Skip to content
Cyber Horizon
Back to Legal

Data Processing Agreement

Cyber Horizon Intelligence Ltd · Registered in England & Wales, company no. 17327222 · Registered office: 124 City Road, London EC1V 2NX

Version 1.5 · Effective 6 September 2026 · Classification: Public

This Data Processing Agreement (“DPA”) forms part of the agreement between:

Processor: Cyber Horizon Intelligence Ltd, registered in England & Wales (company no. 17327222), registered office 124 City Road, London EC1V 2NX (“Cyber Horizon”); and Controller: the Customer,

and applies where Cyber Horizon processes personal data on behalf of the Customer in connection with the Service. Capitalised terms not defined in this DPA have the meaning given in the Master Services Agreement. “Data Protection Law” means the UK GDPR and the Data Protection Act 2018 and, where the Customer is established in the EEA, the EU GDPR; references to Articles of the UK GDPR include the corresponding Articles of the EU GDPR, and references to the ICO include the Customer’s competent supervisory authority. Transfers by an EEA-established Customer to Cyber Horizon in the United Kingdom are made under the European Commission’s adequacy decision for the United Kingdom.

1. Subject matter & duration

Cyber Horizon processes personal data on behalf of the Customer solely to provide the CHI platform services described in the Order Form. Processing continues for the Subscription Term and for the post-termination export, deletion and backup-cycling periods set out in clause 14.

2. Nature & purpose

Storing, organising, structuring and retrieving data submitted by the Customer in connection with GRC workflows, risk assessments, compliance evidence, incident management and vendor-risk activities.

3. Types of personal data

Employee names and work email addresses, security incident details, vendor contact information, audit evidence metadata and access-review records. The Service is not designed around special-category data (Article 9 UK GDPR), and the Customer must not submit it except where the Customer has identified the categories concerned in the Order Form or in Annex 1 and holds a valid Article 9 condition for doing so. Where the Customer has made that declaration, Cyber Horizon applies the additional technical and organisational measures set out in Annex 2 to the data concerned, in addition to the measures that apply to all personal data. The Customer must not submit Article 9 data through any feature Cyber Horizon has designated in the Documentation as unsuitable for it.

4. Data subjects

Customer employees, contractors and third-party vendors whose data the Customer enters as controller.

5. Processing on instructions

Cyber Horizon processes personal data only on the Customer’s documented instructions, including for international transfers, unless required by law — in which case it will inform the Customer before processing unless legally prohibited. Cyber Horizon will immediately inform the Customer if, in its opinion, an instruction infringes the UK GDPR, the Data Protection Act 2018 or other applicable data protection law, and may suspend performance of that instruction until the Customer confirms or withdraws it.

6. Confidentiality of personnel

Personnel authorised to process personal data are bound by confidentiality and access it on a least-privilege, need-to-know basis.

7. Security measures

Cyber Horizon implements appropriate technical and organisational measures (Annex 2), including TLS 1.3 in transit, AES-256 at rest, structurally enforced tenant isolation, multi-factor authentication available to all users and enforceable by the Customer through SSO or authentication settings, full audit logging and a documented incident-response process. Where the Customer has declared Article 9 data under Annex 1, the additional measures set out in Annex 2 apply to it.

8. Sub-processors

Cyber Horizon may engage sub-processors (Annex 3). It maintains a current list and gives at least 30 days’ notice of any new or replacement sub-processor by email to the Customer’s notified contact and by updating that list; the Customer may object on reasonable data-protection grounds within that period and, if the objection is unresolved, terminate the affected service. Cyber Horizon imposes on each sub-processor the same data protection obligations as are set out in this DPA, and remains fully liable to the Customer for the performance of each sub-processor’s obligations.

9. Assistance to the Customer

Taking into account the nature of processing, Cyber Horizon assists the Customer with data-subject requests and with obligations around security, breach notification, DPIAs and prior consultation with the ICO.

