Data processing terms
SegAudit's data processing terms for account and contact data: what is processed, subprocessors and safeguards. Firewall data never reaches SegAudit.
It is incorporated into the EULA for account data only.
SegAudit does not process firewall configurations, traffic logs, or engagement files. Those stay on your systems. These terms cover personal data about your personnel that SegAudit handles to sell, issue, or support a license: name, work email, company, role, billing contact, support messages, and security-pack access records.
Payment card and billing details go to Paddle, the merchant of record, which processes them as an independent controller under its own terms; SegAudit receives the order, the company and the billing contact, never card numbers.
SegAudit LLC is the processor of that account data where you are the controller, and the controller where you are an individual contact. It will:
- process it only to provide the license, take payment, provide support, and keep the records described in the privacy policy;
- not sell it;
- use the vendors on the subprocessors list, and tell you before adding a vendor that handles account data; you may object within thirty (30) days, and if SegAudit cannot address the objection, you may end the affected license and receive a prorated refund of its fees for the unused term;
- bind each vendor to data protection duties at least as protective as these, and remain responsible for them;
- make sure everyone who handles account data is bound to keep it confidential;
- protect it with the security measures described on the trust center;
- delete or return it when the license ends, except records that tax law, the nondisclosure record, or the trial and license acceptance records require;
- notify you without undue delay, and within seventy-two (72) hours, after becoming aware of a breach of account data, and help you meet your own notification duties;
- help you answer a data-subject request about account data, where the law requires it, and help with any data protection impact assessment or regulator consultation that concerns it;
- give you the information needed to show these terms are met, first through its security questionnaire answers and trust center evidence, and allow an audit by you or an independent auditor bound by confidentiality, no more than once a year, on thirty (30) days’ notice, if that information is not enough or a regulator requires it.
Transfers from the EEA, UK, or Switzerland to the United States use the European Commission’s standard contractual clauses (Decision 2021/914, Module 2, controller to processor, or Module 3 if a vendor is a sub-processor) and the UK addendum, once those contracts are in place with Cloudflare, Google, Anthropic, and Amazon Web Services. SegAudit is the importer of account data. The customer is the exporter. Annexes will name the account-data categories in the privacy policy, the vendors on the subprocessors list, and no firewall data. Each of those vendors publishes data processing terms that include these clauses, and SegAudit is confirming that they are in effect for its accounts. Until then, do not treat this paragraph as the signed clauses. Paddle is an independent controller and handles its own transfers. An EU or UK representative will be named before SegAudit sells to customers in those places. These terms do not create a switching right under the EU Data Act for plant data: that data is already on your systems, in files you can export.
Last updated .