Data Processing Addendum

Data Processing Addendum

Effective Date: October 1, 2026Version: 1.0

This Data Processing Addendum (“DPA”) forms part of the agreement governing the use of Blue Lantern Security Inc.’s services between Blue Lantern Security Inc. (“Blue Lantern”) and the business, organization, or managed service provider identified in the applicable account registration, order form, or signed agreement (“Customer”) (the “Agreement”). “Customer” includes a business, organization, or managed service provider that uses a Free Tier account for business purposes. This DPA applies when Blue Lantern processes Customer Personal Data on Customer’s behalf in providing the Services. It becomes effective when Customer accepts the Agreement or a signed document incorporating this DPA. A later countersigned copy confirms the parties’ existing agreement and does not change its effective date. Capitalized terms used but not defined in this DPA, including “Services,” “Authorized Users,” “Seat License,” and “Free Tier,” have the meanings given in the Agreement.

1. Definitions and Scope

1.1 Definitions.

“Customer Personal Data” means personal data or personal information that Blue Lantern processes on Customer’s behalf through the Services. It includes personal information in customer-authorized mailbox integrations, submitted emails and files, URLs submitted or transmitted by monitored browsers, device hostnames and security-check results, directory and integration records, credentials used to operate connected integrations, and resulting reports and run history. It excludes Account Data.

“Account Data” means information Blue Lantern processes for its own account-administration, authentication, billing, support, website, and business-communication purposes. Blue Lantern processes Account Data in its capacity as an independent controller or business, as described in its privacy policy.

“Data Protection Laws” means laws applicable to the parties’ processing of Customer Personal Data, including, where applicable, the EU General Data Protection Regulation (“EU GDPR”), the UK GDPR, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act and its regulations (“CCPA”), and other applicable U.S. state consumer privacy laws.

“Personal Data Breach” means a breach of security affecting systems operated by Blue Lantern or its Subprocessors that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. Unsuccessful attempts that do not compromise Customer Personal Data, including unsuccessful login attempts, pings, and port scans, are excluded.

“Subprocessor” means a third party engaged by Blue Lantern to process Customer Personal Data on its behalf in providing the Services. A platform or integration that Customer independently selects and authorizes under Customer’s own agreement with its provider is not Blue Lantern’s Subprocessor merely because it connects to the Services.

“Restricted Transfer” means a transfer to Blue Lantern for which applicable EU, UK, or Swiss data protection law requires a transfer mechanism because a data exporter subject to that law makes Customer Personal Data available to Blue Lantern in the United States.

1.2 Scope and Roles. Customer determines the purposes for which it deploys the Services, the accounts and systems it connects, the features it enables, and the people and assets it monitors. For Customer Personal Data, Customer is the controller or business and Blue Lantern is its processor or service provider, as those terms apply under Data Protection Laws. If Customer provides the Services to an end client as a managed service provider, Customer may instead act as that end client’s processor and appoint Blue Lantern as its subprocessor. In that case, Customer represents and warrants that each instruction it gives Blue Lantern, and each end-client system it connects to the Services, is authorized by that end client. Customer will obtain the end client’s authorization where required and remain Blue Lantern’s sole contractual point of contact for the end client. End clients are not parties to, or third-party beneficiaries of, this DPA, and Blue Lantern has no direct obligations to them under it except to the extent Data Protection Laws or an incorporated transfer instrument require otherwise. Blue Lantern acts independently with respect to Account Data.

This DPA does not govern an individual’s use of the Services for personal, non-business purposes. Blue Lantern determines its own purposes for processing personal information in connection with that use, and Blue Lantern’s privacy policy, available at https://bluelanternsecurity.io/privacy, addresses that processing. An individual who uses the Services on behalf of a business or organization does so as that Customer’s Authorized User, and this DPA applies to that use.

