Legal · GDPR Art. 28

Data Processing Agreement

Template version: 1.0  ·  Last updated: 15 May 2026  ·  Inquiries: [email protected]

Who needs this DPA? This agreement is required when you use Droidwatch to analyze APK files that contain personal data belonging to your own users or customers. In that scenario, you are the Data Controller and Droidwatch is your Data Processor under GDPR Art. 28. If you only submit your own apps for analysis, you likely do not need a separate DPA — our Privacy Policy governs that relationship.

To execute a binding DPA for your Enterprise account, contact our legal team. We will prepare a countersigned agreement within 5 business days.

Request a Signed DPA

1. Definitions

In this Agreement, the following terms have the meanings set out below. All other capitalized terms have the meanings given in the GDPR.

2. Parties

Data Processor

Droidwatch

Contact: [email protected]

Data Controller

[Customer entity name] — as identified in the applicable Order Form, Master Service Agreement, or Enterprise subscription.

Contact: [Customer's designated data protection contact]

Together referred to as "the Parties." This Agreement is entered into as of the date the Customer accepts Droidwatch's Terms of Service or, for Enterprise customers, the date countersigned by both Parties.

3. Subject Matter, Duration, and Nature of Processing

Subject matter: Droidwatch will process Personal Data that may be contained in or derived from Android application packages (APK, XAPK, AAB) submitted by the Controller, solely for the purpose of providing the Services.

Duration: This Agreement remains in force for as long as the Processor processes Personal Data on behalf of the Controller, and until all Personal Data has been deleted or returned in accordance with Section 13.

Nature of processing: Automated analysis of submitted files, including static code analysis, behavioral analysis in isolated sandboxes, extraction of metadata and security indicators, and generation of analysis reports.

Purpose of processing: Security analysis of Android applications to identify malicious behavior, vulnerabilities, and indicators of compromise, as instructed by the Controller.

4. Schedule A — Processing Details

Schedule A: Categories of Data Subjects

Schedule A: Categories of Personal Data

Personal Data processed under this Agreement may include, depending on the content of submitted APK files:

Droidwatch does not intentionally extract or store personal data beyond what is necessary for security analysis. The Controller is responsible for ensuring that submitted files contain only personal data for which they have a lawful basis for the analysis processing.

Schedule A: Special Categories of Data

The Parties do not anticipate that special categories of personal data (GDPR Art. 9) will be processed under this Agreement. The Controller must not submit files specifically intended to contain special category data without prior written agreement and appropriate additional safeguards.

5. Processor Obligations

Droidwatch, as Processor, shall:

  1. Process Personal Data only on documented instructions from the Controller, including with regard to transfers to third countries, unless required to do so by applicable law. In such cases, Droidwatch shall inform the Controller of that legal requirement before processing, unless prohibited by law on grounds of public interest.
  2. Ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  3. Implement appropriate technical and organisational measures as set out in Section 8.
  4. Respect the conditions for engaging Sub-processors as set out in Section 7.
  5. Assist the Controller, taking into account the nature of the processing, by appropriate technical and organisational measures, insofar as possible, to respond to requests for exercising data subjects' rights.
  6. Assist the Controller in ensuring compliance with GDPR Arts. 32–36 (security, breach notification, DPIAs, prior consultation), taking into account the nature of processing and information available to the Processor.
  7. Delete or return all Personal Data to the Controller upon termination of the Services, and delete existing copies unless applicable law requires storage of the Personal Data (see Section 13).
  8. Make available to the Controller all information necessary to demonstrate compliance with the obligations set out in GDPR Art. 28, and allow for and contribute to audits and inspections conducted by the Controller or an auditor mandated by the Controller (see Section 11).
  9. Inform the Controller immediately if an instruction infringes GDPR or other applicable Union or Member State data protection provisions.

6. Controller Instructions

The Controller's documented instructions for processing are set out in this Agreement and in the applicable Terms of Service. Any additional instructions must be provided in writing to [email protected]. The Controller warrants that it has the legal authority to give such instructions and that they comply with applicable law.

The Controller acknowledges that threat intelligence enrichment (querying file hashes and network IOCs against third-party databases, as described in the Privacy Policy Section 6) forms part of the standard Service. The Controller may opt out of threat intelligence sharing for specific submissions via the API parameter disable_threat_intel=true (Enterprise plans only).

7. Sub-processors

The Controller provides general written authorization for Droidwatch to engage the sub-processors listed in the Privacy Policy (Section 7). Before engaging any new sub-processor or replacing an existing one, Droidwatch shall:

The Controller may object to a new sub-processor within 14 days of notification by providing written reasons. If the Parties cannot resolve the objection within 30 days, the Controller may terminate the relevant Services on written notice, without penalty, within 90 days of the notification.

Droidwatch remains fully liable to the Controller for the performance of Sub-processors' obligations to the extent that Droidwatch would be liable if performing the services itself.

