Data Processing Agreement

Last updated: February 2026

Agreement Framework

Overlay's Data Processing Agreement is based on the Common Paper Data Processing Agreement (Version 1.1). This standardized DPA ensures clear, fair data processing terms aligned with industry best practices and global privacy regulations.

Data Processing Details

Data Controller

You (the customer) are the data controller. Overlay processes data on your behalf as a data processor in order to provide the security monitoring service.

Categories of Data

Overlay processes security telemetry data including: file access events, network connection metadata, shell command invocations, and security alert details generated by AI coding agents operating in your environment. No customer source code is stored or transmitted.

Purpose of Processing

Data is processed solely to provide real-time security monitoring, threat detection, alerting, and the AI Security Engineer analysis capabilities described in our Terms of Service.

Subprocessors

Overlay uses the following subprocessors to deliver the service. We will notify customers of any changes to this list.

SubprocessorLocationPurpose
CloudflareUnited StatesCDN, edge computing, DDoS protection
WorkOSUnited StatesAuthentication, SSO, user management
StripeUnited StatesPayment processing & billing

Data Transfers

Overlay is a Canadian entity. Our subprocessors are based in the United States. For transfers of personal data outside of Canada, we rely on appropriate data transfer safeguards including standard contractual clauses and ensuring our subprocessors maintain adequate security certifications. Details of our security practices are described on our Security page.

Data Retention

Security event data is retained according to your plan's retention period (7 days for Starter, 30 days for Team, custom for Enterprise). Upon termination, all customer data is deleted within 30 days.

Contact

For questions about data processing, contact us at privacy@overlay.run.