1.3 Processing Description. Annex A describes the subject matter, duration, nature, purposes, data subjects, and types of Customer Personal Data processed under this DPA. The Services’ features enabled by Customer determine which described activities occur.


2. Instructions and Customer Responsibilities

2.1 Instructions. Blue Lantern will process Customer Personal Data only on Customer’s documented instructions, including the Agreement, this DPA, Customer’s configuration and use of the Services, and further written instructions the parties agree. Blue Lantern may process Customer Personal Data otherwise where applicable law requires it to do so; it will first notify Customer of the requirement unless the law prohibits notice. If Blue Lantern believes an instruction violates Data Protection Laws, it will inform Customer promptly and may suspend the affected processing while the parties address the concern.

2.2 Customer Responsibilities. Customer is responsible for establishing and maintaining a lawful basis for its use of the Services and for giving any notices or obtaining any consents required for monitoring personnel, mailboxes, browsing activity, devices, and connected systems. Customer will have the rights and authorizations necessary to connect each system and submit each item it asks Blue Lantern to process. Customer is responsible for configuring the scope of its monitoring and for determining whether its use of the Services, including processing involving people outside the United States, is appropriate under applicable law. Blue Lantern does not select monitored people by location.

2.3 Incidental Sensitive Information. Emails, attachments, web pages, and files can contain sensitive information even when Customer does not intend to submit it. Blue Lantern will handle such incidental information under this DPA. Customer will not intentionally use the Services to process protected health information, classified material, payment-card data, or other information requiring a separate contractual or regulatory arrangement unless the parties first agree to that arrangement in writing. Without limiting the preceding sentence, if Customer, or any end client for which Customer acts, is a covered entity or business associate under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”), Customer will not connect to the Services any mailbox, device, browser, directory, or other system that creates, receives, maintains, or transmits protected health information unless Blue Lantern has first reviewed the proposed deployment and the parties have executed a business associate agreement. Blue Lantern may decline any such deployment in its discretion. As between the parties, Customer is responsible for the consequences of any breach of this Section 2.3.


3. Confidentiality, Use, and Security

3.1 Personnel. Blue Lantern will ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations and access it only as needed to operate, support, or secure the Services.

3.2 Use Restrictions. Blue Lantern will process Customer Personal Data to provide and secure the features Customer enables, including retrieving and analyzing submitted or connected content; monitoring Customer-authorized browsers, devices, email, and identity systems; generating findings; maintaining run history; troubleshooting; and preventing misuse of the Services. Blue Lantern will not sell or share Customer Personal Data for cross-context behavioral advertising or use it to build advertising audiences. This restriction concerns Customer Personal Data processed on Customer’s behalf. It does not characterize Blue Lantern’s separate website advertising practices involving Account Data or website visitors, which Blue Lantern’s privacy policy describes.

Blue Lantern may produce aggregated or de-identified service information if it takes reasonable measures to prevent association with Customer or an individual, commits to maintaining the information in de-identified form, does not attempt to re-identify it except to test de-identification, and contractually requires recipients to observe those restrictions. Blue Lantern will not use Customer Personal Data, or security threat indicators derived from it, to analyze threats for or provide the Services to other customers. Blue Lantern will not disclose identifiable Customer Personal Data or identify Customer as the source of a threat indicator without Customer’s authorization.

3.3 Security Measures. Blue Lantern will maintain technical and organizational measures appropriate to the risk presented by its processing, including the measures described in Annex B. Blue Lantern may change particular measures so long as it does not materially reduce the overall protection of Customer Personal Data. Customer remains responsible for its account administrators, Authorized Users, connected systems, and information it exports.

3.4 Integration Credentials. Blue Lantern will use credentials and tokens for connected integrations only to operate the integrations Customer enables, protect them against unauthorized access, and delete them from its live systems immediately when Customer deletes the integration or the account , subject to the backup deletion cycle described in Section 7.3 and legally required retention. Customer can also revoke credentials directly with the relevant integration provider.

