Data Processing Agreement (DPA)

A Data Processing Agreement is a legally binding contract declaring how your data will be used by us (Cyber Legion) and our portal (Cyber Legion) and by any third parties we might rely on for services including but not limited to email, web hosting, storage, and data analytics.
Want to know more? Fill out our data request form to request and sign an electronic DPA.
Our Data Protection Officer
Contact us.

What is the GDPR?

The GDPR or the “General Data Protection Regulation” is a regulation designed to ensure the appropriate protection of personal data in a digital society. It encompasses how, why, and when your data may be used online, the security standards organizations must utilize to protect that data, and penalties for non-compliance.
The GDPR replaces the Data Protection Direction, and like its predecessor, is based on Article 8(1) of the Charter of Fundamental Rights of the European Union, echoing Article 12 of the Universal Declaration on Human Rights, which was first adopted by the UN General Assembly in 1948. It also echoes the Article 16(1) of the Treaty of the Functioning European Union, pursuant to which “everyone has the right to protection of personal data”. The GDPR includes changes to account for digital privacy rights relating to email, digital marketing, encryption and data security, right to be informed/forgotten, and much more. Read the full text of the GDPR here.
The GDPR was first adopted in 2016 and became enforceable by law throughout the EU in May of 2018. It affects all organizations working with, controlling, storing, analysing or implementing Personal Data. Cyber Legion and its third-party organizations are affected by the GDPR.

What are Cyber Legion’s Responsibilities Under the GDPR?

The GDPR requires that Cyber Legion take precautions to protect personal data in every way. This includes but is not limited to ensuring that data is:
• Processed lawfully, fairly, and in a transparent manner
• Collected for specific, explicated, and legitimate purposes and not further processed or controlled in manners incompatible with those purposes. Furthermore, this data must be adequate, relevant, and limited to what is necessary for achieving those purposes.
• Accurate and kept up to date
• Stored securely to prevent accidental loss, destruction, or damage and kept no longer than is necessary to achieve the purpose for which it is collected
Documentation and Compliance – Cyber Legion is also responsible for documenting all data processing activities. We are required to demonstrate our compliance with the above principles in regular GDPR audits. GDPR necessitates implementing data protection by design when developing our processes, products, and systems.
Third-Parties – The GDPR states that Cyber Legion is responsible for negotiating GDPR compliance on behalf of our customers when contracting third-party services. This ensures client protection, even when we utilize third-party services like AWS, GCP, Microsoft Azure, Linode etc.
International Data Transfer – Under the GDPR, Cyber Legion may not transfer any Private Data outside the UK, EU unless the UK, EU Commission has deemed that country to have adequate data processing regulations. Exceptions can be made in the case of using alternative safeguards such as the UK, EU-US Privacy Shield and standard contractual clauses.

What Does “Personal Data” Mean Under the GDPR?

Personal Data, referred to by various terms throughout our website and terms, refers to:
“Personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;”
This data may encompass IP addresses, device IDs, phone numbers, and other information, even when it is subject to change. In any case where information can be used to identify any persona aspect of the user, including physical location, it is considered Private Data.

Your GDPR Rights

Under the GDPR, you have the right to access personal data collected by Cyber Legion and Cyber Legion. Send us a request at “Contact us” and we will provide any data we have stored. We can also transfer a copy of stored data to you with the purpose of you sending it to another processor or controller.
Should you feel this data is incorrect or wish to have it removed, you can submit a correction request. We will process needed changes at our earliest convenience and will notify our data compliance officer in case you are not our customer. Data will be changed or removed from our servers no later than 30 business days following the request. You may also request a restriction of personal processing.

We can help improve your Business

Ensure your Organization Assets are well  protected in front of the Cyber Attacks

Delivery Workflow

Register for Free and get your test done withn 24 to 48 hours

See Workflow

Sample Report

Here is a sample report of a Security Testing Engagement

See Sample Report PDF

Work Request

Order your security test and Get Your Report

Get Your Test Report

1. Client Onboarding

Access to all of Cyber Legion's services is provided through the Web Secure Client Portal. To create a Free account, you can sign up through the portal, or contact the Cyber Legion team and they will set up an account for you.

2. NDA , Agreements & Digital Signature

The integration of Digital Signature in our Web Client Portal allows us to legally sign all necessary documents and agreements, enabling us to carry out security assessments on targeted systems.

3. Submit Work Request

Our pricing structure is adaptable to meet the needs of all clients. By filling out the Work Request Form, you can select from pre-existing services or request a personalized proposal.

The Cyber Legion team will acknowledge your order, set up a project in your account, and proceed with the testing and delivery.

4. Security Testing & Report

We meet agreed upon SLAs and follow security testing framework checklists. Based on our commitment, our team of engineers will utilize all of our tools, automation, and testing capabilities to achieve the objectives.

Within the agreed upon timeframe, you will receive a report on the security test that was conducted, including the results, recommendations, and references for addressing any identified issues.

5. Retesting & Validation of Remediation

We not only identify potential threats, risks, and vulnerabilities, but also provide detailed recommendations for resolution. To ensure complete remediation, we offer complimentary retesting and a range of ongoing security testing options for continued vulnerability detection and verification.