Skip to content
feat.so
Product Targeting SDKs Pricing Blog Docs
Sign in Start free →

Data Processing Agreement

Last updated: 2026-06-03

This Data Processing Agreement ("DPA") is part of the Terms of Service between you ("Customer", the data controller) and feat labs, inc. ("feat", the data processor). It applies whenever feat processes Personal Data on your behalf in connection with the Service.

Plain-English summary: when you push end-user data through feat (e.g. targeting context attributes), you remain the controller; feat is your processor. We process that data only on your documented instructions, keep it confidential, secure it, help you respond to data-subject requests, list our sub-processors transparently, and delete the data when you ask. This summary is informational; the sections below control.

1. Definitions

Capitalised terms used but not defined have the meaning in the GDPR (Regulation (EU) 2016/679), the UK GDPR, the LGPD, or the CCPA/CPRA, as applicable.

2. Roles and subject-matter

Customer is the controller and feat is the processor. The subject-matter is Customer's use of the Service. The duration matches the Term of the Terms of Service.

3. Customer instructions

feat will process Personal Data only on Customer's documented instructions, including those given via the Service's UI, APIs, and support channels. feat will inform Customer if an instruction infringes applicable law.

4. Confidentiality

feat will ensure that personnel with access to Personal Data are bound by confidentiality obligations and have received appropriate privacy training.

5. Security

feat will implement and maintain the technical and organisational measures described at /security, including encryption in transit and at rest, access controls, vulnerability management, logging, and incident response.

6. Sub-processors

Customer authorises feat to engage the sub-processors listed at /legal/subprocessors. feat will give at least 30 days' notice of any addition or replacement (via the subscribe form on that page) and Customer may object on reasonable grounds. feat remains liable for sub-processor acts and omissions.

7. International transfers

Where Personal Data is transferred out of the EU/EEA, UK, or Switzerland, the parties rely on the EU-US Data Privacy Framework (where applicable) and the European Commission's Standard Contractual Clauses (Module 2, controller-to-processor) as a fallback. The UK Addendum and the Swiss addendum are incorporated where relevant.

8. Data subject requests

feat will reasonably assist Customer in responding to requests from data subjects exercising their rights (access, rectification, erasure, portability, restriction, objection), within the timeframes required by applicable law. Requests received directly by feat will be redirected to Customer.

9. Personal data breaches

feat will notify Customer without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data Breach, with the information needed to comply with Customer's notification obligations.

10. Audits

feat will make available the information necessary to demonstrate compliance with Article 28 GDPR, including security reports and certifications when available. On-site audits are limited to once per twelve-month period, on at least 30 days' notice, at Customer's expense.

11. Deletion or return

On termination feat will, at Customer's choice, return or delete Personal Data within 30 days, except where retention is required by law.

12. Liability

Liability under this DPA is subject to the limitations in the Terms of Service, except where applicable law disallows such limitation.

13. Order of precedence

To the extent of any conflict between this DPA and the Terms of Service on a data-protection matter, this DPA controls.

14. Annexes

The categories of data subjects, types of Personal Data, processing purposes, and security measures are set out in the Security and Sub-processors pages, which are incorporated by reference. Updated annexes published on those URLs automatically replace prior versions.

15. Contact

DPA-related notices and questions go to support@feat.so.

feat.so

Feature flags, experiments, and safe deploys for teams who ship a lot.

GH LI RSS
Product
  • Feature flags
  • Targeting
  • Rollouts
  • Kill switch
  • Pricing
  • vs LaunchDarkly
Developers
  • Documentation
  • SDKs
  • OpenFeature
  • Changelog
Company
  • About
  • Blog
  • Contact
Legal
  • Customer Agreement
  • User Terms
  • Privacy
  • Cookies
  • DPA
  • Sub-processors
  • Security
© 2026 feat labs, inc. · made for teams who ship