Data Processing Agreement
Last Updated: August 6, 2026 · Effective Date: August 6, 2026
This Data Processing Agreement (including the annexes attached hereto, this “DPA”) is entered into by the customer identified in the Agreement (“Customer”) and Alter Labs, Inc. (“Alter”) and forms part of the Terms of Service between the parties (as amended, the “Agreement”). This DPA governs Alter’s processing of Personal Data on Customer’s behalf in connection with the Service. Where Customer is itself a processor acting for a third-party controller, references to “Customer” as Controller apply mutatis mutandis and Alter acts as a sub-processor.
1. Definitions
For purposes of this DPA, the terms below have the meanings set forth below. Capitalized terms used but not defined in this DPA have the meanings given in the Agreement.
a. “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity, where “control” refers to the power to direct or cause the direction of the subject entity, whether through ownership of voting securities, by contract, or otherwise.
b. “Applicable Data Protection Laws” means the privacy, data protection, and data security laws and regulations applicable to Alter’s Processing of Personal Data under the Agreement, including, as and to the extent applicable, the State Privacy Laws and the GDPR.
c. “Controller” means the entity that, alone or jointly with others, determines the purposes and means of the Processing of Personal Data, including any “business” or “controller” as defined by the CCPA or other State Privacy Laws.
d. “Customer Data” means information provided or otherwise made available by or on behalf of Customer to Alter for Processing on Customer’s behalf to perform the Service.
e. “Data Subject” means the identified or identifiable natural person to whom Personal Data relates.
f. “EEA” means the European Economic Area.
g. “FADP” means the Swiss Federal Act on Data Protection of 25 September 2020 (as amended and in force from 1 September 2023) and any applicable implementing legislation and ordinances, and, to the extent applicable, its predecessor of 19 June 1992.
h. “FDPIC” means the Swiss Federal Data Protection and Information Commissioner.
i. “GDPR” means, as and where applicable: (i) the General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”); and/or (ii) the EU GDPR as it forms part of UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018 (“UK GDPR”), including, in each case, any applicable national implementing or supplementary legislation (e.g., the UK Data Protection Act 2018) and any successor, amendment, or re-enactment.
j. “Information Security Incident” means a breach of Alter’s security resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data in Alter’s possession, custody, or control. Information Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial-of-service attempts, or other network attacks on firewalls or networked systems.
k. “Personal Data” means Customer Data that constitutes “personal data,” “personal information,” or “personally identifiable information” defined in Applicable Data Protection Laws or information of a similar character regulated thereby, provided that Personal Data does not include such information pertaining to Customer’s business contacts who are Customer personnel or information that Alter receives, collects, or generates independently of the Service and not from or on behalf of Customer.
l. “Process” or “Processing” means any operation performed by Alter (or on Alter’s behalf) for Customer under the Agreement on Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
m. “Processor” means the entity that Processes Personal Data on behalf of the Controller, including any “service provider” or “contractor” as defined by the CCPA.
n. “Restricted Transfer” means the disclosure, grant of access, or other transfer of Personal Data to any person located in: (i) in the context of the EEA, a country outside the EEA without an adequacy decision from the European Commission (an “EU Restricted Transfer”); (ii) in the context of the UK, a country outside the UK without an adequacy decision from the UK Government (a “UK Restricted Transfer”); and (iii) in the context of Switzerland, a country outside Switzerland without an adequacy decision from the Swiss Government (a “Swiss Restricted Transfer”), in each case that would be prohibited without a legal basis under applicable data protection law (including Chapter V of the GDPR, where applicable).
o. “SCCs” means the standard contractual clauses approved by the European Commission pursuant to Implementing Decision (EU) 2021/914.
p. “Security Measures” has the meaning given in Section 4(a).
q. “Service” has the meaning given in the Agreement (Alter’s hosted credential-authorization platform for AI agents).
r. “State Privacy Laws” means, collectively, the comprehensive state-specific data privacy laws (and any implementing regulations) currently in effect and applicable to Alter’s Processing of Personal Data under the Agreement.
s. “Subprocessors” means Alter’s Affiliates and third parties that Alter engages to Process Personal Data in relation to the Service.
t. “Supervisory Authority” means any entity with the authority to enforce Applicable Data Protection Laws, including (i) in the EEA and under the EU GDPR, as defined in the EU GDPR; (ii) in the UK and under the UK GDPR, the UK Information Commissioner’s Office; and (iii) in Switzerland and under the FADP, the FDPIC.
u. “UK Transfer Addendum” means the template Addendum B.1.0 issued by the ICO and laid before Parliament under s119A of the Data Protection Act 2018 on 2 February 2022, as revised under Section 18 of its Mandatory Clauses.
