RUDDERSTACK DATA PROCESSING ADDENDUM (LAST UPDATED OCTOBER 1, 2026)
This Data Processing Addendum (“DPA”) forms part of the agreement between RudderStack, Inc. (“Processor”) and the entity identified as Customer (“Customer”), whether that agreement is (a) the RudderStack Terms of Service available at https://www.rudderstack.com/terms-of-service (the “Terms of Service”), or (b) a master services agreement, subscription agreement, or other written agreement executed between Processor and Customer that incorporates one or more Order Forms (each, an “MSA”) (in each case, the “Agreement”). “Order Form” means an ordering document executed by both parties under an Agreement. This DPA applies where Processor processes Personal Data on behalf of Customer (including authorized affiliates of Customer) in connection with the Services.
1. DEFINITIONS
Capitalized terms not defined here have the meaning given in the Agreement.
1.1 “Applicable Data Protection Laws” means all laws applicable to the Processing of Personal Data under the Agreement, including:
- Regulation (EU) 2016/679 (“GDPR”)
- UK GDPR and Data Protection Act 2018
- Swiss Federal Act on Data Protection (revFADP)
- U.S. state privacy laws (including CCPA/CPRA)
- Any successor or replacement legislation
1.2 “Controller”, “Processor”, “Subprocessor”, “Personal Data”, “Data Subject” and “Processing” each have the meanings given in Applicable Data Protection Laws.
1.3 “Security Incident” means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by Processor. The definition specifically excludes unsuccessful attempts that do not compromise Personal Data.
2. ROLE OF THE PARTIES
2.1 Controller–Processor Relationship
With respect to Customer Personal Data:
- Customer acts as Controller or Processor.
- Processor acts solely as Processor (or Subprocessor, where Customer is a Processor and has documented authority from a Controller).
Processor shall process Personal Data:
- Only on documented instructions from Customer;
- For the purpose of providing the Services (including, where Customer has enabled them, the AI Features described in §2.4, and, where Customer uses it, Lookout as described in §2.5);
- In compliance with Article 28(3) GDPR and equivalent UK and Swiss requirements.
Customer's documented instructions to Processor under Article 28(3) GDPR consist of: (i) the Agreement and this DPA; (ii) for Customers under an MSA, the applicable Order Form and any written change orders or statements of work executed by both parties; (iii) the source, destination, tracking-plan, transformation, and AI Feature configurations (including enabling or disabling AI Features for a workspace) established by Customer through the Account; (iv) Personal Data and processing parameters submitted through the Services; (v) where Customer has enabled AI Features, the instructions set forth in §2.4; and (vi) where Customer uses Lookout, the warehouse connections, credentials, and permissions Customer configures in the Account and makes available to Lookout, the Audiences and Activations (including destinations, sync schedules, approvals, and automation settings) that Customer’s Users create, approve, or configure, and the instructions set forth in §2.5. Instructions outside the foregoing must be agreed in writing by both parties.
2.2 Processor Restrictions
Processor shall not sell Personal Data, process Personal Data for its own marketing or analytics purposes, or determine independent purposes of processing, except that (a) Processor may process Personal Data as instructed in §2.4 (AI Features) and §2.5 (Lookout), and (b) nothing in this DPA restricts Processor's use of information that has been de-identified, anonymized, or aggregated such that it is no longer Personal Data under Applicable Data Protection Laws, provided that Processor maintains and complies with measures reasonably designed to prevent re-identification and does not attempt to re-identify such information.
