What Is a Data Processing Agreement?

A Data Processing Agreement (DPA) is a legally binding contract that defines how SurfaceOwl processes personal data on behalf of our enterprise customers. It's required under:

  • GDPR Article 28 - For EU/EEA customer data
  • UK GDPR - For UK customer data
  • Swiss FADP - For Swiss customer data
  • CCPA - For California residents (optional but recommended)

Do You Need a DPA?

✅ You likely need a DPA if:

  • You process personal data of EU/EEA residents
  • You process personal data of UK residents
  • You process personal data of Swiss residents
  • Your company is in a regulated industry (healthcare, finance, government)
  • Your compliance team or customers request a DPA
  • You're an enterprise customer with data protection obligations

❌ You may NOT need a DPA if:

  • You only process data of US residents (except California)
  • You're a small business without compliance requirements
  • Your data is anonymized or aggregated only (no personal identifiers)

Not sure? Contact us at privacy@surfaceowl.com and we'll help you determine if a DPA is needed.

What's Included in Our DPA

Our standard Data Processing Agreement includes:

1. Roles & Responsibilities

  • You (customer) = Data Controller
  • SurfaceOwl = Data Processor
  • Clear definition of processing purposes and instructions

2. Security Measures

  • Encryption (TLS 1.2+, AES-256)
  • Access controls and authentication
  • Regular security assessments
  • Incident response procedures

3. Sub-Processors

  • Complete list of sub-processors (AWS, Auth0, SparkPost, etc.)
  • 30-day advance notice of changes
  • Right to object to new sub-processors
  • See our full list: Sub-Processors

4. Data Subject Rights

  • Support for access requests
  • Support for deletion requests
  • Support for rectification requests
  • Response within 30 days

5. Data Breach Notification

  • Notification within 72 hours of discovery (GDPR requirement)
  • Details of breach, data affected, and mitigation steps
  • Assistance with customer notification obligations

6. International Data Transfers

  • Standard Contractual Clauses (SCCs) - EU Commission 2021/914
  • UK Addendum - For UK data subjects
  • Swiss FADP compliance - For Swiss data subjects

7. Audit Rights

  • Annual SOC 2 reports (when available)
  • Security questionnaire responses
  • On-site audits (with reasonable notice and limitations)

8. Data Deletion

  • Deletion within 30 days of termination
  • Certification of deletion provided
  • Exceptions for legal retention requirements

9. Liability & Indemnification

  • Limitation of liability provisions
  • Indemnification for data breaches caused by us
  • Insurance coverage details

10. Term & Termination

  • Effective for duration of Services Agreement
  • Termination procedures
  • Post-termination obligations

Two Versions Available

We offer two versions of our DPA to match your business needs:

🚀 Startup Version (Recommended for Most Customers)

Best for:

  • Small to medium businesses (SMB)
  • Mid-market companies
  • Startups and scale-ups
  • Customers who value plain English over legal formality

Features:

  • ✅ Fully GDPR/CCPA compliant
  • ✅ Plain English language (easy to understand)
  • ✅ Honest about our current capabilities
  • ✅ Faster execution (less intimidating to legal teams)
  • ✅ Standard terms (minimal negotiation)

Download: SurfaceOwl_DPA_Startup_Version.pdf (Coming soon)

🏢 Enterprise Version (For Large Organizations)

Best for:

  • Fortune 500 companies
  • Highly regulated industries (healthcare, finance, government)
  • Customers requiring SOC 2 Type II
  • Complex multi-jurisdictional deployments

Features:

  • ✅ Comprehensive security disclosures
  • ✅ Detailed audit rights
  • ✅ Extensive compliance certifications
  • ✅ Formal legal language
  • ✅ Customizable for negotiation

Availability: Contact privacy@surfaceowl.com for enterprise DPA

How to Request a DPA

Standard Process

  1. Contact us at privacy@surfaceowl.com
  2. Subject line: "DPA Request"
  3. Include: - Your company name
    • Contact information
    • Jurisdictions of data subjects (EU, UK, Switzerland, California, etc.)
    • Preferred DPA version (Startup or Enterprise)
  4. We'll respond within 2 business days with:
    • DPA document for review
    • DocuSign link for electronic execution
    • Any questions about your specific needs
  5. Review & Execute - Review with your legal team
    • Suggest any needed modifications
    • Sign via DocuSign

Typical turnaround: 1-2 weeks (standard terms), 2-4 weeks (with negotiation)

Security & Compliance

Current Certifications

Certification Status Details
SOC 2 Type II 🟡 Planned Target: Q3 2026
ISO 27001 🟡 Framework-based Following best practices
GDPR Compliance ✅ Compliant Full GDPR Article 28 compliance
CCPA Compliance ✅ Compliant Service Provider requirements

Infrastructure Security

All customer data is processed using:

  • AWS - SOC 2, ISO 27001, FedRAMP certified
  • Auth0/Okta - SOC 2, ISO 27001 certified
  • Encryption - TLS 1.2+ in transit, AES-256 at rest
  • Access Controls - Role-based access, MFA required
  • Monitoring - 24/7 security monitoring via AWS CloudWatch

Learn more: Security Overview (Coming soon)

Frequently Asked Questions

Q: How long does it take to execute a DPA?

A: Standard DPA (no negotiation): 1-2 weeks. Custom DPA (with negotiation): 2-4 weeks.

Q: Can we modify the DPA terms?

A: Yes, for enterprise customers. Small changes (contact info, governing law) are usually quick. Substantive changes (liability caps, audit rights) may require legal review.

Q: Does the DPA cost extra?

A: No, there is no additional fee for executing a DPA. It's included with your Services Agreement.

Q: What if we need a HIPAA BAA?

A: A HIPAA Business Associate Agreement (BAA) is separate from a DPA. We are not currently HIPAA-ready. Please contact us if you have healthcare compliance needs so we can discuss timelines.

Q: Can we use our own DPA template?

A: We prefer to use our standard DPA, but we will review customer DPA templates on a case-by-case basis for enterprise deals. Please send your template to privacy@surfaceowl.com for review.

Q: What happens if we don't sign a DPA?

A: If you're required to have a DPA under GDPR or other regulations, we cannot process personal data on your behalf without one. For US-only, non-regulated customers, a DPA is optional but recommended.

Q: How do you handle sub-processor changes?

A: We provide 30-day advance notice via email and our sub-processors page. You have the right to object, and we'll work with you to find an alternative solution.

Q: Where is our data stored?

A: Customer data is primarily stored in AWS us-east-1 (N. Virginia) with backups in us-west-2 (Oregon). See our sub-processors page for details on international data transfers.

Q: How quickly do you notify us of a data breach?

A: We commit to notification within 72 hours of becoming aware of a breach affecting your data, consistent with GDPR requirements.

Document History

Date Change
2025-11-02 Initial publication of DPA overview page

This page provides information about our Data Processing Agreement. The actual DPA is a legally binding contract that will be executed separately. This page does not constitute legal advice.