2. Duration and scope of DPA
a. This DPA will remain in effect so long as Alter Processes Personal Data, notwithstanding the expiration or termination of the Agreement.
b. Alter’s access to and Processing of Personal Data is not part of the consideration exchanged by the parties under the Agreement.
c. Processing of Personal Data subject to the GDPR is subject to Annex 2 (European Annex).
d. Processing of Personal Data subject to the State Privacy Laws with respect to which Customer is a Business, Controller, Processor, or Service Provider (as defined in the State Privacy Laws) is subject to Annex 3 (State Privacy Laws Annex).
3. Customer instructions
Alter will Process Personal Data only in accordance with Customer’s documented instructions, including as set forth in this DPA, the Agreement, any applicable Order, the configuration and API calls Customer makes through the Service, and any other written instructions Customer provides from time to time that are consistent with the Agreement and this DPA. To the extent Customer requests instructions outside the scope of the Service or that would require Alter to materially change the Service or undertake additional work not contemplated by the Agreement, the parties will agree to such instructions in a mutually executed amendment. By entering into this DPA, Customer instructs Alter to Process Personal Data to provide the Service and to perform its other obligations and exercise its rights under the Agreement. The details of Alter’s Processing (including the respective roles of the parties) are described in Annex 1.
4. Security
a. Alter Security Measures. Alter will implement and maintain technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data as described in Annex 4 (the “Security Measures”), taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing and the risks to Data Subjects. Alter may update the Security Measures from time to time, including to maintain or improve security or address changes in Applicable Data Protection Laws, so long as the updated measures do not materially decrease the overall protection of Personal Data.
b. Personnel. Alter will ensure that personnel authorized to Process Personal Data are subject to appropriate confidentiality obligations and have received appropriate training, and will limit access to those who need it to provide the Service.
c. Information Security Incidents. Alter will notify Customer without undue delay of any Information Security Incident of which Alter becomes aware. Such notification will describe, to the extent then known, available details of the incident, including steps taken to mitigate potential risks and steps Alter recommends Customer take. Alter’s notification of, or response to, an Information Security Incident will not be construed as Alter’s acknowledgement of any fault or liability with respect to the incident. Alter will reasonably cooperate with Customer and take such commercially reasonable steps, to the extent within Alter’s control, as Customer may reasonably request and the parties mutually agree in good faith to assist in the investigation. Customer is solely responsible for complying with notification laws applicable to Customer and fulfilling any third-party notification obligations related to any Information Security Incident. If Customer determines that an Information Security Incident must be notified to any Supervisory Authority, Data Subject(s), the public, or others, then to the extent such notice directly or indirectly refers to or identifies Alter, and where permitted by applicable law, Customer will (i) notify Alter in advance and (ii) in good faith consult with Alter and consider any clarifications or corrections Alter may reasonably request that relate to Alter’s involvement and are consistent with applicable law.
d. Customer’s security responsibilities and assessment. Without limiting Alter’s obligations under this Section 4, Customer is solely responsible for its use of the Service, including (i) making appropriate use of the Service to ensure a level of security appropriate to the risk; (ii) securing the account authentication credentials, systems, and devices Customer uses to access the Service; (iii) securing Customer’s systems and devices that Customer makes available for Alter to access; and (iv) backing up Personal Data, as applicable. Customer acknowledges that it has evaluated the Service, the Security Measures, and Alter’s commitments under this DPA and, based on information made available by Alter, determines that they are adequate to meet Customer’s needs and provide a level of security appropriate to the risk.
5. Data Subject rights
a. Assistance. Taking into account the nature of the Processing, Alter will provide Customer with assistance reasonably necessary and technically feasible for Customer to fulfill requests by Data Subjects to exercise their rights under Applicable Data Protection Laws (“Data Subject Requests”) with respect to Personal Data in Alter’s possession or control. To the extent such assistance requires work beyond the Service, Customer will compensate Alter at Alter’s then-current professional-services rates (made available on request), and Alter will provide a good-faith estimate of applicable fees on request.
b. Customer responsibility. If Alter receives a Data Subject Request, Alter will (i) promptly notify Customer (unless prohibited by applicable law) and (ii) advise the Data Subject to submit the request to Customer. Customer is solely responsible for responding to any such request, unless otherwise required by applicable law.
