Data Processing Agreement
Last updated: March 8, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Cupola Labs, LLC (“Processor”, “we”, “us”) and the entity or individual agreeing to these terms (“Controller”, “you”) for the use of Relic (“Service”). This DPA applies where and to the extent that we process Personal Data on your behalf in the course of providing the Service, and such processing is subject to applicable Data Protection Laws including the EU General Data Protection Regulation (GDPR), UK GDPR, and the California Consumer Privacy Act (CCPA).
1. Definitions
- Personal Data — any information relating to an identified or identifiable natural person, as defined under applicable Data Protection Laws
- Processing — any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion
- Data Protection Laws — all applicable laws relating to the processing of Personal Data, including GDPR, UK GDPR, and CCPA
- Sub-processor — any third party engaged by us to process Personal Data on your behalf
2. Scope and Purpose of Processing
We process Personal Data solely for the purpose of providing the Service to you. The nature of processing includes:
- Account authentication and session management
- Storage and transmission of encrypted data (secret values are encrypted client-side using AES-256-GCM before reaching our servers — we cannot access or decrypt them)
- Subscription and billing management
- Anonymized product analytics (only with consent for EU/EEA users, opt-out available for CLI/TUI)
Categories of Personal Data
- Name, email address, and profile image (from OAuth providers)
- Subscription and billing status
- Usage and audit log data
- IP address (for analytics and security, where applicable)
Categories of Data Subjects
- Users of the Service (account holders)
- Collaborators invited by account holders
3. Obligations of the Processor
We shall:
- Process Personal Data only on your documented instructions, unless required by law
- Ensure that persons authorized to process Personal Data are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures, including client-side encryption (AES-256-GCM + Argon2id), TLS in transit, and access controls
- Not engage another processor without your prior authorization (see Sub-processors below)
- Assist you in responding to data subject requests (access, rectification, erasure, portability, restriction, and objection)
- Assist you in ensuring compliance with breach notification obligations under applicable law
- Delete or return all Personal Data upon termination of the Service, at your choice, unless retention is required by law
- Make available all information necessary to demonstrate compliance and allow for audits upon reasonable request
4. Sub-processors
You authorize us to engage the following sub-processors. We will notify you of any changes to sub-processors and provide you the opportunity to object.
| Sub-processor | Purpose | Location |
|---|---|---|
| Convex | Backend infrastructure, encrypted data storage | United States |
| PostHog | Anonymized product analytics | United States |
| Stripe | Payment processing | United States |
| Autumn | Billing and subscription management | United States |
| Resend | Transactional email delivery | United States |
| Cloudflare | CDN, DNS, web application hosting | Global |
5. International Data Transfers
Where Personal Data is transferred outside the EEA, UK, or Switzerland, we ensure that appropriate transfer mechanisms are in place, including Standard Contractual Clauses (SCCs) as approved by the European Commission, or other lawful transfer mechanisms under applicable Data Protection Laws.
6. Security Measures
We implement the following technical and organizational measures to protect Personal Data:
- Zero-knowledge architecture — secret values are encrypted on-device using AES-256-GCM with keys derived via Argon2id before transmission
- Encryption keys never leave the user's device
- TLS encryption for all data in transit
- OAuth-based authentication via industry-standard providers
- Rate limiting and abuse prevention
- Audit logging of all data operations
- Role-based access with cryptographic key isolation per project
7. Data Breach Notification
In the event of a Personal Data breach, we will notify you without undue delay and no later than 72 hours after becoming aware of the breach. The notification will include the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to address the breach.
8. Data Subject Requests
We will assist you in fulfilling data subject requests under applicable Data Protection Laws. Users can exercise the following rights directly through the Service:
- Access and portability — Export data via the CLI, TUI, or web dashboard
- Erasure — Delete account and all associated data from the dashboard
- Objection to analytics — Reject cookies via the consent banner (EU/EEA) or disable CLI/TUI telemetry
For requests that cannot be handled self-service, contact us at support@withrelic.com.
9. Term and Termination
This DPA remains in effect for the duration of our processing of Personal Data on your behalf. Upon termination of the Service agreement, we will delete all Personal Data in accordance with our Privacy Policy unless retention is required by applicable law.
10. Contact
For questions about this DPA or to exercise any rights, contact us at support@withrelic.com.
See also our Privacy Policy and Terms of Service.