Legal
Data Processing Addendum
This Data Processing Addendum (the "DPA") supplements the Master Services Agreement (or equivalent commercial contract) between you ("Customer", the "Controller") and TurboFinOps(the "Processor") and applies whenever TurboFinOps processes Personal Data on behalf of the Customer.
Effective date: 2026-05-19· Governing law: laws of England & Wales (UK-GDPR alignment) · Hosting region: EU (Frankfurt) by default.
Quick read for procurement
- Article 28 processor termsStandard GDPR / UK-GDPR processor obligations, including data return and deletion, security measures, and audit rights.
- SCCs incorporatedEU Standard Contractual Clauses (SCCs) and UK IDTA addendum apply to any onward transfers outside the EEA / UK.
- EU-hosted by defaultAll Customer Personal Data is stored in Supabase eu-west-2 (Frankfurt). US data residency is opt-in only.
- Subprocessors listedCurrent subprocessors with processing purpose and region are published at /subprocessors. Customer receives 30-day notice of changes.
1. Definitions
Capitalised terms used but not defined in this DPA have the meaning given in the GDPR (Regulation (EU) 2016/679), the UK-GDPR, or the Master Services Agreement between the Parties. For the avoidance of doubt:
- "Personal Data" means any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR.
- "Processing" means any operation performed on Personal Data, automated or manual, including collection, storage, transfer and erasure.
- "Subprocessor" means any third party engaged by the Processor to Process Personal Data on behalf of the Controller.
- "SCCs" means the Standard Contractual Clauses adopted by the European Commission under Decision 2021/914.
2. Scope and purpose
The Processor will Process Personal Data only as necessary to provide the TurboFinOps service to the Controller (the "Services"), and only on documented instructions from the Controller (typically expressed through the Services configuration, API usage, and Master Services Agreement).
Categories of data subjects: Controller's employees, contractors, customers (where Controller has uploaded customer attribution data for unit economics), and end users of Controller's applications.
Categories of Personal Data: name, email, role, organisation membership, cloud-resource tag values that may contain user identifiers, audit-log actor identifiers, optional cost-attribution customer identifiers supplied by Controller, and AI-usage end-user identifiers supplied by Controller. Special-category data is not requested and should not be supplied.
3. Processor obligations (Article 28 GDPR)
The Processor shall:
- Process Personal Data only on documented instructions from the Controller, including with regard to transfers, unless required by Union or Member State law to Process otherwise (in which case the Processor shall inform the Controller of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest).
- Ensure that persons authorised to Process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement the technical and organisational measures referred to in Article 32 GDPR (see Annex II).
- Respect the conditions for engaging Subprocessors set out in Section 5 of this DPA.
- Taking into account the nature of the Processing, assist the Controller by appropriate technical and organisational measures, in so far as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the data subject's rights.
- Assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 GDPR taking into account the nature of Processing and the information available to the Processor.
- At the choice of the Controller, delete or return all the Personal Data to the Controller after the end of the provision of services relating to Processing, and delete existing copies unless Union or Member State law requires storage of the Personal Data.
- Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, subject to reasonable advance notice and confidentiality protections.
4. Security measures (Article 32)
The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption in transit via TLS 1.2+ on all customer-facing and back-end network paths.
- Encryption at rest: Postgres-level transparent data encryption (Supabase) and application-layer AES-256-GCM with HKDF-derived keys for cloud credentials, API keys, and webhook secrets. Optional HSM integration (AWS KMS / Azure Key Vault / GCP Cloud KMS).
- Tenant isolation enforced at the database layer via PostgreSQL row-level security (RLS) on all tenant-scoped tables, verified by an automated quarterly audit script.
- Access control: SAML SSO + SCIM provisioning, per-organisation role-based access (Admin, FinOps, Security, Auditor, Viewer), multi-factor authentication available.
- Audit logging: append-only audit log on every state-changing operation; logs retained per Customer plan for at least 30 days (Free) or 90 days (Pro) or longer for Enterprise.
- Vulnerability management: weekly automated dependency scans (Dependabot + `npm audit`), annual external penetration test (in preparation), continuous static analysis.
- Network controls: HTTPS-only, Helmet security headers, Content Security Policy, HSTS, per-organisation rate limiting, CSRF Origin/Referer enforcement on state-changing requests.
- Incident response: documented runbook with severity ladder, on-call escalation, and SLA-bound notification of Customer within 72 hours of confirmed Personal Data breach.
Detailed control mapping is maintained in the SOC 2 readiness document (provided on request to enterprise prospects under NDA).
5. Subprocessors
The Controller authorises the Processor to engage Subprocessors to provide the Services. The current list of Subprocessors is published at /subprocessorsand maintained current with at least 30 days' advance notice of any additions or replacements.
The Processor remains fully liable to the Controller for the performance of any Subprocessor's obligations and ensures that each Subprocessor is bound by data-protection obligations no less protective than those in this DPA.
The Controller may object in writing to a new Subprocessor on reasonable data-protection grounds within 15 days of notice. If the objection cannot be resolved, the Controller may terminate the affected portion of the Services without penalty.
6. International data transfers
Personal Data is stored in the European Union (Frankfurt, Germany) by default. Where Personal Data is transferred outside the EEA or the United Kingdom (for example, for Subprocessor services located in the United States), the transfer is governed by:
- the EU Standard Contractual Clauses (SCCs) adopted by Commission Decision 2021/914, Module Two (Controller to Processor), which are hereby incorporated by reference; and
- the UK International Data Transfer Addendum (IDTA) for UK Personal Data, also incorporated by reference.
The Processor will undertake transfer impact assessments where required and supplement the SCCs with additional safeguards (such as encryption keys held in the data-exporting jurisdiction) where appropriate.
7. Data subject rights and breach notification
The Processor will, where technically feasible, assist the Controller in responding to requests by data subjects exercising their rights under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection). The Customer Settings panel provides self-service organisation archive and purge endpoints to support data subject erasure.
The Processor will notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of any Personal Data breach affecting the Controller's data, including a description of the breach, likely consequences, and measures taken or proposed to address it.
8. Data retention and deletion
On termination of the Master Services Agreement, the Processor will, at the Controller's choice, return or delete all Personal Data within 30 days, except where Union or Member State law requires longer retention.
Each plan carries a default retention window for high-volume telemetry tables (audit log, AI usage call records, daily resource cost): 30 days (Free), 180 days (Pro), 365 days (Enterprise), or longer where contractually agreed.
9. Audit rights
The Controller has the right to audit the Processor's compliance with this DPA, by reviewing reasonably available third-party certifications (SOC 2, ISO 27001 — when issued) and by requesting additional information via written notice. On-site or third-party audits may be conducted subject to reasonable advance notice and confidentiality obligations, no more than once per twelve-month period unless required by law or following a confirmed incident.
10. Contact
For data-protection queries: privacy@turbofinops.com.
For security-incident reports: security@turbofinops.com.
To request a countersigned PDF copy of this DPA, email privacy@turbofinops.com with your legal entity details. The countersigned copy is sent within five business days.