6. Customer responsibilities
a. Customer will ensure (and is solely responsible for ensuring) that it has provided all notices to, and obtained all consents and permissions from, third parties (including Data Subjects), and has reserved all necessary rights, as required under Applicable Data Protection Laws for Alter to Process Personal Data as contemplated by the Agreement.
b. Customer represents and warrants that Customer Data does not and will not contain social security or other government-issued identification numbers; protected health information subject to HIPAA or other information regarding an individual’s medical history, condition, or treatment; health insurance information; biometric information; consumer online-banking usernames or passwords, or credentials to any financial accounts; bank account or routing numbers; tax return data; payment-card data subject to PCI DSS; personal data of children under 16; or any other special-category or sensitive data (as defined in Applicable Data Protection Laws) (“Restricted Data”), in each case except as expressly permitted under an executed Order or written addendum. For the avoidance of doubt, Restricted Data does not include the Connected-Account Credentials (OAuth access and refresh tokens, API keys, and managed secrets) that the Service is designed to store and broker, or the ordinary business, accounting, customer, invoice, and payment records that documented Provider operations transmit between Customer and a Provider.
c. Customer will ensure that there is, and will be throughout the term of the Agreement, a valid legal basis for Alter’s Processing of Personal Data as required under all Applicable Data Protection Laws (including, where applicable, Articles 6, 9(2), and/or 10 of the GDPR), and that all Data Subjects have been presented with all required notices and have provided all required consents relating to that Processing.
d. Where Customer enables diagnostic payload capture, Customer acknowledges and warrants that it is responsible for the contents transmitted through that feature and will not route Restricted Data through it, and will not route any special-category data through it without an appropriate legal basis and safeguards. This obligation supplements Customer’s Restricted Data representations above.
7. Subprocessors
a. Consent. Customer specifically authorizes the engagement of Alter’s Affiliates as Subprocessors and generally authorizes Alter to engage third parties as Subprocessors in accordance with this Section 7.
b. Information about Subprocessors. Information about Subprocessors, including their functions and locations, is available in Annex 5 and at Alter’s sub-processor page (the “Subprocessor Site”). Alter may continue to use those Subprocessors engaged as of the effective date of this DPA.
c. Requirements. When engaging any Subprocessor, Alter will enter into a written contract containing data-protection obligations no less protective than those in this DPA, to the extent applicable to the nature of the Subprocessor’s services. Alter remains responsible for the performance of the obligations subcontracted to each Subprocessor and is liable for its acts and omissions to the same extent as Alter would be had it performed the Processing itself.
d. Objection. When Alter engages a new Subprocessor after the effective date, Alter will notify Customer (including the name and location of the Subprocessor and the activities it will perform) by updating the Subprocessor Site and providing written notice (including by email) to Customer’s designated contact. If Customer objects within thirty (30) days after receipt of such notice on reasonable grounds relating to the protection of Personal Data, the parties will work together in good faith to find a mutually acceptable resolution. If they cannot, Customer may, as its sole and exclusive remedy, terminate the affected Service by written notice and pay all amounts due as of termination.
8. Audits
Customer may audit Alter’s compliance with its obligations under this DPA up to once per year, and on such other occasions as required by Applicable Data Protection Laws solely to the extent Customer is legally required to conduct the audit or a competent Supervisory Authority requires it, in each case on written request providing reasonable detail. Alter will contribute to such audits by providing the information and assistance reasonably necessary to conduct the audit. If the controls to be assessed are addressed in a SOC 2 Type 2, ISO 27001, NIST, or similar report issued by a qualified third-party auditor within twelve (12) months of the request, and Alter confirms there have been no known material changes in the audited controls since the report, Customer agrees to accept that report in lieu of an audit of those controls. To request an audit, Customer must submit a proposed audit plan at least two weeks in advance, and any third-party auditor must sign a customary non-disclosure agreement (acceptance not to be unreasonably withheld); Alter may object to an auditor that is, in Alter’s reasonable opinion, not independent, a competitor, or otherwise manifestly unsuitable, in which case Customer will appoint another auditor or conduct the audit itself. Audits must occur during regular business hours, be subject to the agreed plan and Alter’s security and other relevant policies, and not unreasonably interfere with Alter’s operations, and nothing in this Section requires Alter to breach any duty of confidentiality. Any audit is at Customer’s sole expense, and Customer will reimburse Alter for reasonable, documented costs (including Alter’s reasonable internal time at its then-current professional-services rates).