2.3 CCPA and CPRA Compliance
For the purposes of the CCPA and CPRA, Processor acts as a 'Service Provider' and shall not: (i) 'sell' or 'share' Personal Data (as those terms are defined by the CCPA); (ii) retain, use, or disclose Personal Data for any purpose other than for the specific business purposes of providing the Services (including the AI Features and the processing described in §2.4, and Lookout and the processing described in §2.5); or (iii) combine Personal Data received from Customer with Personal Data received from other sources, except as expressly permitted by the CCPA. Processor may use Personal Data for internal use to build or improve the quality of the Services to the extent permitted by Cal. Code Regs. tit. 11, §7050, and may use de-identified information in accordance with Cal. Civ. Code §1798.140(m), including by publicly committing to maintain and use it only in de-identified form. Processor shall comply with the CCPA as applicable to it as a Service Provider and provide the same level of privacy protection as the CCPA requires of Customer; shall notify Customer if Processor determines that it can no longer meet its obligations under the CCPA; and shall not retain, use, or disclose Personal Data outside the direct business relationship between Customer and Processor. Customer may take reasonable and appropriate steps to ensure that Processor uses Personal Data in a manner consistent with Customer’s obligations under the CCPA, including through §9, and, upon notice, to stop and remediate any unauthorized use of Personal Data. Processor certifies that it understands and will comply with the restrictions in this §2.3. With respect to Lookout, (A) Processor will build Customer’s Audiences only from Personal Data that Customer makes available to Processor, and will not combine that Personal Data with personal data Processor receives from or on behalf of any other person; and (B) each disclosure of Personal Data to a Third Party Product through an Activation is made at Customer’s direction and is Customer’s disclosure, and Customer is responsible for determining whether it constitutes a 'sale' or 'sharing' of Personal Data, for providing any required notices, and for honoring any required opt-outs.
2.4 AI Features
Where Customer enables AI Features (as defined in the Agreement) for a workspace, Customer instructs Processor to process Personal Data contained in Prompts, Outputs, Workspace Context, and the Customer Data that the AI Features read, in order to: (a) provide, operate, monitor, secure, and support the AI Features and generate Outputs for Customer; (b) generate and maintain Workspace Context for Customer's Account; and (c) evaluate the quality, safety, and performance of the AI Features using Prompts and Outputs from which Customer end-user Personal Data has been redacted, unless Customer opts out of such evaluation through a method made available by Processor or specified in the Agreement. In performing this processing Processor shall: (i) transmit Prompts, Outputs, and Customer Data for model inference only to a Subprocessor listed in §5.3 and, for AI Features other than Lookout, only within the geographic region (United States or European Union) of the AWS region selected for Customer's Account under §5.3 (the embedding generation, observability, and analytics processing described in §5.3 is not performed in the region Customer selects); (ii) ensure that inputs to and outputs from any large-language model, and inputs to any embedding model, are not used to train or improve any model, are not disclosed to any developer or provider of the model other than the model-hosting or embedding Subprocessor listed in §5.3, and are not retained by that Subprocessor beyond processing of the request, except that, for Lookout, a model-hosting Subprocessor may retain them solely for abuse monitoring and legal compliance for the limited period provided in its standard terms; (iii) retain Prompts and Outputs for as long as Customer elects to keep them in the Services, delete them upon Customer's deletion of the applicable workspace, upon Customer's request, and upon termination in accordance with §10, and retain any redacted copies, summaries, or metadata derived from Prompts or Outputs that Processor transmits to the observability and analytics Subprocessors identified in §5.3 only for as long as needed for the purposes described in this §2.4, and delete them, including any such data held by those Subprocessors, upon Customer’s request in accordance with §10; (iv) apply measures designed to redact Customer end-user Personal Data, including both field names and field values, from Prompts (including any Customer Data a User includes in a Prompt) and Outputs before they are persisted beyond the User's active session, and make available to Customer controls to delete conversation history; and (v) delete Prompts, Outputs, and Workspace Context in accordance with §10 upon Customer's request or upon Customer's deletion of the applicable workspace. Processor will not use Personal Data to train or fine-tune any machine-learning or large-language model. Capitalized terms used in this §2.4 and not defined in this DPA have the meanings given in the Agreement.
