Data Processing Agreement

Standard DPA for customers who require GDPR and CCPA compliant data processing terms.

Last updated: April 2026

Section 1

Parties

This Data Processing Agreement ("DPA") is entered into between:

This DPA supplements and forms part of the Seracade Terms of Service.

Section 2

Definitions

Section 3

Scope of Processing

Seracade processes the following categories of data on behalf of the Controller:

Processing is performed for the following purposes:

Duration of processing: the active service period plus 90 days for log expiration.

Section 4

Processor Obligations

Seracade shall:

Section 5

Sub-processors

The Controller authorizes the use of the following Sub-processors:

Sub-processor Purpose Location
Cloudflare, Inc. Infrastructure, Workers compute, KV storage US / Global edge
Resend, Inc. Transactional email delivery US
OpenRouter Model replay during audit (if applicable) US

Seracade will notify the Controller at least 30 days before adding or replacing a Sub-processor. The Controller may object to any new Sub-processor by providing written notice within that period.

Section 6

Data Retention

All retention periods run automatically. The Controller may request early deletion at any time.

Section 7

Data Subject Rights

The Controller is responsible for responding to Data Subject requests (access, rectification, erasure, restriction, portability, and objection).

Seracade will assist the Controller in fulfilling these requests. The Controller or any Data Subject may request deletion of Personal Data at any time by contacting support@seracade.com.

Seracade will respond to deletion requests within 5 business days.

Section 8

Security Measures

Seracade implements the following technical and organizational measures to protect Personal Data:

Full details are available at seracade.com/security.

Section 9

Breach Notification

Seracade will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a Personal Data breach.

Notification will include:

Section 10

International Transfers

Seracade processes data on Cloudflare's global edge network, which may result in Personal Data being processed outside the Controller's jurisdiction.

Where transfers are made to countries without an adequacy decision, Seracade relies on the Sub-processors' own transfer mechanisms (SCCs, DPAs, or equivalent safeguards).

Section 11

Governing Law

This DPA shall be governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to its conflict of laws provisions.

Any disputes arising from this DPA shall be subject to the exclusive jurisdiction of the courts of the State of Delaware.

Execute This DPA
To execute this DPA, email support@seracade.com with your company name and authorized signatory. We will counter-sign within 2 business days.