This DPA applies automatically to paid and trial use of the Service where Camper processes Customer Personal Data as a processor (or “service provider” / “contractor” under applicable U.S. state privacy laws), and may be incorporated by reference into an Order or the Terms of Service. If the parties sign a separate DPA, that signed document controls to the extent of conflict. Capitalized terms not defined here have the meanings in the Terms of Service or applicable data-protection law.
1. Parties and hierarchy
“Camper” (processor) means the operator of the Service at https://getcamper.io and https://app.getcamper.io. Contact for privacy and DPA notices: hello@getcamper.io (subject: “DPA”).
“Customer” (controller) means the legal entity that has entered into an agreement with Camper for the Service and that determines the purposes and means of processing Customer Personal Data (or that instructs Camper on behalf of such controller).
Order of precedence for data-processing subject matter: (1) this DPA (including Annexes); (2) Standard Contractual Clauses or other transfer tool attached or incorporated; (3) the Terms of Service / Order; (4) the Privacy Policy (for transparency only, not to expand processing beyond this DPA).
2. Definitions
- “Applicable Data Protection Law” means all privacy and data-protection laws applicable to the processing of Customer Personal Data under this DPA, including where applicable the EU GDPR, UK GDPR, Swiss FADP, and U.S. state privacy laws (e.g. CCPA/CPRA).
- “Customer Personal Data” means personal data that Camper processes on behalf of Customer in providing the Service, including workforce directory attributes pushed to Camper (e.g. via SCIM), org placement and role attributes, membership and resource-control metadata, and audit events relating to those data subjects—excluding Camper Account Data.
- “Camper Account Data” means personal data Camper processes as an independent controller, including Customer operators’ account credentials and contact details, billing contacts, marketing leads submitted outside a tenant, and Camper’s own security and product telemetry that is not processed solely on Customer’s documented instructions.
- “Subprocessor” means a third party engaged by Camper to process Customer Personal Data in connection with the Service.
- “Security Incident” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data transmitted, stored, or otherwise processed by Camper.
- “Service” has the meaning in the Terms of Service: Camper’s multi-tenant control plane for aligning org-linked SaaS resources with Customer’s directory and policies.
- Terms such as “controller,” “processor,” “process,” “personal data,” “data subject,” and “supervisory authority” have the meanings given in Applicable Data Protection Law (and analogous terms under U.S. law, including “business,” “service provider,” and “consumer”).
3. Scope and roles
This DPA applies only to Camper’s processing of Customer Personal Data as a processor (or service provider/contractor). Camper Account Data is governed by the Privacy Policy, not by Customer’s controller instructions under this DPA.
Customer is the controller of Customer Personal Data (or a processor itself that appoints Camper as a sub-processor). Customer is solely responsible for: (a) the lawfulness of processing and of instructions to Camper; (b) providing notices and obtaining consents where required; (c) ensuring an appropriate lawful basis for SCIM and connector-driven processing of workforce data; and (d) not instructing Camper to process data in violation of Applicable Data Protection Law.
Details of processing (subject matter, duration, nature, purpose, types of data, and categories of data subjects) are set out in Annex I.
4. Processing instructions
Camper will:
- Process Customer Personal Data only on documented instructions from Customer, including as configured by Customer in the Service (directory mappings, org policies, resource links, pins, connector authorizations, operator actions, and API/SCIM submissions), unless required to do otherwise by applicable law (in which case Camper will notify Customer before processing, unless the law prohibits notice).
- Not process Customer Personal Data for Camper’s own purposes, for third-party advertising, or for “selling” or “sharing” personal information as those terms are defined under the CCPA/CPRA, except as permitted for service providers or as Customer expressly instructs.
- Immediately inform Customer if, in Camper’s opinion, an instruction infringes Applicable Data Protection Law (without obligation to provide legal advice).
Customer’s instructions are documented in this DPA, the Agreement, and Customer’s use of the Service. Additional written instructions require Camper’s agreement if they require material new product functionality or unreasonable cost.
5. Confidentiality of personnel
Camper ensures that persons authorized to process Customer Personal Data are bound by confidentiality obligations (contractual or statutory) and receive appropriate training regarding data protection. Access is limited on a need-to-know basis, including time-boxed support access when Customer requests assistance or when needed to maintain security or availability of the Service.
6. Security
Taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing, as well as risk to data subjects, Camper implements appropriate technical and organizational measures to protect Customer Personal Data, as described in Annex II and summarized on the Trust Center.
Customer is responsible for configuring the Service securely (including IdP, SSO, operator roles, dry-run approvals, and third-party connector scopes) and for securing systems under Customer’s control.
Camper may update Annex II measures provided the overall security posture is not materially diminished.
7. Subprocessors
Customer authorizes Camper to engage Subprocessors to process Customer Personal Data. Current Subprocessors are listed in Annex III and on the Trust Center.
Camper will impose data-protection obligations on Subprocessors that are substantially no less protective than those in this DPA, to the extent applicable to the subcontracted services. Camper remains responsible to Customer for Subprocessor performance of those obligations.
Notice of changes. Camper will provide notice of intended addition or replacement of a Subprocessor by updating Annex III / the Trust Center and, where Customer has subscribed to notices or is on a paid plan with an admin email on file, by email at least 15 days before the new Subprocessor processes Customer Personal Data (except for emergency replacements needed to maintain security or availability, in which case notice will follow as soon as practicable).
