Data Processing Agreement
For customers who process personal data of EU/EEA residents, we offer a comprehensive Data Processing Agreement (DPA) compliant with GDPR Article 28.
Last updated: July 31, 2026
What's Included
GDPR Article 28 Compliance
Covers all required processor obligations under EU data protection law.
Standard Contractual Clauses (SCCs)
EU Commission-approved Module 2 clauses for controller-to-processor transfers.
UK GDPR Addendum
Covers UK-specific requirements post-Brexit.
Security Incident Response
48-hour notification commitment with detailed incident reporting.
Subprocessor Management
30-day advance notice of subprocessor changes with objection rights.
Technical & Organizational Measures
Detailed security controls including encryption, access controls, and monitoring.
Request DPA
To request our Data Processing Agreement, please contact us with your company information. We typically respond within 2 business days.
Data Processing Details
| Subject Matter | Provision of AI-powered application generation and hosting services |
| Duration | For the term of your subscription, plus data retention period |
| Nature of Processing | Storage, retrieval, AI processing, hosting, transmission |
| Purpose | To enable you to create, deploy, and manage web applications |
| Data Categories | Account information, application content, user prompts, generated code, usage data |
| Data Subjects | Your authorized users; end users of your generated applications |
International Data Transfers
OverSkill's infrastructure and subprocessors are primarily located in the United States (see our
Subprocessors list).
Data collected by apps you build on OverSkill, including end-user data, is hosted in AWS us-east-1 (USA)
via our database subprocessor. Where you or your app's end users are located outside the United States, the following
cross-border transfer mechanisms apply.
EU / EEA & UK (GDPR)
Transfers of EU/EEA and UK personal data to the United States are made under the EU Commission's Standard Contractual Clauses (SCCs, Module 2 — controller-to-processor), together with the UK International Data Transfer Addendum, supported by supplementary technical and organizational measures (encryption in transit and at rest, access controls). These are included in our DPA on request.
Japan (APPI)
Under Japan's Act on the Protection of Personal Information (APPI), providing personal data to a third party in a foreign country generally requires the data subject's prior consent, unless equivalent protection measures are ensured. For customers in Japan, OverSkill relies on your consent obtained at the point of collection for the transfer of personal data to the United States for hosting and processing, and we contractually require our U.S. subprocessors to maintain protections substantially equivalent to those required under APPI. We do not currently rely on a Japan-specific adequacy or accreditation scheme; the consent-plus-equivalent-safeguards basis described here is the mechanism in place today.
Data residency: OverSkill does not currently offer in-region (e.g. Japan- or EU-resident) data storage for generated apps' data; app data is hosted in the United States. If your use case requires in-region data residency or a specific transfer mechanism not described above, contact [email protected] so we can confirm what we can support before you rely on it.
Key Protections
48-Hour Breach Notification
We commit to notifying you of any confirmed security incident within 48 hours of discovery.
Audit Rights
You have the right to review our data protection policies and request third-party audit reports.
Data Deletion
Upon termination, 30-day export window followed by deletion within 90 days (backup rotation).
Data Subject Rights
We assist you in responding to data subject access, rectification, and deletion requests.
Objection Rights
Object to new subprocessors within 30 days with right to terminate if concerns aren't resolved.
Transfer Mechanisms
Standard Contractual Clauses (Module 2) with supplementary measures for EU/EEA/UK transfers, and consent-plus-equivalent-safeguards for Japan (APPI). See International Data Transfers above.
Frequently Asked Questions
Do I need a DPA?
If you're using OverSkill to process personal data of EU/EEA residents (including employee or customer data), GDPR Article 28 requires you to have a DPA with your data processors. Even if you're not legally required to have one, a DPA provides additional contractual protections.
Is the DPA free?
Yes, we provide our standard DPA at no additional cost to all customers.
Can we use our own DPA template?
We prefer to use our standard DPA which has been designed for our services. However, for enterprise customers with specific requirements, we can discuss modifications. Please contact [email protected].
How does OverSkill handle data transfers to the US for customers in Japan?
OverSkill's hosting and processing take place in the United States. Under Japan's APPI, cross-border transfer of personal data generally requires the data subject's prior consent unless equivalent protection is ensured. For customers in Japan, we rely on your consent obtained at collection for the transfer to the US, and we contractually require our US subprocessors to maintain protections substantially equivalent to APPI. We do not currently offer Japan-resident data storage. If you need a different mechanism or in-region residency, contact [email protected] before relying on it.
How is the DPA executed?
Once you request the DPA, we'll send you a copy for review. The DPA can be executed electronically via DocuSign or a click-through acceptance, depending on your preference.
Questions About Our DPA?
Our legal team is here to help. Contact us with any questions about our Data Processing Agreement or data protection practices.
[email protected]