Legal
Longboard Data Processing Addendum (DPA)
Last updated: August 11, 2026
1. Introduction
This Data Processing Addendum ("DPA") forms part of the agreement between Longboard LLC ("Longboard," "we") and the customer identified in the applicable order or subscription agreement (the "Brand," or "you") (the "Agreement") and governs Longboard's processing of Personal Information on the Brand's behalf in connection with the Longboard services (the "Services").
Where this DPA conflicts with the Agreement on the subject of data protection, this DPA controls. Capitalized terms not defined here have the meaning given in the Agreement or the Longboard Privacy Policy.
2. Definitions
- "Applicable Privacy Law" means the U.S. state comprehensive privacy laws applicable to the processing, including the California Consumer Privacy Act as amended (the "CCPA") and the comprehensive privacy laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other U.S. states, as applicable.
- "Personal Information" means information relating to an identified or identifiable individual that Longboard processes on the Brand's behalf under the Agreement ("Tenant Data"), as further described in Annex A.
- "Controller" / "Business" means the entity that determines the purposes and means of processing; "Processor" means the entity that processes Personal Information on behalf of the Controller.
- "Subprocessor" means a third party engaged by Longboard to process Personal Information on the Brand's behalf.
- "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Information.
3. Roles of the Parties
With respect to Brand Data, the Brand is the Controller / Business and Longboard is the Processor. Longboard processes Brand Data only on the Brand's documented instructions, including as set out in the Agreement, this DPA, and the Brand's use and configuration of the Services.
For clarity, Longboard is an independent Controller (not a Processor) with respect to the limited data described as "controller" data in the Longboard Privacy Policy — account, billing, authentication, marketing, and security/operational telemetry. That processing is governed by the Privacy Policy, not this DPA.
4. Scope, Nature, and Purpose of Processing
The subject matter, duration, nature and purpose of the processing, and the categories of Personal Information and data subjects are described in Annex A. Longboard will process Brand Data only:
(a) to provide, secure, and support the Services under the Agreement;
(b) on the Brand's documented instructions; and
(c) as required by applicable law, in which case Longboard will inform the Brand of that legal requirement before processing unless the law prohibits it.
Longboard will promptly inform the Brand if, in its opinion, an instruction infringes Applicable Privacy Law.
5. Longboard's Obligations
Longboard will:
1. Process only on instructions as described in Section 4;
2. Confidentiality — ensure that personnel authorized to process Brand Data are bound by confidentiality obligations;
3. Security — implement and maintain the technical and organizational measures described in Annex B;
4. Assist the Brand — taking into account the nature of the processing, provide reasonable assistance to enable the Brand to (i) respond to requests from individuals exercising their privacy rights (Section 8), and (ii) meet its obligations regarding security, breach notification, and, where applicable, data protection assessments;
5. Breach notification — notify the Brand of a Security Incident as described in Section 9;
6. Deletion or return — delete or return Brand Data as described in Section 10; and
7. Compliance information — make available to the Brand information reasonably necessary to demonstrate compliance with this DPA, as described in Section 11.
6. Subprocessors
The Brand provides general authorization for Longboard to engage Subprocessors to process Brand Data. Longboard's current Subprocessors are listed at https://longboard.surf/legal/subprocessors.
Longboard will: (a) impose data-protection obligations on each Subprocessor that are substantially equivalent to those in this DPA; (b) remain responsible for each Subprocessor's performance of its obligations; and (c) provide the Brand with a mechanism to obtain notice of the addition or replacement of a Subprocessor and a reasonable opportunity to object on reasonable data-protection grounds.
7. Security
Longboard will maintain the technical and organizational measures described in Annex B, designed to protect Brand Data against a Security Incident, appropriate to the nature of the data and the risk. The Brand is responsible for its own use and configuration of the Services, including access management for its authorized users.
8. Data Subject Requests
Taking into account the nature of the processing, Longboard will provide reasonable assistance to enable the Brand to respond to requests from individuals to exercise their rights under Applicable Privacy Law (access, correction, deletion, portability, and opt-out, as applicable). If Longboard receives such a request directly from an individual with respect to Brand Data, it will, unless legally required to act, refer the individual to the relevant Brand or forward the request to the Brand.
