This agreement describes how Gideon Defender, Inc. processes and protects personal data on behalf of customers using the Gideon security platform.
Last updated: August 20, 2026
Agreement and scope
This Data Processing Agreement (DPA) forms part of the Master Subscription Agreement, Terms of Service, or other principal agreement (Agreement) entered into by and between Gideon Defender, Inc. (Gideon or Processor) and the entity entering into the Agreement (Customer or Controller).
This DPA governs Gideon's processing of Personal Data on Customer's behalf in connection with the services provided under the Agreement. It applies when incorporated into or otherwise made part of the Agreement.
1. Definitions
Business and Service Provider have the meanings given under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA). For purposes of this DPA, Customer is the Business and Gideon is the Service Provider with respect to Personal Information processed under the Agreement.
Controller means the entity that determines the purposes and means of processing Personal Data, which is Customer for the processing covered by this DPA.
Data Protection Laws means applicable privacy and data protection laws and regulations, including, as applicable, the General Data Protection Regulation (EU) 2016/679 (GDPR), the UK GDPR, and the CCPA.
Personal Data and, for CCPA purposes, Personal Information mean information relating to an identified or identifiable natural person that Gideon processes on Customer's behalf under the Agreement.
Processor means the entity that processes Personal Data on behalf of the Controller, which is Gideon for the processing covered by this DPA.
Security Incident means a confirmed accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored, or otherwise processed by Gideon.
Subprocessor means a third-party processor engaged by Gideon to assist in providing the services.
2. Roles and scope of processing
2.1 Roles of the parties
For Personal Data processed under this DPA, Customer is the Controller and, where the CCPA applies, the Business. Gideon is the Processor and, where the CCPA applies, the Service Provider. Gideon will process Personal Data only on Customer's behalf and in accordance with Customer's documented instructions, and will not sell or share Personal Information as those terms are defined by the CCPA.
2.2 Details of processing
Categories of Data Subjects: Customer's employees, contractors, and authorized users who administer or authenticate through Gideon's identity, endpoint, and access management platform.
Types of Personal Data: Professional contact information, including names, corporate email addresses, and usernames; device metadata; IP addresses; authentication and access logs; WebAuthn and FIDO2 credential metadata; and telemetry required for identity verification, device posture assessment, and access policy enforcement.
Nature and purpose: Providing Gideon's cybersecurity platform, including Gideon Identity for passkey and FIDO2-based identity and access management, Gideon Endpoint Management for zero-touch device management and endpoint protection, and Gideon Access for just-in-time access management.
Duration: The term of the Agreement and any additional period for which applicable law requires Gideon to retain the data.
3. Gideon's obligations as Processor
3.1 Compliance with instructions
Gideon will process Personal Data in accordance with Customer's documented instructions, including instructions concerning international transfers, unless applicable law requires otherwise. If legally permitted, Gideon will inform Customer before processing required by law.
3.2 Confidentiality
Gideon will ensure that personnel authorized to process Personal Data are subject to confidentiality obligations.
3.3 Security measures
Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, Gideon will implement and maintain appropriate technical and organizational measures designed to provide security appropriate to the risk. These measures include encryption in transit and at rest, phishing-resistant credential enforcement using FIDO2 and WebAuthn, role-based access controls, and regular system reviews.
Gideon's SOC 2 Type II audit is in progress. Upon completion, Gideon will make the report available to Customer under a mutually acceptable nondisclosure agreement. Until then, Gideon will provide current security documentation and respond to reasonable customer security questionnaires upon request.
3.4 Subprocessors
Customer provides general authorization for Gideon to engage Subprocessors. Gideon will provide its current Subprocessor list upon request and give Customer reasonable advance notice of an intended addition or replacement, allowing Customer to object on reasonable data protection grounds. Gideon remains responsible for each Subprocessor's performance of its data protection obligations to the extent required by applicable law and the Agreement.
3.5 Data Subject rights
To the extent legally permitted, Gideon will promptly notify Customer if it receives a request from a Data Subject concerning Personal Data processed under this DPA. Gideon will not respond directly unless Customer authorizes it or applicable law requires it, and will provide reasonable assistance so Customer can respond to requests involving access, correction, deletion, or other applicable rights.
3.6 Security Incident notification
Gideon will notify Customer without undue delay and no later than 72 hours after becoming aware of a confirmed Security Incident affecting Customer's Personal Data. To the extent known, the notice will describe the nature of the incident, the categories and approximate number of affected Data Subjects, and measures taken or proposed to address it. Gideon will take reasonable steps to mitigate the effects of the Security Incident.
3.7 Deletion or return
Upon termination or expiration of the Agreement, Gideon will, at Customer's choice, delete or return Personal Data without undue delay and in accordance with the Agreement, unless applicable law requires continued storage.
It has complied and will continue to comply with applicable Data Protection Laws concerning its collection, processing, and transfer of Personal Data to Gideon.
It has provided necessary notices and obtained the consents or other legal bases required for Gideon to process Personal Data as contemplated by the Agreement.
5. International data transfers
If Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland will be transferred to a country that is not recognized as providing an adequate level of protection, the parties will put an applicable lawful transfer mechanism in place before relying on that transfer. This may include the European Commission's Standard Contractual Clauses, Module Two for Controller-to-Processor transfers, and, where applicable, the UK International Data Transfer Addendum.
Any required transfer annexes, descriptions of transfers, and technical and organizational measures must be completed by the parties. If an executed transfer mechanism conflicts with this DPA, that transfer mechanism controls for the affected transfer.
6. CCPA-specific terms
To the extent Gideon processes Personal Information subject to the CCPA on Customer's behalf, Gideon will:
Not sell or share Personal Information.
Not retain, use, or disclose Personal Information for a purpose other than providing the services specified in the Agreement or as otherwise permitted by the CCPA.
Not retain, use, or disclose Personal Information outside the direct business relationship between Gideon and Customer.
Not combine Personal Information received from Customer with Personal Information received from another source except as permitted by the CCPA.
Certify that it understands and will comply with these restrictions.
7. Audit rights
Gideon will make information reasonably necessary to demonstrate compliance with this DPA available through its security documentation and Trust Center. With at least 30 days' written notice and no more than once per calendar year, except following a confirmed Security Incident or when required by a regulator, Customer may request an audit or compliance questionnaire. The request is subject to appropriate confidentiality safeguards and must not unreasonably disrupt Gideon's operations. Once available, Gideon may provide its SOC 2 Type II report in lieu of an on-site audit where the report reasonably addresses the requested controls.
8. Contact information
For questions about this DPA or Gideon's data protection practices, contact the privacy and security team.
Legal entity: Gideon Defender, Inc.
Mailing address: 2621 NE 212th Ter, Miami, FL 33180, United States.