GDPR Compliance
At VxLabs Security ("we"), we design our products and services with privacy and security in mind. As a company operating within the European Union, we take compliance with the EU General Data Protection Regulation (GDPR) seriously.
This page provides an overview of our GDPR approach. It does not replace our Privacy Policy or any specific Data Processing Agreements (DPAs) we conclude with our customers.
1. Roles and Responsibilities
Depending on the context, VxLabs Security may act as:
- Data Controller for personal data related to our own website, marketing, business contacts, recruitment and internal operations.
- Data Processor where we process personal data on behalf of our customers within our products and services (e.g. ThreatZ and related modules), in accordance with a written Data Processing Agreement (DPA).
In processor scenarios, our customers remain responsible as controllers for defining the purposes and means of processing. We implement appropriate technical and organisational measures to support them in meeting their GDPR obligations.
2. Data Processing Agreements (DPA)
For customers who use our SaaS or cloud-based solutions, we offer a Data Processing Agreement that:
- defines the subject matter, duration, nature and purpose of processing;
- specifies types of personal data and categories of data subjects;
- sets out our obligations as a processor under Art. 28 GDPR;
- regulates sub-processing, international transfers and security measures;
- provides mechanisms for data subject requests and audit rights where appropriate.
If you are an existing or prospective customer and require a copy of our DPA, please contact us at: privacy@threatz.io.
3. Lawful Bases and Purpose Limitation
We ensure that all processing of personal data is based on a valid legal ground under GDPR (e.g. contract, legitimate interest, consent, legal obligation).
Key principles we follow:
- Purpose limitation - data is collected for specific, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes.
- Data minimisation - we only process data that is relevant and necessary.
- Storage limitation - we retain data only as long as required for the stated purposes or legal obligations.
4. Data Subject Rights
We support our customers and users in exercising their rights under GDPR, including:
- right of access;
- right to rectification;
- right to erasure ("right to be forgotten");
- right to restriction of processing;
- right to data portability;
- right to object to processing based on legitimate interests;
- right to withdraw consent.
If you wish to exercise any of your rights in relation to data processed by VxLabs Security:
- for website, marketing or recruitment data, contact us directly at privacy@threatz.io;
- for data processed within a customer environment (e.g. within ThreatZ), please contact your employer/organisation (the controller), who may then forward the request to us as needed.
We respond to requests in accordance with GDPR timeframes and requirements.
5. Sub-Processors and International Transfers
We work with carefully selected third-party providers to deliver our services (e.g. hosting, infrastructure, analytics, communication tools).
Where these providers process personal data on our behalf:
- we enter into Data Processing Agreements in line with Art. 28 GDPR;
- we assess their security and privacy practices as part of our vendor management;
- for providers outside the EU/EEA, we rely on:
- adequacy decisions, or
- Standard Contractual Clauses (SCCs) and appropriate supplementary measures.
Customers may request an up-to-date list of sub-processors relevant to their services.
6. Security and "Privacy by Design"
Security and privacy are built into our processes and services as part of "privacy by design and by default":
- role-based access control and least-privilege principles;
- secure development lifecycle and internal security reviews;
- encryption of data in transit and, where appropriate, at rest;
- logging and monitoring of access and system activity;
- regular backups and business continuity planning;
- internal policies and training for employees handling personal data.
7. Data Retention and Deletion
We maintain internal policies for data retention and deletion that:
- define retention periods for different categories of data (e.g. contracts, logs, support tickets);
- ensure that personal data is not stored longer than necessary for the original purpose;
- specify deletion or anonymisation mechanisms when data is no longer needed.
For customer data in our SaaS products, we:
- provide export options (where applicable and agreed in contracts);
- delete or anonymise data in accordance with the relevant Agreement and DPA;
- ensure that residual copies in backups are handled in line with industry practice and legal requirements.
8. Support in Customer Compliance
Our goal is to help our customers meet their own regulatory obligations. We do this by:
- providing documentation about our data protection and security practices;
- offering a DPA aligned with GDPR Art. 28;
- supporting data subject requests where we act as a processor;
- providing logging, reporting and configuration capabilities in our products, where relevant for compliance.
If you are planning a formal compliance assessment, audit or customer review related to our services, please reach out to us early so we can support you efficiently.
9. Contact for Data Protection
For any GDPR or privacy-related questions, please contact:
Franz-Mayer-Str. 1
93053 Regensburg
Germany
Email: privacy@threatz.io
If a dedicated Data Protection Officer (DPO) is appointed, we will publish their contact details here.
10. Updates
We may update this GDPR Compliance page from time to time to reflect legal developments, new guidance, or changes in our services. Please refer to this page regularly for the latest information.