This Data Processing Agreement ("DPA") is incorporated into and forms part of the RedLens AI Terms of Service between South 301 LLC ("Processor") and Customer ("Controller"). This DPA governs the processing of personal data by RedLens AI on behalf of Customer.
"Controller" means the Customer who determines the purposes and means of processing personal data.
"Processor" means RedLens AI (South 301 LLC), who processes personal data on behalf of the Controller.
"Personal Data" means any information relating to an identified or identifiable natural person.
"Processing" means any operation performed on personal data.
"Sub-processor" means any third party engaged by the Processor to assist in processing personal data.
RedLens AI processes personal data solely to deliver the security assessment services described in the Terms of Service.
Storage, analysis, and generation of security assessment results. Transmission of assessment data to AI processing infrastructure. Generation of compliance reports and vulnerability findings.
Customer employees and authorized users of the RedLens AI platform.
Account information (name, email, job title), usage data, assessment configurations, and security findings generated during platform use.
Where RedLens AI's monitoring of its own AI features is active, this can also include a short excerpt — at most 500 characters, retained no more than 30 days, readable by RedLens AI platform staff only — of text a user entered into a RedLens AI copilot. See the Privacy Policy, Section 1.
Where Customer's integration elects to send tool-call telemetry from its own AI agents, this can also include the name of a tool an agent invoked and up to 2,000 characters each of the arguments passed to it and the result returned. Such arguments and results may contain Personal Data, Protected Health Information, or criminal justice information originating in Customer's systems of record, and Customer determines what is transmitted. RedLens AI does not currently store, process for detection, or retain this telemetry; if that changes, the Privacy Policy, Section 1 will describe the change before it takes effect, and the retained text will be subject to the same staff-only access and 30-day deletion terms stated above.
Customer authorizes RedLens AI to engage the following sub-processors:
RedLens AI will notify Customer of any intended additions or replacements of sub-processors with 30 days notice. Customer may object to new sub-processors within 14 days.
For healthcare customers, RedLens AI will execute a separate Business Associate Agreement (BAA) covering Protected Health Information (PHI) as required by HIPAA. The BAA supersedes conflicting provisions of this DPA with respect to PHI. Contact support@redlens.ai to initiate a BAA.
RedLens AI implements and maintains the following technical and organizational measures:
All data processing occurs within the United States. RedLens AI does not transfer personal data outside the United States without appropriate safeguards. Customers subject to GDPR should contact us to discuss appropriate transfer mechanisms.
This DPA is effective for the duration of the subscription agreement. Upon termination, RedLens AI will delete all personal data within 90 days, except where retention is required by law.
One narrow, specific exception: where Customer has used RedLens AI's third-party AI vendor assessment feature, RedLens AI retains the resulting authorization-attestation record (who authorized the assessment, the target system, and the authorization basis) after account termination. This record exists to establish RedLens AI's own lawful-access basis under applicable computer-fraud and unauthorized-access laws before any assessment traffic was sent to a system RedLens AI does not operate — standard practice among security-testing providers, comparable to a penetration-testing firm retaining its engagement-authorization letters after an engagement ends. It is RedLens AI's own accountability record, not Customer's operational data, and is not affected by any other deletion or retention provision in this DPA or the Privacy Policy.
To execute this DPA or request a signed copy: support@redlens.ai
South 301 LLC DBA RedLens AI · August 2026
Legal Notice: This DPA is provided as a professional template. Execute signed copies with each enterprise customer. Have legal counsel review for GDPR adequacy and applicable regulations.