Data Processing Agreement

Last updated: March 8, 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between Cupola Labs, LLC (“Processor”, “we”, “us”) and the entity or individual agreeing to these terms (“Controller”, “you”) for the use of Relic (“Service”). This DPA applies where and to the extent that we process Personal Data on your behalf in the course of providing the Service, and such processing is subject to applicable Data Protection Laws including the EU General Data Protection Regulation (GDPR), UK GDPR, and the California Consumer Privacy Act (CCPA).

1. Definitions

  • Personal Data — any information relating to an identified or identifiable natural person, as defined under applicable Data Protection Laws
  • Processing — any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion
  • Data Protection Laws — all applicable laws relating to the processing of Personal Data, including GDPR, UK GDPR, and CCPA
  • Sub-processor — any third party engaged by us to process Personal Data on your behalf

2. Scope and Purpose of Processing

We process Personal Data solely for the purpose of providing the Service to you. The nature of processing includes:

  • Account authentication and session management
  • Storage and transmission of encrypted data (secret values are encrypted client-side using AES-256-GCM before reaching our servers — we cannot access or decrypt them)
  • Subscription and billing management
  • Anonymized product analytics (only with consent for EU/EEA users, opt-out available for CLI/TUI)

Categories of Personal Data

  • Name, email address, and profile image (from OAuth providers)
  • Subscription and billing status
  • Usage and audit log data
  • IP address (for analytics and security, where applicable)

Categories of Data Subjects

  • Users of the Service (account holders)
  • Collaborators invited by account holders

3. Obligations of the Processor

We shall:

  • Process Personal Data only on your documented instructions, unless required by law
  • Ensure that persons authorized to process Personal Data are bound by confidentiality obligations
  • Implement appropriate technical and organizational security measures, including client-side encryption (AES-256-GCM + Argon2id), TLS in transit, and access controls
  • Not engage another processor without your prior authorization (see Sub-processors below)
  • Assist you in responding to data subject requests (access, rectification, erasure, portability, restriction, and objection)
  • Assist you in ensuring compliance with breach notification obligations under applicable law
  • Delete or return all Personal Data upon termination of the Service, at your choice, unless retention is required by law
  • Make available all information necessary to demonstrate compliance and allow for audits upon reasonable request

4. Sub-processors

You authorize us to engage the following sub-processors. We will notify you of any changes to sub-processors and provide you the opportunity to object.

Sub-processorPurposeLocation
ConvexBackend infrastructure, encrypted data storageUnited States
PostHogAnonymized product analyticsUnited States
StripePayment processingUnited States
AutumnBilling and subscription managementUnited States
ResendTransactional email deliveryUnited States
CloudflareCDN, DNS, web application hostingGlobal

5. International Data Transfers

Where Personal Data is transferred outside the EEA, UK, or Switzerland, we ensure that appropriate transfer mechanisms are in place, including Standard Contractual Clauses (SCCs) as approved by the European Commission, or other lawful transfer mechanisms under applicable Data Protection Laws.

6. Security Measures

We implement the following technical and organizational measures to protect Personal Data:

  • Zero-knowledge architecture — secret values are encrypted on-device using AES-256-GCM with keys derived via Argon2id before transmission
  • Encryption keys never leave the user's device
  • TLS encryption for all data in transit
  • OAuth-based authentication via industry-standard providers
  • Rate limiting and abuse prevention
  • Audit logging of all data operations
  • Role-based access with cryptographic key isolation per project

7. Data Breach Notification

In the event of a Personal Data breach, we will notify you without undue delay and no later than 72 hours after becoming aware of the breach. The notification will include the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to address the breach.

8. Data Subject Requests

We will assist you in fulfilling data subject requests under applicable Data Protection Laws. Users can exercise the following rights directly through the Service:

  • Access and portability — Export data via the CLI, TUI, or web dashboard
  • Erasure — Delete account and all associated data from the dashboard
  • Objection to analytics — Reject cookies via the consent banner (EU/EEA) or disable CLI/TUI telemetry

For requests that cannot be handled self-service, contact us at support@withrelic.com.

9. Term and Termination

This DPA remains in effect for the duration of our processing of Personal Data on your behalf. Upon termination of the Service agreement, we will delete all Personal Data in accordance with our Privacy Policy unless retention is required by applicable law.

10. Contact

For questions about this DPA or to exercise any rights, contact us at support@withrelic.com.

See also our Privacy Policy and Terms of Service.