DATA PROTECTION ADDENDUM
Breachday LLC · breachday.io
Version 1.4 · Effective Date: October 5, 2026
| Provider | Breachday LLC, a Colorado limited liability company breachday.io · compliance@breachday.io |
| Agreement | Breachday Terms of Service (breachday.io/terms), incorporated herein by reference |
| Subprocessor List | breachday.io/subprocessors (30 days advance notice for new subprocessors, subject to emergency exception) |
| Breach Notice | compliance@breachday.io · Within 48 hours after Breachday determines a Security Incident occurred |
| Governing Law | State of Colorado, consistent with the Agreement |
Adapted from Bonterms DPA Version 1.0 (CC BY 4.0). Bonterms does not provide legal advice.
1. Definitions
1.1 "Agreement" means the Breachday Terms of Service located at breachday.io/terms and any applicable Order Form, MSP Agreement, Enterprise agreement, or other written agreement governing the Service.
1.2 "Controller" means the person or entity that determines the purposes and means of Processing Personal Data, including the equivalent term under applicable Data Protection Laws. Customer is the Controller when using the Service for its own organization unless applicable law provides otherwise. Where Customer acts for a Client, the Client is the Controller.
1.3 "Customer Data" has the meaning in the Agreement and includes data, content, and materials submitted to or generated within the Service by Customer or its users.
1.4 "Customer Instructions" means the documented instructions contained in the Agreement, this DPA, Customer's authorized use and configuration of the Service, and other reasonable written instructions consistent with the Agreement. Customer Instructions include Processing reasonably necessary to provide, host, secure, support, administer, and maintain the Service; generate reports and exports; maintain backups; prevent fraud and abuse; enforce usage limits and MSP licensing; and comply with applicable legal obligations.
1.5 "Customer Personal Data" means Personal Data contained in Customer Data that Breachday Processes on behalf of Customer under this DPA.
1.6 "Data Protection Laws" means privacy and data protection laws applicable to Processing Customer Personal Data under the Agreement, including as applicable the CCPA/CPRA, Colorado Privacy Act and other U.S. state privacy laws, EU GDPR, UK GDPR, Swiss FADP, and implementing regulations, as amended.
1.7 "Data Subject" means an identified or identifiable individual to whom Customer Personal Data relates.
1.8 "DPA Effective Date" means the date Customer accepts the Agreement or executes this DPA, whichever occurs first.
1.9 "Personal Data" means personal data, personal information, or similar regulated information relating to an identified or identifiable individual under applicable Data Protection Laws.
1.10 "Processing" means any operation performed on Personal Data, including collection, storage, retrieval, access, use, transmission, disclosure, deletion, or destruction.
1.11 "Processor" means a person or entity that Processes Personal Data on behalf of a Controller, including equivalent terms such as service provider or contractor where applicable. Breachday is Customer's Processor for Customer Personal Data, or Customer's Subprocessor where Customer acts as a Processor for a Client.
1.12 "Restricted Transfer" means a transfer of Customer Personal Data requiring a recognized transfer mechanism under the EU GDPR, UK GDPR, Swiss FADP, or another applicable Data Protection Law.
1.13 "Security Incident" means a breach of security that Breachday determines has resulted in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data Processed by Breachday. Unsuccessful attempts that do not result in unauthorized access to Customer Personal Data, such as failed logins, scans, or blocked attacks, are not Security Incidents.
1.14 "Service" means the Breachday tabletop exercise platform at app.breachday.io and associated features, APIs, exports, and System Templates.
1.15 "Specified Notice Period" means 48 hours after Breachday determines that a Security Incident affecting Customer Personal Data has occurred.
1.16 "Subprocessor" means a third party engaged by Breachday to Process Customer Personal Data on Breachday's behalf in connection with the Service.
1.17 "Subprocessor List" means Breachday's current list at breachday.io/subprocessors.
1.18 "Client" means a third-party organization on whose behalf Customer is authorized to use the Service under an MSP Agreement or other written agreement with Breachday.
1.19 "MSP Agreement" means a separate written agreement permitting Customer to use the Service for Clients.
2. Scope and Duration
2.1 Roles of the Parties
(a) Customer's own use. Where Customer uses the Service for its own organization, Customer is Controller and Breachday is Processor for Customer Personal Data.
(b) Use on behalf of Clients. Where Customer uses the Service for a Client under an MSP Agreement or other written authorization from Breachday, the Client is Controller, Customer is a Processor acting for the Client, and Breachday is Customer's Subprocessor. Customer represents that it has the Client's authorization to engage Breachday and the Subprocessors; Customer is responsible for passing Client instructions to Breachday, handling Client requests and audits, and notifying the Client of Security Incidents reported by Breachday. Breachday's obligations under this DPA run to Customer unless the applicable MSP Agreement states otherwise.