9. Return and deletion
a. Upon the date of cessation of any Service involving the Processing of Personal Data (the “Cessation Date”), Alter will promptly cease all Processing of Personal Data other than for storage and Processing necessary to effect return, deletion, or anonymization, or as otherwise permitted or required under this DPA or applicable law.
b. To the extent technically feasible, on written request made within thirty (30) days after the Cessation Date (the “Post-cessation Storage Period”), Alter will, within a commercially reasonable period and as elected by Customer, either (i) return a complete copy of Personal Data in Alter’s possession by secure transfer, promptly following which Alter will delete or anonymize all other copies, or (ii) delete or anonymize all Personal Data in Alter’s possession.
c. If Customer does not instruct Alter within the Post-cessation Storage Period, Alter will, within a commercially reasonable time after it expires, delete or anonymize all Personal Data then in its possession, custody, or control to the fullest extent technically feasible.
d. Alter may retain Personal Data to the extent permitted or required by applicable law, for no longer than that law requires, provided that Alter will (i) maintain its confidentiality and protect it in accordance with the Security Measures, (ii) Process it only as necessary for the purpose the law requires, and (iii) delete or anonymize it once no longer required to be retained. Credentials are deleted from the production secrets service by immediately blocking access and requesting permanent deletion without a recovery window; the provider may require a short asynchronous interval to complete physical deletion, during which the Credentials remain inaccessible and must not be read, refreshed, or used. Certification of deletion under Clauses 8.5 and 16(d) of the SCCs will be provided only on Customer’s written request.
10. Artificial intelligence and automated processing
a. Alter will not use Personal Data to train, fine-tune, develop, or improve any artificial-intelligence or machine-learning model, whether Alter’s own or a third party’s. This restriction does not apply to Alter’s use of information that was irreversibly de-identified before model development, or operational telemetry that does not contain Personal Data, to provide, secure, and improve the Service.
b. Alter will require its Subprocessors, including any AI model providers, not to use Personal Data for their own model training, fine-tuning, development, or improvement purposes.
c. Processor Materials. Alter’s own platform, software, models, security data, and de-identified or aggregated data that do not identify Customer, any End User, or any individual (“Processor Materials”) are not Personal Data or Customer Data and are not subject to this Section 10 or to the return-and-deletion obligations in Section 9.
11. Miscellaneous
a. Except as expressly modified by this DPA, the Agreement remains in full force and effect. To the extent of any conflict between this DPA and the other terms of the Agreement regarding the Processing of Personal Data, this DPA controls. Notices Alter is required or permitted to give Customer under this DPA may be given in accordance with the Agreement’s notice provisions, to Customer’s data-protection contact in Annex 1, to Alter’s primary points of contact with Customer, or to any email address Customer designates for Service-related communications; Customer is solely responsible for ensuring those addresses are valid.
b. Alter will cooperate in good faith with Customer to consider any amendments reasonably necessary to address compliance with Applicable Data Protection Laws.
c. Alter may, on written notice, vary this DPA solely to the extent necessary to maintain compliance with Applicable Data Protection Laws, provided that any such variation will not materially reduce the protections afforded to Personal Data or materially increase Customer’s obligations without Customer’s written agreement, and may include varying or replacing the SCCs in accordance with Paragraph 3.4 of Annex 2.
d. To the extent permitted by Applicable Data Protection Laws and the SCCs (if and as they apply), the total aggregate liability of either party under or in connection with this DPA and the SCCs will not exceed any limitations or caps on, and is subject to any exclusions of, liability and loss agreed in the Agreement; provided that nothing in this Section 11(d) affects any person’s liability to Data Subjects under the third-party-beneficiary provisions of the SCCs.
e. In the event of any conflict or inconsistency between (i) this DPA and the Agreement, this DPA prevails; or (ii) any SCCs entered into under Paragraph 3 of Annex 2 and this DPA and/or the Agreement, the SCCs prevail in respect of the Restricted Transfer to which they apply.
f. This DPA is governed by the law and jurisdiction stated in the Agreement, unless Applicable Data Protection Laws require otherwise.
