Connect a repo or start from a template — we build, deploy, and route it with SSL.
Docs, an API, and a CLI — wired to the same platform your services run on.
Effective October 8, 2026
This summary is for convenience — the full text below is what governs.
This Data Processing Agreement is part of the Terms of Service between you and ComputeSphere LLC (“ComputeSphere”, “we”). It applies whenever we process personal data on your behalf while providing the platform, and data protection law requires a contract between us for that processing.
You don’t need to sign anything for it to take effect: it applies from the day you accept the Terms, or from the effective date above if you already have an account, and it lasts for as long as we hold your data. If you need a copy signed by both parties for your records, email [email protected] and we’ll send one.
It does not cover the personal data we handle for our own purposes, such as your account and billing details and visits to our website. We are the controller of that data, and the Privacy Policy covers it.
For personal data in customer data, you are the controller (or a processor acting for your own customers) and we are your processor. You decide what personal data goes on the platform and why; we process it only to provide the service to you.
You are responsible for:
This DPA is not a HIPAA business associate agreement, and we do not sign one today. Don’t place protected health information on the platform if your use of it would require one.
Hosting and running your services: building and deploying them, routing traffic to them, storing their data, collecting their logs and metrics, and giving you support when you ask for it.
For as long as you have an account, and afterwards until the data is deleted as described in Return and deletion.
Storage, transmission, computation, backup and deletion, carried out by automated systems. Our staff do not look at customer data except as described in Processing on your instructions.
Whatever you choose to put on the platform. We don’t control or inspect it. It commonly includes names, email addresses, account identifiers, IP addresses and anything else your services store or write to their logs.
The people your services deal with: typically your customers and users, your staff, and visitors to the sites and applications you host.
We have regional presence in the United States and Europe. Customer data is stored in the region you choose for each environment and stays there; the console shows the regions open to your account. Traffic to your services passes through our edge provider’s network, which has locations around the world, on its way to that region.
We process personal data in customer data only on your documented instructions. The Terms, this DPA, and what you do in the console, API and CLI are your complete instructions: deploying a service, attaching a domain or deleting a volume each tell us what to do with the data involved.
We do not sell personal data in customer data, use it for advertising, combine it with data from other sources, or use it for any purpose of our own. Our staff access customer data only when that is needed to run or secure the platform, to fix a fault, or to help with a support request you raise.
If we believe an instruction breaks data protection law, we’ll tell you and may pause it until you confirm or change it. If a law requires us to process the data in some other way, we’ll tell you first unless that law forbids it.
Everyone at ComputeSphere who is able to access customer data is bound by a duty of confidentiality, and access is limited to the people who need it for their work, logged, and reviewed.
We keep technical and organisational measures in place to protect customer data, suited to the risk. Today they are:
The security page of our docs describes these in more detail, including what remains your responsibility. We may change the measures as the platform develops, but not in a way that lowers the overall level of protection.
We do not yet hold a SOC 2 report or an ISO 27001 certificate of our own. The data centres and cloud services we run on are certified by their operator; those certificates do not cover the ComputeSphere layer.
You give us general authorisation to use sub-processors. The current list, with what each one does and where, is on our Sub-processors page.
We put each sub-processor under a written contract that protects personal data to at least the standard of this DPA, and we remain responsible to you for what they do with it.
Before a new sub-processor starts handling customer data, we’ll update that page and email your account owner at least 30 days ahead. If you object on reasonable data protection grounds within that period, we’ll work with you on a way to avoid the new sub-processor. If we can’t find one, you may cancel the affected service before the change takes effect and we’ll refund any fees you paid in advance for the time after cancellation. Where we must replace a sub-processor urgently, to keep the service running or secure, we’ll tell you as soon as we can instead.
You can read, correct, export and delete customer data yourself through the console, API and CLI, and that is the main way we help you answer people who exercise their rights.
If someone sends us a request about personal data in your customer data, we won’t answer it ourselves. We’ll tell them to contact you and, where we can tell which account it concerns, pass the request to you without undue delay. If you can’t meet a request with the tools the platform gives you, we’ll give you reasonable help on request.