3.5 External Analysis Requests. Customer understands that a requested WHOIS, RDAP, or DNS lookup may transmit the relevant domain or IP address to an external service, and that loading a URL may disclose that URL to its host. Blue Lantern will limit these requests to what is reasonably necessary to perform the analysis. Blue Lantern may load URLs that Customer submits or that monitored browsers transmit automatically. Before loading a URL transmitted automatically by a monitored browser, Blue Lantern removes the URL fragment (the portion after “#”) and the common tracking parameters utm_source, utm_medium, utm_campaign, utm_term, utm_content, gclid, gbraid, wbraid, fbclid, dclid, _gl, gclsrc, and gad_source; it does not remove other query parameters or path components, and it loads the page only in its isolated analysis environment. Customer will not manually submit URLs containing personal information, authentication tokens, or single-use links in their paths or query strings unless it is authorized to do so. An external service that receives a request in this manner does not become Blue Lantern’s Subprocessor solely because it responds to that request.


4. Subprocessors

4.1 Authorization and Responsibility. Customer generally authorizes Blue Lantern to use the Subprocessors identified in the Subprocessor List made available under Section 4.2 and to engage new Subprocessors in accordance with Sections 4.2 and 4.3. Blue Lantern will enter into written terms requiring each Subprocessor to protect Customer Personal Data under data protection obligations no less protective in substance than those in this DPA, to the extent applicable to the nature of the services the Subprocessor provides. Blue Lantern remains responsible to Customer for its Subprocessors’ performance of their applicable data protection obligations, subject to the Agreement and any mandatory terms of applicable transfer instruments.

4.2 List and Changes. Blue Lantern will make its current list of Subprocessors, their functions, and processing locations available at https://bluelanternsecurity.io/subprocessors (the “Subprocessor List”). From the effective date of this DPA, the Subprocessor List supersedes the initial list in Annex B. Blue Lantern will notify Customer’s account administrator by email at least 15 days before a new Subprocessor begins processing Customer Personal Data, except where an urgent replacement is reasonably needed to address a security or continuity risk. In an urgent case, Blue Lantern will notify Customer as soon as practicable.

4.3 Objections. Customer may object to a new Subprocessor on reasonable data-protection grounds by notifying Blue Lantern within 10 days after receiving notice. Blue Lantern will consider the objection in good faith and may offer a reasonable way to avoid the affected processing. If the objection cannot be resolved, Customer may terminate the affected paid Services before the new Subprocessor begins processing Customer Personal Data or, for an urgent replacement under Section 4.2, within 30 days after receiving Blue Lantern’s notice, and receive a refund of prepaid fees attributable to the unused portion. Subject to the following sentence, this termination right and refund are Customer’s sole and exclusive remedy for an unresolved objection to a Subprocessor. This contractual remedy does not restrict rights that applicable Data Protection Laws or an incorporated transfer instrument make non-waivable.


5. Personal Data Breaches

5.1 Notification. Blue Lantern will notify Customer without undue delay after becoming aware of a Personal Data Breach. Blue Lantern will send an initial notice to Customer’s account administrator using the contact information in Customer’s account. Blue Lantern need not establish the incident’s complete scope before sending that notice. Customer is responsible for keeping its account administrator’s contact information current, and a notice sent to that contact information is effective when sent.

5.2 Information and Cooperation. The initial notice will describe what Blue Lantern reasonably knows about the incident and identify a contact for follow-up. Blue Lantern will provide further information as it becomes available, including reasonably available information about affected data, likely consequences, and containment and remediation measures. Blue Lantern will take reasonable steps to investigate, contain, and mitigate the incident and provide reasonable assistance for Customer’s legally required notifications. Customer controls notices to its data subjects and regulators, except where law requires Blue Lantern to notify them directly. An incident notice does not constitute an admission of fault.


