← Back to Legal

Legal

Data Processing Agreement

Last updated: June 19, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Customer," "Controller") and Dino, operated by AltraBlock Inc, Wilmington, Delaware, United States ("Dino," "Processor"), governing Dino's processing of personal data on Customer's behalf.

1. Roles

Customer is the Controller of personal data it processes using Dino. Dino is the Processor and processes personal data only on Customer's documented instructions. For account identity and billing data, Dino may act as an independent Controller.

2. Subject matter and duration

Processing is for the purpose of providing the Dino platform, for the term of Customer's subscription, plus the deletion window in our Data Retention and Deletion Policy.

3. Nature and purpose

Storing and processing API configurations, encrypted credentials, scan data and findings, identity data, and tenant-anonymous analytics, to deliver the service.

4. Data and data subjects

Data subjects include Customer's authorized users and any individuals whose personal data appears in Customer's API responses captured during scanning. Customer controls which targets it scans and therefore what data its scans capture, and Customer is responsible for having a lawful basis for any personal data its scans process.

5. Processor obligations

Dino will: process only on documented instructions; ensure persons authorized to process are bound by confidentiality; implement the technical and organizational measures in Annex A; engage sub-processors only as set out in Section 7; assist Customer with data-subject requests and with security, breach, and impact-assessment obligations; delete or return data at the end of the service per our Data Retention and Deletion Policy; and make available the information necessary to demonstrate compliance and allow audits as set out in Section 8.

6. Security measures

Dino's technical and organizational measures are described in our Security Overview and Credential Handling pages and summarized in Annex A. They include AES-256-GCM per-tenant encryption, tenant isolation, access controls, SSO, SCIM, MFA, audit logging, redaction of secrets, and regional data residency.

7. Sub-processors

Customer authorizes Dino to engage the sub-processors listed at our Sub-processors page. Dino will give notice before adding or replacing a sub-processor that processes customer personal data, and Customer may object on reasonable data-protection grounds. Dino remains liable for its sub-processors.

8. Audit

Dino will make available its compliance documentation, including its SOC 2 report once available, and will respond to reasonable audit requests, subject to confidentiality and reasonable limits on frequency and scope.

9. International transfers

Where Dino transfers personal data out of the EEA, the United Kingdom, or Switzerland, the European Commission Standard Contractual Clauses apply and are incorporated by reference, with the UK International Data Transfer Addendum and the Swiss addendum as applicable. Where Dino or a relevant sub-processor is certified under the EU-US Data Privacy Framework, that mechanism may also apply. Dino's regional residency offering lets Customer minimize cross-border transfer.

10. Breach notification

Dino will notify Customer of a personal-data breach without undue delay and within 72 hours of confirming the breach, as described in our Incident Response process, including, to the extent known, the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken.

11. Deletion and return

On termination, Dino deletes or returns customer personal data per our Data Retention and Deletion Policy, except where retention is legally required.

12. Liability and precedence

Liability under this DPA is subject to the limitations in the agreement between the parties. In the event of conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the main agreement with respect to the processing of personal data.

13. Governing law

This DPA is governed by the State of Delaware, United States, without prejudice to the governing law of the Standard Contractual Clauses.

Annexes

  • Annex A: Technical and organizational measures (Security Overview and Credential Handling).
  • Annex B: Sub-processors (the Sub-processors page).
  • Annex C: Standard Contractual Clauses, executed, with modules selected.

To request a signed DPA, contact legal@usedino.dev.

For general questions, visit our Contact page.