Data Processing Addendum
Last updated September 25, 2026
This Data Processing Addendum ("DPA") forms part of the agreement ("Agreement") between Alesian Security LLC, a Colorado limited liability company ("Alesian"), and the customer named in the Agreement or Order Form ("Customer"). It applies when Alesian processes Customer Personal Data. Terms not defined here have the meanings given in the Agreement.
1. Definitions
- Customer Personal Data: personal data that Alesian processes on behalf of Customer in providing the Service, as described in Annex 1.
- Data Protection Laws: all laws on privacy and personal data that apply to a party's processing under the Agreement, including, where applicable, the GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended (CCPA), the Colorado Privacy Act, and similar US state laws.
- Restricted Transfer: a transfer of Customer Personal Data from the EEA, UK or Switzerland to a country not recognized as providing adequate protection.
- SCCs: the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914.
- UK Addendum: the International Data Transfer Addendum issued by the UK Information Commissioner.
- Security Incident: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data on systems controlled by Alesian or its Subprocessors.
- Subprocessor: a third party Alesian engages to process Customer Personal Data.
- "Controller", "processor", "data subject", "personal data" and "processing" have the meanings given in the GDPR, and include the equivalent terms in other Data Protection Laws (such as "business", "service provider", "contractor" and "consumer" under the CCPA).
2. Roles and instructions
2.1 Roles. Customer is the controller (or a processor acting for its own controller) and Alesian is a processor of Customer Personal Data.
2.2 Instructions. Alesian will process Customer Personal Data only on Customer's documented instructions. The Agreement, this DPA and Customer's configuration and use of the Service are Customer's complete instructions. Alesian will tell Customer if it believes an instruction breaks Data Protection Laws, and may suspend the affected processing until the instruction is changed. If law requires other processing, Alesian will tell Customer first unless the law forbids it.
2.3 Customer's responsibilities. Customer is responsible for the lawfulness of its instructions and for having a lawful basis, and giving any notices, needed for Alesian to process Customer Personal Data.
2.4 No sensitive data. Customer will not provide special category data, government identifiers, financial account or card numbers, health information, or children's data. The Service is not designed for it.
2.5 Separate controller data. This DPA does not cover data for which Alesian is itself a controller, including account and billing data and public information about domain names that Alesian collects itself. The Privacy Policy covers that data.
3. Confidentiality
Alesian will ensure that everyone it authorizes to process Customer Personal Data is bound by a duty of confidentiality.
4. Security
4.1 Alesian will maintain the technical and organizational measures in Annex 2, appropriate to the risk. Alesian may update them provided the overall protection is not reduced.
4.2 Customer is responsible for its own use of the Service, including managing user access, requiring a second sign-in factor where appropriate, and keeping its credentials secure.
5. Security Incidents
5.1 Alesian will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident.
5.2 The notice will describe, as far as then known, the nature of the incident, the categories and approximate number of data subjects and records affected, likely consequences, and the measures taken or proposed. Alesian will provide further information as it becomes available and take reasonable steps to contain and remediate the incident.
5.3 Notifying or responding to an incident is not an admission of fault or liability.
6. Subprocessors
6.1 Authorization. Customer authorizes Alesian to engage the Subprocessors listed at alesiansecurity.com/legal/subprocessors.
6.2 Obligations. Alesian will impose data protection terms on each Subprocessor that protect Customer Personal Data to the standard of this DPA, and remains responsible for their performance.
6.3 Changes. Alesian will give at least 14 days' notice of a new Subprocessor by updating the list and emailing customers who subscribe to updates at admin@alesiansecurity.com.
6.4 Objection. Customer may object on reasonable data protection grounds within 10 days of notice. The parties will discuss the objection in good faith. If they cannot resolve it, Customer may terminate the affected Service and receive a refund of prepaid fees for the unused period.
7. Data subject requests and assistance
7.1 Taking into account the nature of the processing, Alesian will help Customer respond to requests from data subjects. If Alesian receives a request directly, it will refer the requester to Customer and will not otherwise respond unless Customer authorizes it or the law requires it.
7.2 Alesian will give Customer reasonable information and help with data protection impact assessments and consultations with supervisory authorities about the Service.
7.3 Assistance beyond what the Service's own features provide, and beyond a reasonable level, may be charged at rates agreed in advance.
8. Audits
8.1 Alesian will make available the information reasonably necessary to demonstrate its compliance with this DPA, including by answering one reasonable security questionnaire each year and providing its Security Overview.
8.2 If that information is not sufficient to show compliance, or a supervisory authority requires it, Customer may, at its own cost and no more than once a year, carry out an audit with 30 days' notice, during business hours, subject to confidentiality and in a way that does not disrupt the Service or expose other customers' data.
9. International transfers
9.1 Alesian processes Customer Personal Data in the United States. Its Subprocessors process data in the locations on the Subprocessor list.