6. Assistance, Compliance Information, and Audit

6.1 Requests and Assessments. Taking into account the nature of the processing and information available to it, Blue Lantern will reasonably assist Customer in responding to data-subject requests that Customer cannot address through available account functions. If Blue Lantern receives a request concerning Customer Personal Data directly, it will direct the requester to Customer where it can identify Customer, unless law requires a different response. Blue Lantern will also provide information reasonably available to it to assist with a required data protection impact assessment, prior consultation, or breach assessment relating to its Services. Blue Lantern may charge Customer its reasonable, documented costs for assistance under this Section 6.1 or Section 5.2 that goes beyond making information available through the Services’ self-service functions or Blue Lantern’s standard documentation, except where the assistance is required because of Blue Lantern’s breach of this DPA. Blue Lantern will bear its own costs of investigating, containing, and remediating a Personal Data Breach and of providing the notices and information required by Section 5. Blue Lantern will give Customer a good-faith estimate before incurring chargeable costs.

6.2 Compliance Information. On reasonable request and subject to confidentiality protections, Blue Lantern will provide the information reasonably necessary to demonstrate its compliance with this DPA. It may initially satisfy a request with its available SOC 2 Type 1 report, its security documentation, and written responses to reasonable follow-up questions. A SOC 2 Type 1 report addresses controls at a point in time; this DPA makes no representation that Blue Lantern has completed a SOC 2 Type 2 examination.

6.3 Further Review. Where the material provided under Section 6.2 is insufficient to meet a right to review required by applicable Data Protection Laws or an applicable transfer instrument, Customer may request a further audit by written notice given at least 30 days in advance. Customer may request no more than one audit in any 12-month period, unless a competent supervisory authority requires it or a Personal Data Breach affecting Customer Personal Data has occurred since the last audit. The parties will agree in good faith on its scope, timing, and method. It will ordinarily be conducted remotely during normal business hours by an independent auditor that is bound by confidentiality and is not a competitor of Blue Lantern, without access to other customers’ information, privileged material, or information whose disclosure would compromise security. Customer will give Blue Lantern a copy of the audit report at no charge, and the report is Blue Lantern’s confidential information. Customer will bear its own audit costs and Blue Lantern’s reasonable documented incremental costs, except to the extent an audit establishes Blue Lantern’s material breach of this DPA. This section does not narrow an audit right that applicable law or an incorporated transfer instrument prohibits the parties from limiting.


7. Retention, Return, and Deletion

7.1 Ordinary Retention. The Services ordinarily delete email and file content within 24 hours after analysis, whether Customer submits it manually or the Services retrieve it through a connected mailbox integration, and delete generated reports ninety (90) days after they are generated. Run history, which can include scanned URLs and device hostnames, is retained for the life of Customer’s account and is deleted when the account is deleted, unless Customer deletes it earlier through an available feature or makes an effective deletion request. Application and security logs are retained for one (1) year, sign-in records are retained until the user deletes their account, and support records for up to one (1) year, for security, troubleshooting, and record-keeping purposes, and integration credentials are retained only as described in Section 3.4. An effective deletion request is a written request sent by Customer’s account administrator to the address in Section 10.4 that identifies the account and the Customer Personal Data to be deleted. Blue Lantern will complete an effective deletion request within thirty (30) days after receipt, subject to the exceptions in Section 7.3. A consumer request that Customer forwards under Section 8.3 follows the period stated in that section. Customer is responsible for exporting reports while they remain available.

7.2 Cancellation and Account Closure. Cancelling a Seat License does not itself close Customer’s account. The account may revert to the Free Tier, and ordinary retention and deletion practices continue to apply to data still associated with it. When a Seat License is cancelled, paid continuous-monitoring features stop, and enrolled device agents, browser extensions, and mailbox integrations stop transmitting Customer Personal Data for those features, at the end of the paid billing period in which the cancellation occurs. Customer is responsible for uninstalling device agents and browser extensions, and disconnecting integrations, that it no longer intends to use. Customer may close its account at any time through its account settings or by written request to the address in Section 10.4; only an account administrator may delete an organization account, and an Authorized User may delete only that user’s own personal account. On closure of Customer’s account or termination of the Agreement in full, Customer may request return of Customer Personal Data that Blue Lantern still holds when it receives the request. Blue Lantern will provide data reasonably available for export through existing functionality or another reasonably practicable format; the request does not suspend the ordinary deletion periods for submitted content or reports.