2.5 Lookout
Where Customer uses Lookout (as defined in the Agreement), Customer instructs Processor to process the Personal Data in Customer’s data warehouse that Customer authorizes Lookout to access, in order to: (a) analyze such data and generate Outputs in response to Prompts; (b) build, refresh, store, and display Audiences, and retrieve and display Audience membership; and (c) perform Activations by transmitting Audience membership to the Third Party Products that Customer selects, at the instruction of a User or in accordance with the sync schedules, approvals, automation settings, and other guardrails configured or enabled by Customer. In performing this processing Processor shall: (i) access Customer’s data warehouse only through the warehouse connection(s) configured in Customer’s Account, with the credentials, and within the scope, that Customer authorizes, and query data in place, on a read-only basis, without maintaining copies of warehouse tables, except that the Services write sync-state tables and related metadata to a RudderStack-designated schema within Customer’s data warehouse; (ii) store the credentials Customer provides for its data warehouse and for Third Party Products encrypted at rest, use them only to provide the Services (including Lookout) to Customer, and delete them following Customer’s deletion of the applicable connection or workspace and upon termination, in each case in accordance with §10; (iii) retain query results and samples that appear in Prompts or Outputs as set forth in §2.4, and not persistently store Audience membership, which Processor processes transiently (including in temporary caches) only as needed to display results to Users and perform Activations; (iv) delete Audiences, and any cached Audience membership, upon Customer’s deletion of the applicable Audience or workspace, upon Customer’s request, and upon termination in accordance with §10; and (v) where Processor has enabled Customer’s workspace for the Lookout embedding rollout, transmit the notes and search queries Users submit to the embedding Subprocessor identified in §5.3 and store the resulting vector embeddings, together with those inputs, in Processor’s own systems as context artifacts, retained until the applicable context artifact or workspace is deleted, Customer requests deletion, or the Agreement terminates, in each case in accordance with §10. Destinations and Activations that Customer configures through Lookout are maintained in Customer’s Account with Customer’s other configurations, are not deleted merely because Customer deletes an Audience or stops using Lookout, and remain until Customer deletes them or the Agreement terminates. The redaction measures in §2.4(iv) do not apply to Audience membership, which necessarily contains the identifiers that Customer directs Processor to activate. Customer will connect each Third Party Product that receives Personal Data through an Activation using credentials for Customer’s own account with that Third Party Product. Third Party Products so connected are recipients selected by Customer and act under Customer’s own agreements with them; they are not Subprocessors of Processor. Customer is responsible for having a lawful basis for each such disclosure and for any agreement or transfer mechanism that Applicable Data Protection Laws require for it. Capitalized terms used in this §2.5 and not defined in this DPA have the meanings given in the Agreement.
2.6 Customer Responsibilities
Customer is responsible for (a) the accuracy, quality, and legality of Personal Data and the means by which Customer acquired it; (b) providing all notices and obtaining all consents, authorizations, and other legal bases required under Applicable Data Protection Laws for Processor to process Personal Data as contemplated by the Agreement and this DPA; and (c) ensuring that its instructions to Processor comply with Applicable Data Protection Laws. Customer will not provide Processor with Personal Data that the Agreement prohibits Customer from providing.
3. SUBJECT MATTER AND DETAILS OF PROCESSING
Details of processing are described in Annex I (incorporated below), including:
- Nature and purpose
- Categories of Data Subjects
- Categories of Personal Data
- Duration
- Sensitive data (if any)
4. PROCESSOR OBLIGATIONS
Processor shall:
- Process Personal Data only on documented instructions.
- Inform Customer without undue delay if, in Processor’s opinion, an instruction infringes Applicable Data Protection Laws.
- Ensure personnel are bound by appropriate confidentiality provisions.
- Implement appropriate technical and organizational measures (as set forth in Annex II).
- Provide reasonable assistance to Customer in responding to Data Subject requests.
- Provide reasonable assistance to Customer with DPIAs and regulator consultations.
- Notify Customer without undue delay after becoming aware of a Security Incident.
- Delete or return Personal Data upon termination (Section 10).
- Maintain records of processing as required by law.
5. SUBPROCESSORS
5.1 General Authorization
Customer provides general authorization for Processor to engage Subprocessors.
5.2 Subprocessor Safeguards
Processor shall:
- Enter into written agreements with Subprocessors imposing data protection obligations equivalent to those in this DPA as required under Article 28(4) GDPR.
- Remain fully liable for Subprocessor performance, subject to any limitations set forth in the Agreement.
