Varaxon Scan Hub — Data Processing Addendum
Document set version: v1.0, effective September 11, 2026
Last updated: September 11, 2026
Business: Varaxon Technologies LLC
Service: Varaxon Scan Hub (https://scan.varaxontech.com)
Contact: support@varaxontech.com
Effective date: The date the customer accepts this Addendum
This Data Processing Addendum (the “DPA”) forms part of the Varaxon Scan Hub Terms of Service between Varaxon Technologies LLC (“Varaxon”) and the customer identified in the applicable order or account (“Customer”). It applies only when Customer submits personal data to Varaxon for processing on Customer’s behalf.
1. Roles and scope
“Customer Data” means personal data and other information contained in a scan export, report input, or related material that Customer submits to Varaxon for processing on Customer’s behalf. It does not include account, billing, security, support, or service-usage records for which Varaxon determines the purposes of processing.
For Customer Data in uploaded Nessus or Greenbone exports and report inputs, Customer is the Controller (or equivalent business) and Varaxon is the Processor. If Customer is itself processing the data for an end client, Customer may be a Processor and Varaxon may act as Customer’s Subprocessor. In either case, Customer represents that it has authority from the relevant Controller to appoint Varaxon and to give the processing instructions in this DPA, and that it will pass on any legally required instructions and obligations that apply to Varaxon’s processing. Customer remains responsible for having a lawful basis, providing required notices, obtaining required permissions, and ensuring that its scans and exports are authorized.
For account registration, billing, security, support, and service-usage records that Varaxon determines the purposes of processing, Varaxon acts as an independent controller as described in its Privacy Policy. Those records are outside the processor scope of this DPA.
Zero-retention processing statement: the synchronous report path processes Customer Data in request-scoped memory and does not intentionally retain the uploaded scan or generated report after the request completes. Varaxon does not put scan contents in application logs or email. This statement applies to the current synchronous service; a future asynchronous path may not process Customer Data until its storage, retention, deletion, and access controls are documented and approved.
Anonymous pre-flight uploads made without an account are covered by the Privacy Policy’s pre-flight notice, not by this DPA, because no Customer has accepted this DPA for that upload.
2. Processing instructions and purpose
Varaxon will process Customer Data only to provide, secure, maintain, and support the service, generate the requested vulnerability report, comply with documented Customer instructions, or as required by law. Varaxon will not sell Customer Data or use it for advertising. Varaxon will not use Customer Data to train an AI model or to assign security scores outside the deterministic service pipeline.
3. Data and data subjects
Depending on Customer’s export, Customer Data may include hostnames, IP addresses, ports, service metadata, usernames or account identifiers, vulnerability identifiers and descriptions, scanner metadata, and other system or security information. Customer determines the categories of data subjects represented in an export and must not upload data it is not authorized to process.
4. Confidentiality and personnel
Varaxon will restrict access to Customer Data to personnel and contractors who need it to provide the service, are bound by confidentiality obligations, and receive appropriate security training. Varaxon will not place scan contents, hostnames, IP addresses, CVEs, plugin output, or filenames in application logs or email messages.
5. Security measures
Varaxon maintains a security program designed to use reasonable technical and organizational measures appropriate to the nature and risks of processing. Depending on the service configuration and applicable data, those measures may include:
- password hashing with a unique salt for each password;
- storing API-key and session secrets only as hashes;
- CSRF protection on state-changing browser forms;
- session and CSRF cookies configured with Secure, HttpOnly, and SameSite attributes;
- per-identity rate limits on authentication, email, and report routes;
- an upload-size cap and large-upload concurrency controls;
- XML parsing that rejects external entities and DTDs;
- restricted operational logging that excludes Customer Data; and
- access controls and TLS for service connections.
Varaxon maintains an internal security-control summary that may be made available for reasonable due-diligence purposes under confidentiality obligations. The summary is informational, is not incorporated into this Addendum, and does not modify or expand Varaxon's contractual obligations.