(c) Breachday controller activities. This DPA does not govern Personal Data that Breachday Processes as an independent Controller for its own Account administration, billing, security logging, fraud prevention, legal compliance, or corporate operations as described in the Privacy Policy, except to the extent applicable law requires otherwise.
2.2 Scope
This DPA applies to Breachday's Processing of Customer Personal Data on behalf of Customer to the extent that Processing is subject to Data Protection Laws.
2.3 Duration
This DPA begins on the DPA Effective Date and continues until Breachday has ceased Processing Customer Personal Data on Customer's behalf, subject to lawful retention and backup expiration.
2.4 Order of Precedence
In the event of conflict, the following order applies: (1) applicable Standard Contractual Clauses or other agreed transfer mechanism for a Restricted Transfer; (2) this DPA for Processing Customer Personal Data; (3) an applicable MSP Agreement, Order Form, Enterprise agreement, or other executed agreement for matters expressly addressed there; and (4) the remaining Agreement. To the extent permitted by Data Protection Laws, claims under this DPA are subject to the liability terms of the Agreement unless an executed agreement expressly states otherwise.
3. Processing of Customer Personal Data
3.1 Customer Instructions
Breachday will Process Customer Personal Data only in accordance with Customer Instructions, including the operational purposes expressly described in Section 1.4, or as required by applicable law. If law requires Processing beyond Customer Instructions, Breachday will notify Customer before the Processing unless legally prohibited. Breachday will promptly notify Customer if Breachday determines that a Customer Instruction infringes applicable Data Protection Laws.
3.2 Details of Processing
The subject matter, nature, purpose, duration, categories of Customer Personal Data, and categories of Data Subjects are described in Schedule 1.
3.3 Confidentiality
Breachday will limit access to Customer Personal Data to personnel and authorized Subprocessors that need access to perform the Agreement. Personnel authorized to Process Customer Personal Data will be subject to binding confidentiality obligations. Breachday will protect Customer Personal Data as Confidential Information under the Agreement and, regardless of whether the Agreement contains a separate confidentiality provision, will use at least reasonable care to prevent unauthorized use or disclosure.
3.4 AI Processing and No Model Training
Breachday will not use Customer Data to train or fine-tune Breachday or third-party AI models. When Customer uses the AI Scenario Builder, prompt and response content is transmitted through OpenRouter for inference. Breachday configures routing to require ZDR-eligible provider endpoints and to deny provider data collection where supported. Under OpenRouter's ZDR controls, eligible inference providers do not persist prompt or response content after processing. ZDR does not prevent transient Processing and does not prevent OpenRouter from retaining non-content request metadata under its own policies. Customer must not intentionally include Sensitive Personal Data or real credentials in AI prompts unless Breachday has expressly approved such Processing in writing.
3.5 Compliance with Laws
Each party will comply with Data Protection Laws applicable to its own Processing. Customer is responsible for establishing any lawful basis, notices, authorizations, and permissions required for Breachday to Process Customer Personal Data in accordance with the Agreement.
3.6 CCPA/CPRA Service Provider and Contractor Terms
To the extent the CCPA/CPRA applies and Breachday Processes Personal Information as a service provider or contractor, the parties agree that:
- Customer discloses Personal Information to Breachday only for the specific business purposes described in Schedule 1 and the Customer Instructions, including providing, securing, supporting, and administering the Service.
- Breachday will not sell or share Personal Information, as those terms are defined by the CCPA/CPRA.
- Breachday will not retain, use, or disclose Personal Information outside the direct business relationship with Customer or for a purpose other than the specific business purposes in this DPA, except as permitted by the CCPA/CPRA and implementing regulations.
- Breachday will not combine Personal Information received from or on behalf of Customer with Personal Information received from another person or collected from Breachday's own interaction with a consumer except as permitted by the CCPA/CPRA and implementing regulations.
- Breachday will provide the same level of privacy protection required of service providers and contractors under applicable CCPA/CPRA requirements and will notify Customer if Breachday determines it can no longer meet those obligations.
- Customer may take reasonable and appropriate steps to help ensure Breachday uses Personal Information consistently with Customer's obligations, including the audit and information rights in Section 8, and may require Breachday to stop and remediate unauthorized use of Personal Information.
- Breachday will cooperate with Customer as reasonably necessary for applicable CCPA/CPRA consumer requests, cybersecurity audits, and risk assessments to the extent information is within Breachday's possession or control and the request is applicable to the Service.
