1. Scope
This DPA applies to all personal data processed by Augur on behalf of the customer while providing the Augur service. It supplements our Terms and Privacy Policy.
Legal
When you use Augur, you are the controller and we are the processor for any personal data you submit. This page is our standard DPA. Enterprise customers can request a signed copy via legal@augur.news.
This DPA applies to all personal data processed by Augur on behalf of the customer while providing the Augur service. It supplements our Terms and Privacy Policy.
Customer = data controller. Decides what data to send to Augur (account email, watch-zone definitions, alert destinations).
Augur = data processor. Processes the data only to provide the service. Does not sell, share or use it for advertising.
See the dedicated /security page. Headline controls: TLS 1.3 everywhere, AES-256 at rest, Postgres row-level security per tenant, key rotation quarterly, no password-based SSH on production hosts.
Augur uses the following sub-processors to deliver the service. We notify customers 30 days before adding or replacing any sub-processor with material access to customer data. Subscribe to the blog RSS feed for these notices.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Postgres database, authentication, file storage | Frankfurt, EU |
| Vercel | Frontend + serverless function hosting | US + EU edge |
| Hetzner Cloud | Ingest workers, AIS bridge, signal engine | Falkenstein, EU |
| Stripe | Subscription billing + payment processing | Dublin, EU (data) / global processing |
| Resend | Transactional email (welcome, alerts, digests) | US, SOC2 Type II certified |
| Sentry | Error monitoring (optional, only if SENTRY_DSN is set) | US |
Primary data residency is EU (Frankfurt). Where a sub-processor (Stripe, Sentry, Resend) operates infrastructure outside the EU, transfers are covered by the EU Standard Contractual Clauses incorporated by reference.
Augur will assist the customer in responding to data subject requests (access, rectification, erasure, portability) within 30 days. Account holders can self-serve deletion from /settings/danger.
This DPA lasts as long as the underlying service contract. On termination, Augur deletes customer data within 30 days (subject to legal retention for billing records). A signed certificate of deletion is available on request.