Legal
Data Processing Addendum
Last updated · 14 February 2026 · FastCollab Systems Private Limited
This Data Processing Addendum ("DPA") forms part of, and is subject to, the Terms of Service between the Customer ("Controller") and FastCollab Systems Private Limited ("Processor"). It governs the Processing of Personal Data carried out by the Processor on behalf of the Controller in connection with the Probe platform.
1. Roles & scope
For data submitted by the Controller via the Service, the Controller acts as the data controller and FastCollab Systems Private Limited acts as the data processor. The Processor will Process Personal Data only on documented instructions from the Controller, including with regard to transfers to a third country.
2. Categories of data & data subjects
- Data subjects: the Controller's end users and the Controller's employees who interact with the Service.
- Personal data: identifiers (email, name), authentication metadata, IP addresses, test artefacts and any data the Controller chooses to upload as part of a recorded test.
3. Security measures
- Encryption at rest (AES-128 / Fernet) for credentials, login state vaults and platform secrets.
- TLS in transit for all customer-facing endpoints.
- Bcrypt password hashing, brute-force lockout, audit logs of all super-admin emulation events.
- Role-based access control with a least-privilege model.
4. Subprocessors
The Processor maintains a list of approved subprocessors. The current list is available on request. The Processor will provide reasonable prior notice of any intended change of subprocessor and a reasonable period for the Controller to object to that change.
5. International transfers
Where Personal Data is transferred outside the European Economic Area, the Processor relies on the Standard Contractual Clauses adopted by the European Commission, supplemented by additional safeguards where required.
6. Data subject requests
The Processor will, taking into account the nature of the Processing, assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising data subject rights.
7. Breach notification
The Processor will notify the Controller without undue delay (and in no event later than 72 hours) after becoming aware of a Personal Data Breach affecting the Controller's Personal Data.
8. Return & deletion
Upon termination of the Service, the Processor will, at the choice of the Controller, delete or return all Personal Data to the Controller and delete existing copies unless legal obligations require continued storage.
9. Contact
FastCollab Systems Private Limited · dpo@fastcollab.com