# RadiantOS Data Processing Agreement
## 1. Subject Matter
RadiantOS Ltd ("Processor") processes Personal Data on behalf of the Customer ("Controller") in connection with the RadiantOS MSP platform.
## 2. Duration
This DPA is effective for the duration of the Controller's subscription.
## 3. Nature and Purpose
The Processor provides RMM, PSA, backup, SaaS backup, vault, billing, reporting, automation, observability and website/customer portal tooling. Personal Data covers end-user identifiers, device identifiers, operational telemetry, support content, billing metadata and customer-selected backup/restore content.
## 4. Categories of Data Subjects
MSP employees, customer administrators, technicians, billing users, end users of MSP customer organisations and website visitors where applicable.
## 5. Sub-Processors
See [Sub-processor list](/legal/sub-processors). Controllers receive prior notice of any material sub-processor change.
## 6. Security Measures
- Regional Vultr Managed PostgreSQL for tenant data with encryption at rest.
- Regional Vultr Archival Object Storage for backups, reports, recordings, exports, screenshots and generated artifacts.
- First-party RadiantOS Vault for credential storage; raw secrets are never stored in Markdown, logs, analytics or public documents.
- Encryption in transit with TLS 1.2+ everywhere and mTLS where required by the agent/control-plane architecture.
- Row-level security or equivalent tenant/region enforcement on every tenant-scoped table and route.
- MFA and step-up approval for destructive or high-risk actions.
- Sentry and PostHog instrumentation with PII and secret masking.
- Signed agent command envelopes, audit logging and retention/legal-hold controls.
## 7. Data Residency
Customers can select US or EU residency for clients/users. The application, API, worker, queue, database and archive-storage paths route to the selected region. Cross-region movement is permitted only through approved policy, migration, support or disaster-recovery workflows with audit evidence.
## 8. Sub-Processor Changes
RadiantOS gives prior written notice for new or replaced material sub-processors. Controller may object within the notice window and terminate the affected Service if the objection cannot be resolved.
## 9. International Transfers
For EU tenants, transfers outside the EEA use Standard Contractual Clauses or another approved transfer mechanism where required.
## 10. Data Subject Rights
Controller may export, correct or delete tenant data through the product workflows or support process, subject to legal hold, retention and backup restore constraints.
## 11. Breach Notification
RadiantOS notifies Controller without undue delay after confirming a reportable breach and provides information reasonably available at the time.
## 12. Audit Rights
Controller may request audit information and security evidence subject to reasonable confidentiality, timing and operational safeguards.
## 13. Return and Deletion
On termination, Controller may export data during the configured grace period. After the grace period, production data and eligible backup data are deleted according to the retention, legal-hold and proof-of-deletion policies.
## 14. Governing Law
The laws stated in the applicable order form, terms or customer agreement apply.