Privacy Policy
Last updated: July 31st, 2026
This page sets forth Section 9 ("Data Protection and Privacy") of the Serverless Customer Agreement, which governs how Serverless Inc. processes Personal Data in connection with the Services. Capitalized terms used below are defined in the Customer Agreement.
9. Data Protection and Privacy
9.1 Compliance with Data Protection Laws
Each Party shall comply with all Applicable Laws relating to data protection and privacy in connection with its Processing of Personal Data under this Agreement.
9.2 Roles of the Parties
With respect to the Processing of Personal Data under this Agreement, Customer is the Data Controller and Serverless is the Data Processor.
9.3 Processing of Personal Data
(a) Instructions. Serverless shall Process Personal Data only on documented instructions from Customer, including with regard to transfers of Personal Data to a third country or an international organization, unless required to do otherwise by Applicable Law.
(b) Purpose Limitation. Serverless shall not Process Personal Data in a manner that is incompatible with the purposes outlined in this Agreement or as otherwise instructed by Customer.
9.4 Obligations of Serverless as Processor
(a) Confidentiality. Serverless shall ensure that persons authorized to Process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
(b) Security Measures. Serverless shall implement and maintain appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include, but are not limited to:
- Encryption: Personal Data shall be encrypted in transit over public networks using industry-standard encryption protocols. Data stored with our cloud hosting providers shall use industry-standard encryption at rest.
- Access Control: Systems containing Personal Data shall be protected by user ID and passwords. Access to systems shall be granted on a need-to-know basis and promptly terminated when no longer required.
- Logging and Monitoring: All access to systems containing Personal Data shall be logged and monitored for suspicious activity.
- Regular Security Assessments: Serverless shall conduct regular assessments of its security measures to ensure their continued effectiveness.
(c) Data Breach Notification. Serverless shall notify Customer without undue delay, and in any event within 24 hours after becoming aware of a Personal Data breach affecting Customer's Personal Data. Such notification shall include:
- A description of the nature of the breach, including, where possible, the categories and approximate number of Data Subjects concerned.
- The name and contact details of the data protection officer or other contact point where more information can be obtained.
- A description of the likely consequences of the breach.
- A description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects.
9.5 Sub-processors
(a) Authorization. Customer authorizes Serverless to engage Sub-processors to Process Personal Data, provided that Serverless shall ensure that any Sub-processors comply with the same data protection obligations as set out in this Agreement.
(b) List of Sub-processors. Serverless shall maintain an up-to-date list of Sub-processors, which includes their identities and countries of location, available upon Customer's request.
(c) Changes to Sub-processors. Serverless shall inform Customer of any intended changes concerning the addition or replacement of Sub-processors, giving Customer the opportunity to object to such changes.
9.6 Assistance to Customer
(a) Data Subject Rights. Serverless shall assist Customer, at Customer's expense, by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligations to respond to requests from Data Subjects exercising their rights under Applicable Law.
(b) Data Protection Impact Assessments. Upon Customer's request, Serverless shall provide assistance to Customer in relation to data protection impact assessments and prior consultations with supervisory authorities, where required by Applicable Law.
9.7 Data Location
Customer acknowledges and agrees that Personal Data may be processed in the United States.
9.8 Return and Deletion of Personal Data
(a) Obligation upon Termination. Upon termination of this Agreement, Serverless shall, at Customer's choice, delete or return all Personal Data to Customer, unless retention is required by Applicable Law.
(b) Retention Required by Law. If retention is required by Applicable Law, Serverless shall notify Customer of such requirement.
Contact
Serverless, Inc. 522 San Anselmo Avenue San Anselmo, CA 94960
Email: contact@serverless.com