logoComputeSphere

Data Processing Agreement

Effective October 8, 2026

The short version

  • You decide what personal data goes on the platform. We process it only to run the service for you.
  • It applies automatically as part of the Terms. Ask us if you need a signed copy.
  • We have regional presence in the United States and Europe. Your data stays in the region you choose for each environment.
  • We tell you before we add a sub-processor, and without undue delay if a security incident affects your data.
  • When your account closes, we delete your data.

This summary is for convenience — the full text below is what governs.

1. How this DPA applies

This Data Processing Agreement is part of the Terms of Service between you and ComputeSphere LLC (“ComputeSphere”, “we”). It applies whenever we process personal data on your behalf while providing the platform, and data protection law requires a contract between us for that processing.

You don’t need to sign anything for it to take effect: it applies from the day you accept the Terms, or from the effective date above if you already have an account, and it lasts for as long as we hold your data. If you need a copy signed by both parties for your records, email [email protected] and we’ll send one.

It does not cover the personal data we handle for our own purposes, such as your account and billing details and visits to our website. We are the controller of that data, and the Privacy Policy covers it.

2. Definitions

  • Customer data means the content you put on the platform or that your services produce there: code and images, configuration and environment variables, databases and stored files, the traffic your services receive, and the logs they write.
  • Personal data means any information in customer data that relates to an identified or identifiable person.
  • Data protection law means the privacy and data protection laws that apply to the processing of personal data under this DPA. Depending on where you and your users are, that includes the EU and UK General Data Protection Regulations, the Nigeria Data Protection Act 2023, and United States state privacy laws such as the California Consumer Privacy Act.
  • Controller, processor, data subject and processing have the meanings data protection law gives them. Where a law uses “business” and “service provider” instead, those terms apply in the same way.
  • Sub-processor means another company we engage that processes personal data in customer data.
  • Security incident means a breach of our security that leads to the accidental or unlawful destruction, loss, alteration or disclosure of, or access to, personal data in customer data.

3. Roles of the parties

For personal data in customer data, you are the controller (or a processor acting for your own customers) and we are your processor. You decide what personal data goes on the platform and why; we process it only to provide the service to you.

You are responsible for:

  • having a lawful basis, and giving any notices or collecting any consents needed, for the personal data you put on the platform;
  • the instructions you give us, which must comply with the law;
  • the parts of security that are yours: your application, your credentials and API tokens, and who you invite to your account; and
  • deciding whether the platform suits the data you plan to run on it.

This DPA is not a HIPAA business associate agreement, and we do not sign one today. Don’t place protected health information on the platform if your use of it would require one.

4. Details of the processing

Subject matter and purpose

Hosting and running your services: building and deploying them, routing traffic to them, storing their data, collecting their logs and metrics, and giving you support when you ask for it.

Duration

For as long as you have an account, and afterwards until the data is deleted as described in Return and deletion.

Nature of the processing

Storage, transmission, computation, backup and deletion, carried out by automated systems. Our staff do not look at customer data except as described in Processing on your instructions.

Types of personal data

Whatever you choose to put on the platform. We don’t control or inspect it. It commonly includes names, email addresses, account identifiers, IP addresses and anything else your services store or write to their logs.

Categories of data subjects

The people your services deal with: typically your customers and users, your staff, and visitors to the sites and applications you host.

Where it is processed

We have regional presence in the United States and Europe. Customer data is stored in the region you choose for each environment and stays there; the console shows the regions open to your account. Traffic to your services passes through our edge provider’s network, which has locations around the world, on its way to that region.

5. Processing on your instructions

We process personal data in customer data only on your documented instructions. The Terms, this DPA, and what you do in the console, API and CLI are your complete instructions: deploying a service, attaching a domain or deleting a volume each tell us what to do with the data involved.

We do not sell personal data in customer data, use it for advertising, combine it with data from other sources, or use it for any purpose of our own. Our staff access customer data only when that is needed to run or secure the platform, to fix a fault, or to help with a support request you raise.

If we believe an instruction breaks data protection law, we’ll tell you and may pause it until you confirm or change it. If a law requires us to process the data in some other way, we’ll tell you first unless that law forbids it.

6. Confidentiality

Everyone at ComputeSphere who is able to access customer data is bound by a duty of confidentiality, and access is limited to the people who need it for their work, logged, and reviewed.

7. Security measures

We keep technical and organisational measures in place to protect customer data, suited to the risk. Today they are:

  • Encryption in transit. Public traffic uses TLS 1.2 or later, with certificates issued and renewed automatically. Traffic is encrypted again between the edge and our gateway, and internal traffic is encrypted at the infrastructure layer.
  • Encryption at rest. Images, configuration, secrets, logs and metrics are encrypted at rest. Secrets are decrypted only where your service runs.
  • Isolation. Accounts are isolated from each other, and so are environments within an account and the spherelets that run each service.
  • Access control. Roles at account and project level, API tokens limited to a scope you choose, and single sign-on on the plans that include it.
  • Records. Actions that change state are recorded by the platform.
  • Scanning. Every image the platform builds is scanned for known vulnerabilities.
  • Edge protection. Managed protection against denial-of-service attacks and a managed web application firewall.
  • Incident response. Documented procedures, and published reports after incidents.

The security page of our docs describes these in more detail, including what remains your responsibility. We may change the measures as the platform develops, but not in a way that lowers the overall level of protection.