7.3 End-of-Service Election. On closure of Customer’s account or termination of the Agreement in full (the “End of Service”), Customer may elect return or deletion of remaining Customer Personal Data. If Customer elects deletion or gives no election within 15 days after the End of Service, Customer instructs Blue Lantern to delete or irreversibly de-identify remaining Customer Personal Data in accordance with its documented deletion procedures. If Customer elects return, Blue Lantern will make the data available as described in Section 7.2 and then delete or irreversibly de-identify remaining copies in the same manner. Blue Lantern will complete that process without undue delay, subject to information it must retain by law and copies held in backups pending their ordinary, access-restricted deletion cycle, which will not exceed seven (7) days. It will not use retained copies for another purpose. On reasonable written request, Blue Lantern will confirm completion of deletion.


8. U.S. State Privacy Terms

8.1 Limited Purposes. Where the CCPA or another applicable U.S. state privacy law governs Customer Personal Data, Customer discloses that information to Blue Lantern solely for the limited and specified business purposes of providing, securing, supporting, and troubleshooting the security-analysis and monitoring features Customer enables, as described in Sections 3.2, 3.4, and 3.5 and Annex A. Blue Lantern will comply with the provisions of that law applicable to it as a service provider, contractor, or processor and will provide the same level of privacy protection that law requires of businesses.

8.2 Restrictions. Blue Lantern will not sell or share Customer Personal Data; retain, use, or disclose it outside its direct business relationship with Customer or for purposes beyond the limited purposes in Section 8.1; or combine it with information obtained from another customer or from Blue Lantern’s own interactions with individuals, except to the extent the applicable law permits. Blue Lantern certifies that it understands and will comply with these restrictions.

8.3 Oversight and Remediation. Customer may take reasonable and appropriate steps to verify that Blue Lantern processes Customer Personal Data consistently with applicable law, including through Section 6. Blue Lantern will notify Customer if it determines it can no longer meet its applicable obligations. On notice of unauthorized processing, Customer may take reasonable and appropriate steps to stop and remediate it, including directing Blue Lantern to suspend affected processing. Customer will tell Blue Lantern when a consumer request requires action by Blue Lantern and provide the information reasonably needed to fulfill it; Blue Lantern will complete the required action within thirty (30) days after receiving Customer’s notice and that information, or by any earlier date that Customer reasonably specifies in that notice as necessary to meet a legal deadline applicable to the request (but not earlier than ten (10) business days after receipt), or within a longer period the parties agree in writing.


9. International Transfers

9.1 Conditional Application. This section applies only to a Restricted Transfer. The presence of an EU-, UK-, or Swiss-located person in data processed by a U.S. customer does not, by itself, establish that Customer makes a Restricted Transfer to Blue Lantern. Customer will notify Blue Lantern in writing before Customer, or an end client for which Customer acts, begins making a Restricted Transfer, and will provide the information needed to complete the applicable transfer instrument, including the name, address, and contact details of each data exporter and the identity of its competent supervisory authority. The parties will then reasonably cooperate to assess the particular transfer. As provided in the Agreement, Blue Lantern does not offer organization accounts or Seat Licenses to Customers established in the European Economic Area, the United Kingdom, or Switzerland, or to managed service providers for use on behalf of end clients established in those jurisdictions, except under a signed agreement, and Blue Lantern may suspend the affected Services if it learns that a Customer or end client is so established without such an agreement.

