Data processing agreement
Under Article 28 GDPR, between the organisation using Firmline CRA (the controller, “you”) and FIRMLINE PC, trading as Firmline, THIMATON KATOCHIS 60, 41335, LARISA, GREECE (the processor, “we”). Part of the terms of service. Last updated 3 October 2026.
1. What we process, and why
Purpose and nature: providing Firmline CRA to you: storing, matching, displaying, emailing and exporting
the data your organisation puts in, as described in the terms.
Duration: as long as your organisation exists in Firmline CRA, then until deletion under section 8.
Data subjects: your team members, and anyone you name in what you record (for example a researcher who
reported a vulnerability).
Personal data: names and work email addresses, sign-in and activity records (who decided or recorded what,
and when), and any personal data you write into cases, decisions, reports and advisories. We don’t expect
special categories of data, and you agree not to enter them.
2. Your instructions
We process the data only on your documented instructions: these terms, and what you do in the app (for example connecting an issue tracker, or publishing an advisory). We’ll tell you if we think an instruction breaks data protection law. If the law requires us to process data otherwise, we’ll tell you first unless the law forbids it.
3. Confidentiality
Only people who need access to run the service have it, and they’re bound to confidentiality.
4. Security
We take the measures in Annex 1 and keep them up to date.
5. Sub-processors
You authorise the sub-processors in Annex 2. We’ll email you at least 30 days before adding or replacing one; if you object on reasonable data-protection grounds and we can’t resolve it, you may end the service and we’ll delete your data. Each sub-processor is bound by data-protection terms at least as protective as these. Services you connect yourself (an issue tracker) receive data on your instruction under your own agreement with them; they aren’t our sub-processors.
6. Where the data is
In the EU: on our server in Finland and with Scaleway in France. We don’t transfer personal data outside the EU/EEA. OSV.dev, NVD and ENISA’s EUVD receive package URLs, component names and vulnerability IDs only, which contain no personal data.
7. Helping you
We help you answer requests from data subjects (Settings lets you export all data, remove members and delete the organisation), and with security, impact assessments and consultations, as far as our part of the processing allows. We tell you of a personal-data breach affecting your data without undue delay, and within 48 hours of becoming aware of it, with what we know and what we’re doing.
8. At the end
Export your data from Settings at any time. When you delete your organisation, or the service ends, we delete your data from the live system within 30 days. Encrypted backups expire within 12 months; until then they’re used only to recover from a disaster, and anything restored from them that you had deleted is deleted again. We keep nothing unless the law requires it.
9. Audits
We make available the information you need to show these obligations are met, and answer your questions in writing. You, or an auditor bound to confidentiality, may audit our processing once a year with 30 days’ notice, at your cost, without access to other customers’ data.
Annex 1: security measures
- Traffic is encrypted with TLS, and browsers are told to use HTTPS only (HSTS).
- Sign-in is by single-use emailed link; sign-in links, sessions and API tokens are stored only as SHA-256 hashes.
- Issue-tracker tokens are encrypted at rest (AES-256-GCM) and never shown or exported.
- Every query is limited to the signed-in organisation; cross-site requests are refused; a strict Content Security Policy applies; sign-in is rate-limited.
- An audit log records who did what, and when.
- The server runs only what the service needs, behind a firewall, with SSH by key only, intrusion banning and automatic security updates. The app runs as an unprivileged user in a container.
- Nightly backups: local, and off-site encrypted (restic) with a separate provider; restores are tested.
- Errors and failed background jobs alert us by email; an external check watches availability.
Annex 2: sub-processors
- Hetzner Online GmbH, Germany: the server that runs Firmline CRA, in its data centre in Helsinki, Finland.
- Scaleway SAS, France: sending emails (sign-in links, invitations, reminders), and storing the encrypted off-site backups, both in Paris.