Data Processing Addendum
Last updated: September 26, 2026
Operator: Syed Umar Ali Qadri, 2446 N MacArthur Blvd.
Contact: [email protected]
This Data Processing Addendum ("DPA") forms part of the Terms of Service between TestersWiz and a customer that uses the App Security Check, the Database Security Audit or the security track for a business ("Customer"). It applies automatically when such a Customer submits Customer Personal Data. If you need a signed copy, email [email protected].
1. Definitions and scope
"Data Protection Law" means the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and any other law on the processing of personal data that applies to the processing under this DPA. "Customer Personal Data" means personal data contained in a submission the Customer makes to the security tools — an application package, pasted database configuration or a dependency list — and in the findings and reports produced from it. Terms such as controller, processor, processing, data subject and personal data breach have the meanings given in the GDPR.
The Customer is the controller (or a processor acting for its own controller) and TestersWiz is the Customer's processor (or sub-processor) for Customer Personal Data. For all other personal data, including the Customer's account and billing data, TestersWiz is a controller and the Privacy Policy applies. If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA prevails.
2. The Customer's obligations
The Customer is responsible for having a lawful basis for the submission and for the accuracy of its instructions. The Terms and the Acceptable Use Policy require the Customer not to submit credentials or rows of its customers' data; Customer Personal Data should therefore be limited to what is incidentally contained in an application or configuration (for example test accounts, contact details or identifiers built into an app). The Customer must not submit special categories of personal data or data relating to criminal convictions.
3. TestersWiz's obligations
- Instructions. Process Customer Personal Data only on the Customer's documented instructions, which are this DPA, the Terms and the Customer's use of the tools, including to other countries only as section 5 allows, unless the law requires otherwise (in which case TestersWiz will tell the Customer first unless the law forbids it). TestersWiz will tell the Customer if it believes an instruction infringes Data Protection Law.
- Confidentiality. Ensure that anyone authorised to process Customer Personal Data is bound by confidentiality, and give administrators access only to provide support, investigate abuse or a failed scan, or comply with law.
- Security. Implement the technical and organisational measures in Annex 2, appropriate to the risk (GDPR Article 32).
- Sub-processors. The Customer gives general authorisation to the sub-processors listed in section 6 of the Privacy Policy. TestersWiz will give at least 30 days' notice of an intended addition or replacement by updating that list and emailing the Customer's account address. The Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve it, the Customer may stop using the affected tool and TestersWiz will refund unused paid credits. TestersWiz imposes data protection obligations on each sub-processor no less protective than this DPA and remains responsible for them.
- Data subject requests. Taking into account the nature of the processing, help the Customer respond to requests from data subjects, and pass on any such request received directly.
- Assistance. Help the Customer, as reasonably needed and with the information available to TestersWiz, with security, breach notification, data protection impact assessments and prior consultation (GDPR Articles 32 to 36).
- Personal data breaches. Notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with the information the Customer needs to meet its own obligations, as it becomes available.
- Deletion. Delete Customer Personal Data on the schedule in Annex 1, when the Customer deletes a scan or audit, or when the Customer's account is deleted, unless the law requires it to be kept. Reports can be exported before deletion.
- Information and audits. Make available the information needed to demonstrate compliance with this DPA, and allow audits by the Customer or its independent auditor on reasonable notice, no more than once a year unless a supervisory authority requires otherwise or following a breach, at the Customer's cost and under confidentiality.
4. International transfers
TestersWiz is based in the United States. To the extent processing involves a transfer of Customer Personal Data from the EEA to a country without an adequacy decision, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 ("SCCs"), Module Two (controller to processor) or Module Three (processor to processor) as applicable, are incorporated into this DPA, with the Customer as data exporter and TestersWiz as data importer. For the SCCs: Clause 7 does not apply; under Clause 9 option 2 (general authorisation) applies with the notice period in section 3; the optional wording in Clause 11 does not apply; Clauses 17 and 18 select the law and courts of Ireland; Annex I is Annex 1 below and Annex II is Annex 2 below. For transfers from the UK, the International Data Transfer Addendum issued by the UK Information Commissioner applies, completed with the same information. For transfers from Switzerland, the SCCs apply with the Swiss Federal Data Protection and Information Commissioner as the competent authority and references to Member States read as including Switzerland.
5. Liability and term
Each party's liability under this DPA is subject to the limitations in the Terms, except where Data Protection Law or the SCCs do not allow them. This DPA lasts as long as TestersWiz processes Customer Personal Data.
Annex 1 — Details of processing
- Subject matter and nature: automated static security analysis of submissions and production of reports, as described in section 8 of the Terms.
- Purpose: providing the security tools to the Customer.
- Categories of data subjects: people whose personal data is contained in a submission, such as the Customer's staff, contractors, test users and end users.
- Categories of personal data: whatever is contained in a submission, which may include names, email addresses, usernames, identifiers, hostnames and keys (secrets are masked before storage).
- Duration and retention: the APK is deleted when the scan finishes (a daily clean-up deletes it after 30 days if that fails); stored scan output is deleted when the full report is written, or after 30 days for an unlocked free check; scanner logs are kept 7 days; reports and audit results are deleted after 365 days; pasted database configuration is never stored; all are deleted earlier when the Customer deletes them or the account.
- Location: apps are stored and analysed in Ireland (EU); findings and reports are stored in Canada; pasted database configuration is processed in memory in the United States; for paid App Security Check reports, a redacted finding summary is processed by Anthropic in the United States.
Annex 2 — Technical and organisational measures
- Uploaded apps are encrypted at rest with a dedicated key, in a bucket that refuses unencrypted writes.
- Apps are analysed in an isolated network with no route to the internet, in a single-use environment destroyed after each scan; they are never installed or run.
- Uploads are checked by their contents, and oversized or malformed archives are refused.
- Anything that looks like a secret is masked before it is stored, shown or sent to an AI provider.
- Only a redacted finding summary, never the app, code or evidence, is sent to the AI provider.
- Database-level row security restricts each record to its owner; audits have no administrator view.
- Data is encrypted in transit; sessions use cookies page scripts cannot read.
- Abuse-prone actions are rate-limited per account and per IP address.
- Deletion schedules in Annex 1 are enforced by automated jobs.