Data Processing Agreement
Effective June 23, 2026 · Last updated June 23, 2026
This Data Processing Agreement (“DPA”) is entered into between Aether Dynamic Solutions LLC, a Wyoming limited liability company (“Aether,” “Processor”), and the customer that has agreed to Aether’s Terms of Service (the “Client,” “Controller”). It forms part of, and is governed by, that agreement (the “Agreement”). Where this DPA conflicts with the Agreement on data protection, this DPA controls.
1. Definitions
“Personal Data,” “Controller,” “Processor,” “Processing,” and “Data Subject” have the meanings given under applicable US state privacy laws (including the CCPA/CPRA). “Client Data” means data the Client submits to, or authorizes Aether to gather for, an assessment. “Subprocessor” means any third party engaged by Aether to process Client Data.
2. Roles of the parties
The Client is the Controller (or acts on behalf of the Controller) of Client Data. Aether is the Processor (service provider), and processes Client Data only on the Client’s documented instructions to provide the Services described in the Agreement. Aether will not sell Client Data or use it for its own commercial purposes or for advertising.
3. Scope and purpose of processing
Aether processes Client Data solely to perform cybersecurity risk assessments and deliver Reports as set out in the Agreement, and as further described in Annex A. The Client warrants that it has the authority and lawful basis to provide the Client Data and to authorize the assessment of the systems it submits.
4. Aether’s obligations
- Process Client Data only on the Client’s documented instructions, including as set out in the Agreement;
- Ensure personnel authorized to process Client Data are bound by confidentiality;
- Implement the technical and organizational security measures described in Annex B;
- Assist the Client, taking into account the nature of processing, in responding to Data Subject rights requests;
- Make available information reasonably necessary to demonstrate compliance with this DPA;
- Notify the Client without undue delay, and within 72 hours of discovery, of any breach affecting Client Data.
5. Subprocessors
The Client authorizes Aether to engage the Subprocessors listed in Annex C. Aether will impose data protection obligations on each Subprocessor no less protective than this DPA, and remains responsible for their performance. Aether will give the Client reasonable notice of any new Subprocessor, and the Client may object on reasonable data-protection grounds.
6. Data Subject rights and assistance
Taking into account the nature of the processing, Aether will assist the Client by appropriate measures, insofar as possible, in fulfilling the Client’s obligations to respond to requests from Data Subjects to access, correct, delete, or restrict their Personal Data.
7. Security
Aether will maintain the security measures in Annex B, including encryption of Client Data in transit and at rest, access controls on a least-privilege basis, multi-factor authentication on administrative accounts, and audit logging. Aether will review these measures periodically.
8. Personal data breach
Upon becoming aware of a breach affecting Client Data, Aether will notify the Client without undue delay and within 72 hours of discovery, describe the nature of the breach, the data affected, likely consequences, and the measures taken or proposed, and reasonably cooperate with the Client’s response.
9. Return and deletion of data
On termination of the Agreement, or on the Client’s written request, Aether will return or delete Client Data within 30 days, unless retention is required by law. Backups are deleted in the ordinary course of Aether’s retention cycle.
10. Audits
Aether will make available, on reasonable written request and no more than once per year (unless required by a regulator or following a breach), information necessary to demonstrate compliance with this DPA, subject to confidentiality and reasonable security and operational limits.
11. Location of processing
Client Data is processed and stored in the United States. Aether will not transfer Client Data outside the United States without the Client’s prior agreement and an appropriate legal transfer mechanism.
12. Liability
Each party’s liability under this DPA is subject to the limitations of liability set out in the Agreement.
13. Term
This DPA takes effect when the Client accepts the Agreement and remains in effect for as long as Aether processes Client Data.
Annex A — Details of processing
Subject matter: Provision of cybersecurity risk assessments.
Duration: For the term of the Agreement.
Nature and purpose: Assessing the security posture of the Client’s Authorized Systems and producing Reports.
Categories of data: Business name and website domain; domains/IPs the Client authorizes for scanning; exposed services/open ports; software and tech-stack inventory; security questionnaire answers; Client contact name and email.
Excluded data: Aether does not collect SSNs, financial account or card numbers, end-customer PII, health data, or credit history.
Data subjects: The Client’s authorized personnel/contacts.
Annex B — Security measures
- Encryption of Client Data in transit and at rest;
- Role-based access controls on a least-privilege basis;
- Multi-factor authentication on administrative accounts;
- Audit logging of access and key actions;
- Periodic review of security controls.
Annex C — Approved Subprocessors
Note: Update this list as tools are finalized. Current/intended subprocessors:
- Cloud hosting / storage — US-based provider (to be finalized);
- Payment processing — Stripe, Inc.;
- Website analytics — Google Analytics (GA4);
- Email — Hostinger.