We do not yet hold a SOC 2 report or an ISO 27001 certificate of our own. The data centres and cloud services we run on are certified by their operator; those certificates do not cover the ComputeSphere layer.

8. Sub-processors

You give us general authorisation to use sub-processors. The current list, with what each one does and where, is on our Sub-processors page.

We put each sub-processor under a written contract that protects personal data to at least the standard of this DPA, and we remain responsible to you for what they do with it.

Before a new sub-processor starts handling customer data, we’ll update that page and email your account owner at least 30 days ahead. If you object on reasonable data protection grounds within that period, we’ll work with you on a way to avoid the new sub-processor. If we can’t find one, you may cancel the affected service before the change takes effect and we’ll refund any fees you paid in advance for the time after cancellation. Where we must replace a sub-processor urgently, to keep the service running or secure, we’ll tell you as soon as we can instead.

9. Requests from individuals

You can read, correct, export and delete customer data yourself through the console, API and CLI, and that is the main way we help you answer people who exercise their rights.

If someone sends us a request about personal data in your customer data, we won’t answer it ourselves. We’ll tell them to contact you and, where we can tell which account it concerns, pass the request to you without undue delay. If you can’t meet a request with the tools the platform gives you, we’ll give you reasonable help on request.

10. Security incidents

If we become aware of a security incident, we’ll notify you without undue delay and no later than 72 hours after we confirm it, by email to your account owner.

We’ll tell you what we know at that point and add to it as we learn more: what happened, what data and roughly how many people are affected as far as we can tell, what we have done and are doing about it, and who to contact. We’ll take reasonable steps to contain the incident and limit its effects.

Notifying you is not an admission of fault. It is up to you to decide whether to notify a regulator or the people affected, and we’ll give you the information we hold that you need to do so. Incidents caused by your own application, credentials or configuration are not security incidents under this DPA.

11. Help with your own obligations

Taking into account what we know about the processing, we’ll give you reasonable help with data protection impact assessments and with consulting a regulator, where the law requires these of you and you can’t complete them from the information we publish.

12. International transfers

ComputeSphere is based in the United States, and customer data may be stored in or reached from there (see Details of the processing). If your personal data comes from somewhere that restricts sending it abroad, the following apply.

European Economic Area and Switzerland

The European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914) form part of this DPA for transfers of personal data subject to the EU GDPR. Module Two applies where you are a controller and Module Three where you are a processor. In those clauses: the optional docking clause applies; the general authorisation option for sub-processors applies, with the notice period in Sub-processors; the optional independent dispute resolution wording does not apply; the governing law and the courts are those of Ireland; and the annexes are completed by Details of the processing, Security measures and the Sub-processors page. For data subject to Swiss law, the clauses apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection.

United Kingdom

For transfers subject to the UK GDPR, the clauses above apply as amended by the UK Information Commissioner’s International Data Transfer Addendum, which also forms part of this DPA, with its tables completed by the same sections.

Nigeria

For personal data subject to the Nigeria Data Protection Act 2023, this DPA is the contract under which the data is transferred, and we will protect it to the standard set out here. You remain responsible for confirming that you have a lawful basis under that Act for sending the data outside Nigeria.

If any of these mechanisms is replaced or found invalid, we’ll work with you in good faith to put another lawful one in place. Where the clauses conflict with the rest of this DPA, the clauses win.

13. Return and deletion

While you have an account you can export customer data at any time through the API and the console, and you can ask support for a bulk export of everything in your account. Deleting a service or a resource removes its data as the data page of our docs describes.

When your account is closed, by you or by us, we delete the customer data in it within 90 days. During that period you can ask us to restore the account or to send you an export. Copies in backups are overwritten within a further 35 days.

We keep data longer only where a law requires it, for example invoices and payment records, and we go on protecting it under this DPA until it is deleted. On request we’ll confirm in writing that deletion is complete.

14. Information and audits

On request we’ll give you the information you reasonably need to check that we meet this DPA: answers to a security questionnaire, the current and past sub-processor lists, and, under a confidentiality agreement, architecture documentation and summaries of penetration tests.

If that doesn’t answer a requirement of data protection law, you or an independent auditor you appoint may audit our processing of your personal data. An audit may take place once in any 12 months, and also after a security incident or when a regulator requires one. Give us at least 30 days’ written notice and agree the scope and timing with us first. It takes place in business hours, under a confidentiality agreement, without access to other customers’ data or to systems where access would weaken security, and at your cost.

15. Liability and order of precedence

The limits and exclusions of liability in the Terms apply to this DPA, taken together with the Terms and not in addition to them. Nothing here limits either party’s liability to an individual, or to a regulator, where data protection law does not allow it to be limited.

If this DPA and the Terms disagree about the processing of personal data, this DPA wins. If the Standard Contractual Clauses apply and disagree with either, the clauses win.

16. Governing law

This DPA is governed by the same law and is subject to the same courts as the Terms: the laws of the State of Texas and the state or federal courts located in Texas. The one exception is the Standard Contractual Clauses, which are governed as set out in International transfers.

17. Changes to this DPA

We may update this DPA when the platform or the law changes. We’ll change the effective date above and, if a change reduces your rights, tell your account owner by email before it takes effect. A copy signed by both parties changes only by agreement in writing.

18. Contact us

Questions about this DPA or how we handle your data? Email [email protected]. For a signed copy or a security review, email [email protected]. You can also write to ComputeSphere LLC at 325 N. St. Paul Street, Suite 3100, Dallas, Texas 75201, USA.