5.3 Subprocessor List
Amazon Web Services EMEA SARL (“AWS EU”) — European Union - Cloud Service Provider (infrastructure hosting; and, where Customer enables AI Features, large-language-model inference via Amazon Bedrock in an EU region, with inputs and outputs not retained, not used for model training, and not disclosed to third-party model developers)
Amazon Web Services, Inc. (“AWS USA”) — United States - Cloud Service Provider (infrastructure hosting; and, where Customer enables AI Features, large-language-model inference via Amazon Bedrock in a US region, with inputs and outputs not retained, not used for model training, and not disclosed to third-party model developers)
Microsoft Corporation (India) Private Limited (“Microsoft”) — resource located in the United States deployed on a global basis, so Microsoft may process requests in any Azure region - Embedding generation (for workspaces Processor has enabled for the Lookout embedding rollout, which may include workspaces in which Customer has not enabled Lookout, generation of vector embeddings from the notes and search queries Users submit; inputs are not used to train or improve any model and are not shared with OpenAI, and Microsoft does not store the resulting embeddings, which Processor stores as described in §2.5)
Langfuse GmbH, a ClickHouse company (Germany) — United States (Langfuse Cloud US region) - Observability (where Customer enables AI Features, tracing and debugging of the AI Features; Prompts and Outputs generated in Customer workspaces are masked before transmission, and the traces transmitted carry metadata only, consisting of Lookout user, session, and workspace identifiers, counts, and enumerated values)
Snowflake Inc. — United States - Product analytics (where Customer enables AI Features, usage events and summaries of Prompts, used for product analytics and quality evaluation of the AI Features)
Customer may select which AWS region serves as Processor's Cloud Service Provider Subprocessor as follows: (a) for Customers under an MSA, by specifying the region on the applicable Order Form; and (b) for Customers under the Terms of Service, by selecting the region during Account creation on the Site, or thereafter through Account settings prior to the ingestion of Personal Data. AWS USA is the default Cloud Service Provider absent affirmative selection by Customer. Once Personal Data has been ingested into a selected region, a change of region constitutes a migration that may require Processor's assistance and may be subject to operational and commercial terms communicated to Customer at the time of the request. Customer’s selection of an AWS region does not apply to the other Subprocessors listed above, which process Personal Data in the locations stated for each. Only the AWS Subprocessors, and model inference performed via Amazon Bedrock, process Personal Data in the region Customer selects. The other Subprocessors process Personal Data in the locations stated above, including where Customer selects the European Union region, and Microsoft may process Personal Data in any Azure region. Transfers of Personal Data to Subprocessors outside the EEA, the United Kingdom, or Switzerland are made under the mechanisms set forth in §6. Each onward transfer of Personal Data by Processor to a Subprocessor is made under the transfer mechanism provided in Processor’s agreement with that Subprocessor.
5.4 Notification of Changes
Processor shall:
- Provide at least thirty (30) days' prior notice of new Subprocessors;
- Deliver such notice (a) for Customers under an MSA by email to the signatory or designated data privacy contact identified in the Agreement or applicable Order Form; and (b) for Customers under the Terms of Service, by email to the Account administrator and, in the alternative or in addition, by in-product or Website notice;
- Permit Customer to object within twenty (20) days of notice on reasonable data protection grounds.
If Customer's objection cannot be resolved, the parties will work in good faith to implement alternative safeguards. If the parties cannot resolve the objection within thirty (30) days after Processor receives it, Customer may, as its sole and exclusive remedy, terminate the Services that cannot be provided without the objected-to Subprocessor by written notice to Processor, and Processor will refund any prepaid fees for those Services covering the period after termination.
6. INTERNATIONAL DATA TRANSFERS
6.1 Data Privacy Framework (DPF)
Processor maintains certification under the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework (collectively, the “DPF”), and the DPF serves as the transfer mechanism for transfers of Personal Data to Processor in the United States from the EEA, the UK, and Switzerland, respectively. If the DPF is invalidated, Processor’s certification lapses, or the DPF does not cover a transfer, the SCCs apply to that transfer as set forth in §§6.2–6.4.
