Legal
Data Processing Agreement
Last updated 31 July 2026
Where you send us data containing personal data, you are the controller and we are the processor. These are the terms on which we act.
1. Scope and roles
This agreement supplements the Terms of Service. You are the controller for workflow data you send to Obsevo Cloud; {{LEGAL_ENTITY}} is the processor. For account and billing data we are the controller, and the privacy policy covers that.
2. Subject matter and duration
We process your data to provide workflow monitoring, detection, alerting and reporting, for as long as your account is active plus the retention periods described in the privacy policy.
3. Categories of data and data subjects
Ordinarily processed: workflow and node names, run status, timings, item counts, error text, and AI model and token metadata.
Possible, depending on your workflows: personal data contained in error messages, or in log lines and business events you choose to send. These are free-form fields, and what goes into them is under your control rather than ours.
Not processed in agent mode: execution payloads, prompt and completion content, and credentials.
Data subjects are typically your own staff and whoever appears in the data your workflows handle.
4. Our obligations
- Process personal data only on your documented instructions, including for transfers.
- Ensure people authorised to process it are bound by confidentiality.
- Implement appropriate technical and organisational measures — described on the security page, which is deliberately specific about what is and is not in place.
- Not engage a new subprocessor without updating the subprocessors page beforehand, and remain liable for their performance.
- Assist you with data-subject requests, and with security and impact assessments.
- Notify you without undue delay after becoming aware of a personal data breach, with the information we hold at the time.
- On termination, delete or return personal data at your choice, subject to any legal retention requirement.
5. Your obligations
You confirm you have a lawful basis for the data you send us, that you are entitled to connect the n8n instances you connect, and that you will not deliberately place special category data into free-form fields such as error messages or log lines.
6. International transfers
Where personal data is transferred outside your jurisdiction, the parties rely on the transfer mechanism the applicable law provides, including standard contractual clauses where relevant. Subprocessor locations are listed on the subprocessors page.
7. Audits
We will make available the information reasonably necessary to demonstrate compliance with this agreement, and will contribute to audits conducted by you or an auditor you mandate, on reasonable notice and no more than once a year unless a supervisory authority requires otherwise.
We hold no third-party audit report to offer instead. What we can offer is a direct answer to a specific question, in writing, from the person who built the thing being asked about.
8. Signing this
A countersigned DPA needs a legal entity to sign it, and that entity does not exist yet. Until it does, this page states the terms we intend to be held to rather than an agreement you can execute.
If you need a signed DPA before adopting Obsevo, get in touch through the contact page— knowing that someone is waiting on it is genuinely useful to us.