprocessor list and emailing Customers who have subscribed to updates at email to privacy@pistos.io.
5.4 Objections. Customer may object to a new Subprocessor on reasonable data protection grounds by giving written notice within the notice period. The parties will discuss the objection in good faith. If Pistos cannot reasonably accommodate the objection, for example by offering a change to the configuration or use of the Services, Customer may terminate the affected Services by written notice. Customer will then receive a refund of any prepaid fees for the rest of the subscription term after termination takes effect.
5.5 Emergency replacement. Pistos may replace a Subprocessor without advance notice where the replacement is urgently needed for security or business continuity reasons. In that case, Pistos will notify Customer promptly afterwards, and Section 5.4 applies.
6. Security Incidents
6.1 Notification. Pistos will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident. Notice will be sent to the Customer's designated security or administrative contact.
6.2 Content. To the extent the information is available, the notice will describe: the nature of the Security Incident; the categories and approximate number of Data Subjects and records concerned; the likely consequences; and the measures taken or proposed to address the Security Incident and reduce its effects. Where Pistos cannot provide all of this information at once, it may provide it in phases.
6.3 Response. Pistos will take reasonable steps to contain, investigate, and remediate the Security Incident, and will reasonably cooperate with Customer so Customer can meet its own notification obligations.
6.4 No admission. Pistos's notification of or response to a Security Incident is not an acknowledgement of fault or liability.
6.5 Exclusions. Unsuccessful attempts or activities that do not compromise the security of Customer Personal Data are not Security Incidents. These include pings, port scans, denial-of-service attacks, and failed log-in attempts.
7. Data Subject Requests
7.1 Tools. The Services include features that Customer can use to access, correct, export, and delete Customer Personal Data.
7.2 Requests received by Pistos. If Pistos receives a request from a Data Subject relating to Customer Personal Data, it will direct the Data Subject to Customer where the Customer can be identified, and will not respond to the request directly unless Customer authorizes it or the law requires it. Where Customer cannot fulfil a request using the Services, Pistos will provide reasonable assistance under Section 4.4.
8. International Transfers
8.1 Locations. Customer Personal Data is hosted in the United States of America. Pistos and its Subprocessors may process Customer Personal Data in the countries listed in Annex 3, subject to this Section 8.
8.2 EEA transfers. For Restricted Transfers from the EEA, the SCCs are incorporated into this DPA by reference and apply as follows:
- Module Two (Controller to Processor) applies where Customer is a Controller, and Module Three (Processor to Processor) applies where Customer is a Processor;
- in Clause 7, the optional docking clause applies;
- in Clause 9, Option 2 (general written authorization) applies, with the notice period set out in Section 5.3;
- in Clause 11, the optional language does not apply;
- in Clause 17, Option 1 applies, and the SCCs are governed by the law of Ireland;
- in Clause 18(b), disputes will be resolved before the courts of Ireland;
- Annex I of the SCCs is completed with the information in Annex 1 of this DPA; and
- Annex II of the SCCs is completed with the information in Annex 2 of this DPA.
8.3 UK transfers. For Restricted Transfers from the UK, the SCCs apply as varied by the UK Addendum. Tables 1 to 3 of the UK Addendum are completed with the information in Section 8.2 and Annexes 1 to 3 of this DPA. In Table 4, either party may end the UK Addendum as set out in its Section 19.
8.4 Swiss transfers. For Restricted Transfers from Switzerland, the SCCs apply with these changes: references to the GDPR are read as references to the FADP; the Swiss Federal Data Protection and Information Commissioner is the competent Supervisory Authority; and "Member State" is read to include Switzerland, so that Data Subjects in Switzerland can bring claims in their place of habitual residence.
8.5 Adequacy frameworks. If Pistos is certified under the EU-U.S. Data Privacy Framework, the UK Extension, or the Swiss-U.S. Data Privacy Framework, Pistos may rely on that certification for Restricted Transfers to Pistos while it remains valid. The SCCs will apply if the certification lapses or is invalidated.