3.7 U.S. State Processor Terms
To the extent another applicable U.S. state privacy law imposes processor contract requirements, Breachday will Process Customer Personal Data according to Customer Instructions, maintain confidentiality, assist with applicable consumer-rights requests and security obligations, delete or return data as described in this DPA, and make compliance information available as required by that law. The parties intend this DPA to satisfy processor-contract requirements to the extent applicable.
4. Subprocessors
4.1 Authorization and Current Subprocessors
Customer generally authorizes Breachday to engage the Subprocessors identified at breachday.io/subprocessors for the specific services described there. Where Customer acts for a Client, Customer provides this authorization on the Client's behalf to the extent Customer is authorized to do so.
| Subprocessor | Processing Location | Role / Data Processed |
|---|---|---|
| Supabase | United States project region as configured; supporting infrastructure may vary | Database, authentication, realtime features, and object storage for application data |
| Vercel | Primary U.S. deployment; distributed network/edge infrastructure may vary | Application hosting and serverless compute; request data passes through the hosting layer |
| Cloudflare | Configured backup storage / distributed network infrastructure | Encrypted disaster-recovery backup storage and related network services |
| Stripe | United States and other locations under Stripe's global infrastructure | Payment processing and subscription management; payment card data held by Stripe |
| Resend | Provider infrastructure locations applicable to email delivery | Transactional email delivery |
| OpenRouter | Varies by ZDR-eligible inference endpoint unless region-restricted | AI model routing; prompt/response content routed only to ZDR-eligible endpoints under Breachday configuration; non-content request metadata may be retained |
4.2 Subprocessor Obligations
Breachday will enter into a written agreement or binding terms with each Subprocessor imposing data protection obligations appropriate to the Processing and will remain responsible for Subprocessor performance to the extent required by applicable Data Protection Laws and this DPA.
4.3 Notice of New Subprocessors
Breachday will update the Subprocessor List and provide at least 30 days' advance notice before a new Subprocessor begins Processing Customer Personal Data, ordinarily through in-Service notice and/or email. If an emergency replacement or new provider is reasonably necessary to maintain security, legal compliance, or Service continuity and 30 days' advance notice is not practicable, Breachday will provide notice as soon as reasonably practicable.
4.4 Objection to New Subprocessors
Customer may reasonably object to a new Subprocessor on documented data-protection grounds within 30 days after notice. The parties will work in good faith to address the concern. If they cannot reasonably resolve the objection, Customer may terminate the affected Service as its sole contractual remedy for the objection and receive a pro-rata refund of prepaid, unused fees attributable to the terminated affected Service.
5. Security
5.1 Security Measures
Breachday will maintain reasonable technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access. Schedule 2 describes the current control framework. Breachday may update specific implementations over time provided it does not materially reduce the overall security of the Service during an active Subscription.
5.2 Security Incident Response
Breachday will use reasonable efforts to detect, investigate, contain, and mitigate Security Incidents. Breachday will notify Customer without undue delay and no later than the Specified Notice Period after Breachday determines that a Security Incident affecting Customer Personal Data occurred. Notice will include information reasonably available to Breachday regarding the nature of the incident, affected data, known consequences, mitigation steps, and a contact for follow-up, and Breachday may provide information in phases as the investigation develops. Security Incident notice is not an admission of fault or liability. Customer is responsible for regulatory, individual, Client, or third-party notices that apply to Customer, with reasonable assistance from Breachday where required by law.
5.3 Customer Responsibilities
Customer is responsible for evaluating whether the Service meets Customer's legal and security requirements; configuring roles and access appropriately; enabling available security features suitable for Customer's risk; protecting room codes and credentials; and avoiding submission of prohibited Sensitive Personal Data.
6. Data Subject and Consumer Requests
If Breachday receives a request directly from a Data Subject relating to Customer Personal Data, Breachday will, where legally permitted, direct the request to Customer or notify Customer. Breachday will not independently respond on Customer's behalf except as required by law. Upon Customer's request, Breachday will provide reasonable assistance through available technical and organizational measures to help Customer respond to requests under applicable Data Protection Laws.
7. Data Return and Deletion
7.1 During the Subscription Term
Customer may access, export, and delete Customer Data through available Service features. Supported export formats may include PDF, DOCX, and JSON.
7.2 Post-Expiration Retention Period
Unless an applicable MSP, Enterprise, or Order Form provides otherwise, expiration of a paid Subscription begins a six-month read-only retention period during which retained Customer Data remains available for export. Breachday provides deletion reminders at 30 and 5 days before scheduled deletion. At the end of the period, Breachday deletes Customer Personal Data from active systems unless Customer renews or requests earlier deletion.