10. Data-subject rights

Cyber Horizon assists the Customer in fulfilling data-subject requests (access, rectification, erasure, portability). In-product export and erasure are available; Cyber Horizon responds to controller assistance requests within 5 business days.

11. Personal-data breach

Cyber Horizon notifies the Customer without undue delay and in any event within 24 hours of becoming aware of a personal-data breach, with the information required to meet the Customer’s obligations. This is the processor commitment under Article 28(3)(f) and Article 33(2); the Customer’s own 72 hours deadline to the ICO under UK GDPR Art. 33(1) runs separately.

12. Audit & compliance

Cyber Horizon makes available the information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates. Such audits are conducted: not more than once in any twelve-month period, except following a personal-data breach affecting the Customer or where a supervisory authority requires it; on at least 30 days’ written notice; during UK business hours; by an auditor bound by confidentiality who is not a competitor of Cyber Horizon; and limited in scope to Cyber Horizon’s processing of the Customer’s personal data, with no access to any other customer’s data or to shared infrastructure that cannot be segregated. Each party bears its own costs, save that Cyber Horizon’s reasonable costs are recoverable for any audit beyond the annual one. Where Cyber Horizon’s certifications, independent penetration test reports or completed security questionnaires reasonably address the Customer’s request, provision of those satisfies this clause. The limits in this clause on frequency, notice and scope do not apply to an audit, inspection or request carried out by, or at the direction of, a supervisory authority or other competent or resolution authority to which the Customer is subject, where that authority is entitled by law to require it; Cyber Horizon will cooperate fully with any such authority.

13. International transfers

Customer Data is stored in the European Union by default (Supabase, eu-west-1). Per-organisation regional residency in the United States, the United Kingdom and APAC is available on request; a dedicated regional project is provisioned before data is loaded. No managed region is currently available in the Middle East. Sub-processors, the services they provide and the regions in which they process Customer Data are listed in Annex 3. Restricted transfers outside the UK or EEA are made under an adequacy decision or appropriate safeguards (such as the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses). The instrument in force for each sub-processor is recorded in the transfer register and available on request.

14. Deletion on termination

Upon termination, Customer data is retained for 30 days so it can be exported. At the end of that export window Cyber Horizon will, at the Customer’s choice, delete or return all personal data and delete existing copies, within 30 days after the end of that export window. Where no election has been made by the end of the export window, Cyber Horizon will delete the personal data. Deletion or return from production systems is completed within the same period — database records and uploaded files alike. Residual copies remain in encrypted backups until those backups age out on their retention schedule, currently up to 90 days. Identity records held by our authentication sub-processor and billing records held by our payment sub-processor are not erased automatically: they are retained so that the subscription and its invoices are not orphaned, and to meet statutory accounting-record retention requirements. We delete them on written request to privacy@cyberhorizon.co, except where we are legally required to keep them.

15. Liability & governing law

This DPA is governed by the laws of England & Wales and is subject to the liability provisions of the principal agreement between the parties. The courts of England & Wales have exclusive jurisdiction.

Annex 1 — Details of processing

Subject matter, duration, nature/purpose, data types and data subjects: as set out in clauses 1–4 above.

Special-category data declared by the Customer (Article 9 UK GDPR) is completed in the executed Order Form or in the countersigned copy of this Annex: the categories declared, the Article 9 condition relied on by the Customer, and the features in which it will be submitted. Where that is left blank or marked “None”, the Customer confirms it will not submit Article 9 data and clause 3 applies.

