Data Processing Agreement
Last updated: February 2026
Agreement Framework
Overlay's Data Processing Agreement is based on the Common Paper Data Processing Agreement (Version 1.1). This standardized DPA ensures clear, fair data processing terms aligned with industry best practices and global privacy regulations.
Data Processing Details
Data Controller
You (the customer) are the data controller. Overlay processes data on your behalf as a data processor in order to provide the security monitoring service.
Categories of Data
Overlay processes security telemetry data including: file access events, network connection metadata, shell command invocations, and security alert details generated by AI coding agents operating in your environment. No customer source code is stored or transmitted.
Purpose of Processing
Data is processed solely to provide real-time security monitoring, threat detection, alerting, and the AI Security Engineer analysis capabilities described in our Terms of Service.
Subprocessors
Overlay uses the following subprocessors to deliver the service. We will notify customers of any changes to this list.
| Subprocessor | Location | Purpose |
|---|---|---|
| Cloudflare | United States | CDN, edge computing, DDoS protection |
| WorkOS | United States | Authentication, SSO, user management |
| Stripe | United States | Payment processing & billing |
Data Transfers
Overlay is a Canadian entity. Our subprocessors are based in the United States. For transfers of personal data outside of Canada, we rely on appropriate data transfer safeguards including standard contractual clauses and ensuring our subprocessors maintain adequate security certifications. Details of our security practices are described on our Security page.
Data Retention
Security event data is retained according to your plan's retention period (7 days for Starter, 30 days for Team, custom for Enterprise). Upon termination, all customer data is deleted within 30 days.
Contact
For questions about data processing, contact us at privacy@overlay.run.