Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer organization ("Customer") and Backsplice LLC ("Processor", "we") and governs our processing of personal data in the records Customer puts into Backsplice. An organization admin accepts it for Customer in the dashboard before any governance records can be created or changed, and the version accepted is recorded on the organization. Organization setup (profile, members, sign-in and integration settings) can be done first.
1. Definitions
Terms used here have the meanings given by the data protection law that applies to the processing ("Applicable Law"). [Counsel: which laws to name, for example the GDPR, the UK GDPR and US state privacy laws, and whether to use "controller" and "processor" or "business" and "service provider" as well.]
- "Customer Personal Data" means personal data in the records and files Customer or its users put into the service.
- "Processing" means any operation on personal data, including collecting, storing, retrieving, using, disclosing and deleting it.
- "Sub-processor" means a third party we engage to process Customer Personal Data.
2. Scope and Instructions
We process Customer Personal Data only to provide the service under the Terms of Service and Customer's documented instructions. Customer's use and configuration of the service (for example, inviting users, connecting a webhook, SIEM or identity provider, sharing an auditor or guest link, or turning on Watney) are instructions. If the law requires us to process Customer Personal Data otherwise, we will tell Customer first unless the law forbids it.
- Data subjects: Customer's users, and people named in Customer's records, such as vendor contacts, incident reporters, reviewers and staff on training records
- Categories of data: names, email addresses, job titles, and whatever else Customer's users type or upload
- Duration: while Customer's organization exists, and then as section 7 describes
Customer is responsible for having a lawful basis to put Customer Personal Data into the service. [Counsel: position on special-category and sensitive data.]
3. Sub-processors
Customer authorizes us to use sub-processors in these categories:
- Hosting: the servers and storage the service runs on
- Email delivery: sending service email
- Payments: Stripe, for billing and subscriptions
- AI model provider: the provider named on Watney's system card, for an organization whose admin has turned Watney on, and for Backsplice's own staff assistant, which when switched on can include account names and email addresses from any organization in what it sends. It is off today. [Counsel: how to describe the staff assistant before it is switched on.]
[Counsel: confirm sub-processor list.] We bind each sub-processor to data protection terms that protect Customer Personal Data at least as well as this DPA. [Counsel: advance notice of a new sub-processor, and Customer's right to object.]
4. Security Measures
We maintain technical and organizational measures to protect Customer Personal Data, including:
- HTTPS everywhere, with HTTP Strict Transport Security
- Session cookies that are secure, HttpOnly and SameSite=Strict
- Multi-factor authentication (TOTP and passkeys), SAML single sign-on and SCIM provisioning
- A per-organization IP allowlist, and role-based access (admin, contributor, auditor)
- A hash-chained audit log: a later change to a recorded entry is detectable unless it is made by someone holding the application's signing key and database access, so the log is tamper-evident, not immutable
- TOTP secrets, and the payment-processor API keys we store, encrypted with AES-256-GCM (card numbers go to Stripe, never to us)
[Counsel: personnel confidentiality commitment, and whether to attach a fuller security annex.]
5. Data Subject Requests
We will help Customer, taking into account the nature of the processing, to respond to requests from data subjects to exercise their rights under Applicable Law. If we receive such a request about Customer Personal Data, we will pass it to Customer and not answer it ourselves, other than to acknowledge it and refer the person to Customer. [Counsel: time to forward a request.]
6. Personal Data Breach
If we become aware of a personal data breach affecting Customer Personal Data, we will notify Customer without undue delay. [Counsel: notification window.] The notice will include, as far as then known:
- What happened, and the categories and approximate number of people and records affected
- A contact for more information
- The likely consequences
- What we have done or propose to do about it
We will cooperate with Customer's investigation. Customer decides whether a breach must be reported to a regulator or to the people affected.
7. Deletion and Return
Return. An organization admin can download a copy of the organization's data at any time before deletion: from its settings page, or, while the organization is locked, from the lock page. This includes the demo.
Deletion. Customer Personal Data in an organization is permanently deleted:
- 30 days after an organization admin requests closure, unless an admin cancels the request before then; or
- 90 days after the organization is locked because its demo or its paid subscription ended, unless a plan is chosen before then. Customer's admins are emailed when the organization is locked and 14 days before this deletion.
Deletion removes the organization's records, its uploaded evidence files and the export files generated for it. [Counsel: a lapsed organization is kept longer after its lock than a requested closure is after its request; confirm both windows are acceptable as the deletion obligation on termination.]
What we keep. After deletion we keep the security audit log (its entries stay, labeled with the organization's identifier), deactivated user accounts for people who belonged to no other organization, and billing event records. Copies of deleted data also remain in our database and file backups until those backups expire. [Counsel: the backup retention period to state.] The service's retention job currently keeps each audit log entry for six years from when it was written. [Counsel: retention period and legal basis.] Anything we keep stays subject to this DPA while we keep it.
We will confirm deletion in writing on request. [Counsel: confirm this commitment.]
8. Audits and Information
On request, we will give Customer the information reasonably needed to show that we meet this DPA. [Counsel: audit rights, notice, frequency, cost and confidentiality conditions.]
9. International Transfers
Customer Personal Data is processed in the United States. [Counsel: hosting location, and the transfer mechanism (for example the EU Standard Contractual Clauses and the UK Addendum) for Customers outside the United States.]
10. Watney and the Model Provider
Watney processes Customer Personal Data only after an organization admin opts in, and it is not part of the demo. Each task sends the model provider only what it needs: records Customer's users typed, documentation they pasted in, and the contents of uploaded evidence files (or its earlier summaries of them) when Watney reviews or drafts an answer or summarizes evidence. Watney proposes and never decides; it does not approve a system, set a risk tier or publish a card. The provider and models are named on Watney's system card.
11. Contact
For questions about this DPA or our processing of Customer Personal Data, contact:
Backsplice LLC
[email protected]
© 2026 Backsplice LLC. All rights reserved. · Privacy Policy · Terms of Service · DPA