Legal

Data Processing Agreement

Pursuant to GDPR Article 28  ·  Last updated: May 12, 2026

Table of Contents

  1. Definitions
  2. Subject Matter & Duration
  3. Nature & Purpose of Processing
  4. Obligations of the Processor
  5. Sub-processors
  6. Data Subject Rights
  7. Security Measures
  8. Data Breach Notification
  9. Return & Deletion of Data
  10. Audit Rights
  11. International Transfers
  12. Governing Law

This Data Processing Agreement ("DPA") forms part of the agreement between Customer (the "Controller") and Cutoverstream LLC (the "Processor") for the use of the CutoverStream Service. It satisfies the requirements of GDPR Article 28 for processing of personal data on behalf of the Controller.

1. Definitions

In this DPA, the following terms have the meanings given below:

2. Subject Matter & Duration

This DPA governs the processing of Personal Data by Cutoverstream LLC on behalf of the Customer in connection with the provision of the CutoverStream Service as described in the Terms of Service.

This DPA is effective for the duration of the subscription agreement and terminates upon expiration or termination of the Customer's account, subject to the data retention provisions in Section 9.

3. Nature, Purpose & Categories of Data Processed

CategoryExamplesPurpose
User IdentityNames, email addresses, usernamesAuthentication, account management
Professional DataJob titles, team names, phone numbersUser profile and collaboration features
Project DataCutover plan content, task assignments, commentsCore Service functionality
Usage DataLogin times, feature usage, API callsService operation and improvement
Technical DataIP addresses, session tokens, error logsSecurity and troubleshooting

The Controller is responsible for ensuring that the Personal Data submitted to the Service is lawfully collected and that data subjects have been informed of processing in accordance with applicable law.

4. Obligations of the Processor

Cutoverstream LLC, as Processor, agrees to:

5. Sub-processors

The Controller provides general authorization for Cutoverstream LLC to engage the following sub-processors:

Sub-processorServiceLocationData Processed
Cloudflare, Inc.Infrastructure, database, CDNUnited States / GlobalAll Customer Data
Clerk, Inc.Authentication & identityUnited StatesUser identity data
Stripe, Inc.Payment processingUnited StatesBilling & payment data
Resend, Inc.Email deliveryUnited StatesEmail addresses, notification content
Functional Software (Sentry)Error monitoringUnited StatesTechnical error data
Anthropic, PBCAI narrative generationUnited StatesProject data (only when AI feature used)

Cutoverstream LLC will notify the Controller of any intended addition or replacement of sub-processors with at least 14 days' notice, giving the Controller the opportunity to object. Each sub-processor is bound by data processing terms providing equivalent protections to this DPA.

6. Data Subject Rights

If Cutoverstream LLC receives a request from a data subject exercising their rights under GDPR (access, rectification, erasure, portability, restriction, or objection), we will:

Data subjects may also submit requests directly to privacy@cutoverstream.com and we will coordinate with the appropriate Controller.

7. Technical & Organizational Security Measures

Cutoverstream LLC implements the following measures in accordance with GDPR Article 32:

8. Data Breach Notification

In the event of a Personal Data breach, Cutoverstream LLC will:

The Controller is responsible for notifying the relevant supervisory authority and affected data subjects where required by law.

9. Return & Deletion of Data

Upon termination of the agreement, Cutoverstream LLC will:

Billing records required by law (typically 7 years) are retained in accordance with applicable tax regulations, with only the minimum necessary data retained.

10. Audit Rights

Cutoverstream LLC will provide the Controller with all information reasonably necessary to demonstrate compliance with this DPA. The Controller may conduct audits or inspections, with at least 30 days' written notice, no more than once per calendar year, and at the Controller's expense.

Audits must be conducted during business hours and must not unreasonably disrupt Cutoverstream LLC's operations. The Controller agrees to treat all audit findings as confidential.

11. International Data Transfers

Customer Data is processed primarily in the United States. For transfers of Personal Data from the EEA or UK to the United States, Cutoverstream LLC relies on Standard Contractual Clauses (SCCs) as adopted by the European Commission.

By accepting this DPA, the parties are deemed to have entered into the Module Two (Controller to Processor) Standard Contractual Clauses, which are incorporated herein by reference.

12. Governing Law

This DPA is governed by the laws of the State of North Carolina, United States, consistent with the Terms of Service, except where EU/UK GDPR requirements mandate otherwise.

Agreement Execution

This DPA is entered into automatically upon acceptance of the CutoverStream Terms of Service. For enterprise customers requiring a countersigned DPA for their records, contact legal@cutoverstream.com.

Data Processor
Cutoverstream LLC
Chapel Hill, NC, United States
Data Controller
Customer Organization
As specified in account registration
Organization Admin email on file

Need a countersigned DPA?

Email legal@cutoverstream.com with your organization details and we will provide a signed copy within 5 business days.