## What Is a Data Processing Agreement?

A Data Processing Agreement (DPA) is a legally binding contract that defines how SurfaceOwl processes personal data on behalf of our enterprise customers. It's required under:

- **GDPR Article 28** \- For EU/EEA customer data
- **UK GDPR** \- For UK customer data
- **Swiss FADP** \- For Swiss customer data
- **CCPA** \- For California residents (optional but recommended)

## Do You Need a DPA?

### ✅ You likely need a DPA if:

- You process personal data of **EU/EEA residents**
- You process personal data of **UK residents**
- You process personal data of **Swiss residents**
- Your company is in a **regulated industry** (healthcare, finance, government)
- Your compliance team or customers **request a DPA**
- You're an **enterprise customer** with data protection obligations

### ❌ You may NOT need a DPA if:

- You only process data of **US residents** (except California)
- You're a **small business** without compliance requirements
- Your data is **anonymized** or **aggregated only** (no personal identifiers)

**Not sure?** Contact us at **privacy@surfaceowl.com** and we'll help you determine if a DPA is needed.

## What's Included in Our DPA

Our standard Data Processing Agreement includes:

### 1. Roles & Responsibilities

- You (customer) = Data Controller
- SurfaceOwl = Data Processor
- Clear definition of processing purposes and instructions

### 2. Security Measures

- Encryption (TLS 1.2+, AES-256)
- Access controls and authentication
- Regular security assessments
- Incident response procedures

### 3. Sub-Processors

- Complete list of sub-processors (AWS, Auth0, SparkPost, etc.)
- 30-day advance notice of changes
- Right to object to new sub-processors
- See our full list: [Sub-Processors](/content/legal/sub-processors/index.html)

### 4. Data Subject Rights

- Support for access requests
- Support for deletion requests
- Support for rectification requests
- Response within 30 days

### 5. Data Breach Notification

- Notification within **72 hours** of discovery (GDPR requirement)
- Details of breach, data affected, and mitigation steps
- Assistance with customer notification obligations

### 6. International Data Transfers

- **Standard Contractual Clauses (SCCs)** \- EU Commission 2021/914
- **UK Addendum** \- For UK data subjects
- **Swiss FADP compliance** \- For Swiss data subjects

### 7. Audit Rights

- Annual SOC 2 reports (when available)
- Security questionnaire responses
- On-site audits (with reasonable notice and limitations)

### 8. Data Deletion

- Deletion within **30 days** of termination
- Certification of deletion provided
- Exceptions for legal retention requirements

### 9. Liability & Indemnification

- Limitation of liability provisions
- Indemnification for data breaches caused by us
- Insurance coverage details

### 10. Term & Termination

- Effective for duration of Services Agreement
- Termination procedures
- Post-termination obligations

## Two Versions Available

We offer two versions of our DPA to match your business needs:

### 🚀 Startup Version (Recommended for Most Customers)

**Best for:**

- Small to medium businesses (SMB)
- Mid-market companies
- Startups and scale-ups
- Customers who value plain English over legal formality

**Features:**

- ✅ Fully GDPR/CCPA compliant
- ✅ Plain English language (easy to understand)
- ✅ Honest about our current capabilities
- ✅ Faster execution (less intimidating to legal teams)
- ✅ Standard terms (minimal negotiation)

**Download:** SurfaceOwl_DPA_Startup_Version.pdf _(Coming soon)_

### 🏢 Enterprise Version (For Large Organizations)

**Best for:**

- Fortune 500 companies
- Highly regulated industries (healthcare, finance, government)
- Customers requiring SOC 2 Type II
- Complex multi-jurisdictional deployments

**Features:**

- ✅ Comprehensive security disclosures
- ✅ Detailed audit rights
- ✅ Extensive compliance certifications
- ✅ Formal legal language
- ✅ Customizable for negotiation

**Availability:** Contact privacy@surfaceowl.com for enterprise DPA

## How to Request a DPA

### Standard Process

1. **Contact us** at privacy@surfaceowl.com
2. **Subject line:** "DPA Request"
3. **Include:**   - Your company name
   - Contact information
   - Jurisdictions of data subjects (EU, UK, Switzerland, California, etc.)
   - Preferred DPA version (Startup or Enterprise)
4. **We'll respond** within 2 business days with:
   - DPA document for review
   - DocuSign link for electronic execution
   - Any questions about your specific needs
5. **Review & Execute**   - Review with your legal team
   - Suggest any needed modifications
   - Sign via DocuSign

**Typical turnaround:** 1-2 weeks (standard terms), 2-4 weeks (with negotiation)

## Security & Compliance

### Current Certifications

| Certification | Status | Details |
| --- | --- | --- |
| **SOC 2 Type II** | 🟡 Planned | Target: Q3 2026 |
| **ISO 27001** | 🟡 Framework-based | Following best practices |
| **GDPR Compliance** | ✅ Compliant | Full GDPR Article 28 compliance |
| **CCPA Compliance** | ✅ Compliant | Service Provider requirements |

### Infrastructure Security

All customer data is processed using:

- **AWS** \- SOC 2, ISO 27001, FedRAMP certified
- **Auth0/Okta** \- SOC 2, ISO 27001 certified
- **Encryption** \- TLS 1.2+ in transit, AES-256 at rest
- **Access Controls** \- Role-based access, MFA required
- **Monitoring** \- 24/7 security monitoring via AWS CloudWatch

Learn more: [Security Overview](/content/security/index.html) _(Coming soon)_

## Frequently Asked Questions

### Q: How long does it take to execute a DPA?

**A:** Standard DPA (no negotiation): 1-2 weeks. Custom DPA (with negotiation): 2-4 weeks.

### Q: Can we modify the DPA terms?

**A:** Yes, for enterprise customers. Small changes (contact info, governing law) are usually quick. Substantive changes (liability caps, audit rights) may require legal review.

### Q: Does the DPA cost extra?

**A:** No, there is no additional fee for executing a DPA. It's included with your Services Agreement.

### Q: What if we need a HIPAA BAA?

**A:** A HIPAA Business Associate Agreement (BAA) is separate from a DPA. We are not currently HIPAA-ready. Please contact us if you have healthcare compliance needs so we can discuss timelines.

### Q: Can we use our own DPA template?

**A:** We prefer to use our standard DPA, but we will review customer DPA templates on a case-by-case basis for enterprise deals. Please send your template to privacy@surfaceowl.com for review.

### Q: What happens if we don't sign a DPA?

**A:** If you're required to have a DPA under GDPR or other regulations, we cannot process personal data on your behalf without one. For US-only, non-regulated customers, a DPA is optional but recommended.

### Q: How do you handle sub-processor changes?

**A:** We provide 30-day advance notice via email and our [sub-processors page](/content/legal/sub-processors/index.html). You have the right to object, and we'll work with you to find an alternative solution.

### Q: Where is our data stored?

**A:** Customer data is primarily stored in AWS us-east-1 (N. Virginia) with backups in us-west-2 (Oregon). See our [sub-processors page](/content/legal/sub-processors/index.html) for details on international data transfers.

### Q: How quickly do you notify us of a data breach?

**A:** We commit to notification within **72 hours** of becoming aware of a breach affecting your data, consistent with GDPR requirements.

## Document History

| Date | Change |
| --- | --- |
| 2025-11-02 | Initial publication of DPA overview page |

_This page provides information about our Data Processing Agreement. The actual DPA is a legally binding contract that will be executed separately. This page does not constitute legal advice._
