Data processing agreement
Last updated 20 November 2025. This addendum sets out the terms on which OAuthRadar processes personal data on your behalf. The signed DPA is the operative document.
You are the controller of the personal data in your grant inventory. OAuthRadar is the processor and acts only on your documented instructions. Tokens are held under envelope encryption in a separate keyspace and are never displayed in full; access to a customer inventory is not a permission any staff role holds.
We notify you of a personal-data breach within 24 hours of confirmation, without waiting for the full post-mortem, and update you as facts are established. Sub-processors are listed on the security page and changes are notified 30 days in advance.