Effective Date: Date of first use of the Services
Last Updated: December 2, 2025
This Data Processing Addendum ("DPA") forms part of, and is subject to, the Obvious Services Agreement (the "Agreement") by and between Obvious and Customer. Notwithstanding anything in the Agreement to the contrary, to the extent Obvious engages in the Processing of Customer Personal Data that is subject to Applicable Data Protection Laws, this DPA applies. Capitalized terms used but not defined in this DPA have the meanings given to them in the Agreement. In the event of a conflict between the Agreement and this DPA, this DPA shall control solely to the extent of the conflict.
For purposes of this DPA, the following terms shall have the meanings set forth below. To the extent these terms are defined in Applicable Data Protection Laws (including but not limited to the GDPR, UK GDPR, and CCPA), these definitions are intended to be consistent with those laws.
"Applicable Data Protection Laws"
means all laws, regulations, and binding legal requirements relating to the privacy, protection, security, or processing of Personal Data, including, without limitation: (a) European Union Regulation 2016/679 as implemented by local law in the relevant EEA member nation ("GDPR"); (b) the UK Data Protection Act 2018 and the retained EU law version of the GDPR as it forms part of the law of the United Kingdom by virtue of section 3 of the European Union (Withdrawal) Act 2018 ("UK GDPR"); (c) the Swiss Federal Data Protection Act ("Swiss FDPA"); (d) the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, the "CCPA"); and (e) any other applicable privacy, data protection, or data security laws or regulations in any jurisdiction governing the Processing of Personal Data, as each may be amended, superseded, or replaced from time to time.
Common Terms
"Controller", "Data Subject", "Personal Data", "Personal Data Breach", "Processing", "Processor" and "Supervisory Authority" (and any analogous terms) will have the meaning(s) given in the Applicable Data Protection Laws, and terms such as "Process" and "Processed" shall be construed accordingly.
"Customer Affiliate"
means an entity that directly or indirectly controls, is controlled by, or is under common control with Customer, where "control" means ownership or control of more than 50% of the voting interests of the subject entity. Customer Affiliates are permitted to use the Services pursuant to the Agreement between Obvious and Customer, and the terms of this DPA shall apply to any Processing of Personal Data of Customer Affiliates as if such Customer Affiliate were the Customer hereunder.
"Customer Personal Data"
means Personal Data that Customer or any Customer Affiliate uploads or provides to Obvious as part of the Service and that is governed by this DPA.
"EEA"
means the European Economic Area.
"Restricted Transfer"
means a transfer of Customer Personal Data that is subject to restrictions under Applicable Data Protection Laws, including but not limited to: (a) a transfer of Customer Personal Data from the EEA, United Kingdom, or Switzerland to a country or territory outside of those jurisdictions which is not subject to an adequacy decision or adequacy regulations.
"SCCs"
means the standard contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the European Council.
"Service Provider"
has the meaning given in the CCPA and other Applicable Data Protection Laws for an entity that processes personal data on behalf of a business.
"Subprocessor"
means any third party, including any affiliate of the Processor, engaged by the Processor to Process Customer Personal Data on behalf of the Customer in connection with the Agreement. For clarity, a Subprocessor is a Processor engaged by another Processor to carry out specific Processing activities on behalf of the Customer, as contemplated by Article 28 of the GDPR and the UK GDPR.
"UK Addendum"
means the international data transfer addendum to the SCCs issued by the Information Commissioner for Parties making Restricted Transfers under S119A(1) Data Protection Act 2018.
As applicable and where such concepts are recognized by Applicable Data Protection Law, Customer is the Controller and Obvious is the Processor or Service Provider (in each case, or words of similar import under Applicable Data Protection Laws) in respect of all Customer Personal Data made available to and Processed by Obvious in connection with the provision of the Services for the term of the Agreement. For this purpose, Obvious will Process Customer Personal Data as contemplated in and in accordance with the Agreement and this DPA.
The subject matter, nature, purpose, and duration of the Processing, as well as the categories of Customer Personal Data and Data Subjects, are described in Exhibit 1 of this DPA.