6.2 EU Transfers
Where required, the 2021 EU Standard Contractual Clauses (Commission Implementing Decision 2021/914) are incorporated as follows:
- Module Two (Controller to Processor)
- Module Three (Processor to Processor)
- Docking clause enabled
- Clause 9(a): Option 2 (general written authorization), with notice of changes as set forth in §5.4
- Clause 11(a): the optional language does not apply
- Clause 13(a) and Annex I.C: the competent supervisory authority is determined in accordance with Clause 13(a)
- Governing law: Ireland (unless otherwise agreed)
- Clause 18: the courts of Ireland (unless otherwise agreed)
- Annex I = Annex I of this DPA
- Annex II = Annex II of this DPA
By accepting this DPA — whether through acceptance of the Terms of Service in connection with creating an Account, by execution of an MSA that incorporates this DPA, or by signing this DPA as a standalone document — both parties are deemed to have executed the EU Standard Contractual Clauses (and, where §6.3 applies, the UK International Data Transfer Addendum) for purposes of Articles 28 and 46 GDPR. The Annexes to the SCCs and the UK Addendum are completed by reference to Annex I and Annex II of this DPA, and the parties' contact details for purposes of the SCCs are those associated with the Account or the MSA, as applicable.
6.3 UK Transfers
The UK International Data Transfer Addendum to the EU SCCs is incorporated and deemed executed. For purposes of the UK Addendum: Table 1 is completed with the parties’ details described in §6.2; Table 2 is completed with the Modules and elections set forth in §6.2; Table 3 is completed by Annex I and Annex II; and, for Table 4, neither party may end the UK Addendum under its Section 19.
6.4 Switzerland
EU SCCs apply with modifications required under Swiss law. For transfers subject to the Swiss Federal Act on Data Protection (“FADP”): (a) the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority to the extent the transfer is governed by the FADP; (b) references to the GDPR include the corresponding provisions of the FADP; and (c) the term “Member State” in Clause 18(c) does not prevent data subjects in Switzerland from bringing legal proceedings in Switzerland.
7. SECURITY MEASURES
Processor shall implement technical and organizational measures appropriate to the risk assumed by Processor as further set forth in Annex II, including:
- Encryption (TLS 1.2+ in transit; AES-256 at rest)
- Role-based access control
- Multi-tenant logical separation
- Logging and monitoring
- Regular vulnerability testing
- Incident response procedures
- Secure backup and disaster recovery
- Personnel screening and training
- Other details as set forth in Annex II.
Security measures will not materially decrease during the term.
8. SECURITY INCIDENTS
Processor shall notify Customer of any Security Incident affecting Customer’s Personal Data without undue delay, and where feasible within seventy-two (72) hours, after confirming the Security Incident, and shall provide the following details to the extent known (which Processor may provide in phases as information becomes available):
- Nature of incident
- Categories and approximate volume
- Likely consequences
- Remediation measures
Processor shall reasonably cooperate with Customer in fulfilling regulatory notification obligations, although notification does not constitute admission of liability by Processor.
9. AUDITS
9.1 Audit Reports
Subject to reasonable confidentiality provisions, Processor shall make available:
- SOC 2 Type II (or equivalent)
- Summary security and privacy documentation
9.2 Audit Rights
If the reports and documentation provided under §9.1 do not reasonably demonstrate Processor’s compliance with Article 28 GDPR:
- Customer may conduct an audit once per year (or more frequently if required by a supervisory authority or following a Security Incident), on at least thirty (30) days’ prior written notice, during normal business hours, and subject to reasonable confidentiality obligations.
- Audits will be conducted remotely, because Processor’s infrastructure is hosted by its Subprocessors, and will include reasonable access to relevant personnel and system logs necessary to demonstrate compliance with Article 28 GDPR.
- Audit must not compromise other customers’ data.
- Costs borne by Customer unless material non-compliance found.
10. DATA RETENTION AND DELETION
10.1 Export.
Customer may export Personal Data, where applicable, before the effective date of termination of the Agreement and during any post-termination period described in the Agreement.
