Western Tactics
Office Background

Data Processing Agreement

Last updated: 26 August 2026

This Data Processing Agreement ("DPA") in accordance with Article 28 of the General Data Protection Regulation (GDPR) applies to the processing of personal data by Western Tactics in the context of the delivery of the cybersecurity awareness platform Orbit (app.westerntactics.nl) to the Customer.

Section I: General Provisions

Clause 1: Purpose and Scope

  • The purpose of this DPA is to ensure compliance with Article 28(3) and (4) of Regulation (EU) 2016/679 (GDPR).
  • The Controller (the Customer) and the Processor (Western Tactics) are the parties specified in Annex I.
  • This DPA applies to the processing of personal data as specified in Annex II.
  • Annexes I through IV form an integral part of this DPA.

Clause 2: Relationship to the Main Agreement

This DPA forms an integral part of the Agreement between Western Tactics and the Customer and governs the processing of personal data by Western Tactics on behalf of the Customer.

Clause 3: Interpretation

  • Terms used in this DPA from Regulation (EU) 2016/679 (GDPR) have the same meaning as in that Regulation.
  • This DPA must be read and interpreted in light of the provisions of the GDPR.

Clause 4: Hierarchy

In the event of any conflict between this DPA and any other agreement between the Parties, this DPA shall prevail exclusively to the extent that the conflict relates to the processing and protection of personal data. The limitations of liability agreed in the Main Agreement remain applicable to this DPA, to the extent permitted under applicable law.

Section II: Obligations of the Parties

Clause 5: Instructions and Purpose Limitation

  • The Processor shall process personal data solely on the basis of documented instructions from the Controller, unless required to do so by Union or Member State law.
  • The Processor shall process the data exclusively for the specific purposes set out in Annex II.
  • If the Processor believes that an instruction from the Controller infringes the GDPR or other Union or Member State data protection provisions, the Processor shall inform the Controller immediately.

Clause 5A: Rights and Obligations of the Controller

The Controller is responsible for the lawfulness of the processing of personal data and for the lawfulness, accuracy, and adequacy of the instructions provided to the Processor. The Controller guarantees that a valid legal basis exists for the processing and that data subjects have been informed in accordance with the GDPR, where required.

The Controller has the right to issue documented instructions regarding the processing of personal data during the term of the Main Agreement, provided these fall within the cybersecurity awareness services provided via Orbit, this DPA, and applicable legislation. If an instruction entails additional work, functionalities, or costs for the Processor outside the agreed Services, the Parties shall consult in advance regarding implementation, planning, and any additional compensation.

Clause 6: Security of Processing (TOMs)

  • The Processor shall implement the technical and organizational measures (TOMs) specified in Annex III to protect personal data against loss, destruction, unauthorized alteration, or access.
  • Access to personal data is granted exclusively to personnel of the Processor for whom it is strictly necessary (on a "need-to-know" basis) and who are bound by an obligation of confidentiality.

Clause 7: Engagement of Sub-processors

  • The Controller hereby grants general authorization to the Processor to engage sub-processors from an agreed list (such as cloud and database partners). The Processor shall inform the Controller in writing at least 14 calendar days in advance of any intended additions or replacements.
  • The Processor shall impose data protection obligations upon every sub-processor that are substantially the same as those imposed on the Processor under this DPA, in accordance with Article 28(4) GDPR. The Processor remains fully liable to the Controller for the performance of the sub-processors' obligations. An up-to-date overview of sub-processors is available on the Western Tactics website.

Clause 8: International Transfers

Personal data shall only be transferred outside the European Economic Area (EEA) if Chapter V of the GDPR is complied with, including on the basis of an adequacy decision, the EU-US Data Privacy Framework where applicable, or appropriate safeguards such as the European Commission's Standard Contractual Clauses.

Clause 9: Assistance to the Controller

  • The Processor shall promptly notify the Controller of any requests received from data subjects (such as access or erasure requests) and shall not respond to them independently.
  • The Processor shall assist the Controller in ensuring compliance with obligations under the GDPR (such as security measures and DPIAs).

