Data Processing Agreement

For customers who process personal data of EU/EEA residents, we offer a comprehensive Data Processing Agreement (DPA) compliant with GDPR Article 28.

Last updated: July 31, 2026

What's Included

GDPR Article 28 Compliance

Covers all required processor obligations under EU data protection law.

Standard Contractual Clauses (SCCs)

EU Commission-approved Module 2 clauses for controller-to-processor transfers.

UK GDPR Addendum

Covers UK-specific requirements post-Brexit.

Security Incident Response

48-hour notification commitment with detailed incident reporting.

Subprocessor Management

30-day advance notice of subprocessor changes with objection rights.

Technical & Organizational Measures

Detailed security controls including encryption, access controls, and monitoring.

Request DPA

To request our Data Processing Agreement, please contact us with your company information. We typically respond within 2 business days.

Your business email address
Company name and address
Your OverSkill account email (if different)
Request DPA via Email

[email protected]

Data Processing Details

Subject Matter Provision of AI-powered application generation and hosting services
Duration For the term of your subscription, plus data retention period
Nature of Processing Storage, retrieval, AI processing, hosting, transmission
Purpose To enable you to create, deploy, and manage web applications
Data Categories Account information, application content, user prompts, generated code, usage data
Data Subjects Your authorized users; end users of your generated applications

International Data Transfers

OverSkill's infrastructure and subprocessors are primarily located in the United States (see our Subprocessors list). Data collected by apps you build on OverSkill, including end-user data, is hosted in AWS us-east-1 (USA) via our database subprocessor. Where you or your app's end users are located outside the United States, the following cross-border transfer mechanisms apply.

EU / EEA & UK (GDPR)

Transfers of EU/EEA and UK personal data to the United States are made under the EU Commission's Standard Contractual Clauses (SCCs, Module 2 — controller-to-processor), together with the UK International Data Transfer Addendum, supported by supplementary technical and organizational measures (encryption in transit and at rest, access controls). These are included in our DPA on request.

Japan (APPI)

Under Japan's Act on the Protection of Personal Information (APPI), providing personal data to a third party in a foreign country generally requires the data subject's prior consent, unless equivalent protection measures are ensured. For customers in Japan, OverSkill relies on your consent obtained at the point of collection for the transfer of personal data to the United States for hosting and processing, and we contractually require our U.S. subprocessors to maintain protections substantially equivalent to those required under APPI. We do not currently rely on a Japan-specific adequacy or accreditation scheme; the consent-plus-equivalent-safeguards basis described here is the mechanism in place today.

Data residency: OverSkill does not currently offer in-region (e.g. Japan- or EU-resident) data storage for generated apps' data; app data is hosted in the United States. If your use case requires in-region data residency or a specific transfer mechanism not described above, contact [email protected] so we can confirm what we can support before you rely on it.

Key Protections

48-Hour Breach Notification

We commit to notifying you of any confirmed security incident within 48 hours of discovery.

Audit Rights

You have the right to review our data protection policies and request third-party audit reports.

Data Deletion

Upon termination, 30-day export window followed by deletion within 90 days (backup rotation).

Data Subject Rights

We assist you in responding to data subject access, rectification, and deletion requests.

Objection Rights

Object to new subprocessors within 30 days with right to terminate if concerns aren't resolved.

Transfer Mechanisms

Standard Contractual Clauses (Module 2) with supplementary measures for EU/EEA/UK transfers, and consent-plus-equivalent-safeguards for Japan (APPI). See International Data Transfers above.

Frequently Asked Questions

Do I need a DPA?

If you're using OverSkill to process personal data of EU/EEA residents (including employee or customer data), GDPR Article 28 requires you to have a DPA with your data processors. Even if you're not legally required to have one, a DPA provides additional contractual protections.

Is the DPA free?

Yes, we provide our standard DPA at no additional cost to all customers.

Can we use our own DPA template?

We prefer to use our standard DPA which has been designed for our services. However, for enterprise customers with specific requirements, we can discuss modifications. Please contact [email protected].

How does OverSkill handle data transfers to the US for customers in Japan?

OverSkill's hosting and processing take place in the United States. Under Japan's APPI, cross-border transfer of personal data generally requires the data subject's prior consent unless equivalent protection is ensured. For customers in Japan, we rely on your consent obtained at collection for the transfer to the US, and we contractually require our US subprocessors to maintain protections substantially equivalent to APPI. We do not currently offer Japan-resident data storage. If you need a different mechanism or in-region residency, contact [email protected] before relying on it.

How is the DPA executed?

Once you request the DPA, we'll send you a copy for review. The DPA can be executed electronically via DocuSign or a click-through acceptance, depending on your preference.

Questions About Our DPA?

Our legal team is here to help. Contact us with any questions about our Data Processing Agreement or data protection practices.

[email protected]