10.2 Deletion.
Upon Customer's written request, Processor shall delete or return Personal Data within thirty (30) days, except for copies retained on backup systems, which shall be deleted within Processor's standard backup cycle and in any event within ninety (90) days. Following termination of the Agreement and expiration of any post-termination period described in the Agreement, Processor shall delete Personal Data on the same schedule, whether or not Customer requests deletion, except to the extent retention is required by applicable law. Upon Customer's written request following deletion, Processor shall certify completion. Prompts, Outputs, Workspace Context, and Audience membership are Personal Data for purposes of this §10 to the extent they contain Personal Data; Processor shall additionally delete them upon Customer's deletion of the applicable workspace and upon termination of the Agreement, and shall delete redacted evaluation copies on the schedule set forth in §2.4, and shall handle Audience membership as set forth in §2.5.
10.3 Lifecycle States Under the Terms of Service.
For Customers under the Terms of Service, transition of an Account into the Grace Period or Paused Subscription state set forth in §§1.5, 1.6, and 11 of the Terms of Service does not by itself trigger the deletion obligation in §10.2. During the Paused Subscription state, no new Personal Data is ingested through the Services, Processor may make the AI Features (including Lookout) unavailable, no Activations are performed, Audience definitions are retained with the Account configurations, and Personal Data ingested prior to pause continues to be purged on the schedule set forth in Annex II, and Prompts and Outputs are retained until deleted by Customer and, in any event, are deleted with the Account configurations upon expiration of the Preservation Period. Account configurations (including source, destination, warehouse-connection, tracking-plan, and transformation configurations and their associated credentials, which may reference Personal Data fields) are retained for the Preservation Period set forth in §1.6 of the Terms of Service and are then deleted, except where Customer requests earlier deletion under §10.2 or reactivates the Account prior to expiration of the Preservation Period.
11. DATA SUBJECT REQUESTS
Processor shall:
- Notify Customer of requests received in a timely manner.
- Provide reasonable assistance to Customer in responding to such requests.
- Not respond directly to a Data Subject’s request, except to direct the Data Subject to Customer or as required by applicable law.
12. LIABILITY
Liability under this DPA shall be subject to the liability limitations in the Agreement. Nothing in this DPA limits liability where such limitation is prohibited by Applicable Data Protection Laws. Each party remains responsible for administrative fines imposed due to its own violations. To the extent permitted by Applicable Data Protection Laws, the exclusion of indirect, incidental, special, and consequential damages in the Agreement applies to all claims between the parties arising out of or related to this DPA or the SCCs.
13. CONFIDENTIALITY
All information exchanged under this DPA is confidential under the Agreement.
14. TERM
This DPA remains in effect for the duration of the Agreement and for as long as Processor processes Personal Data.
15. MODIFICATIONS
15.1 Customers Under the Terms of Service.
Processor may materially update this DPA from time to time by providing at least thirty (30) days' prior notice via email to the Account administrator or by in-product or Website notice. Continued use of the Services after the effective date constitutes acceptance. No such update will materially diminish the protections afforded to Personal Data under this DPA.
15.2 Customers Under an MSA.
The version of this DPA in effect on the effective date of the applicable Order Form (or, in the absence of an Order Form, the MSA) applies for the duration of that Order Form or MSA and may be modified only by a written instrument signed by both parties, except that Processor may make updates required by changes in Applicable Data Protection Laws upon written notice to Customer.
ANNEX I – DETAILS OF PROCESSING
List of Parties: Data exporter: Customer, as identified in the Agreement or the Account (role: controller for Module Two; processor for Module Three), using the Services under the Agreement. Data importer: RudderStack, Inc., 631 Howard Street, Floor 5, San Francisco, CA 94105, legal@rudderstack.com (role: processor), providing the Services under the Agreement. Each party’s acceptance of this DPA as described in §6.2 constitutes its signature of this Annex I.
Nature and Purpose:
Provision of customer data pipeline, routing, transformation, and integration services. Where Customer enables AI Features: provision of an in-product AI assistant that reads Customer's workspace configuration, event delivery logs, and sample event payloads to respond to User Prompts; generation of Workspace Context; operational monitoring and observability of the AI Features; and quality and safety evaluation of the AI Features on redacted Prompts and Outputs, in each case as instructed in §2.4. Where Customer uses Lookout: analysis of Personal Data in Customer’s data warehouse that Customer authorizes Lookout to access, building and refreshing Audiences, and transmitting Audience membership to Third Party Products selected by Customer, in each case as instructed in §2.5.
