Self-serve the paperwork.
Sign DPA, BAA, SCCs and jurisdictional addenda click-through from your dashboard. Custom edits go through the account team.
Data Processing Addendum
GDPR Art. 28 compliant. Covers processing purposes, sub-processors, technical measures, breach notification and audit rights. Available click-through at signup.
HIPAA Business Associate Agreement
For eligible plans (Team and above). Restricts routing to BAA-signed upstreams and pins logs to a HIPAA-scoped store.
EU Standard Contractual Clauses
2021 modular SCCs (Module 2, controller-to-processor). Attached to the DPA when data leaves the EEA.
UK International Data Transfer Addendum
ICO-approved addendum to SCCs for UK personal data transferred abroad.
Swiss FADP addendum
Extends SCCs to Swiss data subjects; identifies FDPIC as competent authority.
KSA & UAE addenda
Local addenda covering KSA PDPL (SDAIA), UAE PDPL and DIFC DPL cross-border transfer requirements.
EU-US Data Privacy Framework
We self-certify under DPF for US transfers as a supplemental mechanism alongside SCCs.
Acceptable Use Policy
Prohibits use for weapons, CSAM, non-consensual sexual content, mass surveillance, and EU AI Act prohibited practices.
Service Level Agreement
99.9% (Pro) and 99.99% (Enterprise) uptime commitments with service-credit remediation.
Do I need to email you to sign a DPA?+
No. Standard DPA, SCCs, UK IDTA and Swiss addendum are click-through in your dashboard. Only custom redlines require the account team.
Is the BAA free?+
It's included in the Team and Enterprise plans. Free tier is not HIPAA-eligible because it uses shared caching and pooled logging.
Can we operate under a Master Services Agreement?+
Yes — Enterprise plans include a mutually negotiated MSA + Order Form structure with the DPA as an exhibit.