12. Government and legal-process requests
If Alter receives a legally binding request from a public authority, court, or other third party to access or disclose Customer Personal Data (a “Request”), Alter will, unless legally prohibited: (a) promptly notify Customer of the Request and, where lawful and practicable, direct the requesting party to Customer; (b) disclose only the Customer Personal Data legally required; and (c) use commercially reasonable efforts to challenge or narrow any Request that Alter reasonably considers overbroad, unlawful, or inconsistent with Applicable Data Protection Laws, including by seeking a protective order or equivalent where appropriate. Where Alter is legally prohibited from notifying Customer, Alter will use commercially reasonable efforts to obtain a waiver so that it may provide Customer with as much information as it is lawfully able to share.
Annex 1 — Data processing details
Alter / “Data Importer” details. Name: Alter Labs, Inc. Address: 169 Madison Ave, STE 15836, New York, NY 10016, USA. Contact for data protection: privacy@alterauth.com. Activities relevant to the transfer: provision of the Alter credential-authorization Service for AI agents. Role: Processor (or Sub-processor, as applicable).
Customer / “Data Exporter” details. Name: the entity that is Customer under the Agreement. Address: [Customer’s registered address]. Contact for data protection: [Customer’s data-protection contact]. Role: Controller (or Processor, where Customer is itself a processor for a third-party controller).
Categories of Data Subjects. Customer’s End Users and other users of the Customer Application; and Customer’s personnel (employees and contractors) and other business contacts whose information Customer submits in connection with the Service.
Categories of Personal Data. End User identifiers passed by Customer (e.g., subject identifiers and email-style identifiers from Customer’s identity provider), display names, released identity claims, and group memberships used for authorization; Connected-Account metadata (Provider, account display name/email, Provider subject identifiers, granted scopes, and token expiry/refresh metadata); Credentials (OAuth access/refresh tokens, API keys, and managed secrets), stored encrypted in the vault; authorization and approval data (Grants, policy decisions, delegation context, and human-approval decisions); audit and usage data (including IP addresses, actor/agent identifiers, actions, and results); and, where Customer explicitly enables diagnostic payload capture, size-capped and retention-limited Provider request and response bodies.
Special categories of data. None intended. As set out in Section 6(b), Restricted Data (which includes “sensitive data” as defined in Clause 8.7 of the SCCs) must not be submitted to the Service without the parties’ prior written agreement.
Nature and purpose of Processing. Receiving, holding, using, updating, protecting, sharing (to authorized Providers on Customer’s instruction), returning, and erasing Personal Data to store and refresh Credentials; enforce Grants and policies; broker authorized calls to Providers on Customer’s instruction; generate audit logs; and provide related support.
Frequency of transfer. Continuous, for the duration of the Agreement.
Duration of Processing / retention. The term of the Agreement plus any legally required retention period; Sections 9 and 10(c) govern deletion, de-identification, and the separate treatment of independently generated security fields.
Transfers to Subprocessors. As described in the Subprocessor List (Annex 5) / Subprocessor Site.
Annex 2 — European Annex
1. Processing of Personal Data. 1.1 Where Alter receives an instruction from Customer that, in its reasonable opinion, infringes the GDPR, Alter will inform Customer. 1.2 Customer acknowledges that any instructions it issues regarding the Processing of Personal Data will comply with the GDPR and all other applicable laws.
2. Data protection impact assessment and prior consultation. 2.1 Taking into account the nature of the Processing and the information available to Alter, Alter will provide reasonable assistance to Customer, at Customer’s cost, on written request, to the extent reasonably necessary and technically feasible, with data protection impact assessments and prior consultations with Supervisory Authorities as required under Article 35 or 36 of the GDPR, solely in relation to Alter’s Processing of Personal Data. 2.2 Except to the extent prohibited by applicable law, Customer will be responsible for all time spent by Alter (at Alter’s then-current professional-services rates) providing such assistance and will reimburse Alter on demand.
