Last updated August 12, 2026
Last updated August 12, 2026. Contact legal@oauth.work for the executed DPA. Some bracketed values remain placeholders until transfer and certification details are finalized.
This Data Processing Agreement ("DPA") forms part of the Terms of Service between OAUTH.WORK ("Processor", "we") and the customer organization ("Controller", "you") and applies where we process personal data on your behalf in providing the OAUTH.WORK identity platform (the "Service"). Terms not defined here have the meaning given in the GDPR.
You are the controller and we are the processor for personal data you route through the Service. Where you are yourself a processor for your own customer, we act as sub-processor and your instructions must be consistent with that arrangement. Each party complies with the data protection law applicable to it.
We implement appropriate technical and organizational measures under Article 32, including:
We may update these measures as the Service evolves, provided the level of protection is not materially reduced.
You give general authorization for the following sub-processors:
We will give at least [30] days' notice before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period; if we cannot accommodate the objection, you may terminate the affected part of the Service without penalty. We impose data protection obligations on each sub-processor no less protective than this DPA and remain liable for their performance.
Identity providers you connect — enterprise directories, social login providers, SCIM clients — are your integrations, not our sub-processors.
Where personal data is transferred out of the EEA, the UK, or Switzerland to a country without an adequacy decision, the transfer is governed by [TRANSFER MECHANISM — e.g. the EU Standard Contractual Clauses, Module [TWO/THREE], incorporated by reference, with the UK Addendum and the Swiss amendments as applicable]. Docking clause: [DOCKING CLAUSE POSITION]. We conduct and document transfer impact assessments where required.
We will notify you without undue delay, and in any event within [72] hours, of becoming aware of a personal data breach affecting your data. Notification will describe the nature of the breach, the categories and approximate volume of data and data subjects affected, likely consequences, the measures taken or proposed, and a contact point. We will provide further detail as the investigation progresses and will assist you in meeting your own notification obligations. Notice will be sent to the security contact on your account — keep it current.
You may export your data at any time through the management API. On termination you may export for [30] days, after which we delete live records. Copies in encrypted backups are purged on the backup retention cycle of 90 days (aligned with platform backup retention). We may retain personal data where required by law, for so long as required, subject to the protections in this DPA. On request we will confirm deletion in writing.
We will make available the information necessary to demonstrate compliance with Article 28 and will allow for and contribute to audits, including inspections, conducted by you or an independent auditor you mandate. In the first instance we will satisfy audit requests by providing [CERTIFICATIONS / THIRD-PARTY REPORTS — e.g. SOC 2 Type II, once obtained] and responses to a security questionnaire. On-site inspections are limited to [once per 12 months] absent a breach or regulator requirement, require [30] days' notice, must not compromise other customers' confidentiality, and are at your cost.
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms, to the extent permitted by applicable law.
In case of conflict, the order is: (1) the Standard Contractual Clauses, (2) this DPA, (3) the Terms. This DPA supersedes any conflicting data processing terms previously agreed.
Need a countersigned DPA for an enterprise deployment? legal@oauth.work. Security contact: security@oauth.work.