Legal
Data Processing Addendum
Last updated: 27 August 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between La Costa Services, LLC (“Skans Labs”) and a business customer (“Customer”), and applies where Skans Labs processes personal data on the Customer’s behalf in providing the Services. Where the EU or UK GDPR applies, the Customer is the “controller” and Skans Labs the “processor”; where the CCPA/CPRA applies, the Customer is the “business” and Skans Labs a “service provider.”
How little we process
The Skans appliance is designed to keep operational data on the Customer’s own premises. In the ordinary course, the personal data Skans Labs processes as a processor is limited to the Customer’s account and contact details, the identities of the people the Customer invites to its account, and licensing and check-in metadata. Skans Labs does not receive the contents of the Customer’s network, endpoints, or monitored systems.
Scope and instructions
Skans Labs processes personal data only to provide and secure the Services, and only on the Customer’s documented instructions (including these Terms), unless required by law — in which case we will inform the Customer unless the law forbids it. We will tell the Customer if, in our opinion, an instruction infringes applicable data-protection law.
Confidentiality and security
Personnel authorized to process personal data are bound by confidentiality. We maintain appropriate technical and organizational measures, including encryption in transit, access controls on a least-privilege basis, hardened and access-gated infrastructure with no publicly exposed databases, and audit logging.
Sub-processors
The Customer authorizes Skans Labs to engage sub-processors to provide the Services. Current sub-processors include Cloudflare (edge, hosting, CDN and cookieless analytics), our infrastructure host, and our email-relay provider, each bound by data-protection obligations no less protective than this DPA. We will give the Customer a way to learn of, and reasonable notice of, changes to sub-processors so the Customer can object on reasonable data-protection grounds.
International transfers
Where personal data is transferred out of the EEA, UK, or Switzerland, Skans Labs relies on an appropriate transfer mechanism, such as the Standard Contractual Clauses, which are incorporated by reference where required.
Assistance
Taking into account the nature of the processing, Skans Labs will assist the Customer, by appropriate technical and organizational measures and insofar as possible, to respond to data-subject requests and to meet its obligations for security, breach notification, and data-protection impact assessments.
Personal-data breaches
Skans Labs will notify the Customer without undue delay after becoming aware of a personal-data breach affecting the Customer’s data, with the information the Customer reasonably needs to meet its own notification obligations.
Return and deletion
On termination, and at the Customer’s choice, Skans Labs will delete or return the personal data it processes on the Customer’s behalf, except where retention is required by law. Account holders can also export or delete their data at any time from Settings.
Audits
Skans Labs will make available information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits on reasonable notice and subject to confidentiality.
Contact
Data-protection enquiries: [email protected] (subject “Data protection”). La Costa Services, LLC, California, USA.