Data Processing Agreement

Last updated 7 September 2026 · Forms part of our terms of service

1. Roles

For personal data you submit to Bulwark, you are the controller and BastionShield Technologies Ltd is the processor. We process that data only on your documented instructions, which are the instructions given through the product and this agreement.

For your own account data — the name and email of the people on your team, and your billing details — we act as controller, and our privacy policy applies.

2. What we process

Bulwark records that an agent action happened. It is designed not to hold the contents of that action, and content-bearing fields are stripped before anything is written to storage, along with masking of values that pattern-match payment cards, email addresses, national identifiers, bank details, phone numbers and access tokens.

We therefore expect to process agent identifiers, action types, resource names, policy verdicts, reviewer identities and timestamps. If you deliberately place personal data into a field we preserve — a resource name, for example — we will process it, and you remain responsible for that choice as controller.

3. Sub-processors

You give general authorisation for the sub-processors below. We will give you at least 30 days' notice by email before adding or replacing one, during which you may object and, if we cannot resolve the objection, terminate without penalty.

Sub-processorPurposeLocationData
Fly.ioApplication and database hostingLondon (LHR), United KingdomAll customer data at rest and in transit
ResendTransactional email (invites, password resets, verification codes)United StatesRecipient name and email address only
Amazon Web Services (Route 53)DNSGlobalNone — DNS resolution only

4. International transfers

Customer data is stored in the United Kingdom. The only routine transfer outside the UK is transactional email through Resend in the United States, which carries recipient name and email address only. That transfer relies on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. We will provide the executed documentation on request.

5. Security measures

Article 32 measures we actually operate: TLS 1.3 in transit and encryption at rest; logical tenant separation enforced at the data layer; scrypt password hashing; role-based access control on every mutating endpoint; API keys stored only as hashes; content stripping and masking before storage; and a per-tenant, hash-chained audit trail you can verify offline without our software.

We hold no third-party security certification. We are not SOC 2 or ISO 27001 certified and do not claim to be. Our security page describes our posture without implying otherwise.

6. Personnel and confidentiality

Access to production is limited to personnel who need it, under confidentiality obligations. We are a small team: at present that is a single named individual, and we would rather tell you that than describe a segregation-of-duties model we do not operate.

7. Assisting you

We will assist you with data subject requests, data protection impact assessments, and consultations with a supervisory authority, taking into account the nature of the processing and the information available to us. Because we hold metadata rather than content, we can usually export or delete a data subject's records quickly.

8. Breach notification

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need to meet your own Article 33 obligations. We notify affected customers before any public disclosure.

9. Deletion and the audit chain

You may delete your organisation at any time from Settings. Deletion is immediate and irreversible: the organisation, its users, agents, policies, approvals, API keys and the entire evidence chain are erased, and we keep no copy.

One honest limitation. The evidence chain is append-only by design — that is what makes it tamper-evident — so we cannot remove a single record from the middle of it without destroying the property the chain exists to provide. Erasure is therefore at organisation granularity, not per record. Where you need a narrower right to erasure satisfied, the practical answer is that we hold metadata rather than content in the first place.

10. Audits

We will make available the information needed to demonstrate compliance with Article 28 and will accept audits or inspections by you or your auditor, on reasonable notice and no more than once a year unless a supervisory authority or a breach requires otherwise.

11. Contact

BastionShield Technologies Ltd, registered in England & Wales, 124 City Road, London EC1V 2NX. Data protection enquiries: info@bastionshieldtechnologies.com. We have not appointed a Data Protection Officer, as we are not required to. You have the right to lodge a complaint with the Information Commissioner's Office.

This page describes how we process data and forms part of our contract with you. It is not legal advice to you, and it does not determine your own compliance obligations — those depend on your systems, your controls and your assessor.