1. Parties and roles
- Controller: the organisation named in the order (the "Organisation").
- Processor: Marcus Lenngren, trading as ThreatNoir, Sweden (organisation number stated in the order), operating ThreatNoir Academy at quiz.threatnoir.com (the "Processor").
The Organisation decides whom it enrols and for what purpose. The Processor processes personal data only on the Organisation's documented instructions, as set out in this agreement.
2. Subject matter, nature, purpose and duration
The Processor provides a weekly security-awareness exercise and, for members the Organisation flags, a quarterly executive brief, with a per-person completion record and a training register. The Organisation uses the register as evidence of training activity, for example under NIS2 Article 20(2) and 21(2)(g) or DORA Article 13(6). Organisations may also draft their own quizzes in Studio.
Processing lasts for the term of the order and the retention periods in section 11. The categories of people and data are listed in Annex 1.
3. Instructions
The Organisation instructs the Processor to:
- enrol the people its administrators invite, and remove the people they remove;
- send them the invitation, sign-in links, one email when each week's exercise is published and any quiz the Organisation sends, each with an unsubscribe option;
- record eligibility and completion, and make completion, time and score per person available to the Organisation's administrators;
- produce training registers on request, and send administrators a weekly digest;
- in Studio, draft quizzes from the brief and material an administrator provides, for that administrator to review before publishing.
Settings and actions of the Organisation's administrators in the service are instructions too. Any other processing needs a written instruction. The Processor tells the Organisation if it believes an instruction breaks data protection law, and does not carry it out.
4. Confidentiality
Only the Processor's operator has access to the Organisation's personal data, and is bound by confidentiality. Anyone the Processor later authorises will be bound in the same way before getting access.
5. Security
The Processor applies the technical and organisational measures in Annex 2 (GDPR Article 32), and may improve them but not lower the level of protection.
6. Sub-processors
The Organisation authorises the sub-processors in Annex 3. The Processor tells the Organisation's administrators by email at least 30 days before adding or replacing one. The Organisation may object on reasonable data protection grounds; if that cannot be resolved, it may end the affected part of the order without penalty.
The Processor binds each sub-processor to data protection obligations at least as protective as this agreement, and remains responsible to the Organisation for its sub-processors' performance.
7. Location and transfers
The Processor is based in Sweden. The Organisation's data is stored in the EU, and the application runs in the EU. Where a sub-processor in Annex 3 handles data from outside the EU/EEA, the transfer is covered by the EU-US Data Privacy Framework or the European Commission's standard contractual clauses, as stated there.
8. Assistance
The Processor helps the Organisation answer requests from the people it enrolled: it exports a person's record as CSV, corrects it, or erases it (section 11). It forwards to the Organisation any request it receives directly about an Academy record. On request it also provides the information the Organisation needs for an impact assessment or a prior consultation.
9. Personal data breaches
The Processor notifies the Organisation of a personal data breach affecting the Organisation's data without undue delay, and within 48 hours of becoming aware of it. The notice describes what happened, the people and data affected, the likely consequences and the measures taken, so the Organisation can meet GDPR Article 33. Information that is not yet available follows as soon as it is.
10. What administrators see
Administrators see completion, time and score per person, and the questions missed most across the Organisation only once at least five people have answered them. They cannot see which answers a person got wrong: individual answers are kept only for the person's own result and for statistics, and are never made available to the Organisation.
The Organisation will not use the service to evaluate individual employees beyond confirming participation. Before enrolment it informs the people it enrols about this processing and, where that applies, consults their representatives.
11. Retention, return and deletion
- Membership and completion records are kept while a person is a member and for 24 months after they are removed, so the training register stays truthful for audits. After that the person's name and email address are erased automatically, and the register shows a nameless "Former member" with a stable reference.
- On the Organisation's written request, the Processor erases a person's identity data within 30 days.
- Keyed IP hashes are removed after 30 days.
