This Data Processing Agreement ("DPA") forms part of the Adversary X Terms of Service and applies to every customer. It sets out the terms on which Canary Zero Ltd processes personal data on a customer's behalf, as required by Article 28 of the UK GDPR.
Where a customer has signed a separate Data Processing Agreement with us, that signed version applies in place of this one.
| Field | Detail |
|---|---|
| Processor | Canary Zero Ltd, a company registered in England and Wales, 71–75 Shelton Street, London WC2H 9JQ ("Canary Zero") |
| Customer | The organisation that has accepted the Adversary X Terms of Service (the "Customer"). |
| Principal Agreement | The Adversary X Terms of Service, together with any Order Form or Enterprise Agreement between Canary Zero and the Customer. |
| Customer capacity | Controller, where the Customer uses Adversary X for its own organisation. Processor, where the Customer is a managed service provider using Adversary X on behalf of its Clients (see clause 3.3). |
| Effective Date | The date the Customer first accepts the Terms of Service, or the date access is first provisioned, whichever is earlier. |
| Customer privacy contact | The Account Administrator’s email address held in the Customer’s account, unless the Customer tells us to use a different contact. |
| Canary Zero privacy contact | support@adversary-x.com |
1.1 Canary Zero provides Adversary X, an AI-driven cyber incident, crisis and operational-resilience tabletop exercise platform (the "Services"), to the Customer under the Principal Agreement.
1.2 In providing the Services Canary Zero will process personal data on behalf of the Customer. This Data Processing Agreement ("DPA") sets out the terms on which that processing takes place, as required by Article 28 of the UK GDPR.
1.3 This DPA forms part of, and is subject to, the Principal Agreement. If there is a conflict between this DPA and the Principal Agreement in relation to the processing of personal data, this DPA prevails.
2.1 In this DPA the following terms have the meanings given below. Terms defined in Data Protection Law (including "controller", "processor", "data subject", "personal data", "personal data breach", "processing" and "supervisory authority") have the same meaning here.
3.1 The parties acknowledge that, in respect of Customer Personal Data, the Customer is the controller (or, under clause 3.3, a processor acting for its Clients) and Canary Zero is a processor.
3.2 Canary Zero acts as an independent controller, and this DPA does not apply, in respect of: (a) account credentials and authentication data for the Customer's users; (b) billing and contractual records; (c) Canary Zero's own security, audit and operational logs; (d) anonymised and aggregated benchmark statistics that do not identify the Customer, its Clients or any individual; and (e) Canary Zero's communications with the Customer's personnel. That processing is described in the Adversary X Privacy Policy.
3.3 Managed service providers. Where the Customer is a managed service provider using the Services on behalf of its Clients, the Customer warrants that (a) it is authorised by each Client, as controller, to engage Canary Zero as a sub-processor on the terms of this DPA; (b) its contract with each Client contains data protection terms no less protective than this DPA; (c) it will pass on to Canary Zero only those instructions that are consistent with its Clients' instructions; and (d) it will handle all communication with its Clients and their data subjects. Canary Zero has no direct contractual relationship with Clients, and references in this DPA to the Customer's instructions include instructions the Customer gives on behalf of its Clients.
3.4 The Customer is responsible for ensuring it has a lawful basis for the processing, that appropriate notices have been given to data subjects (including exercise participants whose names and roles are recorded in the Services), and that the Customer Personal Data does not include special category data, criminal offence data, or real operational data (such as live credentials or customer records) that is not required to run a tabletop exercise.
4.1 Instructions. Canary Zero will process Customer Personal Data only on the documented instructions of the Customer, which are: (a) to provide the Services in accordance with the Principal Agreement and the configuration selected by the Customer's users; (b) as further set out in Annex 1; and (c) any other reasonable written instruction consistent with the Principal Agreement. Canary Zero will inform the Customer if, in its opinion, an instruction infringes Data Protection Law, and may suspend the relevant processing until the instruction is confirmed or withdrawn.
4.2 Required by law. Canary Zero may process Customer Personal Data where required by UK or EU law to which it is subject, in which case it will inform the Customer of that requirement before processing unless the law prohibits this on important grounds of public interest.