Categories of Data Subjects:
End users, customers, employees, or other individuals whose data is submitted by Customer or is accessed in Customer’s data warehouse at Customer’s direction.
Categories of Personal Data:
Data transmitted by Customer via the Services, including identifiers, contact information, device information, event data, and other categories determined by Customer. Where Customer enables AI Features: Personal Data contained in Prompts submitted by Users and in Customer Data (including event payloads) read by the AI Features in response to Prompts, and User identifiers associated with AI Feature sessions. Where Customer uses Lookout: Personal Data in the warehouse schemas, tables, and fields that Customer authorizes Lookout to access, which may include identifiers and contact information (such as names, email addresses, phone numbers, and mailing addresses, in plain or hashed form), behavioral, engagement, and purchase or transaction history, and other customer attributes, together with Audience membership.
Sensitive Data:
Processor does not intentionally collect special category data and will process such data only to the extent permitted by the Agreement and on Customer’s documented instructions.
Duration:
For the term of the Agreement and applicable retention period. Prompts and Outputs: until deleted by Customer, and in any event upon deletion of the applicable workspace or termination of the Agreement (§2.4, §10); redacted copies, summaries, and metadata transmitted to the observability and analytics Subprocessors identified in §5.3: no fixed period; retained for as long as needed for the purposes in §2.4 and deleted on Customer’s request (§2.4(iii), §10). Context artifacts (vector embeddings and the notes and search queries from which they are generated): until the applicable context artifact or workspace is deleted, Customer requests deletion, or the Agreement terminates (§2.5). Workspace Context: for the term of the Agreement or until deletion of the applicable workspace. Audience membership: processed transiently (including temporary caching) and not persistently stored by Processor (§2.5).
For Customers under the Terms of Service during the Trial Period and the Grace Period, Customer shall not transmit special category Personal Data, regulated health data, financial account credentials, government-issued identifiers, or children's data through the Services. The data-type restrictions set forth in §3.2(f) of the Terms of Service apply in full during these periods, and any contrary documented instruction is overridden.
Frequency of Transfer:
Continuous, for the duration of the Agreement.
Competent Supervisory Authority:
Determined in accordance with Clause 13(a) of the SCCs (and, for transfers subject to the FADP, as set forth in §6.4).
ANNEX II – TECHNICAL & ORGANIZATIONAL SECURITY MEASURES
Technical and Organizational Security Measures:
MODULES TWO AND THREE: Transfer controller to processor and processor to processor
RudderStack as data importer will implement the following types of security measures:
Data Security & Retention
- Minimal Data Retention: The platform is engineered to minimize data persistence. Except as described below for AI Feature Data and Lookout Data, Customer data processed by RudderStack is retained for no longer than three (3) hours unless Customer specifically chooses to use RudderStack event storage for up to a maximum of 30 days.
- AI Feature Data: Where Customer enables AI Features, conversation history (Prompts and Outputs) is stored in the Control Plane in the AWS region selected for Customer's Account, encrypted at rest (AES-256) and in transit, subject to the same RBAC, logging, backup and access controls described in this Annex, and is retained until deleted by Customer (or upon workspace deletion or termination). This conversation history is an exception to the Minimal Data Retention and Purging Protocols described above. Before persistence beyond the active session, Prompts and Outputs are redacted of Customer end-user data (field names and field values); redacted copies, summaries, and metadata transmitted to the observability and analytics Subprocessors identified in §5.3 are not subject to a fixed retention period and are deleted on Customer’s request in accordance with §2.4(iii) and §10. For AI Features other than Lookout, model inference is performed via Amazon Bedrock in the same region with zero retention at the model layer, and cross-region inference is disabled. Redacted copies, summaries, and metadata described in §2.4 and §5.3 are transmitted to the applicable observability and analytics Subprocessors for operational monitoring, debugging, product analytics, and quality evaluation. Those Subprocessors process this data in the locations stated in §5.3, which are outside the European Union regardless of the AWS region selected for Customer’s Account, and the embedding Subprocessor may process data in any of its regions. Vector embeddings generated for the Lookout embedding rollout, and the notes and search queries from which they are generated, are stored by Processor in Processor’s own systems as context artifacts and retained as set forth in §2.5.