9.2 For Restricted Transfers from the EEA, the SCCs are incorporated into this DPA as follows: Module Two (controller to processor), or Module Three (processor to processor) where Customer is a processor; clause 7 (docking) applies; clause 9 option 2 (general authorization) applies, with the notice period in section 6.3; the clause 11 optional redress wording does not apply; clauses 17 and 18 select Irish law and the courts of Ireland; Annexes I and II are completed by Annexes 1 and 2 of this DPA.
9.3 For Restricted Transfers from the UK, the UK Addendum is incorporated, completed with the information in this DPA, and either party may end it as permitted by its Table 4.
9.4 For Restricted Transfers from Switzerland, the SCCs apply with the changes the Swiss authority requires, with the Swiss FDPIC as competent authority.
9.5 If a transfer mechanism is invalidated or replaced, the parties will cooperate to put a lawful alternative in place.
10. Return and deletion
When the Agreement ends without renewal, Alesian will keep Customer Personal Data for 90 days so that the Service can continue if Customer renews late, and will then delete it within 30 days. Customer may instead ask, at any time, for deletion within 30 days, and may ask for an export in a machine-readable format before deletion. Copies in backups expire on their normal cycle (no more than about 60 days) and are protected from further use until then. Alesian may keep data the law requires it to keep, and will protect it and use it for no other purpose.
11. US state law terms
Where the CCPA or a similar US state law applies, Alesian:
(a) will process Customer Personal Data only for the business purposes set out in the Agreement and Annex 1;
(b) will not sell or share it, or use it for cross-context behavioral advertising;
(c) will not retain, use or disclose it outside the direct business relationship with Customer, or combine it with personal information from other sources, except as those laws allow;
(d) will comply with those laws and provide the same level of privacy protection they require, and tell Customer if it can no longer do so;
(e) grants Customer the right, on notice, to take reasonable steps to stop and remedy unauthorized use; and
(f) may de-identify or aggregate Customer Personal Data as permitted by those laws, and will not attempt to re-identify it.
12. Liability and precedence
12.1 Each party's liability under this DPA is subject to the limitations in the Agreement, except where Data Protection Laws or the SCCs prohibit limiting it.
12.2 If there is a conflict, the following order applies: the SCCs and UK Addendum; this DPA; the Agreement.
12.3 This DPA lasts as long as Alesian processes Customer Personal Data. It is governed by the law that governs the Agreement, except where the SCCs or Data Protection Laws require otherwise.
Annex 1 — Details of processing
Parties. Data exporter: Customer (details in the Order Form). Data importer: Alesian Security LLC, Arvada, Colorado, admin@alesiansecurity.com. Role: processor.
Subject matter and nature. Receiving, storing, analyzing and displaying data to monitor Customer's email authentication and identify sources of mail spoofing Customer's domains (mail defense), as ordered.
Purpose. Providing, securing and supporting the Service ordered by Customer.
Duration. The term of the Agreement plus the deletion period in section 10.
Frequency. Continuous.
Data subjects.
- Mail defense: recipients and apparent senders of messages that failed authentication; operators and administrators of mail servers that send email using Customer's domains (where identifiable from IP address or host name).
Categories of personal data.
- Mail defense (aggregate reports): IP addresses and host names of sending servers, sending domains, message counts, SPF/DKIM/DMARC results, report metadata.
- Mail defense (failure / forensic reports): the above, plus message headers, which can include sender and recipient email addresses, subject lines, message identifiers and, where the reporting provider includes it, message content or attachments, which Alesian discards on receipt.
Sensitive data. None intended. Failure reports may incidentally contain message content; Alesian uses it only to identify the source of spoofed mail, and strips message bodies and attachments on receipt, keeping only the message headers.
Retention. DMARC reports: the Subscription Term plus 90 days. All: deleted per section 10.
Competent supervisory authority. As determined by clause 13 of the SCCs.
Annex 2 — Technical and organizational measures
- Encryption: TLS for all data in transit to and from the Service. Storage volumes (including the database) and backups encrypted at rest with AES-256, using AWS-managed encryption.
- Access control: production access limited to named Alesian personnel who need it; second factor required for Alesian's cloud and administrative accounts; least-privilege IAM roles for services.
- Application security: passwords hashed with Argon2id; second factor available to users and enforceable by administrators; role-based permissions within each account; tenant isolation of Customer data; account action logging.
- Network: origin servers accept traffic only from the content delivery network; secrets held in a managed secrets store, not in code.
- Resilience: automated backups expiring after 30 days; documented restore procedure.
- Retention: automatic deletion of expired sessions and failed sign-in records; retention periods in Annex 1.
- Change management: code review before deployment; dependency updates.
- Incident response: documented procedure for identifying, containing and notifying Security Incidents within 72 hours.
- Personnel: confidentiality obligations for everyone with access.
Annex 3 — Subprocessors
See alesiansecurity.com/legal/subprocessors. At the date of this DPA, those that process Customer Personal Data are Amazon Web Services (United States, hosting and backups), and MX Route (DMARC report receipt, United States).