- When the order ends, the Processor gives the Organisation a final training register on request, then deletes the Organisation's data within 30 days. Backups expire within a further 30 days.
12. Information and audits
The Processor makes available the information needed to show it meets this agreement. The Organisation may audit compliance once a year on 30 days' notice, in the first instance through the Processor's written documentation and test evidence, and more often after a personal data breach.
13. Term, liability and precedence
This agreement lasts as long as the order and the retention periods in section 11, which survive the end of the order together with sections 8 and 9. Liability follows the order. If the order and this agreement conflict on personal data, this agreement prevails. Swedish law applies.
Annex 1. Description of the processing
| People | The Organisation's employees, contractors and members of its management body whom it enrols, and its administrators. |
| Membership data | Work email address; display name if set; role (administrator or member); management-body flag; status and when the person was invited, joined or removed; email preferences; unsubscribe token; invitation token (stored as a hash) and its expiry. |
| Participation | Per exercise: eligibility, completion time, score and time taken. Per answer: the option chosen and whether it was right, kept for the person's own result and for statistics only (section 10). |
| Sign-in | The account identifier and email address in the authentication service; session cookies. |
| Logs | An email send log (message type, period, keyed hash of the recipient address, provider message id); keyed IP hashes, removed after 30 days. |
| Studio | The brief, pasted material and drafts an administrator creates. These should contain no personal data and are screened for it before any processing. |
| Training registers | The CSV and PDF registers administrators export, which list members and their completion. Each is stored with a hash and a verification id. |
| Special categories | None. |
| Purpose | Delivering security-awareness training and recording participation as evidence of training activity. |
| Frequency | Continuous, for the term of the order. |
Annex 2. Technical and organisational measures
- Location: database, authentication and files in the EU (AWS Ireland); the application runs in the EU (Stockholm).
- Access control: the database denies all direct access (row-level security on every table). All access goes through server code that checks, on every request, which organisation it belongs to; another organisation's data answers "not found".
- Authentication: single-use, time-limited sign-in links, with no passwords. Invitations are 256-bit tokens, stored only as hashes, single use and valid for 14 days.
- Encryption: TLS for all traffic; data encrypted at rest by the database provider.
- Data minimisation: individual answers are never shown to the Organisation; most-missed statistics only in aggregate (at least five people); IP and email addresses in logs only as keyed hashes; IP hashes removed after 30 days.
- Studio safeguards: before any AI call, a deterministic screen rejects personal data (including Swedish personal identity numbers and card numbers) and injection attempts. The AI provider does not train models on this data.
- Evidence integrity: each exported register is hashed (SHA-256) and can be verified by its id, without exposing personal data.
- Testing: automated tests check the separation between organisations and that no database object can be read with the public key.
- Email: no tracking pixels or click tracking; an unsubscribe link in every message.
- Operations: production access is limited to the Processor's operator; secrets are kept out of source code.
- Resilience: daily database backups by the database provider.
Annex 3. Sub-processors
| Sub-processor | Service and data | Location and safeguard |
|---|---|---|
| Supabase | Database, sign-in and file storage: all data in Annex 1. | EU (AWS Ireland). Supabase's DPA with standard contractual clauses covers support access from outside the EU. |
| Vercel | Hosting and running the application: requests in transit (IP address, session cookie) and technical logs. | EU (Stockholm) for the application, plus a global delivery network. Vercel's DPA with standard contractual clauses. |
| Resend | Email delivery: recipient address, organisation name, message content. | USA. Resend's DPA: standard contractual clauses and the EU-US Data Privacy Framework. |
| Anthropic | Studio only: drafting questions from an administrator's brief and material, after the personal-data screen. | USA. Anthropic's DPA with standard contractual clauses; no model training on this data. |
| Google Workspace | Email correspondence with administrators at academy@threatnoir.com. | EU and USA. Google's Cloud Data Processing Addendum. |
Cloudflare provides DNS for quiz.threatnoir.com. It does not see the service's traffic or data, so it is not a sub-processor.