Data Processing Agreement
Standard Contractual Clauses and enterprise data processing commitments across GANGA platform services.
EU SCCs Module 2
Transfer Mechanism
AES-256 / TLS 1.3
Encryption Standard
Within 72 Hours
Breach Notification SLA
GDPR / UK GDPR / LGPD
Regulatory Coverage
Agreement Overview
LEGAL STATUS: ACTIVELast updated: August 21, 2026
This Data Processing Agreement ("DPA") applies when the GANGA Offensive Ops platform processes personal data on behalf of enterprise customers who act as data controllers under applicable international data protection regulations (GDPR, UK GDPR, LGPD, and equivalent frameworks).
General Terms & Applicability
LEGAL CORE- This Data Processing Agreement ("DPA") forms a legally binding addendum between GANGA Offensive Ops Pvt. Ltd. ("Processor") and the customer ("Controller") governing the processing of personal data.
- This DPA applies whenever the Controller processes personal data through the GANGA Offensive Ops platform and associated security scanning infrastructure.
- In the event of any conflict between this DPA and the primary Terms of Service, this DPA shall strictly prevail with respect to data protection obligations.
Scope, Nature & Processing Purpose
OPERATIONAL SCOPE- The Processor processes personal data strictly upon documented, lawful instructions from the Controller to deliver contracted security assessment capabilities.
- Processing activities include: account authentication, authorized OSINT reconnaissance aggregation, vulnerability evidence indexing, and platform telemetry.
- The Processor shall never process, sell, or disclose personal data for any purpose other than providing the agreed offensive security services unless compelled by applicable law.
Standard Contractual Clauses (SCCs)
CROSS-BORDER- For cross-border personal data transfers from the EEA, United Kingdom, or Switzerland to third countries without an adequacy decision, the parties agree to incorporate the European Commission Standard Contractual Clauses (Module 2: Controller to Processor).
- The SCCs are incorporated by reference. In the event of any discrepancy, the SCCs shall take legal precedence for international data transfers.
- The parties conduct Transfer Impact Assessments (TIAs) and enforce technical supplementary measures to safeguard data against unauthorized interception.
Authorized Sub-Processors
INFRASTRUCTURE- The Processor engages vetted third-party sub-processors strictly for cloud infrastructure, payment processing, and security delivery.
- Cloud Infrastructure: AWS and GCP for isolated computing, encrypted blob storage, and database orchestration.
- Payment Handling: Stripe for PCI-DSS Level 1 compliant billing processing and automated fraud prevention.
- Platform Monitoring: Telemetry collectors (opt-in only) to track real-time system performance and scanner health.
- Notification Obligation: The Processor shall notify the Controller at least 30 days prior to engaging any new sub-processor, with a 14-day objection window.
Technical & Organizational Security Measures
DEFENSE-IN-DEPTH- Data Encryption: All data is encrypted at rest using AES-256-GCM and in transit using TLS 1.3 with forward secrecy.
- Access Controls: Strict role-based access control (RBAC), multi-factor authentication (MFA), and mandatory least-privilege policies across all engineering staff.
- Continuous Monitoring: Automated real-time intrusion detection, anomaly monitoring, and proactive vulnerability management.
- Independent Audits: Regular third-party penetration testing, code security reviews, and external cryptographic audits.
Data Subject Rights Assistance
PRIVACY RIGHTS- The Processor provides prompt technical assistance to help Controllers fulfill their obligations under GDPR Articles 15-22.
- Right of Access: Machine-readable data exports (JSON/CSV) generated on request from the dashboard.
- Right to Rectification & Erasure: Account data and indexed telemetry permanently purged within 30 days of verified instruction.
- Right to Restriction & Objection: Granular controls to halt automated data collection for specified target profiles.
Data Retention & Secure Deletion
LIFECYCLE- OSINT Scans & Target Intelligence: Automatically purged from cache after 30 days unless explicitly saved to an active engagement record.
- Account Telemetry: Retained for the duration of the active subscription or until deletion is formally requested.
- Encrypted Backups: Immutable disaster recovery backups purged on a rolling 90-day retention schedule.
- Certification of Deletion: Formal written confirmation of data destruction provided upon Controller request.
Data Breach Notification & Response
INCIDENT SLA- Notification Timeline: The Processor shall notify the Controller without undue delay and no later than 72 hours after confirming a security incident.
- Incident Dossier: Disclosures include the nature of the breach, affected data categories, estimated scope, mitigation steps taken, and designated contact points.
- Remediation & Forensic Support: Full cooperation in forensic investigations and implementation of corrective measures to prevent recurrence.
Data Protection Officer Contact
DPO OFFICE- For questions regarding this DPA, data transfer impact assessments, or privacy rights execution:
- Email: dpo@gangaoffensiveops.com.np
- Postal: GANGA Offensive Ops Pvt. Ltd., SundarHaraicha-5 Morang, Koshi Province, Nepal
- Response Window: Written response guaranteed within 30 business days.