8. Technical and Organisational Measures

Droidwatch implements and maintains the following technical and organisational measures (TOMs) appropriate to the risk:

CategoryMeasure
Encryption in transitTLS 1.2+ (HTTPS) for all data in transit
Encryption at restAES-256-GCM for sensitive fields; disk encryption for storage volumes
Access controlRole-based access control (RBAC); multi-factor authentication for production access; principle of least privilege
IsolationAPK analysis in isolated sandbox containers with no network access to production systems; seccomp profiles and dropped Linux capabilities
Audit loggingAppend-only, tamper-protected audit log of all significant actions; retained minimum 12 months
Vulnerability managementRegular dependency updates; automated scanning for known CVEs
Data minimizationOnly metadata and indicators extracted from files; raw binaries deleted per retention schedule
PersonnelBackground checks and confidentiality obligations for personnel with access to production data
Incident responseDocumented incident response procedure; 72-hour breach notification commitment
Backup and recoveryRegular encrypted backups with defined RTO/RPO targets

These measures may be updated from time to time to reflect advances in technology, provided that updates do not materially reduce the overall security level. Enterprise customers may request the current version of our full TOMs documentation.

9. Data Breach Notification

In the event of a Security Incident affecting Personal Data processed under this Agreement, Droidwatch shall:

  1. Notify the Controller without undue delay and, where feasible, within 72 hours of becoming aware of the incident.
  2. Provide, as information becomes available: a description of the nature of the incident; the categories and approximate number of data subjects and records affected; the likely consequences of the incident; measures taken or proposed to address the incident.
  3. Co-operate with the Controller in investigating the incident and in notifying affected data subjects and supervisory authorities where required.
  4. Take reasonable steps to mitigate the effects of the incident and to prevent recurrence.

Notification shall be sent to the Controller's designated contact by email. The Controller is responsible for making any required notifications to supervisory authorities and data subjects under GDPR Arts. 33–34. Droidwatch's breach notification obligation is not an acknowledgment of fault or liability.

10. DPIAs and Prior Consultation

Upon the Controller's written request, Droidwatch shall provide reasonable assistance to the Controller in conducting a Data Protection Impact Assessment (DPIA) under GDPR Art. 35, and in carrying out prior consultation with a supervisory authority under Art. 36, where required. Such assistance shall be limited to information and documentation reasonably within Droidwatch's control and directly relevant to the Services.

11. Audit and Inspection Rights

Droidwatch shall make available to the Controller all information reasonably necessary to demonstrate compliance with this Agreement and GDPR Art. 28, and shall allow for and contribute to audits and inspections. In practice:

12. International Transfers

Where the Services involve the transfer of Personal Data outside the EU/EEA to countries that do not benefit from an EU adequacy decision, Droidwatch shall ensure appropriate safeguards are in place in accordance with GDPR Chapter V. For transfers to sub-processors in the United States and other third countries, Droidwatch relies on the European Commission's Standard Contractual Clauses (Module 3: processor to processor) or Module 2 (controller to processor) as applicable.

Copies of the applicable SCCs are available upon written request to [email protected]. Transfers from the UK are covered by the UK IDTA (International Data Transfer Agreement) or UK Addendum to the EU SCCs as appropriate.

Enterprise customers may request data residency restrictions (EU-only processing) where technically and commercially feasible. Additional charges may apply.

13. Termination and Return of Data

Upon termination or expiry of the Services, or upon written request from the Controller at any time, Droidwatch shall, at the Controller's election:

Deletion does not apply to anonymized, non-personal data derived from submissions (e.g., aggregated detection statistics) or to data that Droidwatch is required by applicable law to retain. Where retention is required by law, Droidwatch will restrict further processing of such data to the minimum necessary to fulfill the legal obligation and will notify the Controller of the retention requirement.

Audit logs containing incidental personal data (e.g., IP addresses) will be retained for the minimum period required for SOC 2 compliance (12 months) even after Service termination, after which they will be deleted.

14. Liability

Each Party's liability under this Agreement is subject to the limitations set out in the applicable Terms of Service or Master Service Agreement. In the event of a conflict, the terms most protective of Personal Data shall prevail.

Each Party shall be liable to the other for any damage caused by a breach of this Agreement. The Processor's liability is limited to damages attributable to its own processing activities and those of its Sub-processors.

Where a data subject brings a claim against both Controller and Processor, the Controller shall not recover from Droidwatch that part of compensation corresponding to the Controller's own fault.

15. Order of Precedence

In the event of any conflict or inconsistency between this Agreement and the Terms of Service, the terms of this Agreement shall prevail with respect to the processing of Personal Data. In the event of any conflict between this Agreement and applicable data protection law (including GDPR), applicable law shall prevail.

This Agreement does not reduce or override any obligation imposed on Droidwatch by applicable law; rather, it supplements and clarifies the obligations that apply by default under GDPR Art. 28.

Note: This DPA template is provided for informational purposes and represents Droidwatch's standard terms. It does not constitute a legally binding agreement until countersigned by both Parties. To execute a binding DPA, contact [email protected].

Ready to sign? Send us an email and our legal team will prepare a countersigned DPA for your organization within 5 business days.

Request a Signed DPA