4.3 Confidentiality. Canary Zero will ensure that all persons authorised to process Customer Personal Data are bound by written confidentiality obligations and receive appropriate data protection training, and will limit access to those who need it to provide the Services.
4.4 Security. Canary Zero will implement and maintain the Security Measures, and such further measures as are appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing. Canary Zero may update the Security Measures from time to time provided the overall level of security is not reduced.
4.5 Data subject requests. Taking into account the nature of the processing, Canary Zero will assist the Customer by appropriate technical and organisational measures in responding to requests from data subjects exercising their rights under Data Protection Law. The Services include self-service export and deletion for individual users. Canary Zero will promptly (and in any case within five business days) notify the Customer if it receives a request directly from a data subject relating to Customer Personal Data, and will not respond to it except on the Customer's instructions or where required by law.
4.6 Assistance with compliance. Canary Zero will provide reasonable assistance to the Customer in meeting its obligations under Articles 32 to 36 of the UK GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to Canary Zero. Canary Zero may charge its reasonable costs for assistance that goes beyond what is required of a processor by Data Protection Law.
4.7 Deletion and return. On termination or expiry of the Principal Agreement, or on the Customer's earlier written request, Canary Zero will delete all Customer Personal Data within 30 days, or return it in a commonly used machine-readable format if the Customer so requests before deletion, and will delete existing copies unless UK or EU law requires storage. Customer Personal Data may persist in encrypted backups for up to a further 30 days before those backups are cycled out and will not be restored except to recover from a system failure. Sub-processors listed in Annex 2 may retain residual copies of Customer Personal Data for up to 90 days after deletion in accordance with their own data processing terms (currently Clerk and Resend).
4.8 Records. Canary Zero will maintain a record of the categories of processing carried out on behalf of the Customer as required by Article 30(2) of the UK GDPR and make it available to the Customer on request.
5.1 The Customer gives Canary Zero general written authorisation to engage the Sub-processors listed in Annex 2, and any replacement or additional Sub-processor appointed in accordance with this clause 5.
5.2 Canary Zero will give the Customer at least 30 days' prior written notice (by email to the Customer privacy contact) of any intended addition or replacement of a Sub-processor. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection in good faith within a further 30 days, the Customer may terminate the affected Services on written notice without penalty and Canary Zero will refund any prepaid fees for the unexpired period.
5.3 Canary Zero will impose on each Sub-processor, by written contract, data protection obligations that are no less protective than those in this DPA, and will remain fully liable to the Customer for the performance of each Sub-processor's obligations.
5.4 Canary Zero will maintain the current list of Sub-processors in the Adversary X Privacy Policy at adversary-x.com/privacy.
6.1 Canary Zero will not make a Restricted Transfer of Customer Personal Data unless it has first put in place a valid transfer mechanism under Data Protection Law. The transfer mechanisms currently relied on for each Sub-processor are described in Annex 2.
6.2 Where the Customer is established in the EEA and EU GDPR applies, the parties will additionally enter into the EU Standard Contractual Clauses (Module 2 or Module 3 as applicable) on request, which are incorporated by reference.
6.3 The Customer acknowledges that the AI features of the Services rely on a Sub-processor that processes data in the United States and that scenario content entered by its users is transferred there for the purpose of generating exercise content, under the transfer mechanism stated in Annex 2. This clause does not apply to a Client tenant configured to use the Managed Service Provider's own Anthropic API key (MSP bring-your-own-key): in that case Anthropic processes the tenant's data under the Managed Service Provider's own contract with Anthropic, Canary Zero effects no Restricted Transfer of that data, and Anthropic is not a Sub-processor of Canary Zero for those requests.
7.1 Canary Zero will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
7.2 The notification will describe, to the extent known, the nature of the breach including the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it, and a point of contact. Canary Zero may provide the information in phases as it becomes available.
7.3 Canary Zero will cooperate with the Customer and take reasonable steps as directed by the Customer to investigate, mitigate and remediate the breach. Canary Zero will not notify a supervisory authority or data subjects of a breach affecting Customer Personal Data on the Customer's behalf unless the Customer instructs it to do so or the law requires it.