3. Restricted transfers. 3.1 (EU) To the extent any Processing under this DPA involves an EU Restricted Transfer from Customer to Alter, the parties comply with their respective obligations in the SCCs, which are deemed populated in accordance with Part 1 of Attachment 1 and entered into and incorporated by reference. 3.2 (UK) To the extent any Processing involves a UK Restricted Transfer, the parties comply with the SCCs as varied by the UK Transfer Addendum, deemed varied and populated in accordance with Part 2 of Attachment 1 and entered into and incorporated by reference. 3.3 (Swiss) To the extent any Processing involves a Swiss Restricted Transfer, the parties comply with the SCCs as varied and populated by Part 3 of Attachment 1; nothing in the applicable SCCs will limit the rights of Data Subjects under Clause 18(c) to bring proceedings in Switzerland where Switzerland is their habitual residence. 3.4 (Adoption of new transfer mechanism) Alter may, on notice, vary this DPA and replace the relevant SCCs with (a) any new or replacement form of SCCs prepared and populated to maintain compliance with Applicable Data Protection Laws, provided the replacement does not materially decrease the overall protection of Personal Data; or (b) another valid transfer mechanism Alter reasonably determines is necessary to maintain compliance with Chapter V of the GDPR and that does not materially diminish the data-protection safeguards. 3.5 (Full-form SCCs) On specific written request of a Supervisory Authority, Data Subject, or further Controller (with suitable supporting evidence), and to the extent required to evidence Customer’s compliance, Alter will provide Customer within a reasonable time with an executed version of the relevant SCCs for countersignature and onward provision. 3.6 When complying with its transparency obligations under Clause 8.3 of the SCCs, Customer will not provide or make available, and will take appropriate steps to protect, Alter’s and its licensors’ trade secrets, business secrets, confidential information, and other commercially sensitive information. 3.7 For Clause 10(a) of Module Three, Customer acknowledges there are no circumstances in which it would be appropriate for Alter to notify a third-party controller of a Data Subject Request, and any such notification is Customer’s sole responsibility. 3.8 For Clause 15.1(a), and except to the extent prohibited by applicable law or the relevant public authority, Customer is solely responsible for making any notifications to Data Subjects. 3.9 Section 7 governs Alter’s appointment and use of Subprocessors under the SCCs, and Customer’s approval under Section 7 constitutes its documented instruction to effect onward transfers to such Subprocessors as required under Clause 8.8. 3.10 Audits under Clauses 8.9(c)–(d) of the SCCs are subject to Section 8. 3.11 Certification of deletion under Clauses 8.5 and 16(d) is provided only on Customer’s written request.
Attachment 1 — Population of SCCs. Part 1: The parties are deemed to have signed the SCCs at the relevant signature blocks. Module Two applies to any EU or Swiss Restricted Transfer where Customer is a Controller; Module Three applies to any EU, UK, or Swiss Restricted Transfer where Customer is itself a Processor. Clause 7 (docking) is not used. Clause 9: Option 2 (general written authorization) applies, with the notice period in Section 7(d) of the DPA (thirty (30) days). Clause 11 optional language is not used. Clause 13 text is retained. Clause 17: Option 1 applies and the SCCs are governed by the law of Ireland for EU Restricted Transfers. Clause 18: disputes for EU Restricted Transfers are resolved by the courts of Ireland. Annex I of the SCC Appendix is populated with Annex 1 of this DPA (Customer as exporter; Alter as importer); the competent supervisory authority is determined under Clause 13 by reference to Customer’s EU establishment, its Article 27 representative, or the Member State where affected Data Subjects are located. Annex II of the SCC Appendix refers to Section 4 and Annex 4 of this DPA. Part 2 (UK): the SCCs apply as varied by the UK Transfer Addendum; Tables 1–3 are populated with Annex 1 and this Attachment; Table 4 selects “Data Importer”; the Mandatory Clauses apply; the ICO is the competent authority. Part 3 (Swiss): “GDPR” reads as the FADP, “Member State” includes Switzerland, and “supervisory authority” means the FDPIC.
Annex 3 — State Privacy Laws Annex
-
For this Annex, “business,” “controller,” “processor,” “commercial purpose,” “sell,” “share,” “service provider,” and “contractor” have the meanings in the applicable State Privacy Laws, and “personal information” means Personal Data to the extent it constitutes “personal information” or “personal data” governed by the State Privacy Laws.
-
The parties intend that, with respect to any personal information, Alter is a service provider, contractor, and/or processor. Alter (a) acknowledges that personal information is disclosed only for the limited and specified purposes described in the Agreement; (b) will comply with applicable obligations under the State Privacy Laws and provide the same level of privacy protection as required of a business; (c) agrees that Customer may take reasonable and appropriate steps to help ensure that Alter’s use of personal information is consistent with Customer’s obligations; (d) will notify Customer if it determines it can no longer meet its obligations; and (e) agrees that Customer may, on reasonable notice, take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.
