Template version: 1.0 · Last updated: 15 May 2026 · Inquiries: [email protected]
Who needs this DPA? This agreement is required when you use Droidwatch to analyze APK files that contain personal data belonging to your own users or customers. In that scenario, you are the Data Controller and Droidwatch is your Data Processor under GDPR Art. 28. If you only submit your own apps for analysis, you likely do not need a separate DPA — our Privacy Policy governs that relationship.
To execute a binding DPA for your Enterprise account, contact our legal team. We will prepare a countersigned agreement within 5 business days.
Request a Signed DPAIn this Agreement, the following terms have the meanings set out below. All other capitalized terms have the meanings given in the GDPR.
[Customer entity name] — as identified in the applicable Order Form, Master Service Agreement, or Enterprise subscription.
Contact: [Customer's designated data protection contact]
Together referred to as "the Parties." This Agreement is entered into as of the date the Customer accepts Droidwatch's Terms of Service or, for Enterprise customers, the date countersigned by both Parties.
Subject matter: Droidwatch will process Personal Data that may be contained in or derived from Android application packages (APK, XAPK, AAB) submitted by the Controller, solely for the purpose of providing the Services.
Duration: This Agreement remains in force for as long as the Processor processes Personal Data on behalf of the Controller, and until all Personal Data has been deleted or returned in accordance with Section 13.
Nature of processing: Automated analysis of submitted files, including static code analysis, behavioral analysis in isolated sandboxes, extraction of metadata and security indicators, and generation of analysis reports.
Purpose of processing: Security analysis of Android applications to identify malicious behavior, vulnerabilities, and indicators of compromise, as instructed by the Controller.
Personal Data processed under this Agreement may include, depending on the content of submitted APK files:
Droidwatch does not intentionally extract or store personal data beyond what is necessary for security analysis. The Controller is responsible for ensuring that submitted files contain only personal data for which they have a lawful basis for the analysis processing.
The Parties do not anticipate that special categories of personal data (GDPR Art. 9) will be processed under this Agreement. The Controller must not submit files specifically intended to contain special category data without prior written agreement and appropriate additional safeguards.
Droidwatch, as Processor, shall:
The Controller's documented instructions for processing are set out in this Agreement and in the applicable Terms of Service. Any additional instructions must be provided in writing to [email protected]. The Controller warrants that it has the legal authority to give such instructions and that they comply with applicable law.
The Controller acknowledges that threat intelligence enrichment (querying file hashes and network IOCs against third-party databases, as described in the Privacy Policy Section 6) forms part of the standard Service. The Controller may opt out of threat intelligence sharing for specific submissions via the API parameter disable_threat_intel=true (Enterprise plans only).
The Controller provides general written authorization for Droidwatch to engage the sub-processors listed in the Privacy Policy (Section 7). Before engaging any new sub-processor or replacing an existing one, Droidwatch shall:
The Controller may object to a new sub-processor within 14 days of notification by providing written reasons. If the Parties cannot resolve the objection within 30 days, the Controller may terminate the relevant Services on written notice, without penalty, within 90 days of the notification.
Droidwatch remains fully liable to the Controller for the performance of Sub-processors' obligations to the extent that Droidwatch would be liable if performing the services itself.
Droidwatch implements and maintains the following technical and organisational measures (TOMs) appropriate to the risk:
| Category | Measure |
|---|---|
| Encryption in transit | TLS 1.2+ (HTTPS) for all data in transit |
| Encryption at rest | AES-256-GCM for sensitive fields; disk encryption for storage volumes |
| Access control | Role-based access control (RBAC); multi-factor authentication for production access; principle of least privilege |
| Isolation | APK analysis in isolated sandbox containers with no network access to production systems; seccomp profiles and dropped Linux capabilities |
| Audit logging | Append-only, tamper-protected audit log of all significant actions; retained minimum 12 months |
| Vulnerability management | Regular dependency updates; automated scanning for known CVEs |
| Data minimization | Only metadata and indicators extracted from files; raw binaries deleted per retention schedule |
| Personnel | Background checks and confidentiality obligations for personnel with access to production data |
| Incident response | Documented incident response procedure; 72-hour breach notification commitment |
| Backup and recovery | Regular encrypted backups with defined RTO/RPO targets |
These measures may be updated from time to time to reflect advances in technology, provided that updates do not materially reduce the overall security level. Enterprise customers may request the current version of our full TOMs documentation.
