Data processing agreement

Publisher: Alessio Scatamacchia, operating ASCA

Website: asca-security.com

Contact: contact@asca-security.com

1. Purpose and scope

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer using ASCA (the "Customer") and Alessio Scatamacchia, operating ASCA (the "Processor"). It applies whenever ASCA processes personal data on the Customer's behalf while providing the Service, in accordance with Article 28 of the GDPR.

2. Roles of the parties

The Customer is the data controller for the personal data contained in the applications, credentials and information it submits to the Service. ASCA acts as the data processor and processes this data only on the Customer's documented instructions, which consist of launching scans and using the features of the Service.

3. Description of the processing

• Nature and purpose

  • Storage, decompilation and automated security analysis of the applications submitted by the Customer, and production of reports.

• Categories of data

  • Personal data that may be embedded in the submitted applications, such as hardcoded identifiers, emails or tokens.
  • Test account credentials provided by the Customer for a scan.
  • Names and email addresses of the Customer's workspace members.

• Data subjects

  • The Customer's users, employees, test accounts and workspace members.

• Duration

  • For as long as the Customer uses the Service, then until deletion as described in section 8.

4. Obligations of the processor

  • process the personal data only to provide the Service and on the Customer's instructions;
  • inform the Customer if an instruction appears to infringe data protection law;
  • ensure that anyone authorised to access the data is bound by confidentiality;
  • implement the security measures described in section 5;
  • assist the Customer, as far as possible, in answering data subject requests and in carrying out impact assessments;
  • never use the Customer's data to train AI models.

5. Security measures

  • Each scan runs in an isolated, short-lived environment.
  • Data is encrypted in transit; passwords are stored only as hashes.
  • Test credentials are kept only for the duration of the scan.
  • Access to stored files and databases is restricted to the services that need it.
  • Hosting is provided in data centres located in the European Union.

6. Sub-processors

The Customer authorises ASCA to use the following sub-processors. ASCA will inform the Customer of any intended addition or replacement, giving the Customer the opportunity to object.

  • OVH SAS (France, European Union): hosting of the platform, databases and stored files.
  • DeepSeek (People's Republic of China): large language model analysing application code during scans.
  • Brevo (France): transactional emails, such as workspace invitations.

7. International transfers

Analysing application code with the default model involves a transfer to the People's Republic of China, a country that is not covered by an adequacy decision of the European Commission. Only the code and context strictly needed for the analysis are transferred. By launching a scan with this model, the Customer acknowledges this transfer. Customers who require analysis to remain within the European Union should contact ASCA before launching a scan.

8. Deletion and return of data

When the Customer deletes a scan or closes its account, ASCA deletes the related applications, code, findings and reports within 30 days, unless the law requires otherwise. Before closing its account, the Customer can download its reports from the Service.

9. Personal data breach

ASCA will notify the Customer without undue delay, and where possible within 48 hours, after becoming aware of a personal data breach affecting the Customer's data, with the information available to help the Customer meet its own obligations.

10. Audits

ASCA will make available the information reasonably necessary to demonstrate compliance with this DPA. Requests should be sent to contact@asca-security.com.

11. Governing law

This DPA is governed by French law and follows the duration of the Terms of Service. In case of conflict between this DPA and the Terms of Service regarding personal data, this DPA prevails.