9.2 EU Transfers. For a Restricted Transfer subject to the EU GDPR, the parties incorporate the unmodified standard contractual clauses in Commission Implementing Decision (EU) 2021/914 (“EU SCCs”). Module Two applies when Customer is a controller exporting personal data to Blue Lantern as processor; Module Three applies when Customer exports it as a processor and Blue Lantern receives it as a subprocessor. Clause 7 applies; Clause 9 uses Option 2, with the notice period in Section 4.2; the optional independent dispute-resolution language in Clause 11 does not apply; for Clause 13, the competent supervisory authority is determined under the option in Clause 13(a) that applies to the data exporter, as identified in the information Customer provides under Section 9.1; and the law and courts selected for Clauses 17 and 18 are those of Ireland. The information required for Annexes I, II, and III is supplied by Annex A and Annex B to this DPA, the Subprocessor List, and the information Customer provides under Section 9.1, supplemented by the parties’ account or order details. For a Restricted Transfer subject to the Swiss Federal Act on Data Protection (“FADP”), the EU SCCs apply with these adaptations: references to the EU GDPR are read as references to the FADP; the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority; and the term “Member State” does not prevent data subjects habitually resident in Switzerland from bringing claims in Switzerland.

9.3 UK Transfers. For a Restricted Transfer subject to the UK GDPR, the parties incorporate the ICO’s International Data Transfer Addendum to the EU SCCs (“UK Addendum”). Its Tables 1 through 3 are completed by the parties’ account or order details, the selections in Section 9.2, Annexes A and B, the Subprocessor List, and the information Customer provides under Section 9.1. For Table 4, neither party may end the UK Addendum under its Section 19. The UK Addendum governs its own application, governing law, and forum.

9.4 Transfer Review and Priority. Each party will reasonably cooperate in assessing a Restricted Transfer and any supplementary measures it requires. The EU SCCs or UK Addendum prevail over a conflicting provision of this DPA or the Agreement to the extent of that conflict. Nothing in the Agreement’s liability cap limits a data subject’s rights under those instruments or liability that those instruments prohibit the parties from limiting.


10. Liability, Term, and General Terms

10.1 Liability. As between Blue Lantern and Customer, claims under this DPA count toward, and are subject to, the aggregate liability limits and exclusions in the Agreement, except to the extent Section 9.4 or applicable law requires otherwise. This DPA does not create an additional liability cap, and the Agreement’s limitations on Blue Lantern’s liability do not limit Customer’s obligations under the next sentence. Customer will defend, indemnify, and hold harmless Blue Lantern and its officers and employees from and against third-party claims and regulatory proceedings, including claims by Customer’s personnel, end clients, or other data subjects, and resulting losses, fines, penalties, and reasonable attorneys’ fees, to the extent arising from Customer’s breach of its representations and warranties in Section 1.2 or its failure to meet its obligations under Section 2.2 or Section 2.3. This obligation supplements, and does not limit, Customer’s indemnification obligations under the Agreement, and the procedures in this Section 10.1 apply to both. Blue Lantern will give Customer prompt written notice of the claim, sole control of its defense and settlement, and reasonable cooperation at Customer’s expense; a delay in notice relieves Customer of its obligations only to the extent the delay materially prejudices the defense. Customer will not settle a claim in a manner that imposes an obligation on, or admits fault by, Blue Lantern without Blue Lantern’s prior written consent, and Blue Lantern may participate in the defense with counsel of its choosing at its own expense.

10.2 Term and Changes. This DPA remains effective while Blue Lantern processes Customer Personal Data on Customer’s behalf, including any period required to complete Section 7. Section 3.1, the restrictions on de-identified information and threat indicators in Section 3.2, the confidentiality of audit reports under Section 6.3, Section 10.1, and any other provision that by its nature is intended to survive will survive the end of this DPA. Blue Lantern may update it to reflect changes in law or the Services by posting an updated version, identified by version number and effective date, at https://bluelanternsecurity.io/dpa, provided it gives Customer reasonable advance notice of a material change that reduces protection for Customer Personal Data. An update takes effect on its stated effective date, and Customer’s continued use of the Services after that date constitutes acceptance of the update. Blue Lantern will keep prior versions and make them available on request. An update does not modify a DPA that the parties have signed unless Customer agrees to the update in writing. A change to Subprocessors follows Section 4.