Obvious will only Process Customer Personal Data in accordance with Customer's documented instructions, including as set out in the Agreement and this DPA, unless required to do so by applicable laws. Obvious will immediately inform Customer if it is unable to follow the Processing instructions.
Where Customer is a Processor and Obvious is a Subprocessor, Customer will comply with all applicable laws that apply to Customer's Processing of Customer Personal Data and will ensure that its agreement with its Controller requires compliance with all such applicable laws.
Customer represents and warrants that it has provided all necessary notices and obtained all necessary consents and authorizations under Applicable Data Protection Laws for Obvious to Process Customer Personal Data as contemplated by the Agreement and this DPA.
During the term of the Agreement, Obvious will comply with the Applicable Data Protection Laws that are applicable to Obvious's Processing of Customer Personal Data.
Obvious will make available all information reasonably requested by Customer to demonstrate Obvious's compliance with Applicable Data Protection Laws and this DPA.
Obvious will notify Customer in the event Obvious makes a determination that Obvious can no longer meet its obligations under Applicable Data Protection Laws, in which case Customer may take reasonable and appropriate steps in accordance with the Agreement to stop or remediate any unauthorized Processing of Customer Personal Data.
Obvious will cooperate with and provide reasonable assistance to Customer for: (a) Customer's performance of any data protection impact assessment of the Processing of Customer Personal Data by Obvious, and (b) related consultation with Supervisory Authorities, either or both of which Customer reasonably considers to be required by Applicable Data Protection Laws.
Obvious will not:
Notwithstanding the foregoing provisions of Section 4.1, the restrictions in Section 4.1 shall not apply:
Obvious certifies that it understands the restrictions of this Section 4 and will comply with all Applicable Data Protection Laws.
Obvious will retain Customer Personal Data only for as long as necessary to perform the Services, or for such other purposes as agreed to by the parties or as required by applicable law.
Following the termination of the Agreement, Obvious shall return or safely destroy all non-anonymized and identifiable Customer Personal Data that Obvious obtained in connection with performing the Services within ninety (90) days following such termination (excluding Customer Personal Data retained in archival or backup systems in accordance with Obvious's standard retention policies or subject to legal hold or other legal requirements) and, upon request, Obvious shall notify Customer in writing once all such information has been returned or destroyed, provided that where continued storage is required by applicable law, Obvious shall inform Customer of those requirements.
If return or destruction is impracticable or prohibited by applicable laws, Obvious will prevent additional Processing of Customer Personal Data and will continue to protect the Customer Personal Data remaining in its possession, custody, or control.
For the avoidance of doubt, this Section 5 shall not apply to de-identified or aggregated data (regardless of whether derived from Customer Personal Data) that Obvious uses or generates in accordance with the Agreement provided that such data cannot be used to identify a Data Subject.
Obvious will implement appropriate physical, technical and administrative safeguards designed to protect Customer Personal Data from unauthorized or unlawful destruction, loss, alteration, disclosure or access as provided in the Agreement, in each case as appropriate to the risk of the relevant Processing of Customer Personal Data and as such safeguards may be updated from time to time.
Obvious will maintain annually updated reports or annual certifications of compliance with the following: ISO 27001 and SOC 2 Type II.
Obvious will conduct annual penetration tests and share summary results of such tests to Customer if requested by the Customer.
Obvious will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach impacting the Customer Personal Data that is Processed under this DPA ("Customer Personal Data Breach").
Such notice will include, to the extent known at the time of notification: (a) the nature of the Customer Personal Data Breach, including the categories and approximate number of Data Subjects concerned and the categories and approximate number of Customer Personal Data records concerned; (b) the likely consequences of the Customer Personal Data Breach; and (c) the measures taken or proposed to be taken by Obvious to address the Customer Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.
Obvious's notification of, or response to, a Customer Personal Data Breach will not be construed as an acknowledgement by Obvious of any fault or liability with respect to the Customer Personal Data Breach.
Obvious shall provide reasonable assistance to Customer as required for Customer to investigate and remediate the Customer Personal Data Breach.
