Part 1

Processing Details

Customer Name:
Customer Address:
Customer Contact:
Customer Role:
□ Controller / business
□ Processor / service provider

Categories of Personal Data Stored or Processed Through the Services

  • Contact information: first name, last name, email address.
  • Usage information.
  • Registration/account information: name, email address, password.

Categories of Data Subjects to Whom the Personal Data Mentioned Above Relates

  • Authorized Users

Special Categories of Personal Data

  • None

Frequency of the Transfer

  • Continuous

Nature of the Processing

  • Storage, deletion, rectification, analysis, transfer, aggregation

Purpose of the Processing

  • The performance of the Services, namely the provision of database and tooling services for the development and operation of web and mobile applications.

Retention Period

  • The duration of the Agreement, unless earlier deletion is requested by the Customer in accordance with the functionality of the Services.

Subprocessors

  • As set out in Schedule 3

Supervisory Authority (EU Only)

By signing below and returning to privacy@supabase.io, the Customer agrees to the data processing terms set out in Part 2 of this Data Processing Addendum and warrants that the information in Part 1 of this Data Processing Addendum is complete and accurate.

Signed for and on behalf of the Customer: ___
Name: ___
Position: ___
Date: ___

Part 2

Data Processing Terms

(Version dated 14 March 2025)

This Data Processing Addendum, comprising Part 1 (Processing Details) and Part 2 (Data Processing Terms) (together the "DPA") supplements and, from the date on which Customer signs or otherwise agrees to this DPA, forms part of the agreement entered into between the Customer and Supabase, Inc ("Supabase") on the terms set out at https://supabase.com/terms (the "Agreement") in relation to the transfer and processing of Covered Data in connection with the performance of the Services.

1. DEFINITIONS

1.1 Capitalized terms used but not defined within this DPA will have the meaning set forth in the Agreement.
The following capitalized terms used in this DPA will be defined as follows:

  • Applicable Data Protection Laws means all applicable laws, rules, regulations, and governmental requirements relating to the privacy, confidentiality, or security of Personal Data, as they may be amended or otherwise updated from time to time, including (without limitation): the GDPR, Swiss Data Protection Laws and the US Data Protection Laws.

  • CCPA means the California Consumer Privacy Act of 2018, Cal. Civ. Code § 1798.100 et seq., as amended, including its implementing regulations and the California Privacy Rights Act of 2020.


  • Controller Purposes means:
    (a) aggregating and anonymising information for the purpose of undertaking internal research and development to monitor, test, improve and alter the functionality of the Services;
    (b) monitoring the Customer's and Authorized Users' use of the Services for billing purposes, ensuring the security of the Services and identifying fraudulent or malicious use of the Services; and
    (c) administering the Customer's relationship with Supabase under the Agreement.

  • Covered Data means:
    (a) Personal Data that is provided by or on behalf of Customer to Supabase in connection with Customer's use of the Services, as further described in Part 1 (Processing Details) of this DPA;
    (b) contact information and access credentials relating to, and support requests submitted by, Authorized Users; and
    (c) any other Personal Data that is otherwise collected, generated or Processed by Supabase in connection with the provision of the Services.

  • Customer's Controller means, where the Customer acts as a processor or service provider (as identified in Part 1 (Processing Details)), the controller or business on whose behalf the Customer Processes Covered Data.

  • Data Subject means a natural person whose Personal Data is Processed.

  • Deidentified Data means data created using Covered Data that cannot reasonably be linked to such Covered Data, directly or indirectly.

  • GDPR means Regulation (EU) 2016/679 (the "EU GDPR") or, where applicable, the "UK GDPR", as defined in section 3 of the Data Protection Act 2018.

  • Personal Data means any data or information that:
    (a) is linked or reasonably linkable to an identified or identifiable natural person; or
    (b) is otherwise "personal data," "personal information," "personally identifiable information," or similarly defined data or information under Applicable Data Protection Laws.

  • Processing means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means. "Process", "Processes" and "Processed" will be interpreted accordingly.

  • Security Incident means an actual or suspected breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to (including unauthorized internal access to), Covered Data.

  • Standard Contractual Clauses or SCCs means the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914.

  • Sub-processor means, with respect to any Processing performed by Supabase as a processor service provider, an entity appointed by Supabase to Process Covered Data on its behalf.


2. INTERACTION WITH THE AGREEMENT

2.1 This DPA is incorporated into and forms an integral part of the Agreement. This DPA supplements and (in case of contradictions) supersedes the Agreement with respect to any Processing of Covered Data.

3. ROLE OF THE PARTIES

The Parties acknowledge and agree that:

(a) save as set out in clause 3(b) or clause 3(c), Supabase acts as a processor or service provider in the performance of its obligations under the Agreement and this DPA and Customer acts as a controller or business; (b) to the extent that Customer acts as a processor in respect of Covered Data on behalf of Customer's Controller, Supabase acts as a subprocessor in the performance of its obligations under the Agreement and this DPA; and (c) for the purposes of the GDPR, Supabase acts as a controller with respect to the Processing of Usage Data for the Controller Purposes.