Data processing agreement

Under Article 28 GDPR, between the organisation using Firmline CRA (the controller, “you”) and FIRMLINE PC, trading as Firmline, THIMATON KATOCHIS 60, 41335, LARISA, GREECE (the processor, “we”). Part of the terms of service. Last updated 3 October 2026.

1. What we process, and why

Purpose and nature: providing Firmline CRA to you: storing, matching, displaying, emailing and exporting the data your organisation puts in, as described in the terms.
Duration: as long as your organisation exists in Firmline CRA, then until deletion under section 8.
Data subjects: your team members, and anyone you name in what you record (for example a researcher who reported a vulnerability).
Personal data: names and work email addresses, sign-in and activity records (who decided or recorded what, and when), and any personal data you write into cases, decisions, reports and advisories. We don’t expect special categories of data, and you agree not to enter them.

2. Your instructions

We process the data only on your documented instructions: these terms, and what you do in the app (for example connecting an issue tracker, or publishing an advisory). We’ll tell you if we think an instruction breaks data protection law. If the law requires us to process data otherwise, we’ll tell you first unless the law forbids it.

3. Confidentiality

Only people who need access to run the service have it, and they’re bound to confidentiality.

4. Security

We take the measures in Annex 1 and keep them up to date.

5. Sub-processors

You authorise the sub-processors in Annex 2. We’ll email you at least 30 days before adding or replacing one; if you object on reasonable data-protection grounds and we can’t resolve it, you may end the service and we’ll delete your data. Each sub-processor is bound by data-protection terms at least as protective as these. Services you connect yourself (an issue tracker) receive data on your instruction under your own agreement with them; they aren’t our sub-processors.

6. Where the data is

In the EU: on our server in Finland and with Scaleway in France. We don’t transfer personal data outside the EU/EEA. OSV.dev, NVD and ENISA’s EUVD receive package URLs, component names and vulnerability IDs only, which contain no personal data.

7. Helping you

We help you answer requests from data subjects (Settings lets you export all data, remove members and delete the organisation), and with security, impact assessments and consultations, as far as our part of the processing allows. We tell you of a personal-data breach affecting your data without undue delay, and within 48 hours of becoming aware of it, with what we know and what we’re doing.

8. At the end

Export your data from Settings at any time. When you delete your organisation, or the service ends, we delete your data from the live system within 30 days. Encrypted backups expire within 12 months; until then they’re used only to recover from a disaster, and anything restored from them that you had deleted is deleted again. We keep nothing unless the law requires it.

9. Audits

We make available the information you need to show these obligations are met, and answer your questions in writing. You, or an auditor bound to confidentiality, may audit our processing once a year with 30 days’ notice, at your cost, without access to other customers’ data.

Annex 1: security measures

Annex 2: sub-processors