9. Security Incident Notification
Longboard will notify the Brand without undue delay after becoming aware of a Security Incident affecting Brand Data, and will provide information reasonably available to it to help the Brand meet its own notification obligations. Longboard's notification is not an acknowledgment of fault or liability.
10. Return and Deletion of Brand Data
Upon termination or expiry of the Agreement, Longboard will, at the Brand's election, return and/or delete Brand Data within thirty (30) days, except to the extent Longboard is required by law to retain it, or retains it in routine encrypted backups that age out on the ordinary backup cycle. Longboard operates a Brand-offboarding process that, at the end of a 30-day wind-down window, deletes the Brand's Brand Data across its systems (database records, stored files and their underlying storage objects, and any transient secrets) and generates a durable proof-of-deletion record. Longboard's transient handling and deletion of taxpayer identification numbers and bank account numbers is described in the Privacy Policy (§§3.6–3.7).
11. Audits and Compliance
Longboard will make available to the Brand information reasonably necessary to demonstrate compliance with this DPA.
12. CCPA / U.S. State Service-Provider Terms
To the extent Longboard acts as a "service provider," "processor," or "contractor" under Applicable Privacy Law, Longboard:
(a) will process Brand Data only for the business purposes specified in the Agreement and this DPA, and will not retain, use, or disclose it for any other purpose, or outside the direct business relationship, except as permitted by Applicable Privacy Law;
(b) will not "sell" or "share" Brand Data (as those terms are defined under the CCPA);
(c) will not combine Brand Data with personal information from other sources except as permitted by Applicable Privacy Law;
(d) certifies that it understands and will comply with the restrictions in this Section; and
(e) will notify the Brand if it determines it can no longer meet its obligations under Applicable Privacy Law.
13. International Transfers
Longboard processes and stores Brand Data only in the United States and does not transfer it to, or access it from, any jurisdiction outside the United States.
14. Liability; Order of Precedence
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. In the event of a conflict, this DPA prevails over the Agreement with respect to data protection, and the operative terms prevail over the Annexes.
Annex A — Details of Processing
- Subject matter: provision of the Longboard in-store sampling and brand-service provider management Services.
- Duration: the term of the Agreement, plus the deletion/return period in Section 10.
- Nature and purpose: hosting, processing, and displaying Brand Data to schedule and staff sampling programs, capture activation results, facilitate payments, and generate reporting, as configured by the Brand.
- Categories of data subjects: the Brand's personnel and authorized users; service providers and field representatives engaged in the Brand's programs; and, where the Brand's program captures it, event participants and consumers.
- Categories of Personal Information: identifiers and contact details; profile and availability information; agreement and e-signature records and signer metadata; activation, sampling, and event work product; precise geolocation captured at check-in/check-out; payment-related metadata; and — on a transient basis — taxpayer identification numbers and bank account (ACH) numbers where a Brand uses a connected accounting system. Longboard does not process biometric information, and does not conduct background checks or process government-ID images (see Privacy Policy §3.5).
- Special/sensitive categories: Social Security / taxpayer identification numbers and bank account numbers (transient — see Privacy Policy §§3.6–3.7), precise geolocation, and account log-in credentials.
Annex B — Technical and Organizational Security Measures
- Encryption of data in transit (TLS) and at rest (platform-managed);
- Role-based, least-privilege access controls, and Brand isolation enforced at the database layer by row-level security in a fail-closed configuration (the production application refuses to start unless database-enforced Brand isolation is active);
- Managed-identity authentication for core cloud services (database, secrets vault, blob storage), with third-party integration credentials held in a managed secrets vault;
- Isolation of taxpayer identification numbers and bank account numbers in a dedicated secrets vault, separate from the application database;
- Multi-factor authentication required and enforced for administrative and other privileged accounts (enrollment enforced at sign-in), with step-up re-authentication before sensitive or destructive operations;
- Centralized log collection and append-only audit trails;
- Regular encrypted backups with restore verification;
- Vulnerability management and automated dependency scanning in the build pipeline; and
- Contractual security obligations imposed on Subprocessors.
Annex C — Subprocessors
The current list of Subprocessors is maintained at https://longboard.surf/legal/subprocessors and is incorporated into this DPA by reference.