To the extent that Applicable Data Protection Laws require Customer to comply with requests from Data Subjects regarding the Processing of Customer Personal Data, such as rights to access, correct, or delete their Personal Data ("Data Subject Request") and the request relates to Customer Personal Data (including, where applicable, any special categories of Personal Data as defined under Applicable Data Protection Laws), Obvious will promptly notify Customer of any Data Subject Requests directed to, and directly received by, Obvious and to provide reasonable assistance necessary to fulfill Data Subject Requests, taking into account the nature of Obvious's Processing of Customer Personal Data under the Agreement.
Obvious will forward to Customer promptly any Data Subject Request received by Obvious relating to Customer Personal Data and may advise the applicable Data Subject to submit their request directly to Customer.
If a Data Subject makes a valid request under Applicable Data Protection Laws to delete or opt out of Customer's giving of Customer Personal Data to Obvious, Obvious will assist Customer in fulfilling the request according to the Applicable Data Protection Law.
Customer grants Obvious a general authorization to engage Subprocessors in connection with the performance of Obvious's obligations under the Agreement. Obvious will maintain an up-to-date list of authorized Subprocessors, available at https://trust.obvious.ai ("Subprocessor List").
Obvious will provide Customer with advance notice of any intended additions or replacements to the Subprocessor List by email or through the Services. Such notice shall be provided at least fifteen (15) days prior to the new Subprocessor Processing any Customer Personal Data. If Customer objects to such change on reasonable data protection grounds within fifteen (15) days of notice, the parties will discuss such concerns in good faith. If no resolution is reached, Customer may terminate only the affected portion of the Services without penalty.
To the extent Obvious engages Subprocessors to Process Customer Personal Data, such entities or individuals shall be subject to an appropriate duty of confidentiality and the same level of data protection and security as Obvious under this DPA. Obvious is responsible for the performance of any Subprocessor's obligations in compliance with the terms of this DPA and Applicable Data Protection Laws applicable to Obvious.
Obvious will have a written agreement with each Subprocessor that ensures the Subprocessor only accesses and uses Customer Personal Data to the extent required to perform the obligations subcontracted to it, and consistent with the terms of the Agreement and this DPA.
Obvious remains fully liable for all obligations subcontracted to its Subprocessors, including the acts and omissions of its Subprocessors in Processing Customer Personal Data.
Obvious will provide a copy of its then-current audit report once per each rolling 12-month period upon request of Customer and subject to the confidentiality obligations set out in the Agreement. Such audit report refers to a SOC 2 Type II audit or another industry standard audit that may be deemed appropriate by Obvious and will be conducted by an independent third-party auditor on an annual basis.
Additionally, Obvious will permit an independent Certified Public Accountant engaged by Customer to audit Obvious's compliance with this DPA in the event Customer receives a written inquiry from a competent Supervisory Authority or regulator, in each case relating to Obvious's Processing of Customer Personal Data under this DPA, provided that such audit will be restricted to relevant Customer Personal Data Processing activities and necessary documentation to confirm Obvious's compliance with the terms of this DPA.
Any audit under this Section 10 will be subject to reasonable scheduling, confidentiality obligations, and Obvious's security policies and will not unreasonably interfere with Obvious's business operations. Customer will pay any reasonably incurred costs and expenses incurred by Obvious in the event Customer performs an audit under this Section 10 that is not (a) required by Applicable Data Protection Laws or (b) in response to a Customer Personal Data Breach.
Obvious will maintain records of its compliance with this DPA for 3 years after the DPA ends.
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set forth in the Agreement.
This DPA does not limit any liability to an individual about the individual's data protection rights under Applicable Data Protection Laws. In addition, this DPA does not limit any liability between the parties for violations of the EEA SCCs or UK Addendum.
Nothing in this DPA shall be construed to create any duty or obligation on the part of either party to, or confer any rights, remedies, or benefits upon, any third party (including any Data Subject), except as expressly set forth herein or required under Applicable Data Protection Laws.
This DPA will start when Obvious and Customer agree to this DPA and will continue until the Agreement expires or is terminated. However, Obvious and Customer will each remain subject to the obligations in this DPA and Applicable Data Protection Laws until Customer stops transferring Customer Personal Data to Obvious and Obvious stops Processing Customer Personal Data.