The Customer is responsible for its own endpoint security, account credentials, authorization to scan, and secure handling of downloaded reports. Any asynchronous processing feature must not be enabled for Customer Data until its storage, retention, deletion, and access controls have been documented and approved.
6. Subprocessors
Customer generally authorizes the following subprocessors only as needed for the service:
| Subprocessor | Purpose | Processing-location note |
|---|---|---|
| Stripe | Subscription billing, hosted payment collection, and billing webhooks | Stripe is a global provider; its current privacy and data-processing terms and applicable processing locations control |
| Resend | Transactional account email, including verification and password-reset messages | Resend is a global provider; its current privacy and data-processing terms and applicable processing locations control |
| OVHcloud (OVH), U.S. region | Hosting and infrastructure for the application and account records | U.S.-region hosting under the provider’s then-current terms |
A material subprocessor is a vendor engaged by Varaxon that processes Customer Data or account data on Varaxon's behalf.
Varaxon will maintain a current subprocessor list and will give at least 30 days’ advance notice of a material subprocessor change, unless a shorter period is required by an urgent security or legal circumstance. Customer may raise a reasonable, documented objection on data-protection grounds. If the parties cannot resolve the objection, the parties will discuss a commercially reasonable alternative or termination of the affected service.
7. Assistance
Taking into account the nature of processing, Varaxon will reasonably assist Customer with data-subject requests, security assessments, and legally required breach or regulator inquiries. Varaxon will acknowledge a specific, verified assistance request without undue delay and, where reasonably practicable, provide the requested assistance within 10 business days, subject to the Customer providing the information reasonably necessary to identify the relevant account or request. Customer remains responsible for responding to data subjects and regulators and for meeting any deadline that applies to it as Controller.
8. Personal-data incidents
Varaxon will notify Customer without undue delay and, where reasonably practicable, within 72 hours after confirming a breach of Customer Data in Varaxon’s possession or control. The notice will describe the known nature of the incident, the likely categories affected, the mitigation steps taken, and a contact point for follow-up. Varaxon will not include scan payloads or other unnecessary Customer Data in an incident notice.
9. Return and deletion
At the end of the service, or on a verified written request, Varaxon will delete or return Customer Data processed as a Processor when instructed by Customer, unless retention is required by law. Because the synchronous service is designed not to retain the uploaded scan or generated report after the request, there is ordinarily no retained scan payload to return or delete. There is currently no customer-facing self-service account-deletion control; deletion or closure requests must be directed to support@varaxontech.com and may require account verification. Account, billing, security, and usage records may remain subject to Varaxon’s Privacy Policy and legal obligations.
10. Audits and information
Varaxon will make available reasonable information necessary to demonstrate compliance with this DPA. Any audit must be reasonable in scope, protect other customers’ confidentiality, avoid access to live customer payloads, and occur no more than once annually unless a confirmed incident requires otherwise. Customer bears its own audit costs.
11. International transfers
Varaxon does not accept Customer Data subject to European Union, United Kingdom, or Swiss data-protection transfer restrictions unless the parties have first executed an appropriate written transfer arrangement. Standard Contractual Clauses are an actual transfer mechanism that must be executed, not a general undertaking to adopt one later. Customer must not submit such data before that arrangement is in place.
The initial launch is intended for U.S. customers, but Stripe and Resend may process information globally as described in their then-current terms. If Varaxon or a subprocessor transfers Customer Data outside the United States, the parties will use a lawful transfer mechanism and the supplementary measures required by applicable law. Where a Customer's own obligations require a specific transfer mechanism, the parties will identify that mechanism and the applicable subprocessor processing locations in writing before Varaxon processes Customer Data under this DPA.
12. Order of precedence and term
This DPA remains in effect while Varaxon processes Customer Data as a Processor. If this DPA conflicts with the Terms of Service on data-protection matters, this DPA controls to the extent of the conflict. Liability limits, fees, and other commercial terms remain governed by the customer agreement unless this DPA expressly states otherwise.
Need a countersigned copy for your records? Request one.