7.3 Backup Expiration and Legal Retention
Customer Personal Data deleted from active systems may persist in encrypted disaster-recovery backups for up to 7 days and is permanently deleted through rolling backup expiration. During that period, backups remain protected under Schedule 2 and are used solely for disaster recovery. If a backup is restored, Breachday re-applies recorded deletion requests. Breachday may retain limited Customer Personal Data where required by law, solely for the legally required purpose and subject to continuing confidentiality and security obligations.
7.4 Deletion Confirmation
Upon reasonable written request after deletion is complete, Breachday will provide written confirmation of deletion, subject to backup expiration and lawful retention described above.
7.5 Ephemeral Sessions
Eligible Organizations may enable an ephemeral-session feature that automatically deletes specified Exercise Session data after a configured retention period, with a default of 48 hours where the feature is enabled. The Service may retain limited security, billing, or operational logs independently of ephemeral-session content as described in the Privacy Policy.
8. Audits and Compliance
8.1 Records and Information
Breachday will maintain records of Processing and compliance information required by applicable Data Protection Laws and will make reasonably necessary information available to Customer upon written request, subject to confidentiality and security restrictions.
8.2 Independent Reports
Where available, Breachday may satisfy reasonable audit inquiries first by providing current security documentation, completed third-party assessment summaries, or independent reports subject to confidentiality. Breachday does not represent that it currently holds a SOC 2 report unless expressly stated in writing at the time of the request.
8.3 Customer Audit Rights
Where Customer has an audit right under applicable Data Protection Laws, Customer may, at its expense, conduct an audit of reasonable scope to verify Breachday's compliance with this DPA. Unless a regulator or Security Incident reasonably requires otherwise, an audit must: (i) occur no more than once per calendar year; (ii) be conducted by an independent auditor subject to confidentiality; (iii) be scheduled at a mutually agreed time during regular business hours with reasonable advance notice; (iv) avoid unreasonable disruption to Breachday or the Service; (v) not access another customer's data, credentials, source code, vulnerability details, or information that would compromise security; and (vi) treat findings as Confidential Information. Breachday may charge reasonable costs for unusually burdensome audit support not required by law.
9. Cross-Border Data Transfers
Breachday currently targets U.S.-based customers. The parties will not intentionally commence a Restricted Transfer of Customer Personal Data unless they first implement a transfer mechanism required by applicable law, such as applicable Standard Contractual Clauses, the UK International Data Transfer Addendum or other recognized mechanism, as appropriate. This DPA does not by itself incorporate Standard Contractual Clauses. If the parties execute transfer terms, those terms control to the extent of a conflict regarding the Restricted Transfer.
10. General Provisions
10.1 Amendments. The parties may amend this DPA by written agreement to address changes in Data Protection Laws or Processing. Breachday may make non-material administrative updates with reasonable notice. Material changes that reduce Customer's data-protection rights require notice and, where required by law or the Agreement, Customer consent.
10.2 Severability. If a provision is unenforceable, it will be modified to the minimum extent necessary to make it enforceable, and the remainder remains in effect.
10.3 Entire Agreement. This DPA, together with the Agreement and any applicable transfer terms, constitutes the parties' agreement regarding Breachday's Processing of Customer Personal Data.
10.4 No Third-Party Beneficiaries. This DPA is for the parties and does not create contractual rights for third parties, except to the extent an applicable transfer mechanism or Data Protection Law expressly provides otherwise.
