Data Processing Addendum (DPA) & Security Exemption Notice

Effective Date: August 2026

This Addendum governs all reverse proxy routing, packet inspection, and WAF telemetry provided by SEOSiri Enterprise Labs.

1. Roles of the Parties

The Client acts as the Data Controller. SEOSiri acts strictly as a Data Processor providing automated network boundary defense.

2. Clean Traffic Non-Retention

Legitimate, unflagged HTTP requests pass through edge memory without persistent disk logging. IP addresses of non-malicious visitors are never retained.

3. Cybersecurity Exemption (GDPR & CCPA)

In the event of an active threat signature (SQLi, XSS, BOLA, CSRF, DDoS), telemetry including source IP, network ASN, and payload fragments is logged under EU GDPR Article 6(1)(f) and Recital 49 (Legitimate Interest for Network Security) and California Consumer Privacy Act (CCPA) ยง 1798.145(a)(1).

4. Data Minimization & Auto-Purge

All security incident records are automatically purged after thirty (30) calendar days. Security telemetry is strictly prohibited from being sold, leased, or utilized for behavioral targeting.