8.1 Canary Zero will make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA, including on request its current security documentation, summaries of penetration test and vulnerability scan results, and its sub-processor due diligence.
8.2 No more than once in any 12-month period (or more often following a personal data breach or where required by a supervisory authority), the Customer or an independent auditor mandated by it and bound by confidentiality may audit Canary Zero's compliance with this DPA on at least 30 days' written notice, during business hours, in a manner that does not unreasonably disrupt Canary Zero's operations or compromise the security of other customers. Audits are conducted remotely and by review of documentation unless the parties agree otherwise. The Customer bears its own audit costs.
9.1 Each party's liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability in the Principal Agreement, except that nothing limits either party's liability for a data subject's right to compensation under Article 82 of the UK GDPR to the extent that liability cannot be limited by law. Each party's liability arising out of or in connection with this DPA counts towards, and is not in addition to, the limit of liability in the Principal Agreement, which applies to both parties: the total fees invoiced to the Customer under the Principal Agreement in the 12 months immediately preceding the event giving rise to the claim.
9.2 This DPA takes effect on the Effective Date and continues until Canary Zero ceases to process Customer Personal Data and has complied with clause 4.7.
9.3 If Data Protection Law changes so that this DPA no longer meets its requirements, the parties will negotiate in good faith to amend it.
9.4 This DPA is governed by the laws of England and Wales and the courts of England and Wales have exclusive jurisdiction, consistent with the Principal Agreement.
This DPA is incorporated into the Adversary X Terms of Service and applies without signature. An Enterprise or MSP customer that needs a signed copy can request one at support@adversary-x.com.
| Item | Description |
|---|---|
| Subject matter | Provision of the Adversary X cyber incident, crisis and operational-resilience tabletop exercise platform to the Customer (and, where applicable, its Clients). |
| Duration | The term of the Principal Agreement plus the deletion period in clause 4.7. |
| Nature and purpose | Hosting and storing Customer Personal Data; generating AI-driven exercise scenarios, injects and debriefs from user inputs; scoring exercise performance; producing PDF reports and board packs; sending scheduled exercise reminders; providing an administrative interface to the Customer's designated administrators. |
| Categories of data subjects | The Customer's (and its Clients') employees, contractors and other authorised users of the Services; individuals recorded as exercise attendees; individuals named in custom scenario content entered by users. |
| Categories of personal data | Name; work email address; job title; organisation and industry; region; decisions and free-text responses entered during exercises; attendee names and roles; custom scenario descriptions of the organisation's environment; exercise scores and performance history; AI-generated exercise content associated with the user; usage and diagnostic data. |
| Special category data | None. The Customer must not enter special category or criminal offence data into the Services. |
| Customer instructions | Process Customer Personal Data solely to provide the Services as configured by the Customer's users, including transmission of exercise content to the AI Sub-processor for scenario generation and debriefs; retain according to Annex 1 and clause 4.7; do not use for model training, benchmarking in identifiable form, or any other purpose. |
Current as at September 2026. The live list is maintained at adversary-x.com/privacy.
