Data Processing Addendum
Enterprise customers execute a Data Processing Addendum with their agreement. This page describes what that means — it is not itself a signed contract.
Executed per enterprise agreement.
Request an executable copy or submit redlines at Ollie@safegora.com. A public fill-in-the-blank template is not published here.
What enterprise customers receive
When an enterprise order includes a DPA, SafeGora acts as processor / service provider for Customer Personal Data submitted to the production Services. The executed instrument — not this page — is the binding text.
- Sub-processors that handle Customer Personal Data are listed at /legal/subprocessors.
- Security measures in production are summarized on /security.
- Hosting for the production data plane is in the United States (Google Cloud, us-west1). International-transfer terms, when required, are set in the executed DPA.
- SafeGora is not a HIPAA covered entity or Business Associate and does not execute Business Associate Agreements at this time. Do not upload protected health information.
What this page does not do
- It is not a countersigned DPA and not an order form.
- It does not publish bracketed customer-name placeholders or a self-serve clickwrap DPA.
- It does not claim SOC 2, ISO, VPAT, or trust-center completion.
Owner-blocked (needs legal sign-off)
A public executable DPA with annexes, a self-serve DSAR workflow with published fulfillment times, and any HIPAA path remain owner-blocked. Until those land, procurement works from an executed copy.
Contact
Executable copies, redlines, and data-protection inquiries: Ollie@safegora.com.
Last updated
August 28, 2026 — honest-minimal rewrite. Prior scaffold retired.