Legal Documentation

Logsmith Data Processing Agreement

Last updated: August 18, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Logsmith Inc. ("Logsmith") and the customer ("Customer") governing Customer's use of the Logsmith service (the "Agreement" — our Terms of Service, unless the parties have executed a separate written agreement, in which case that agreement).

1. Scope and Application

1.1 This DPA applies to Logsmith's processing of Customer Personal Data: personal data contained in Customer Data (as defined in the Agreement) that Logsmith processes on Customer's behalf in providing the Service.

1.2 This DPA is incorporated into the Agreement (a) upon Customer's written request, or (b) automatically, to the extent Applicable Data Protection Law requires a data processing contract between the parties. In case of conflict, this DPA prevails over the Agreement with respect to processing of Customer Personal Data; the Agreement's limitation of liability governs liability under this DPA.

1.3 "Applicable Data Protection Law" means the data protection and privacy laws applying to the processing of Customer Personal Data under this DPA, which may include the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended ("CCPA"), and other applicable laws.

1.4 Roles. Customer is the controller (or, where Customer acts for another controller, a processor) and Logsmith is a processor of Customer Personal Data. For CCPA purposes, Logsmith is a service provider and Customer is a business. Each party will comply with its own obligations under Applicable Data Protection Law.

2. Processing Instructions

2.1 Logsmith will process Customer Personal Data only on Customer's documented instructions, which are: (a) to provide, maintain, secure, and support the Service as described in the Agreement; (b) as configured by Customer through the Service, including the systems Customer chooses to connect; and (c) as otherwise instructed in writing by Customer and accepted by Logsmith. Logsmith will inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, and may suspend the affected processing until instructions are clarified.

2.2 Logsmith will not sell Customer Personal Data, share it for cross-context behavioral advertising, retain, use, or disclose it outside the direct business relationship with Customer or for any purpose other than the business purposes in Section 2.1, or combine it with personal data from other sources except as permitted for service providers. Logsmith certifies that it understands and will comply with these restrictions.

2.3 No AI training. Without limiting Section 2.2, Logsmith will not use Customer Personal Data to train, fine-tune, or improve any machine-learning or artificial-intelligence model, and will ensure by contract or configuration that no Subprocessor does so.

3. Details of Processing

The subject matter, duration, nature and purpose of processing, the types of personal data, and the categories of data subjects are set out in Annex I.

4. Confidentiality and Personnel

Logsmith will ensure that persons authorized to process Customer Personal Data are bound by contractual or statutory confidentiality obligations, and will limit access to personnel who need it to provide the Service.

5. Security

Logsmith will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the nature of the data and the risks of the processing. The current measures are described in Annex II. Logsmith may update them from time to time, provided the updates do not materially reduce the overall level of protection.

6. Subprocessors

6.1 Customer generally authorizes Logsmith to engage subprocessors to process Customer Personal Data. The current list is published on our subprocessor page (Annex III), and Logsmith will update that page at least 15 days before adding or replacing a subprocessor. Customers subscribed to notifications (per that page) receive change notices by email.

6.2 Logsmith will impose on each subprocessor data protection obligations materially no less protective than those in this DPA, and remains fully liable to Customer for each subprocessor's performance.

6.3 If Customer reasonably objects to a new subprocessor on data protection grounds within 15 days of the update, the parties will discuss in good faith; if Logsmith cannot reasonably accommodate the objection, Customer may terminate the affected subscription with a pro-rata refund of prepaid fees for the unexpired portion of its term, as its sole remedy.

7. Assistance

7.1 Data subject requests. Taking into account the nature of the processing, Logsmith will assist Customer by appropriate technical and organizational measures in fulfilling Customer's obligation to respond to data subject requests (access, correction, deletion, portability, objection, restriction). If a data subject contacts Logsmith directly regarding Customer Personal Data, Logsmith will refer the request to Customer without responding substantively, except to direct the data subject to Customer.

7.2 Compliance assistance. Logsmith will provide reasonable assistance to Customer with data protection impact assessments, prior consultations with supervisory authorities, and Customer's security and breach-notification obligations under Applicable Data Protection Law, in each case to the extent the required information is available to Logsmith and Customer cannot obtain it otherwise. Logsmith may charge a reasonable fee for assistance that is materially beyond the scope of the Service.

8. Personal Data Breach

Logsmith will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, and the measures taken or proposed. Logsmith will cooperate with Customer and take reasonable steps to mitigate and remediate. Logsmith's notification is not an admission of fault.

9. International Transfers

9.1 Logsmith processes Customer Personal Data in the locations stated in Annex I and on the subprocessor page. Logsmith will not transfer Customer Personal Data protected by a law restricting international transfers except pursuant to a lawful transfer mechanism.