If we become aware of a security incident, we’ll notify you without undue delay and no later than 72 hours after we confirm it, by email to your account owner.
We’ll tell you what we know at that point and add to it as we learn more: what happened, what data and roughly how many people are affected as far as we can tell, what we have done and are doing about it, and who to contact. We’ll take reasonable steps to contain the incident and limit its effects.
Notifying you is not an admission of fault. It is up to you to decide whether to notify a regulator or the people affected, and we’ll give you the information we hold that you need to do so. Incidents caused by your own application, credentials or configuration are not security incidents under this DPA.
Taking into account what we know about the processing, we’ll give you reasonable help with data protection impact assessments and with consulting a regulator, where the law requires these of you and you can’t complete them from the information we publish.
ComputeSphere is based in the United States, and customer data may be stored in or reached from there (see Details of the processing). If your personal data comes from somewhere that restricts sending it abroad, the following apply.
The European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914) form part of this DPA for transfers of personal data subject to the EU GDPR. Module Two applies where you are a controller and Module Three where you are a processor. In those clauses: the optional docking clause applies; the general authorisation option for sub-processors applies, with the notice period in Sub-processors; the optional independent dispute resolution wording does not apply; the governing law and the courts are those of Ireland; and the annexes are completed by Details of the processing, Security measures and the Sub-processors page. For data subject to Swiss law, the clauses apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection.
For transfers subject to the UK GDPR, the clauses above apply as amended by the UK Information Commissioner’s International Data Transfer Addendum, which also forms part of this DPA, with its tables completed by the same sections.
For personal data subject to the Nigeria Data Protection Act 2023, this DPA is the contract under which the data is transferred, and we will protect it to the standard set out here. You remain responsible for confirming that you have a lawful basis under that Act for sending the data outside Nigeria.
If any of these mechanisms is replaced or found invalid, we’ll work with you in good faith to put another lawful one in place. Where the clauses conflict with the rest of this DPA, the clauses win.
While you have an account you can export customer data at any time through the API and the console, and you can ask support for a bulk export of everything in your account. Deleting a service or a resource removes its data as the data page of our docs describes.
When your account is closed, by you or by us, we delete the customer data in it within 90 days. During that period you can ask us to restore the account or to send you an export. Copies in backups are overwritten within a further 35 days.
We keep data longer only where a law requires it, for example invoices and payment records, and we go on protecting it under this DPA until it is deleted. On request we’ll confirm in writing that deletion is complete.
On request we’ll give you the information you reasonably need to check that we meet this DPA: answers to a security questionnaire, the current and past sub-processor lists, and, under a confidentiality agreement, architecture documentation and summaries of penetration tests.
If that doesn’t answer a requirement of data protection law, you or an independent auditor you appoint may audit our processing of your personal data. An audit may take place once in any 12 months, and also after a security incident or when a regulator requires one. Give us at least 30 days’ written notice and agree the scope and timing with us first. It takes place in business hours, under a confidentiality agreement, without access to other customers’ data or to systems where access would weaken security, and at your cost.
The limits and exclusions of liability in the Terms apply to this DPA, taken together with the Terms and not in addition to them. Nothing here limits either party’s liability to an individual, or to a regulator, where data protection law does not allow it to be limited.
If this DPA and the Terms disagree about the processing of personal data, this DPA wins. If the Standard Contractual Clauses apply and disagree with either, the clauses win.
This DPA is governed by the same law and is subject to the same courts as the Terms: the laws of the State of Texas and the state or federal courts located in Texas. The one exception is the Standard Contractual Clauses, which are governed as set out in International transfers.
We may update this DPA when the platform or the law changes. We’ll change the effective date above and, if a change reduces your rights, tell your account owner by email before it takes effect. A copy signed by both parties changes only by agreement in writing.
Questions about this DPA or how we handle your data? Email [email protected]. For a signed copy or a security review, email [email protected]. You can also write to ComputeSphere LLC at 325 N. St. Paul Street, Suite 3100, Dallas, Texas 75201, USA.