10.5 Contact. Privacy, security, and data-protection inquiries: compliance@breachday.io
Schedule 1 - Subject Matter and Details of Processing
| Item | Details |
|---|---|
| Subject Matter | Operation of the Breachday tabletop exercise platform, including authentication, exercise facilitation, report generation, file storage, support, security, and platform administration. |
| Nature of Processing | Collection, storage, organization, retrieval, access, use, transmission, transient AI inference, export generation, backup, and deletion as necessary to provide and secure the Service. |
| Specific Business Purposes | Provide and operate the Service; authenticate users; deliver exercises and reports; provide support; secure the platform; maintain backups; manage authorized MSP access; enforce plan and licensing limits; comply with legal obligations. |
| Duration | During the active Subscription plus applicable read-only retention, unless earlier deleted, with up to 7 additional days in encrypted disaster-recovery backups and any legally required limited retention. |
| Data Subjects | Account holders and organization users; Exercise Participants; MSP users; Client personnel; vendor or business contacts entered by Customer; other individuals whose Personal Data Customer lawfully includes in Customer Data. |
| Account Personal Data | Name, business email, authentication identifiers and hashed credentials, verification status, organization membership and role, 2FA data if enabled, profile image URL if provided, and MSP relationships where applicable. |
| Participant Personal Data | Display name, role-seat selection, session responses, votes, confidence ratings, hotwash feedback, participant session identifiers, timestamps, and limited technical request data such as IP address where captured in security or server logs. |
| Customer-Entered Personal Data | Business contact information and other Personal Data Customer chooses to include in vendor records, scenarios, playbooks, support tickets, lessons learned, or related content. Customer should minimize and anonymize Personal Data where feasible. |
| Special / Sensitive Categories | Breachday does not require and is not intended to Process PHI, special-category data, live payment card data, real credentials, or other Sensitive Personal Data. Customer must not intentionally submit such data unless Breachday expressly approves the Processing in writing and required agreements are in place. |
| Transient AI Processing | AI Scenario Builder prompts and outputs are transiently Processed through OpenRouter and ZDR-eligible inference endpoints. Prompt/response content is not intended to be persistently stored by eligible inference providers after processing; non-content request metadata may be retained by OpenRouter. Customer must not intentionally include Sensitive Personal Data in prompts. |
| Payment Data | Payment card numbers and CVV data are processed by Stripe and are not stored by Breachday. Breachday may store Stripe identifiers, subscription status, and related billing metadata. |
Schedule 2 - Technical and Organizational Measures
Breachday maintains a security program appropriate to the size and nature of the Service. The specific implementation may evolve over time, but Breachday will not materially reduce the overall security of the Service during an active Subscription. Current measures include:
Access Controls
- Role-based access controls for Organization users and privileged Breachday personnel
- Two-factor authentication support for authenticated users and required confirmation controls for high-impact operations
- Restricted privileged access based on operational need
- Controlled MSP access to authorized Client Organizations
- Participant access limited to designated Exercise Sessions through room access controls
Encryption and Credential Protection
- TLS 1.2 or later for application data in transit where supported
- Encryption at rest provided by Breachday infrastructure providers for database and object storage
- Cryptographic protection for room passwords and authentication secrets appropriate to their function
- Encrypted disaster-recovery backup storage
Tenant and Application Security
- Organization-scoped authorization and tenant isolation enforced in application data-access paths
- Separate privileged administrative functions and security logging
- Content Security Policy and other security-related HTTP headers appropriate to the application
- Rate limiting and abuse controls on public or sensitive endpoints
- Webhook authenticity validation where supported by the integration
- Automated static, dynamic, dependency, or equivalent application-security testing integrated into the software-development lifecycle, with findings handled according to risk
Logging, Monitoring, and Incident Response
- Security-relevant privileged administrative actions recorded in restricted audit logs
- Server and security logging used for detection, diagnostics, abuse prevention, and incident response
- Documented processes for investigating and responding to suspected Security Incidents
- Customer Security Incident notification as described in Section 5.2
Data Lifecycle and Resilience
- Automated post-expiration deletion processes for Customer Data
- Optional ephemeral-session deletion for eligible plans
- Deletion of unverified signup accounts after the configured lifecycle
- Rolling retention for server/security logs and disaster-recovery backups
- Daily or otherwise regularly scheduled backup processes appropriate to the Service, with encrypted off-site disaster-recovery copies retained up to 7 days
- Re-application of recorded deletion requests after a backup restore
Organizational Measures
- Confidentiality obligations for personnel with access to Customer Personal Data
- Access review and least-privilege practices appropriate to Breachday's workforce and systems
- Subprocessor privacy and security obligations
- Security vulnerability reporting through compliance@breachday.io
- Reasonable security documentation and audit assistance under Section 8
DPA Setup Page - Execution
By executing this DPA Setup Page, Customer and Breachday agree to be bound by the Breachday Data Protection Addendum (Version 1.4) as of the DPA Effective Date. Customers that accept the Terms of Service electronically are also bound by this DPA to the extent incorporated by the Agreement.
| BREACHDAY LLC (Provider) | CUSTOMER |
| Signature: | Signature: |
| Name: | Name: |
| Title: | Title: |
| Date: | Company: |
| Date: |
Key Terms
| Item | Details |
|---|---|
| Agreement | Breachday Terms of Service - breachday.io/terms |
| DPA Effective Date | ____________________________________________ |
| Subprocessor List | breachday.io/subprocessors |
| Breach Notice Channel | compliance@breachday.io |
| Customer Role | Own organization only / Also serves Clients under an MSP Agreement |
| Schedules Incorporated | Schedule 1 (Subject Matter and Details of Processing); Schedule 2 (Technical and Organizational Measures) |
Questions about this DPA: compliance@breachday.io
Breachday LLC · breachday.io · Aurora, Colorado