Draft pending legal review
This document has not been reviewed by counsel and is not yet binding. Contact us before relying on it.
Data processing addendum
This addendum describes how Sterling Readiness Group, LLC processes personal data on behalf of a customer using Cyber Ambush. It supplements the terms of service and the privacy policy.
Effective date: September 17, 2026
Roles of the parties
Who determines the purpose of processing, and who carries it out.
- The customer is the controller of the personal data processed through its exercises.
- Sterling Readiness Group, LLC is the processor, acting on the customer's behalf.
- Where the customer is itself acting as a processor for another controller, the customer confirms it has the authority to appoint us as a subprocessor.
- Each party is responsible for its own compliance with applicable data protection law in its role.
Subject matter, duration, nature and purpose
What is processed, for how long, and why.
- Subject matter: personal data contained in customer accounts and in the exercises the customer plans, runs and reviews on the platform.
- Duration: for as long as the customer's account is active, and thereafter only as needed to complete deletion or return of data.
- Nature of processing: hosting, storage, access control, display, transmission to the AI gateway for assessment and drafting, generation of after-action reports, export, and deletion.
- Purpose: to provide the Cyber Ambush tabletop exercise platform to the customer, including producing the after-action review and improvement plan for each exercise.
Categories of data subjects and personal data
Whose data is processed, and which fields.
- Data subjects: the customer's personnel who take part in exercises, including Executive Sponsors, Operators, Participants and Evaluators, the last of which also covers observers invited only to watch.
- Personal data: name, work email address, department, assigned exercise role, and the responses, decisions and notes those people record during an exercise.
- The platform is not intended for special-category or sensitive personal data, and the customer must not enter it.
Processing on documented instructions
The limits on what we may do with the data.
- We process personal data only on the customer's documented instructions, which comprise this addendum, the terms of service, the order form and the customer's use of the platform's features.
- We do not process personal data for our own purposes, and we do not sell it or use it for advertising.
- We do not train models on customer exercise content.
- If we believe an instruction would breach applicable data protection law, we will inform the customer without undue delay.
Confidentiality of personnel
Who inside our organization may access customer data.
- Access to customer personal data is limited to personnel who need it to operate or support the service.
- Those personnel are bound by written confidentiality obligations that survive the end of their engagement.
- Access is removed when it is no longer required for the person's role.
Security measures
The technical and organizational measures we apply.
- The technical and organizational measures that apply to customer data — account isolation, role-scoped access, encryption in transit and at rest, and how exercise data reaches the AI — are described on our security and compliance page, which forms part of this addendum rather than being duplicated here.
- We may update those measures over time, provided the level of protection is not reduced.
- We hold no independent certification today. What we do and do not claim is set out on the security and compliance page.
Subprocessors
Who else may process customer personal data.
- The current subprocessors, and what each one does, are listed in the subprocessor table on our security page.
- We will give the customer notice before adding or replacing a subprocessor, so the customer has an opportunity to object on reasonable data protection grounds.
- Each subprocessor is bound by data protection obligations no less protective than those in this addendum, and we remain responsible for its performance.
Data subject requests
How we help the customer answer requests from its people.
- Where a data subject contacts us directly about personal data we process for a customer, we will refer them to the customer rather than respond on the customer's behalf.
- We will provide reasonable assistance so the customer can respond to requests for access, correction, deletion, restriction, objection or portability.
- The platform's own export and deletion features are the primary means of satisfying such requests.
- Requests for assistance with a data subject request should be sent to privacy@sterlingllc.com, or to the processor's postal address below.
Personal data breach notification
What happens if customer personal data is affected by an incident.
- We will notify the customer without undue delay after becoming aware of a personal data breach affecting personal data we process for that customer.
- The notification will describe the nature of the breach, the categories and approximate volume of data involved, the likely consequences and the measures taken or proposed, to the extent known at the time.
- We will provide further information as the investigation progresses, and reasonable assistance with the customer's own regulatory notifications.
- Notifying the customer is not an admission of fault by either party.
- Breach notifications from the customer to the processor, and queries about a notification we have sent, should be directed to privacy@sterlingllc.com.
Deletion or return of data
How deletion works during the subscription and when the relationship ends.
- The customer may export its exercise records and after-action reports at any time while the account is active.
- On written request, whether during the subscription or after termination, we will permanently delete the customer's personal data and exercise data within 30 days and confirm when the deletion is complete.
- Where the customer asks for return rather than deletion, we will provide the data in the platform's export formats before deleting it.
- We will retain personal data beyond that period only where applicable law requires it, and only for as long as that requirement lasts.
Audit and information rights
How the customer can verify our compliance.
- On reasonable written request, we will provide the information reasonably necessary to demonstrate compliance with this addendum, including our current security documentation and self-assessment mappings.
- We hold no third-party audit report or attestation today, so responses will be documentary rather than certificate-based.
- Where documentation is not sufficient, the customer may request an audit no more than once in any 12-month period, on at least 30 days' notice, at a mutually agreed time and scope, subject to confidentiality and without disrupting the service or other customers.
International transfers
Where processing takes place.
- Personal data is processed in the United States.
- Where the customer transfers personal data from a jurisdiction that restricts onward transfer, the parties will put an appropriate transfer mechanism in place, which will be recorded in the order form or an annex to this addendum.
Governing law and venue
Which law applies to this addendum.
- This addendum is governed by the laws of the State of Tennessee, without regard to its conflict of laws rules.
- The parties submit to the exclusive jurisdiction of the state and federal courts located in Davidson County, Tennessee.
- Jurisdiction reflects Sterling Readiness Group, LLC's state of organization. Like the rest of this document, this clause is pending legal review.
Processor's notice address
Where formal notices to the processor should be sent.
41 Peabody St
Nashville, TN 37210
United States
+1 629-280-5900
For data subject requests and personal data breach notifications, notice may also be given to privacy@sterlingllc.com.
Questions about this addendum
How to reach us about data processing.
To request a signed copy, raise a subprocessor objection, or ask about anything in this addendum, reach out through the contact page.