Clause 10: Notification of Personal Data Breaches

In the event of a personal data breach, the Processor shall notify the Controller without undue delay after becoming aware of it, and shall provide all necessary cooperation to handle the incident.

The notification shall contain, to the extent information is available at that time, at least a description of the nature of the breach, the categories of personal data and data subjects concerned, the likely consequences, and the measures taken or proposed. If not all information can be provided simultaneously, it may be provided in phases without undue delay.

Clause 11: Information and Audits

The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR.

The Processor shall allow for and contribute to audits and inspections conducted by the Controller or an independent auditor mandated by the Controller. Except in cases of security incidents, instructions from a supervisory authority, or a substantiated suspicion of non-compliance, audits shall take place no more than once per calendar year, during regular office hours and upon reasonable prior notice. Where reasonably possible, Western Tactics may fulfill this obligation by providing relevant certifications, audit reports, or other security documentation.

Section III: Final Provisions

Clause 12: Non-compliance and Termination

  • If the Processor breaches its obligations under this DPA, the Controller may suspend the processing until compliance is achieved.
  • Upon termination of the Main Agreement, the Processor shall, at the choice of the Controller, delete or return all personal data and delete existing copies, unless applicable law requires further storage. To the extent the Data Act or other applicable law mandates that data remains available during a transition or retrieval period, deletion shall take place after such period expires. Personal data retained solely due to a statutory retention obligation shall not be processed for any other purpose.

Annex I: Specification of the Parties

  • Controller: The Customer (as defined in the signed Proposal / Main Agreement).
  • Processor: Western Tactics (located in Enschede, The Netherlands).

Annex II: Description of the Processing

  • Subject matter: Delivery of the cybersecurity awareness platform Orbit (app.westerntactics.nl).
  • Duration of processing: For the duration of the Main Agreement and, where necessary, for the period specified therein and in this DPA for the return and deletion of personal data.
  • Nature of processing: Collecting, recording, structuring, storing, consulting, using, analyzing, reporting, transmitting, and deleting personal data for the execution of the cybersecurity awareness services provided via Orbit.
  • Purpose of processing: Executing social engineering/phishing simulations, e-learning training, tracking learning results, and compliance reporting on behalf of the Controller.
  • Categories of data subjects: Employees, contractors, administrators, and other contacts authorized by the Customer of the Controller.

Types of personal data

  • Account details (first and last name, business email address).
  • Language and user preferences.
  • SSO/SCIM and Identity Provider identifiers.
  • Training status and training results.
  • Interactions with awareness training.
  • Results/interactions of simulated phishing campaigns.
  • Relevant browser, device, session, and security metadata.

Annex III: Technical and Organizational Measures (TOMs)

The Processor implements at least the following security measures:

  • 1. Encryption: Personal data is protected in transit using TLS 1.2 or higher, with TLS 1.3 applied where supported by the respective systems and connections. Personal data within the primary data storage is stored encrypted using industry-standard encryption, including AES-256 or a technically equivalent security level, to the extent supported by the relevant infrastructure.
  • 2. Access Control: Access to production environments and personal data is restricted based on the least-privilege and need-to-know principles. Western Tactics applies Role-Based Access Control (RBAC) and requires multi-factor authentication (MFA) for administrative access to relevant production systems.
  • 3. Tenant Isolation: Customer data is logically separated through tenant-bound authorization and database controls.
  • 4. Backup and Recovery: Western Tactics applies automated backup and recovery measures to relevant production data. Backups are appropriately protected against unauthorized access.
  • 5. Monitoring and Logging: Relevant production and security systems are monitored, and security-relevant events are logged for detection, investigation, and incident response.
  • 6. Vulnerabilities and Updates: Western Tactics applies security updates and patches based on risk and urgency and implements measures to identify and address vulnerabilities.

Annex IV: Sub-processors

The Controller grants Western Tactics general authorization to engage the sub-processors listed in the current Sub-processors Overview of Western Tactics.

The current overview is available at: westerntactics.com/legal/sub-processors.

Changes in the use of sub-processors shall take place in accordance with Clause 7 of this DPA.