Legal

Data processing agreement

Last updated: 19 September 2026

This agreement is between Runasec Limited (“RunaSec”, “we”, “us”) and the MSP or business that uses RunaCheck or RunaTrain (“Customer”). It forms part of the terms under which the Customer uses our apps (the “Agreement”) and applies whenever we process Customer Personal Information. If it conflicts with the Agreement on personal information, this agreement wins.

1. Meaning of terms

  • Personal Information means information about an identifiable individual. It includes “personal data” under the GDPR and UK GDPR.
  • Customer Personal Information means Personal Information that we process for the Customer through RunaCheck or RunaTrain.
  • Privacy Laws means the New Zealand Privacy Act 2020 and any other privacy law that applies to the Customer Personal Information, including the GDPR and UK GDPR.

2. Roles

The Customer is responsible for the Customer Personal Information (the “controller” under the GDPR, or the “agency” under the Privacy Act). If the Customer is an MSP acting for its own clients, it confirms it has their authority to give us these instructions. We are the Customer’s processor and handle the information only on its behalf.

We are separately responsible for the account details of people who sign in to our apps, as described in our Privacy Policy.

3. What we process

PurposeProviding RunaCheck and RunaTrain to the Customer under the Agreement.
What we doRead, store, analyse and report on Microsoft 365 configuration and user information; make changes and run tasks in the Customer’s tenant when the Customer uses those features; run training and phishing simulations.
Types of informationNames and work email addresses; Microsoft 365 security configuration that may identify users or administrators; training results; phishing simulation activity (such as whether a person clicked, reported or ignored a simulated email).
Whose informationThe Customer’s staff and the staff and users of the Customer’s clients.
How longWhile the Customer uses the apps, then deleted as set out in section 8.

4. What we promise

We will:

  • process Customer Personal Information only to provide the apps and on the Customer’s documented instructions (the Agreement, and its use of the apps, are its instructions), unless the law requires otherwise, and tell the Customer if we think an instruction breaks Privacy Laws;
  • make sure the people who can access it are bound by confidentiality;
  • protect it with reasonable technical and organisational safeguards;
  • not sell it, use it for advertising, or send it to any AI provider;
  • help the Customer respond to requests from individuals and to regulators, and pass on any request we receive about Customer Personal Information without responding to it ourselves, unless the law requires us to;
  • give the Customer the information it reasonably needs to show that we comply with this agreement.

5. What the Customer promises

The Customer will make sure it has the right to connect its tenant (and its clients’ tenants) to the apps and to give us the instructions in this agreement. It will also tell the individuals concerned that their information is being used, and will choose the permissions and features it enables.

6. Sub-processors

The Customer agrees that we may use sub-processors of the types described in our Privacy Policy to help us provide the apps. We will give the Customer our current list of sub-processors on request. We will bind each one to obligations no less protective than these, and we remain responsible for them. We will give the Customer at least 14 days’ notice (by email or in the app) before adding or replacing a provider that will handle Customer Personal Information. If the Customer objects on reasonable data protection grounds and we can’t resolve it, the Customer may cancel the affected service.

7. Where data is held and transfers

We may store and process Customer Personal Information in any country where we or our providers operate, and we may change these locations over time. On request, we will tell the Customer where its data is currently held. Wherever it is, we will protect it as this agreement requires. Where Privacy Laws require it for a transfer, we will use an approved transfer mechanism, such as standard contractual clauses, or rely on an adequacy decision.

8. Breaches, deletion and audits

  • Breaches. If we become aware of a breach affecting Customer Personal Information, we will tell the Customer without undue delay and within 72 hours, with the details we have, and help it assess and respond, including any notification to the Privacy Commissioner or affected individuals.
  • Deletion. We will delete Customer Personal Information within 30 days after the Customer disconnects its tenant or cancels, or sooner if it asks us to. At the Customer’s choice we will return a copy first, and we may keep information only where the law requires it.
  • Audits. Once a year, on reasonable notice and during business hours, the Customer may ask for the information needed to check our compliance with this agreement, and we will answer its questions. If a regulator requires more, we will cooperate.

9. Everything else

Our liability under this agreement is subject to the limits in the Agreement. New Zealand law governs it, and the New Zealand courts have jurisdiction. We may update this agreement to reflect changes in the law or in the apps, and will tell customers about material changes. If you need a signed copy, or have questions, email info [at] runasec [dot] com.