9.2 EEA transfers. Where Customer Personal Data protected by the GDPR is transferred to Logsmith in a country without an adequacy decision, the EU Standard Contractual Clauses (Commission Decision 2021/914), Module Two (controller to processor) — or Module Three where Customer is itself a processor — are incorporated into this DPA by reference, completed as follows: Clause 7 (docking) included; Clause 9(a) Option 2 (general authorization, 15 days); Clause 11 optional language not included; Clause 17: the law of Ireland; Clause 18: the courts of Ireland; Annexes I–III of the SCCs are completed by Annexes I–III of this DPA.

9.3 UK transfers. For Customer Personal Data protected by UK law, the UK International Data Transfer Addendum to the EU SCCs (version B1.0) is incorporated by reference, with the tables completed by the details in this DPA and its Annexes.

9.4 If a transfer mechanism relied on under this Section is invalidated, the parties will cooperate in good faith to implement a lawful replacement.

10. Audits and Information

10.1 Logsmith will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including by completing Customer's reasonable security questionnaires (no more than once in any 12-month period) and providing summaries of any third-party security assessments or certifications it holds.

10.2 Where Applicable Data Protection Law grants Customer a mandatory audit right that Section 10.1 does not satisfy, Customer (or an independent auditor that is not a competitor of Logsmith, bound by confidentiality) may audit Logsmith's compliance with this DPA on at least 30 days' written notice, during business hours, no more than once per year (except following a Personal Data Breach or at a supervisory authority's direction), at Customer's cost and without access to other customers' data.

11. Return and Deletion

Upon termination or expiry of the Agreement, Logsmith will delete Customer Personal Data in accordance with the Agreement (deletion within 30 days, save for copies required by law or residing in routine backups, which are deleted on their ordinary cycle and remain protected by this DPA until deleted). On written request made within 30 days of termination, Logsmith will first provide an export of Output as described in the Agreement. Logsmith will certify deletion on written request.

12. Term

This DPA applies for as long as Logsmith processes Customer Personal Data and terminates automatically when all Customer Personal Data has been deleted or returned.

Annex I

Details of Processing

Parties
Data exporter — Customer (contact details as per its account). Data importer — Logsmith Inc., 2810 N Church St, STE 89321, Wilmington, DE 19802, USA; [email protected].
Subject matter and nature of processing
Automated investigation of production alerts: ingestion, querying, and analysis of telemetry and source code from Customer's connected systems to produce root-cause analyses and proposed code fixes, and delivery of that output to Customer.
Purpose
Provision of the Service under the Agreement.
Duration
The term of the Agreement, plus the retention periods stated in the Agreement (raw Customer Data no longer than 90 days from ingestion; deletion within 30 days of termination).
Categories of data subjects
Customer's personnel; incidentally, end users of Customer's (or its clients') systems whose data appears in telemetry.
Types of personal data
None intentionally processed. Personal data may incidentally appear in logs, traces, alerts, and source code — for example names, usernames, email addresses, IP addresses, and identifiers. Customer is responsible for minimizing such exposure using available redaction and scoping controls.
Special categories
None intended or permitted; Customer must not knowingly expose special-category data to the Service.
Frequency
Continuous, alert-driven.
Locations of processing
Storage at rest in India (Microsoft Azure, Central India); transient model inference in the United States; access by Logsmith personnel from the locations stated in the Privacy Policy.
Annex II

Technical and Organizational Measures

  • Encryption of Customer Data in transit (TLS) and at rest.
  • Role-based access control; access to Customer Data limited to personnel who need it to provide the Service.
  • Multi-factor authentication on administrative access.
  • Logging of access to production systems and Customer Data.
  • Customer credentials stored in a dedicated secrets manager; never in plain text or source code.
  • Read-only integration architecture: the Service holds read-only credentials to Customer systems, except repository access scoped to branch and pull-request creation.
  • Model providers configured not to train on Customer Data; provider-side retention limited to Microsoft's abuse-monitoring logs (up to 30 days, then deleted), as described on the subprocessor page.
  • Segregation of each customer's data.
  • Personnel confidentiality obligations and security training.
  • Vendor assessment of subprocessors and contractual flow-down of data protection obligations.
  • Incident response process supporting the notification commitment in Section 8.
  • Business continuity: infrastructure hosted on a major cloud provider with managed backups.
Annex III

Subprocessors

The authorized subprocessors are listed on our subprocessor page, which forms part of this DPA.

Countersigned copies

Customers requiring a countersigned copy of this DPA may send a signed copy to [email protected]; it is deemed executed by Logsmith upon receipt.