Legal

Data Processing Agreement

Last updated: July 24, 2026

Legal center · Related: Terms of Service · Privacy Policy · End User License Agreement · Acceptable Use Policy

1. Parties & incorporation

This Data Processing Agreement ("DPA") forms part of the agreement between Shubham Gupta trading as Watch Dog ("Processor") and the organization customer ("Controller") that uses Watch Dog organization features. It supplements the Terms of Service or, if applicable, the MSA and Order Form. By creating an organization account or executing an Order Form that references this DPA, Controller agrees to this DPA.

2. Definitions

"Personal Data", "Processing", "Controller", and "Processor" have meanings consistent with the Australian Privacy Principles and, where applicable, the EU/UK GDPR. "Customer Personal Data" means Personal Data contained in audit metadata and account records Processor handles for Controller.

3. Scope of processing

  • Subject matter: providing local-first browser DLP with organization policy, audit logging, and admin dashboard.
  • Duration: for the term of the service and deletion period below.
  • Nature: storage, retrieval, and display of content-free audit metadata and account administration data. File content is not transmitted to Processor.
  • Types of data: user identifiers (e.g. email), org identifiers, event metadata (rule category, destination domain, timestamps), billing contacts.
  • Data subjects: Controller's employees, contractors, and other authorized users.

4. Processor obligations

  • Process Customer Personal Data only on documented instructions from Controller (including configuration in the product).
  • Ensure persons authorized to process data are bound by confidentiality.
  • Implement appropriate technical and organizational security measures (see Security).
  • Assist Controller with data subject requests, DPIAs, and breach response, taking into account the nature of processing.
  • Delete or return Customer Personal Data after end of service, except where law requires retention.
  • Make available information reasonably necessary to demonstrate compliance; audits by mutual agreement on reasonable notice (Enterprise).

5. Controller obligations

Controller warrants it has a lawful basis to monitor users and to provide Customer Personal Data to Processor, and that instructions comply with applicable privacy laws.

6. Sub-processors

Controller authorizes Processor to use the following sub-processors:

  • Supabase — authentication and org-isolated database
  • Vercel — application hosting
  • Stripe — payment processing (billing contacts / customer IDs)

Processor will impose data-protection terms no less protective than this DPA. Material changes to sub-processors will be posted on the Security page and/or notified to Enterprise admins. Controller may object on reasonable data-protection grounds; if unresolved, Controller may terminate the affected services.

7. International transfers

Where Customer Personal Data is transferred internationally, Processor will ensure an appropriate transfer mechanism (including Standard Contractual Clauses with sub-processors where required).

8. Security incidents

Processor will notify Controller without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data, and will provide information reasonably required for Controller to meet its notification obligations.

9. Liability & order of precedence

Liability under this DPA is subject to the limitations in the Terms or MSA. If there is a conflict, the Order Form (if any) prevails, then this DPA for data-protection matters, then the MSA/Terms.

10. Governing law

This DPA is governed by the laws of Western Australia, Australia, unless the MSA states otherwise.

11. Contact

Privacy / DPA requests: support.watchdogdlp@gmail.com. To execute a signed PDF copy for procurement, contact sales.