- Lookout Data: Where Customer uses Lookout, Lookout connects to Customer’s data warehouse through the warehouse connection(s) configured in Customer’s Account, using credentials and permissions scoped by Customer, which are encrypted at rest and shared with the other Services that use the same connection, and are deleted as set forth in §2.5. Queries run in place in Customer’s data warehouse, and Processor does not maintain copies of warehouse tables. Lookout’s warehouse access is read-only, except that the Services write sync-state tables and related metadata to a RudderStack-designated schema within Customer’s data warehouse. Query results and samples surfaced in Prompts and Outputs are handled as AI Feature Data. Processor stores the query definition of each Audience, which is deleted when Customer deletes the Audience or the applicable workspace. Audience membership is not persistently stored by Processor; it is retrieved from Customer’s data warehouse when an Audience is previewed or an Activation runs, may be temporarily cached, and is transmitted to Customer-selected destinations over TLS v1.2 or higher. Model inference for Lookout is performed by the model-hosting Subprocessors identified in §5.3 for Lookout.
- Purging Protocols: Events are stored temporarily in a transient Data Plane database and are either transmitted to their destination or purged within a maximum duration of 3 hours.
- Encryption in Transit: All data traffic to and from RudderStack is transmitted over Secure HTTP (HTTPS) using TLS v1.2 or higher.
- Encryption at Rest: All underlying storage is encrypted using industry-standard AES-256 encryption. Key management and cryptographic operations are handled via AWS KMS.
Infrastructure & Architectural Security
- Logical Multi-Tenancy: RudderStack utilizes a multi-tenancy model to prevent data cross-contamination. Each customer is assigned a unique Workspace ID, and data is logically separated by this identifier.
- Plane Separation: The architecture maintains a strict logical separation between the Control Plane (configuration management) and the Data Plane (core engine for receiving, buffering, and relaying events). This ensures customers maintain ownership over the data stream.
- Database Access Controls: The Data Plane database can only connect to application nodes within the containers cluster. In rare instances where engineer access is required for support or troubleshooting purposes, such access is strictly logged, time-limited, and monitored.
Access Control & Monitoring
- Authentication: The platform enforces Role-Based Access Control (RBAC) to ensure data access is restricted by user ID and privilege. The Enterprise version supports 2-Factor Authentication (MFA) via OTP.
- Continuous Monitoring: RudderStack uses AWS-native tools for resource tracking and security monitoring, including AWS WAF for traffic filtering and AWS GuardDuty for threat detection.
- Network Security: Security groups are configured to "implicitly deny" all traffic, with "explicit allow" rules for necessary incoming traffic only.
Resilience & Organizational Security
- Backup and Recovery: Databases are backed up via AWS Backup on a schedule of daily incremental and weekly full backups, with a 30-day retention period. All backups are encrypted at rest.
- Personnel Security: All staff undergo background screening and are bound by confidentiality obligations. Personnel must complete regular security and privacy training.
Compliance & Supplementary Safeguards
- Third-Party Audits: RudderStack maintains a SOC 2 Type 2 certification, validated annually by a third-party auditor.
- Vendor Risk Management: Processor’s Subprocessors, including AWS, are bound by written agreements imposing data protection obligations no less protective than those in this DPA, and Processor assesses vendor risk at least annually.
- FISA 702 Safeguards: In the event of a government demand for data (e.g., FISA 702), RudderStack will attempt to redirect the authority to the Customer, review the lawfulness of the demand and challenge it where Processor reasonably determines there are grounds to do so, provide the Customer with notice and a copy of the demand, and inform the authority that RudderStack processes the data as a processor on behalf of the Customer and, except for AI Feature Data, Lookout Data, and event data Customer elects to retain in RudderStack event storage, processes it transiently.