| Sub-processor | Service | Location | Transfer mechanism |
|---|---|---|---|
| Supabase Pte. Ltd. (Singapore) | Production database, storage and backups | United Kingdom (AWS London, eu-west-2) | No Restricted Transfer for data at rest (UK). Support or operational access from outside the UK: UK Addendum to EU SCCs (Supabase DPA v1, 1 Aug 2026, incorporated automatically on acceptance of the Supabase Terms of Service — cl. 12.2, no separately executed copy exists; not on DPF list, checked 2026-09-11). Supabase support personnel are distributed globally on a stated “follow-the-sun” model with no published location restriction (Supabase public DPA and subprocessor list, both checked 2026-09-11). Assessed in the TRA (Adversary-X-TRA-DRAFT.docx). |
| Clerk, Inc. | Identity, authentication, sessions, MFA | United States | UK adequacy regulations — UK Extension to the EU-US DPF (listed as Active, checked 2026-09-11; next certification due 30 Jun 2027). The Clerk DPA (26 Nov 2024) also incorporates the UK Addendum. |
| Vercel, Inc. | Application hosting, edge network, logs | United Kingdom (London, lhr1) for application functions; global edge network | UK adequacy regulations — UK Extension to the EU-US DPF (listed 2026-09-11) |
| Anthropic Ireland, Limited | Large language model API for scenario generation and debriefs. No training on inputs or outputs under commercial terms. Where a Managed Service Provider tenant supplies its own Anthropic API key (MSP bring-your-own-key), that tenant's requests are processed under the Managed Service Provider's own contract with Anthropic; Anthropic is not a Sub-processor of Canary Zero for those requests, as nothing passes through Canary Zero's own Anthropic account. | Contracting entity in Ireland; processing in the United States | UK Addendum to EU SCCs (Anthropic DPA, 24 Feb 2025). Not on DPF list, checked 2026-09-11. Assessed in the TRA (Adversary-X-TRA-DRAFT.docx). Both the no-training commitment and the SCC/UK Addendum transfer-mechanism coverage independently confirmed by Sunny direct from the Anthropic commercial contract, 2026-09-11. |
| Plus Five Five, Inc. (Resend) | Transactional email delivery | United States | UK adequacy regulations — UK Extension to the EU-US DPF (listed as Active – re-certification under review, checked 2026-09-11; next certification due 3 Mar 2027). The Resend DPA (27 Aug 2026) also incorporates the UK Addendum. |
| Cloudflare, Inc. | DNS, network proxy, Turnstile bot protection | Global network; US company | UK adequacy regulations — UK Extension to the EU-US DPF (listed 2026-09-11) |
Google, Meta and GoHighLevel process website analytics, advertising and demo-request data for which Canary Zero is the controller. They do not process Customer Personal Data under this DPA. For completeness: Google LLC and HighLevel, Inc. are listed under the UK Extension to the DPF (checked 2026-09-11); Meta Platforms, Inc. is DPF-listed but without the UK Extension — Canary Zero contracts with Meta Platforms Ireland Ltd, so the UK transfer is to Ireland under UK adequacy regulations and onward transfer is Meta's responsibility as controller.
| Area | Measure |
|---|---|
| Encryption | TLS 1.2+ for all data in transit. Encryption at rest for the production database and backups. Customer-supplied integration keys are encrypted at the application layer with a versioned key ring and a documented rotation procedure. |
| Access control | Authentication via a dedicated identity provider with multi-factor authentication required for every user, one active session per user, an 8-hour maximum session lifetime, sign-out after 30 minutes of inactivity, and user-visible sign-in history. Server-side enforcement of tier, tenant and role entitlements on every request. Administrative access limited to named individuals, recorded in an administrative audit log. |
| Tenant isolation | Enterprise and MSP data is scoped by tenant identifier and enforced in the application layer on every query; cross-tenant access is denied by default. |
| Audit logging | Append-only audit log of security-relevant user account actions, enforced at database level and retained for 12 months. Administrative actions logged separately. |
| Application security | Strict nonce-based Content Security Policy; bot protection on public forms; anti-caching of user-specific responses; route allow-listing; webhook signature verification for all inbound integrations. |
| Vulnerability management | Daily automated static analysis and dependency scanning of the codebase with findings triaged and tracked to closure. Critical dependency vulnerabilities pinned or patched on discovery. |
| Change management | All changes developed on a non-production branch, type-checked and tested before promotion to production. Production and development environments use separate credentials, identity instances and databases. |
| Backup and resilience | Automated daily database backups retained for 30 days. Hosting on a managed platform with multi-region edge delivery. |
| Data minimisation | Adversary X is invoiced directly; no card payments are taken through the platform and no card data is held. Only exercise context necessary for scenario generation is sent to the AI Sub-processor; credentials, billing and sign-in data are not. |
| Personnel | All personnel with access to production systems are bound by confidentiality obligations. Canary Zero is operated by security practitioners. |
| Incident response | Documented breach notification process meeting the timescales in clause 7. |
Adversary X is a product of Canary Zero Ltd, company number 14664394, registered in England and Wales.