In the event of a Security Incident affecting Personal Data processed under this Agreement, Droidwatch shall:
Notification shall be sent to the Controller's designated contact by email. The Controller is responsible for making any required notifications to supervisory authorities and data subjects under GDPR Arts. 33–34. Droidwatch's breach notification obligation is not an acknowledgment of fault or liability.
Upon the Controller's written request, Droidwatch shall provide reasonable assistance to the Controller in conducting a Data Protection Impact Assessment (DPIA) under GDPR Art. 35, and in carrying out prior consultation with a supervisory authority under Art. 36, where required. Such assistance shall be limited to information and documentation reasonably within Droidwatch's control and directly relevant to the Services.
Droidwatch shall make available to the Controller all information reasonably necessary to demonstrate compliance with this Agreement and GDPR Art. 28, and shall allow for and contribute to audits and inspections. In practice:
Where the Services involve the transfer of Personal Data outside the EU/EEA to countries that do not benefit from an EU adequacy decision, Droidwatch shall ensure appropriate safeguards are in place in accordance with GDPR Chapter V. For transfers to sub-processors in the United States and other third countries, Droidwatch relies on the European Commission's Standard Contractual Clauses (Module 3: processor to processor) or Module 2 (controller to processor) as applicable.
Copies of the applicable SCCs are available upon written request to [email protected]. Transfers from the UK are covered by the UK IDTA (International Data Transfer Agreement) or UK Addendum to the EU SCCs as appropriate.
Enterprise customers may request data residency restrictions (EU-only processing) where technically and commercially feasible. Additional charges may apply.
Upon termination or expiry of the Services, or upon written request from the Controller at any time, Droidwatch shall, at the Controller's election:
Deletion does not apply to anonymized, non-personal data derived from submissions (e.g., aggregated detection statistics) or to data that Droidwatch is required by applicable law to retain. Where retention is required by law, Droidwatch will restrict further processing of such data to the minimum necessary to fulfill the legal obligation and will notify the Controller of the retention requirement.
Audit logs containing incidental personal data (e.g., IP addresses) will be retained for the minimum period required for SOC 2 compliance (12 months) even after Service termination, after which they will be deleted.
Each Party's liability under this Agreement is subject to the limitations set out in the applicable Terms of Service or Master Service Agreement. In the event of a conflict, the terms most protective of Personal Data shall prevail.
Each Party shall be liable to the other for any damage caused by a breach of this Agreement. The Processor's liability is limited to damages attributable to its own processing activities and those of its Sub-processors.
Where a data subject brings a claim against both Controller and Processor, the Controller shall not recover from Droidwatch that part of compensation corresponding to the Controller's own fault.
In the event of any conflict or inconsistency between this Agreement and the Terms of Service, the terms of this Agreement shall prevail with respect to the processing of Personal Data. In the event of any conflict between this Agreement and applicable data protection law (including GDPR), applicable law shall prevail.
This Agreement does not reduce or override any obligation imposed on Droidwatch by applicable law; rather, it supplements and clarifies the obligations that apply by default under GDPR Art. 28.
Note: This DPA template is provided for informational purposes and represents Droidwatch's standard terms. It does not constitute a legally binding agreement until countersigned by both Parties. To execute a binding DPA, contact [email protected].
Ready to sign? Send us an email and our legal team will prepare a countersigned DPA for your organization within 5 business days.
Request a Signed DPA