Annex 2 — Technical & organisational measures

  • TLS 1.3 in transit (HSTS); AES-256 at rest; AES-256-GCM for integration credentials.
  • Tenant isolation enforced structurally: the organisation is resolved from the verified session, a tenant guard scopes every organisation-scoped query and stamps writes, and at the database layer row-level security is enabled on every table with no grants to the anonymous or authenticated roles — so there is no path to the data that bypasses the guard. Automated isolation tests run on every deploy.
  • Multi-factor authentication is available to all users and can be enforced by the Customer through its own identity provider or Cyber Horizon’s authentication settings; Cyber Horizon does not mandate MFA for Customer users. Single sign-on (SAML 2.0 / OIDC) is available on the Scale and Enterprise tiers. Multi-factor authentication is required for, and enforced on, Cyber Horizon’s own platform-administrator accounts. Least-privilege role-based access; platform administration is separately gated with break-glass alerting.
  • Append-only audit logging; continuous monitoring (Sentry); documented incident response.
  • Secure SDLC with CI, automated tests (incl. tenant-isolation), dependency scanning; OWASP Top 10 reviews.
  • Data minimisation (evidence stored as links); automated retention and deletion.

Additional measures for special-category data. Where the Customer has identified Article 9 data in the Order Form or in Annex 1, Cyber Horizon applies the following measures to it in addition to those above: (a) the records concerned are marked as special category on ingestion and that marking is carried in the audit log; (b) access is restricted to the Customer’s own users holding an elevated role, and Cyber Horizon platform administration cannot read the record content without an access grant recorded in the platform administration audit; (c) the data is excluded from AI processing by default, so no special-category record is sent to a third-party model unless the Customer enables it for that record type in writing; (d) the data is excluded from error telemetry and from support diagnostics; and (e) on erasure the record is deleted rather than anonymised, and the deletion is confirmed to the Customer on request.

Annex 3 — Sub-processors

Sub-processorPurposeRegionTransfer mechanism
SupabaseManaged Postgres, primary data storeEuropean UnionUK adequacy (EEA) + DPA
VercelApplication hosting, compute, CDNUnited States / global edgeEU SCCs with UK Addendum (or IDTA) + DPA
ClerkAuthentication and identityUnited StatesEU SCCs with UK Addendum (or IDTA) + DPA
AnthropicAI processing for assistant and analysisUnited StatesEU SCCs with UK Addendum (or IDTA) · no training on API data
ResendTransactional emailUnited StatesEU SCCs with UK Addendum (or IDTA) + DPA
StripeBilling and paymentsUnited States / globalEU SCCs with UK Addendum (or IDTA) + DPA
SentryError monitoringUnited States / EUEU SCCs with UK Addendum (or IDTA) + DPA
CloudflareBot detection; encrypted off-site backupsUnited States / global edgeEU SCCs with UK Addendum (or IDTA) + DPA · encrypted to a key Cloudflare does not hold
UpstashRate limiting and abuse prevention, keyed on user ID or client IPUnited States / EUEU SCCs with UK Addendum (or IDTA) + DPA
CloudmersiveMalware scanning of uploaded filesUnited StatesEU SCCs with UK Addendum (or IDTA) + DPA · file bytes scanned in transit

The current list is also published at /legal/subprocessors. Changes are notified under clause 8.

Change history

v1.5 — 6 September 2026. Annex 2, first bullet, split into two sentences. It previously read that “SSO/SAML and multi-factor authentication are available to all users”, which was accurate for MFA and not for single sign-on: SSO/SAML is available on the Scale and Enterprise tiers. MFA remains available to every user on every plan and enforceable by the Customer. No other clause changed, and clause 7 is unaltered — its wording (“enforceable by the Customer through SSO or authentication settings”) is a disjunction and remains true at any SSO tiering.

v1.4 — 3 September 2026. Article 9 declaration route and the additional Annex 2 measures; sub-processor notice period set at 30 days; data-subject assistance within 5 business days; audit rights bounded with a supervisory-authority carve-out; transfer register; Annex 3 gains the transfer-mechanism column.

Previous versions

Agreements are version-stamped at signature. If your Order Form names an earlier version, that version governs and remains published: DPA v1.4 · DPA v1.1.

Version
1.5
Effective
6 September 2026
Last reviewed
6 September 2026
Next review
6 September 2027
Classification
Public
Incorporated into the Master Services Agreement by reference.