Legal & Trust
Data Processing Agreement
Document available below.
Annex — updated August 28, 2026
Aggregate vendor risk signal
When Customer assesses a third-party vendor in the Services, Scarlet Risk contributes de-identified risk signal about that vendor — risk category ratings, whether public breach or incident history was noted, the general sensitivity of data involved, and generic data-category labels — to a shared, platform-wide vendor registry.
This signal is stored without Customer's name, company, account identifier, or any other information that identifies Customer, and it is aggregated across all contributing accounts. Other customers assessing the same vendor may see the aggregate risk score, aggregate data categories, and known flags.
No customer can see which other customers use or assess a given vendor, and no account-identifying data is ever shared between accounts. Customer's own assessments, notes, and evidence remain private to Customer's account.
Because this signal is de-identified and aggregated, Scarlet Risk processes it as its own service-improvement data and not as Customer Personal Data. Aggregate signal is retained for the life of the vendor registry entry and is not deleted on account termination, since it contains no data identifying Customer.
This is the current published version of the Data Processing Agreement. For prior versions, custom terms, or questions about scope, contact legal@scarletrisk.com.
