Dunicot A cybersecurity consultancy and advisory firm.

Legal · Data processing

Data processing addendum

The processor-side commitments that apply when we handle your data during an engagement.

Roles

When we test your systems, any personal data we encounter is processed on your documented instructions. You are the controller; Dunicot Private Limited is the processor. This addendum records the commitments that apply, and is incorporated into the engagement contract.

A signed, counter-executed copy is available on request, send yours or ask for ours during scoping.

Subject matter and duration

Processing particulars
ItemDetail
Subject matterSecurity testing of systems nominated by the controller
DurationThe engagement period plus the agreed retention window, by default 24 months for reports
Nature and purposeIdentifying, verifying and documenting security vulnerabilities
Categories of data subjectDetermined by the systems in scope: typically the controller’s users, customers, staff or patients
Categories of personal dataDetermined by the systems in scope; minimised by preference for synthetic data
Special categoriesOnly where unavoidably present in scope, and only with the controller’s written acknowledgement

Data minimisation in testing

The strong preference on every engagement is to test against synthetic or de-identified data. It exercises the same code paths and removes the exposure entirely.

Where real data is unavoidable, we minimise deliberately: access is limited to what proves the finding, evidence is redacted in the report, and extracted samples are truncated to the minimum needed to demonstrate impact. We do not exfiltrate data sets to prove a point. One record proves an authorisation flaw as well as a million do.

Technical and organisational measures

  • Certified ISO/IEC 27001 information security management system.
  • Engagement data encrypted at rest and in transit; multi-factor authentication on every system holding it.
  • Access restricted to the individuals delivering the engagement, on a need-to-know basis.
  • Findings and evidence stored separately from general business systems.
  • Documented incident response, including notification obligations below.
  • Secure destruction of engagement data at closure, with written confirmation on request.

Sub-processors

We do not subcontract testing work without your prior written consent. Infrastructure sub-processors used to store or transmit engagement data are disclosed on request before the engagement begins, and you may object to a proposed change.

Breach notification

If we become aware of a personal data breach affecting your data in our custody, we notify you without undue delay and in any case within 24 hours, with what we know, what we are doing, and what we recommend, and we keep you updated as the picture develops. Twenty-four hours, not seventy-two, because you have your own clock to meet.

Assistance and audit

  • We assist you with data subject requests that touch data in our custody.
  • We provide the information reasonably needed to demonstrate compliance with this addendum.
  • We make our ISO 27001 certificate, scope statement and statement of applicability available under NDA.
  • We accommodate a reasonable audit or questionnaire, on notice and under confidentiality.

Return and deletion

On closure, or at any time on your written instruction, we delete engagement data and confirm deletion in writing: except where retention is required by law, in which case we tell you what is retained and why. Raw testing evidence is destroyed at closure by default; reports are retained only for the agreed window so a retest can be performed against them.