Legal

Data Processing Agreement

Last updated August 12, 2026

Last updated August 12, 2026. Contact legal@oauth.work for the executed DPA. Some bracketed values remain placeholders until transfer and certification details are finalized.

This Data Processing Agreement ("DPA") forms part of the Terms of Service between OAUTH.WORK ("Processor", "we") and the customer organization ("Controller", "you") and applies where we process personal data on your behalf in providing the OAUTH.WORK identity platform (the "Service"). Terms not defined here have the meaning given in the GDPR.

1. Roles and scope

You are the controller and we are the processor for personal data you route through the Service. Where you are yourself a processor for your own customer, we act as sub-processor and your instructions must be consistent with that arrangement. Each party complies with the data protection law applicable to it.

2. Subject matter and details of processing

  • Subject matter — provision of identity, authentication, authorization, and credential issuance services.
  • Duration — the term of the Terms, plus the deletion period in section 9.
  • Nature and purpose — storage, retrieval, transmission, cryptographic signing and verification, federation with identity providers you configure, and audit logging.
  • Categories of data subject — your end users, your workforce and administrators, and, where configured, software agents acting on a user's behalf.
  • Categories of personal data — identifiers and profile attributes; group and role membership; authentication material (password hashes, WebAuthn public-key credentials, TOTP secrets, recovery codes, device metadata); session, grant, consent, and delegation records; federation and social identity links; issued credentials and revocation status; and audit events including timestamps, actor, and source context.
  • Special categories — the Service is not designed for special-category data under Article 9. Do not configure attributes or credential claims that carry it without a prior written arrangement.

3. Processor obligations

  • We process personal data only on your documented instructions, including the configuration you set through the console and management API. The Terms and this DPA are your initial complete instructions.
  • If we are required by law to process beyond your instructions, we will inform you first unless that law prohibits it.
  • We will tell you if, in our opinion, an instruction infringes applicable data protection law.
  • Personnel with access to personal data are bound by confidentiality obligations.
  • We limit access to what is necessary to operate and support the Service.

4. Security measures

We implement appropriate technical and organizational measures under Article 32, including:

  • Tenant isolation — each tenant resolves to its own issuer and DID, and is served by its own signing key.
  • Key management — EdDSA / Ed25519 signing throughout; per-tenant private keys AES-GCM envelope-encrypted at rest under a master key held separately from the database.
  • Token security — sender-constrained (DPoP) access tokens, single-use authorization codes enforced atomically, short-lived delegated tokens, and refresh-token reuse detection with automatic revocation.
  • Encryption — TLS in transit; encryption at rest for the database and backup storage.
  • Auditability — an append-only audit log of authentication, authorization, and administrative actions, exportable to your own SIEM.
  • Resilience — daily encrypted backups plus point-in-time restore on the database tier.

We may update these measures as the Service evolves, provided the level of protection is not materially reduced.

5. Sub-processors

You give general authorization for the following sub-processors:

  • Cloudflare, Inc. (United States) — compute, edge network, key-material caching, backup object storage, bot mitigation, transactional email.
  • Neon Inc. (United States) — managed PostgreSQL.
  • Our payment processor — billing.

We will give at least [30] days' notice before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period; if we cannot accommodate the objection, you may terminate the affected part of the Service without penalty. We impose data protection obligations on each sub-processor no less protective than this DPA and remain liable for their performance.

Identity providers you connect — enterprise directories, social login providers, SCIM clients — are your integrations, not our sub-processors.

6. International transfers

Where personal data is transferred out of the EEA, the UK, or Switzerland to a country without an adequacy decision, the transfer is governed by [TRANSFER MECHANISM — e.g. the EU Standard Contractual Clauses, Module [TWO/THREE], incorporated by reference, with the UK Addendum and the Swiss amendments as applicable]. Docking clause: [DOCKING CLAUSE POSITION]. We conduct and document transfer impact assessments where required.

7. Assistance to the Controller

  • Data subject requests — taking into account the nature of the processing, we assist you with appropriate technical and organizational measures in responding to requests under Chapter III. The management API supports export, correction, and deletion directly. If we receive a request from your data subject, we will refer them to you rather than respond ourselves.
  • DPIAs and consultation — we provide reasonable assistance with data protection impact assessments and prior consultation under Articles 35 and 36.

8. Personal data breach

We will notify you without undue delay, and in any event within [72] hours, of becoming aware of a personal data breach affecting your data. Notification will describe the nature of the breach, the categories and approximate volume of data and data subjects affected, likely consequences, the measures taken or proposed, and a contact point. We will provide further detail as the investigation progresses and will assist you in meeting your own notification obligations. Notice will be sent to the security contact on your account — keep it current.

9. Return and deletion

You may export your data at any time through the management API. On termination you may export for [30] days, after which we delete live records. Copies in encrypted backups are purged on the backup retention cycle of 90 days (aligned with platform backup retention). We may retain personal data where required by law, for so long as required, subject to the protections in this DPA. On request we will confirm deletion in writing.

10. Audit

We will make available the information necessary to demonstrate compliance with Article 28 and will allow for and contribute to audits, including inspections, conducted by you or an independent auditor you mandate. In the first instance we will satisfy audit requests by providing [CERTIFICATIONS / THIRD-PARTY REPORTS — e.g. SOC 2 Type II, once obtained] and responses to a security questionnaire. On-site inspections are limited to [once per 12 months] absent a breach or regulator requirement, require [30] days' notice, must not compromise other customers' confidentiality, and are at your cost.

11. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms, to the extent permitted by applicable law.

12. Order of precedence

In case of conflict, the order is: (1) the Standard Contractual Clauses, (2) this DPA, (3) the Terms. This DPA supersedes any conflicting data processing terms previously agreed.

Executing this DPA

Need a countersigned DPA for an enterprise deployment? legal@oauth.work. Security contact: security@oauth.work.