Customer authorizes Obvious to transfer Customer Personal Data outside the EEA, the United Kingdom, Switzerland, or other relevant jurisdictions as necessary to provide the Services, subject to the requirements of Applicable Data Protection Laws. Obvious will ensure that any such transfer is made in compliance with Applicable Data Protection Laws, including but not limited to the GDPR and the UK GDPR, as applicable.
If Obvious carries out a Restricted Transfer of Customer Personal Data, Obvious will implement appropriate safeguards for such transfers to that territory consistent with Applicable Data Protection Laws. These safeguards may include, but are not limited to:
The parties agree that to the extent that the Processing of Customer Personal Data involves a Restricted Transfer then the parties shall each comply with their respective obligations as set out in the SCCs and/or the UK Addendum, each incorporated herein by reference, and amended as follows:
If required by Applicable Data Protection Laws, Obvious will reasonably assist Customer in conducting any mandated data protection impact assessments or data transfer impact assessments and consultations with relevant Supervisory Authorities, taking into consideration the nature of the Processing and Customer Personal Data.
Customer Personal Data may include but is not limited to:
Obvious will Process Customer Personal Data as long as required to conduct the Processing activities instructed in this DPA or by applicable laws and shall retain the Customer Personal Data as described in Section 5.
Continuous.
Description of the technical and organizational security measures implemented by Obvious and its Subprocessor(s):
Obvious, or Obvious's Subprocessors, implements measures designed to prevent unauthorized persons from gaining access to the Customer Personal Data Processing equipment (namely, database and application servers and related hardware). This shall be accomplished by:
Obvious implements a roles and responsibilities concept with centrally-managed, industry standard SSO providers. Obvious implements an authorization and authentication framework including, but not limited to, the following elements:
Obvious protects systems and applications against malicious software by implementing anti-malware solutions with industry-standard solutions built into all physical hardware. Obvious, and Obvious's Suppliers, defines, documents and implements a backup concept for IT systems, including:
IT systems and applications in non-production environments are logically or physically separated from IT systems and applications in production environments.
Obvious maintains and implements an incident handling process, including but not limited to:
*Specific implementation details are subject to the hosting provider's infrastructure and compliance frameworks. Obvious utilizes enterprise-grade cloud hosting providers that maintain industry-leading security certifications and controls.
This Swiss Addendum forms part of the DPA and applies to any Processing of Customer Personal Data that is subject to the Swiss Federal Act on Data Protection ("Swiss FDPA") or to both the Swiss FDPA and the GDPR.
1.1 Where this Addendum uses terms that are defined in the SCCs, those terms will have the same meaning as in the SCCs. In addition:
1.2 This Addendum will be read and interpreted in light of the provisions of the Swiss FDPA, and so that it fulfills the intention for it to provide appropriate safeguards as required by Article 16 of the Swiss FDPA.
1.3 This Addendum will not be interpreted in a way that conflicts with rights and obligations provided for in the Swiss FDPA.
In the event of a conflict or inconsistency between this Addendum and the provisions of the SCCs or other related agreements between the parties, the provisions which provide the most protection to Data Subjects will prevail.
3.1 To the extent that any Processing of Customer Personal Data is exclusively subject to the Swiss FDPA, the SCCs as incorporated in Section 14.3 of this DPA are amended as follows:
3.2 The Swiss FDPA extends data protection rights to legal entities as well as natural persons. Accordingly, the protections under this DPA and the SCCs as amended by this Addendum shall apply to Personal Data of legal entities to the extent required by the Swiss FDPA.
4.1 To the extent that any Processing of Customer Personal Data is subject to both the Swiss FDPA and the GDPR, this DPA (including the SCCs as incorporated in Section 14.3) will apply:
Customer warrants that it and/or Customer Affiliates have made any notifications to the FDPIC which are required under the Swiss FDPA.
For questions regarding this Data Processing Addendum, please contact us at compliance@obvious.ai
For the complete terms, please refer to our Terms of Service.