8.6 Government access. If Pistos receives a legally binding request from a public authority for access to Customer Personal Data, Pistos will:
- notify Customer promptly, unless the law prohibits it;
- challenge the request where it has reasonable grounds to consider it unlawful; and
- disclose only the minimum information required.
9. U.S. State Privacy Laws
To the extent the CCPA or similar U.S. state laws apply, Pistos is a Service Provider (or Processor) to Customer, and Pistos will not:
(a) Sell or Share Customer Personal Data;
(b) retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in the Agreement, including for any commercial purpose other than providing the Services;
(c) retain, use, or disclose Customer Personal Data outside the direct business relationship between Pistos and Customer; or
(d) combine Customer Personal Data with personal data Pistos receives from or on behalf of others, or collects from its own interactions with consumers, except as permitted by the CCPA.
Pistos will comply with applicable obligations under the CCPA and give the same level of privacy protection the CCPA requires. Pistos will notify Customer if it determines it can no longer meet these obligations. Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data. Pistos certifies that it understands and will comply with the restrictions in this Section 9.
10. Audits
10.1 Information. When Customer asks in writing, and no more than once in any 12-month period, Pistos will make available the information reasonably necessary to demonstrate its compliance with this DPA. This may include completed security questionnaires and, where available, summaries of third-party audit reports or certifications. This information is Pistos's Confidential Information.
10.2 On-site audits. If the information under Section 10.1 is not enough to demonstrate compliance, or if a Supervisory Authority requires it, Customer may perform an audit (on-site or remote) of Pistos's processing of Customer Personal Data, subject to all of the following:
- Customer must give at least 30 days' written notice;
- the audit must take place during normal business hours, no more than once per 12-month period (unless a Security Incident or Supervisory Authority requires otherwise);
- the scope, timing, and duration must be agreed in advance;
- the auditor must be independent, must not be a Pistos competitor, and must be bound by confidentiality obligations; and
- the audit must not unreasonably disrupt Pistos's operations or compromise the security or confidentiality of other customers' data.
Customer bears the costs of any audit, including Pistos's reasonable costs, unless the audit reveals a material breach of this DPA by Pistos.
10.3 SCC audits. The parties agree that audits under Clause 8.9 of the SCCs will be carried out in accordance with this Section 10.
11. Return and Deletion
On termination or expiration of the Agreement, Customer may export Customer Personal Data using the Services for 30 days, as described in Section 5.6 of the Terms. Afterwards, Pistos will delete Customer Personal Data from its production systems. Backup copies will be deleted within 90 days in the ordinary course. Pistos may retain Customer Personal Data where required by law. Retained data remains subject to this DPA and Pistos will process it only for the purposes the law requires. On request, Pistos will certify deletion in writing.
12. Liability
Each party's liability arising out of or related to this DPA, whether in contract, tort, or otherwise, is subject to the exclusions and limitations of liability in the Agreement. Nothing in this DPA limits either party's liability to Data Subjects under the SCCs where such limitation is not permitted.
13. General
13.1 Term. This DPA remains in effect for as long as Pistos processes Customer Personal Data.
13.2 Changes. Pistos may update this DPA to reflect changes in Data Protection Laws, guidance from Supervisory Authorities, or the Services, provided that the updates do not materially reduce the protections given to Customer Personal Data. Pistos will notify Customers of material changes in line with Section 21.1 of the Terms.
13.3 Governing law. This DPA is governed by the law that governs the Agreement, except where the SCCs or Data Protection Laws require otherwise.
Annex 1 — Details of Processing
A. List of parties
Data exporter: Customer, as identified in the Agreement or Order.
- Contact: the Customer account owner or the contact designated in the Services.
- Activities relevant to the transfer: use of the Services as described in the Agreement.
- Role: Controller (or Processor on behalf of its Clients or affiliates).
