What Is a Data Processing Agreement?
A Data Processing Agreement (DPA) is a legally binding contract that defines how SurfaceOwl processes personal data on behalf of our enterprise customers. It's required under:
- GDPR Article 28 - For EU/EEA customer data
- UK GDPR - For UK customer data
- Swiss FADP - For Swiss customer data
- CCPA - For California residents (optional but recommended)
Do You Need a DPA?
✅ You likely need a DPA if:
- You process personal data of EU/EEA residents
- You process personal data of UK residents
- You process personal data of Swiss residents
- Your company is in a regulated industry (healthcare, finance, government)
- Your compliance team or customers request a DPA
- You're an enterprise customer with data protection obligations
❌ You may NOT need a DPA if:
- You only process data of US residents (except California)
- You're a small business without compliance requirements
- Your data is anonymized or aggregated only (no personal identifiers)
Not sure? Contact us at privacy@surfaceowl.com and we'll help you determine if a DPA is needed.
What's Included in Our DPA
Our standard Data Processing Agreement includes:
1. Roles & Responsibilities
- You (customer) = Data Controller
- SurfaceOwl = Data Processor
- Clear definition of processing purposes and instructions
2. Security Measures
- Encryption (TLS 1.2+, AES-256)
- Access controls and authentication
- Regular security assessments
- Incident response procedures
3. Sub-Processors
- Complete list of sub-processors (AWS, Auth0, SparkPost, etc.)
- 30-day advance notice of changes
- Right to object to new sub-processors
- See our full list: Sub-Processors
4. Data Subject Rights
- Support for access requests
- Support for deletion requests
- Support for rectification requests
- Response within 30 days
5. Data Breach Notification
- Notification within 72 hours of discovery (GDPR requirement)
- Details of breach, data affected, and mitigation steps
- Assistance with customer notification obligations
6. International Data Transfers
- Standard Contractual Clauses (SCCs) - EU Commission 2021/914
- UK Addendum - For UK data subjects
- Swiss FADP compliance - For Swiss data subjects
7. Audit Rights
- Annual SOC 2 reports (when available)
- Security questionnaire responses
- On-site audits (with reasonable notice and limitations)
8. Data Deletion
- Deletion within 30 days of termination
- Certification of deletion provided
- Exceptions for legal retention requirements
9. Liability & Indemnification
- Limitation of liability provisions
- Indemnification for data breaches caused by us
- Insurance coverage details
10. Term & Termination
- Effective for duration of Services Agreement
- Termination procedures
- Post-termination obligations
Two Versions Available
We offer two versions of our DPA to match your business needs:
🚀 Startup Version (Recommended for Most Customers)
Best for:
- Small to medium businesses (SMB)
- Mid-market companies
- Startups and scale-ups
- Customers who value plain English over legal formality
Features:
- ✅ Fully GDPR/CCPA compliant
- ✅ Plain English language (easy to understand)
- ✅ Honest about our current capabilities
- ✅ Faster execution (less intimidating to legal teams)
- ✅ Standard terms (minimal negotiation)
Download: SurfaceOwl_DPA_Startup_Version.pdf (Coming soon)
🏢 Enterprise Version (For Large Organizations)
Best for:
- Fortune 500 companies
- Highly regulated industries (healthcare, finance, government)
- Customers requiring SOC 2 Type II
- Complex multi-jurisdictional deployments
Features:
- ✅ Comprehensive security disclosures
- ✅ Detailed audit rights
- ✅ Extensive compliance certifications
- ✅ Formal legal language
- ✅ Customizable for negotiation
Availability: Contact privacy@surfaceowl.com for enterprise DPA
How to Request a DPA
Standard Process
- Contact us at privacy@surfaceowl.com
- Subject line: "DPA Request"
- Include: - Your company name
- Contact information
- Jurisdictions of data subjects (EU, UK, Switzerland, California, etc.)
- Preferred DPA version (Startup or Enterprise)
- We'll respond within 2 business days with:
- DPA document for review
- DocuSign link for electronic execution
- Any questions about your specific needs
- Review & Execute - Review with your legal team
- Suggest any needed modifications
- Sign via DocuSign
Typical turnaround: 1-2 weeks (standard terms), 2-4 weeks (with negotiation)
Security & Compliance
Current Certifications
| Certification | Status | Details |
|---|---|---|
| SOC 2 Type II | 🟡 Planned | Target: Q3 2026 |
| ISO 27001 | 🟡 Framework-based | Following best practices |
| GDPR Compliance | ✅ Compliant | Full GDPR Article 28 compliance |
| CCPA Compliance | ✅ Compliant | Service Provider requirements |
Infrastructure Security
All customer data is processed using:
- AWS - SOC 2, ISO 27001, FedRAMP certified
- Auth0/Okta - SOC 2, ISO 27001 certified
- Encryption - TLS 1.2+ in transit, AES-256 at rest
- Access Controls - Role-based access, MFA required
- Monitoring - 24/7 security monitoring via AWS CloudWatch
Learn more: Security Overview (Coming soon)
Frequently Asked Questions
Q: How long does it take to execute a DPA?
A: Standard DPA (no negotiation): 1-2 weeks. Custom DPA (with negotiation): 2-4 weeks.
Q: Can we modify the DPA terms?
A: Yes, for enterprise customers. Small changes (contact info, governing law) are usually quick. Substantive changes (liability caps, audit rights) may require legal review.
Q: Does the DPA cost extra?
A: No, there is no additional fee for executing a DPA. It's included with your Services Agreement.
Q: What if we need a HIPAA BAA?
A: A HIPAA Business Associate Agreement (BAA) is separate from a DPA. We are not currently HIPAA-ready. Please contact us if you have healthcare compliance needs so we can discuss timelines.
Q: Can we use our own DPA template?
A: We prefer to use our standard DPA, but we will review customer DPA templates on a case-by-case basis for enterprise deals. Please send your template to privacy@surfaceowl.com for review.
Q: What happens if we don't sign a DPA?
A: If you're required to have a DPA under GDPR or other regulations, we cannot process personal data on your behalf without one. For US-only, non-regulated customers, a DPA is optional but recommended.
Q: How do you handle sub-processor changes?
A: We provide 30-day advance notice via email and our sub-processors page. You have the right to object, and we'll work with you to find an alternative solution.
Q: Where is our data stored?
A: Customer data is primarily stored in AWS us-east-1 (N. Virginia) with backups in us-west-2 (Oregon). See our sub-processors page for details on international data transfers.
Q: How quickly do you notify us of a data breach?
A: We commit to notification within 72 hours of becoming aware of a breach affecting your data, consistent with GDPR requirements.
Document History
| Date | Change |
|---|---|
| 2025-11-02 | Initial publication of DPA overview page |
This page provides information about our Data Processing Agreement. The actual DPA is a legally binding contract that will be executed separately. This page does not constitute legal advice.