Data Processing Addendum
This Addendum applies where you use SSH Protector as a business customer and, in doing so, we process personal data for which you are the controller. It forms part of the Terms of Service and takes effect automatically — no signature is required.
1. Scope and roles
In this Addendum, "controller", "processor", "personal data", "processing", "data subject", "personal data breach" and "supervisory authority" have the meanings given in Regulation (EU) 2016/679 (the GDPR).
You are the controller and File Master LLC is the processor for personal data that reaches us because of how you use the service — principally the identifying details of the servers you protect and of the users you invite into your organisation.
We act as an independent controller, not as your processor, for: our own account and billing records about you; security and abuse prevention on our own infrastructure; and the shared threat-intelligence database described in clause 5 of the Privacy Policy, which concerns attacking networks rather than your people. Those activities are governed by the Privacy Policy, not by this Addendum.
2. Subject matter of the processing
The subject matter, duration, nature and purpose of the processing, the categories of personal data and the categories of data subjects are set out in Annex 1. The processing lasts for the term of your subscription, plus the deletion period in clause 10.
3. Processing on instructions
- We process personal data only on your documented instructions, including as to international transfers, unless required to do otherwise by EU or Member State law. The Terms of Service, this Addendum and your configuration of the service together constitute your complete documented instructions.
- Where a legal requirement compels us to process beyond your instructions, we will inform you of that requirement before processing, unless the law prohibits it on important grounds of public interest.
- We will tell you if, in our opinion, an instruction infringes the GDPR or other data protection law. We may suspend the affected processing until the instruction is changed or confirmed.
4. Confidentiality
We ensure that every person authorised to process personal data under this Addendum is bound by an appropriate obligation of confidentiality, whether contractual or statutory, that survives the end of their engagement. Access is limited to personnel who need it to perform their duties.
5. Security measures
We implement appropriate technical and organisational measures under Article 32 of the GDPR, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing, as well as the risk to data subjects. The measures in place are described in Annex 2.
We may update these measures, provided that the overall level of security is not reduced.
6. Sub-processors
- You give general authorisation for us to engage sub-processors. Those engaged at the effective date are listed in Annex 3.
- We will give you at least 30 days' notice by email, to the address on your account, before a new sub-processor begins processing your personal data.
- You may object on reasonable data-protection grounds within that period. We will work with you in good faith to find an alternative. If none is available, you may terminate the affected subscription without penalty and receive a pro-rata refund of prepaid fees for the unused remainder of the term.
- We impose on each sub-processor data protection obligations no less protective than those in this Addendum, and we remain fully liable to you for their performance.
7. Assisting with data-subject rights
The panel lets you view, correct, export and delete the personal data in your organisation yourself, which is normally sufficient to answer a data-subject request.
Where it is not, we will assist you by appropriate technical and organisational measures, insofar as possible, to fulfil your obligation to respond to requests to exercise rights under Chapter III of the GDPR. If a data subject contacts us directly about data we process on your behalf, we will not respond substantively; we will forward the request to you promptly.
8. Assisting with security and impact assessments
Taking into account the nature of processing and the information available to us, we will assist you in ensuring compliance with Articles 32 to 36 of the GDPR — security of processing, breach notification, data protection impact assessments, and prior consultation with a supervisory authority.
9. Personal data breaches
We will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting personal data processed on your behalf. The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the full picture is not available at once, we will provide it in phases without further undue delay.
Notification is not an acknowledgement of fault or liability. Deciding whether to notify a supervisory authority or data subjects remains your responsibility as controller.
10. Return and deletion
On termination of the service, and at your choice, we will delete or return the personal data processed on your behalf, and delete existing copies, unless EU or Member State law requires storage.
In practice: deleting your account through the panel erases account, organisation, server and audit data. Where you make no choice, we delete within 30 days of termination. Encrypted backups are purged on their normal rotation, within 90 days. Accounting records are retained where Bulgarian tax law requires, and remain subject to clause 4.
11. Audits and information
- We will make available to you all information necessary to demonstrate compliance with Article 28 of the GDPR.