Data importer: ITG Security LLC, 30 N Gould St Ste R, Sheridan, WY 82801 USA.
- Contact: privacy@pistos.io
- Activities relevant to the transfer: providing the Services as described in the Agreement.
- Role: Processor (or Subprocessor).
B. Description of processing
| Item | Details |
|---|---|
| Categories of Data Subjects | Customer's employees, contractors, and Authorized Users. Contact persons at Customer's vendors, suppliers, and other third parties (Respondents). Personnel of Customer's Clients (where Customer is a Partner). Visitors to Customer's Trust Center who request access or accept NDAs. Any other individuals whose personal data Customer or its Respondents submit to the Services. |
| Categories of personal data | Contact and identification data (name, work email, phone number, job title, company). Account and authentication data (user IDs, SSO identifiers, roles, permissions). Questionnaire responses, comments, and uploaded evidence that may contain personal data. Trust Center access and NDA request records. Usage, audit, and log data (IP address, device and browser information, activity records). |
| Sensitive data | None intended. Customer will not submit special categories of data except as permitted by Section 3(c). |
| Frequency of transfer | Continuous, for the duration of the Agreement. |
| Nature of processing | Collection, storage, organization, structuring, retrieval, analysis (including automated risk scoring based on rules configured by Customer), display, transmission, export, and deletion. |
| Purpose of processing | To provide, secure, maintain, and support the Services under the Agreement, including vendor risk assessments, risk scoring, control framework mapping, business impact analysis, Trust Center hosting, and customer support. |
| Duration and retention | For the term of the Agreement, plus the return and deletion period in Section 11. |
| Subprocessor transfers | As set out in Annex 3, for the same subject matter, nature, and duration as above. |
C. Competent Supervisory Authority
The Supervisory Authority of the EU Member State in which Customer is established. If Customer is not established in the EU, the Supervisory Authority of the Member State where Customer's EU representative is established. If Customer has no EU representative, the Supervisory Authority of Ireland. For UK transfers, this is the UK Information Commissioner's Office. For Swiss transfers, this is the Swiss Federal Data Protection and Information Commissioner.
Annex 2 — Technical and Organizational Security Measures
- Encryption. Customer Data is encrypted in transit using TLS 1.2 or higher, and at rest using AES-256 or equivalent.
- Access control. Role-based access controls within the Services. Least-privilege access for Pistos personnel. Multi-factor authentication for access to production systems. Access is reviewed at least quarterly and promptly revoked when no longer needed.
- Authentication. Support for SSO/SAML for Customers on eligible plans. Secure password hashing. Session timeouts.
- Tenant isolation. Logical separation of each Customer's data, and of each Client's data within Partner Accounts.
- Logging and monitoring. Logging of access to and changes in production systems. Security monitoring and alerting. Audit logs available to Customers on eligible plans.
- Infrastructure security. Hosting with reputable cloud providers that hold recognized security certifications. Network segmentation and firewalls. Regular patching.
- Secure development. Code review, separate development and production environments, dependency and vulnerability scanning, and periodic penetration testing by internal teams / independent third parties.
- Availability and resilience. Regular backups, stored encrypted and separately from production. Documented disaster recovery procedures, tested at least annually.
- Incident response. A documented incident response plan with defined roles, escalation, and Customer notification procedures.
- Personnel. Background checks where permitted by law. Confidentiality agreements. Security and privacy training at onboarding and at least annually.
- Vendor management. Security and privacy due diligence on Subprocessors before engagement and periodically afterwards.
- Data minimization and deletion. Processing limited to what is needed to provide the Services. Deletion in line with Section 11.
- Governance. A designated person responsible for security and privacy. Security policies reviewed at least annually.
Annex 3 — Subprocessors
| Subprocessor | Purpose | Location of processing |
|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting and storage | United States |
| Sender | Sending system emails and assessment invitations | United States |
| Service Now | Support ticketing | United states |