10.3 Precedence. The Agreement otherwise remains in effect. If this DPA conflicts with the Agreement concerning Customer Personal Data, this DPA controls, subject to Section 9.4. Any signed customer agreement that changes this DPA must identify the affected provision expressly. The privacy policy describes Blue Lantern’s practices but does not replace either party’s obligations under this DPA.

10.4 Notices. Notices from Blue Lantern under this DPA will be sent to Customer’s account administrator or the contact identified in a signed order. Customer will send notices under this DPA, including deletion requests, Subprocessor objections, and audit requests, by email to [email protected].


Annex A: Description of Processing

Subject matter and duration. Blue Lantern processes Customer Personal Data to provide the features Customer enables, for as long as Customer uses those features and through the return or deletion process in Section 7.

Nature and purposes. Processing may include retrieving and analyzing connected mailbox content and metadata; analyzing submitted emails, files, domains, IP addresses, and URLs; monitoring enrolled browsers, which transmit to Blue Lantern the URLs of most web pages visited by monitored users; monitoring enrolled devices, whose agents report hostnames and security-check results; monitoring identity systems; storing integration credentials; generating findings and run history; and maintaining and securing the Services. Cloud analyzers may perform WHOIS, RDAP, and DNS lookups or load URLs from Blue Lantern’s servers as described in Section 3.5.

Categories of people. Customer’s personnel and Authorized Users; people whose mailboxes, browsers, devices, or directory accounts Customer monitors; senders, recipients, and people identified in analyzed materials; and, for managed service providers, comparable individuals associated with their end clients.

Types of information. Names and contact details; email content, attachments, and metadata; submitted files and their contents; visited or submitted URLs; device hostnames and check results; directory, OAuth, and mailbox configuration data; integration credentials; and reports, findings, and run history. Emails and files may incidentally contain sensitive personal information.

Frequency. Processing occurs when Customer submits an item or activates an integration or continuous-monitoring feature. Device agents ordinarily report approximately hourly.

Retention. Blue Lantern retains Customer Personal Data for the periods described in Sections 3.4 and 7 and then deletes or irreversibly de-identifies it, subject to the exceptions in Section 7.3.


Annex B: Security Measures and Subprocessor Information

Measures. Blue Lantern maintains the following measures, which it may update under Section 3.3: encryption of Customer Personal Data in transit using TLS 1.2 or higher and at rest using AES-256 or equivalent provider-managed encryption; role-based access controls and multi-factor authentication for production systems and connected-integration credentials, limited to personnel who need access under Section 3.1; encrypted storage of connected-integration credentials in a dedicated secrets-management service (AWS Secrets Manager); logical separation of customer accounts; authentication and security logging; vulnerability scanning and timely patching of production systems; encrypted backups retained for no more than seven (7) days for the primary application database and thirty-five (35) days for API key records; and documented processes for detecting, responding to, and recovering from security events. Its URL-analysis environment is designed to isolate loaded pages from the production environment. The parties acknowledge that Blue Lantern’s SOC 2 Type 1 report, available through its Vanta Trust Center subject to access restrictions, is evidence of the design of controls as of the date of that examination.

Initial Subprocessors. As of the effective date of this DPA, Blue Lantern uses the following Subprocessors, and from that date the Subprocessor List under Section 4.2 supersedes this list: Amazon Web Services provides hosting, storage, compute, and authentication infrastructure in the United States; and Cloudflare, Inc. provides content delivery and network security services globally, through its edge network.