- We will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits are limited to once per twelve-month period unless a personal data breach has occurred or a supervisory authority requires otherwise, must be requested at least 30 days in advance, must take place during business hours, must not unreasonably disrupt our operations, and are subject to confidentiality.
- The auditor must not be a competitor of ours. Where an audit exceeds what Article 28 requires, we may charge our reasonable costs, agreed with you in advance.
12. International transfers
Personal data processed on your behalf is hosted in the European Union. Where a sub-processor in Annex 3 is established outside the EEA and a transfer of your personal data occurs, it takes place under an adequacy decision where one applies, or otherwise under the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, Module Three (processor to processor), which are incorporated into this Addendum by reference and completed as follows: the data exporter is File Master LLC acting on your behalf; the data importer is the sub-processor; Annexes I, II and III to the Clauses are populated by Annexes 1, 2 and 3 to this Addendum; the optional docking clause applies; the governing law and forum are those of Bulgaria.
13. Liability and precedence
The limitations of liability in the Terms of Service apply to this Addendum, except where the GDPR provides otherwise. If this Addendum conflicts with the Terms of Service or the Privacy Policy on the processing of personal data for which you are the controller, this Addendum prevails. The Standard Contractual Clauses prevail over this Addendum where they conflict.
Annex 1 — Details of processing
| Subject matter | Provision of managed brute-force protection for Linux servers. |
|---|---|
| Duration | The term of the subscription, plus the deletion period in clause 10. |
| Nature and purpose | Collecting failed-authentication telemetry from agents you install; evaluating it against the protection policy you configure; instructing the agent to block sources; storing attack history for the retention window of your plan; presenting it in the panel; delivering alerts you configure. |
| Categories of data subjects | Your personnel who hold accounts in your organisation; where your protected servers are individuals' machines, the users of those machines. |
| Categories of personal data | Email addresses and roles of organisation members; server hostnames, display names, operating system versions and public IP addresses; administrative audit records identifying who performed which action and when; support correspondence. |
| Special categories | None. The service is not designed for special-category data and you must not submit it. |
| Frequency | Continuous for the duration of the subscription. |
Annex 2 — Technical and organisational measures
- Encryption in transit. TLS on every connection between the agent, the browser and the panel.
- Credential storage. Passwords stored only as slow one-way hashes; agent keys stored hashed and centrally revocable.
- Access control. Role-based access within organisations; multi-factor authentication available on all accounts; production access limited to personnel who require it.
- Least privilege on the host. The agent reads only its own host's authentication log and writes only inbound nftables rules on that host; it has no remote-execution capability and opens no inbound port.
- Network hardening of the panel. Strict Content-Security-Policy, HSTS, frame denial, MIME-sniffing protection and a restrictive permissions policy on all responses.
- Auditability. Append-only audit log of administrative actions, retained with the organisation.
- Segregation. Data is partitioned by organisation; cross-tenant access is prevented at the data-access layer.
- Resilience. Agents decide bans locally, so protection survives loss of connectivity to the panel.
- Backups. Encrypted, rotated, and purged on the schedule in clause 10.
- Sub-processor diligence. Data protection terms no less protective than this Addendum imposed on each sub-processor.
Annex 3 — Approved sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Hosting provider (panel, databases, analytics store) | Infrastructure | European Union |
| PayPro Global | International payment processing | Canada / EU |
| YooKassa | Payment processing in the Russian Federation | Russian Federation |
| Google LLC | OAuth sign-in; website analytics | United States / EU |
| GitHub, Inc. | OAuth sign-in | United States |
| IPinfo | Resolving an IP address to its network, operator and country | United States |
| Telegram | Optional alert delivery, where you enable it | Outside the EEA |
| Email delivery provider | Transactional email | European Union |
Contact
File Master LLC
Serena app., office C13, Golden Sands, Varna 9007, Bulgaria
VAT: 180842207
Email: tech.support@recoverytoolbox.com
Phone: +359 88 2253194
SSH Protector