Skip to content

Updated October 4, 2026

Data Processing Addendum.

This Data Processing Addendum (“DPA”) is part of the Terms of Service or other agreement between Deepslate Inc., doing business as Embrasure (“Embrasure”), and the customer (“Customer”) for use of the Service. It applies whenever Embrasure processes Customer Personal Data on Customer's behalf. It takes effect automatically; to receive a countersigned copy, email legal@embrasure.ai.

1. Definitions

“Customer Personal Data” means personal data in Customer Data that Embrasure processes on Customer's behalf. “Data Protection Laws” means laws that apply to that processing, including the GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and U.S. state privacy laws such as the California Consumer Privacy Act. “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. Other capitalized terms have the meaning given in the Terms or in Data Protection Laws.

2. Roles and instructions

Customer is the controller, or a processor acting for its own customers, and Embrasure is a processor or service provider. Embrasure processes Customer Personal Data only on Customer's documented instructions. The agreement, Customer's configuration of the Service, and actions taken by its users are those instructions. Embrasure will tell Customer if it believes an instruction violates Data Protection Laws.

Customer is responsible for the lawfulness of the personal data it provides or connects, including notices and consents. Customer will not provide special category data or protected health information unless the parties have agreed in writing to the safeguards for it.

3. Confidentiality

Embrasure limits access to Customer Personal Data to personnel who need it to provide, secure, or support the Service and who are bound by confidentiality obligations.

4. Security

Embrasure maintains technical and organizational measures designed to protect Customer Personal Data, including:

  • Encryption in transit with TLS, and encryption at rest for stored data and connector credentials.
  • Workspace isolation, role-based access controls, row-level security, and single sign-on and multi-factor authentication options.
  • Least-privilege production access, with administrative actions recorded in audit logs.
  • Versioned and replicated backups, and documented business continuity and disaster recovery plans.
  • Vulnerability management, dependency and secret scanning, and code review before production changes.
  • A documented incident response plan, plus security training and background screening for personnel.

Embrasure may update these measures as long as the overall level of protection is not reduced. More detail is on our Security page.

5. Subprocessors

Customer authorizes Embrasure to use the subprocessors listed on our Subprocessors page. Embrasure binds each subprocessor to written data protection terms at least as protective as this DPA and remains responsible for its performance.

Embrasure will notify workspace owners by email at least 15 days before a new subprocessor begins processing Customer Personal Data. Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, Customer may terminate the affected Service and receive a refund of prepaid fees for the unused period.

6. Assistance

Taking into account the nature of the processing, Embrasure will help Customer respond to data subject requests, mostly through the Service's own controls, and will promptly forward requests it receives directly. Embrasure will provide reasonable information Customer needs for data protection impact assessments and consultations with supervisory authorities.

7. Security incidents

Embrasure will notify Customer without undue delay, and in any case within 72 hours, after becoming aware of a Security Incident. The notice will describe what happened, the data and people likely affected, the likely consequences, and the steps taken or proposed, as that information becomes available. Embrasure will take reasonable steps to contain and remediate the incident. Notice is not an admission of fault.

8. Deletion and return

Customer can export its data from the Service before its workspace ends. Within 30 days after the agreement ends, Embrasure deletes or de-identifies Customer Personal Data, except copies in backups that expire on their normal schedule or data it must keep by law, which stay protected under this DPA until deleted.

9. Audits

On request, and no more than once a year, Embrasure will provide information reasonably needed to show compliance with this DPA. This includes answers to security questionnaires and, once available, third-party audit reports under confidentiality. If that information is not enough to meet a requirement of Data Protection Laws or a supervisory authority, Customer may conduct an audit at its own cost, with 30 days' notice, during business hours, and without access to other customers' data.

10. International transfers

Embrasure processes Customer Personal Data in the United States. For transfers of personal data from the European Economic Area, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 are incorporated by reference. Module Two applies where Customer is a controller and Module Three where it is a processor. The optional docking clause in Clause 7 does not apply. Option 2 of Clause 9(a) (general written authorization) applies, with the notice period in section 5. The optional language in Clause 11 does not apply. Under Clause 17, Option 1 applies and the clauses are governed by Irish law. Under Clause 18, disputes are resolved by the courts of Ireland. Section 12 of this DPA completes the annexes.

For the United Kingdom, the UK International Data Transfer Addendum to those clauses applies. For Switzerland, the clauses apply with references to the Swiss Federal Act on Data Protection and the Swiss Federal Data Protection and Information Commissioner.

11. U.S. state privacy laws

Where U.S. state privacy laws apply, Embrasure will not sell or share Customer Personal Data, will not retain, use, or disclose it outside the direct business relationship or for any purpose other than providing the Service, and will not combine it with personal data from other sources except as those laws permit. Embrasure will notify Customer if it can no longer meet these obligations.

12. Details of processing

Subject matter and durationProviding the Service for the term of the agreement, plus the deletion period in section 8.
Nature and purposeHosting, syncing, storing, querying, analyzing, and generating AI output from Customer Data, and supporting and securing the Service, as directed by Customer.
Data subjectsCustomer's users, and individuals whose personal data appears in the sources Customer connects, such as its employees, customers, prospects, and end users.
Personal dataAccount details such as names, work emails, roles, and authentication identifiers, plus any personal data in data Customer chooses to connect or create.
Special category dataNone, unless agreed in writing under section 2.
FrequencyContinuous, for the term of the agreement.
Technical and organizational measuresSection 4.
SubprocessorsListed on the Subprocessors page, under section 5.

13. General

If this DPA conflicts with the agreement, this DPA controls for the processing of Customer Personal Data. The Standard Contractual Clauses control over both where they apply. Each party's liability under this DPA is subject to the limitations in the agreement, except where Data Protection Laws do not allow it. Questions about this DPA go to privacy@embrasure.ai.