1. Scope and Applicability
This Data Processing Addendum ("DPA") supplements the AlienGate Terms of Service and applies to the processing of personal data and enterprise telemetry data in connection with AlienGate’s threat intelligence, attack surface monitoring, and vulnerability scanning services.
2. Roles and Responsibilities
- Customer as Data Controller: The Customer determines the scope and domains subject to exposure checks and identity monitoring.
- AlienGate as Data Processor: AlienGate processes data solely on behalf of the Customer and in accordance with documented instructions to deliver threat intelligence insights.
3. Data Protection & Security Controls
AlienGate implements strict technical and organizational measures (TOMs) to protect customer data:
- Hashed Credentials: Plaintext secrets and credentials are cryptographically hashed upon ingest. Analysts never view raw usable secrets.
- Workspace Isolation: Logical data separation ensures multi-tenant environments prevent cross-workspace access or data leakage.
- Data Minimization: Only necessary exposure metadata (e.g., domain names, hashed emails, breach sources) is collected to perform dark web monitoring.
4. Sub-processors
AlienGate engages trusted third-party service providers (such as tier-1 cloud hosting, infrastructure protection, and CDN providers) under strict data protection agreements. A full list of active sub-processors is available upon request via compliance@aliengate.io.
5. Incident Management & Breach Notification
In the event of a confirmed personal data breach affecting Customer data processed by AlienGate, AlienGate will notify the Customer without undue delay and no later than 72 hours after becoming aware of the incident.
6. International Data Transfers
Where processing involves cross-border transfers of personal data, AlienGate relies on Standard Contractual Clauses (SCCs) and compliant data transfer mechanisms to ensure equivalent privacy safeguards.