-
Alter will not (a) sell or share any personal information; (b) retain, use, or disclose personal information for any purpose other than providing the Service or as otherwise permitted by the State Privacy Laws; (c) retain, use, or disclose personal information outside the direct business relationship between the parties; or (d) combine personal information received under the Agreement with personal information from another source, except as permitted by the State Privacy Laws and necessary to provide the Service. Alter certifies that it understands and will comply with these obligations.
-
Giving Customer notice of Subprocessor engagements under Section 7 satisfies Alter’s obligation under the State Privacy Laws to give notice of and an opportunity to object to such engagements.
-
Customer may conduct audits in accordance with Section 8 to help ensure Alter’s use of personal information is consistent with its obligations.
Annex 4 — Security Measures
Alter maintains the following technical and organizational measures for the Service (Alter may update these measures so long as they do not materially decrease the overall protection of Personal Data):
- Encryption. End User OAuth tokens and managed secrets are encrypted at rest in a dedicated secrets vault, separate from the application database (which stores metadata and an opaque vault-key reference); OAuth application client secrets are encrypted under versioned keys held outside the database; data is encrypted in transit via TLS.
- Access control. A zero-trust authorization model requires every access to trace to an explicit ownership record; least-privilege internal access; first-party email/password authentication on Alter’s own infrastructure (passwords stored only as salted one-way hashes, two-factor authentication available, bot protection on sign-in/sign-up, and k-anonymity breached-password screening that never transmits a password or its full hash); optional Google or GitHub social authentication selected by the user; HMAC-signed SDK requests; and scoped Personal Access Tokens for automation.
- Network and security. Edge protection (web application firewall, DDoS protection, and bot-management challenges on authentication forms); controls against server-side request forgery on outbound connections (destination resolved, validated, and pinned); and segregation of customer/tenant data via per-organization scoping.
- Logging and monitoring. Audit logging of credential access and lifecycle events, retained for a defined period, protected by access controls and separation of duties; and error monitoring.
- Resilience and recovery. Automated daily database backups with point-in-time recovery; backup procedures including pre-change snapshots; encrypted Credentials held in a dedicated managed secrets service.
- Optional immutable audit archival. Immutable, write-once (Object Lock) audit archival is not part of the baseline Security Measures and is available only as an optional capability a Customer may elect in an Order. Where a Customer elects it, the applicable retention period and a corresponding carve-out from the deletion and de-identification obligations in Section 9 will be specified in that Order.
- Governance. Confidentiality obligations on personnel; vendor and sub-processor due diligence; and secure software-development-lifecycle practices.
Annex 5 — List of Subprocessors
Customer approves Alter’s engagement of the following Subprocessors to Process Customer Personal Data in providing the Service:
- Amazon Web Services, Inc. — Cloud hosting and compute; managed application database (RDS); encrypted secrets vault (Secrets Manager); transactional email (SES); and audit/object storage (S3). Processing location: United States (US East, Northern Virginia). Amazon Data Services, Inc. is the AWS regional infrastructure entity for that region. Contact: 410 Terry Avenue North, Seattle, WA 98109-5210, USA, Attn: AWS Legal.
- Porter Technologies, Inc. — Deployment and infrastructure-management control plane over the AWS hosting environment (classified conservatively as a Subprocessor because its control plane can reach the hosting environment). Processing location: United States. Contact: 80 State Street, Albany, NY 12207-2543, USA.
- Cloudflare, Inc. — Edge network, DDoS protection, WAF, and Turnstile bot protection for authentication. Processing location: global edge. Contact: 101 Townsend Street, San Francisco, CA 94107, USA, Attn: Data Protection Officer.
- Functional Software, Inc. d/b/a Sentry — Error monitoring, performance diagnostics, and consent-gated sampled browser replay on End User surfaces. Processing location: United States. Contact: 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA.
- PostHog, Inc. — Product and documentation analytics, including configured browser replay (a Subprocessor only where configured events contain Customer Personal Data). Processing location: United States (US Cloud). Contact: 2261 Market Street, #4008, San Francisco, CA 94114, USA.
Controller-side service providers that handle Alter’s own account, billing, or analytics data (for example, Stripe for payment processing) are disclosed in Alter’s Privacy Policy and on the Subprocessor Site but are not incorporated here as SCC Subprocessors for processing they perform solely on Alter’s behalf as controller.
Alter’s current list of sub-processors is maintained at https://alterauth.com/legal/sub-processors and is incorporated into this Annex by reference, as updated from time to time. The named list set out above is retained in this Annex.