Objection. Customer may object in writing on reasonable data-protection grounds within 15 days of notice. The parties will discuss in good faith. If no resolution is reached, Customer may terminate the affected Service as its sole remedy, and Camper will refund prepaid unused fees for the terminated portion on a pro-rata basis. Continued use after the notice period without objection constitutes acceptance of the Subprocessor.
Third-party products Customer chooses to connect (e.g. Google Workspace, Slack, Jira, GitHub, Microsoft 365, Customer’s IdP) are not Camper Subprocessors; they are independent controllers or processors engaged by Customer. Camper transmits data to those systems only as instructed by Customer’s configuration.
8. Assistance with data subject rights and compliance
Taking into account the nature of processing, Camper will assist Customer by appropriate technical and organizational measures, insofar as possible, for the fulfilment of Customer’s obligations to respond to requests from data subjects (access, correction, deletion, restriction, portability, objection, and similar rights under Applicable Data Protection Law).
If Camper receives a request directly from a data subject relating to Customer Personal Data, Camper will, to the extent legally permitted, direct the individual to Customer and/or notify Customer, and will not respond substantively except on Customer’s documented instructions or as required by law.
Camper will assist Customer, upon reasonable request and taking into account the nature of processing and information available to Camper, with data protection impact assessments and prior consultations with supervisory authorities, at Customer’s expense if the assistance is material and beyond Camper’s ordinary support.
9. Security Incidents
Camper will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. Notice will include, to the extent known: nature of the incident, categories and approximate number of data subjects and records concerned, likely consequences, and measures taken or proposed. Camper may provide information in phases as investigation proceeds.
Camper will take reasonable steps to mitigate and remediate the Security Incident and will reasonably cooperate with Customer’s investigation and notification obligations. Notification is not an admission of fault or liability.
Customer is responsible for determining whether to notify regulators or data subjects, unless applicable law requires Camper to notify them directly.
10. Return and deletion
Upon termination or expiry of the Service (or earlier upon Customer’s written request where feasible), Camper will, at Customer’s choice, delete or return Customer Personal Data, and delete existing copies, except to the extent retention is required by applicable law or reasonably necessary for backup rotation, dispute resolution, or security logging—in which case Camper will continue to protect the data and isolate it from active processing until deletion.
Customer may export available Customer Data through product features during the subscription term and for a commercially reasonable period after termination upon written request. Credentials Customer configured should be rotated and connections revoked by Customer upon offboarding.
11. Audit and information
Camper will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including relevant summaries of security practices and, when available, third-party audit reports or certifications (Camper does not claim SOC 2 or ISO 27001 as of the effective date).
Customer may request an audit of Camper’s processing of Customer Personal Data no more than once per twelve (12) months (unless required by a supervisory authority or following a Security Incident), on at least thirty (30) days’ written notice, during business hours, without unreasonably disrupting Camper’s business, and subject to confidentiality. Audits may be conducted by Customer or an independent third-party auditor bound by confidentiality and not a competitor of Camper. Remote questionnaire and documentation review will be preferred where sufficient. Customer bears its own audit costs and any reasonable costs Camper incurs for on-site or extensive audits.
12. International transfers
Customer acknowledges that Camper primarily processes and hosts Customer Personal Data in the United States (Google Cloud, us-central1, unless otherwise stated). Customer instructs Camper to transfer Customer Personal Data to the United States and to other countries where Subprocessors operate as needed to provide the Service.
Where Customer Personal Data is transferred from the EEA, UK, or Switzerland to a country not recognized as providing an adequate level of protection, the parties agree that the transfer mechanism in Annex IV applies (EU Standard Contractual Clauses Module Two, and UK/Swiss addenda as applicable), completed as set out therein. If a transfer tool is invalidated or requires update, the parties will cooperate in good faith to implement a valid alternative.
13. U.S. state privacy laws (including CCPA/CPRA)
To the extent Camper processes “personal information” of “consumers” subject to U.S. state privacy laws on Customer’s behalf:
- Camper acts as a “service provider” or “contractor” (as applicable) and will not retain, use, or disclose personal information for any purpose other than the business purposes specified in the Agreement and this DPA, or as otherwise permitted for service providers under those laws.
- Camper will not sell or share personal information, combine it with personal information from other sources except as permitted to provide the Service, or use it outside the direct business relationship with Customer.
- Camper will comply with applicable obligations under those laws and provide the same level of privacy protection as required of Customer with respect to the personal information Camper processes.
- Camper will notify Customer if it can no longer meet its obligations under this Section, and Customer may take reasonable and appropriate steps to stop and remediate unauthorized use.
- Camper certifies that it understands and will comply with these restrictions.
14. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service (or other governing commercial agreement), except to the extent Applicable Data Protection Law prohibits such limitation with respect to a party’s obligations to data subjects. Nothing in this DPA expands Camper’s aggregate liability beyond those commercial terms unless mandatory law requires otherwise.
15. Term
This DPA takes effect on the later of the effective date above and the date Customer first uses the Service to process Customer Personal Data, and continues until Camper ceases processing Customer Personal Data.
16. General
- Governing law. Except where the Standard Contractual Clauses require otherwise, this DPA is governed by the same law as the Terms of Service (Delaware, USA, unless an Order states otherwise).
- Severability; changes. If a provision is invalid, the remainder remains in effect. Camper may update this DPA for legal or operational reasons; material adverse changes will be noticed as with Terms updates. Continued use after the effective date of an update constitutes acceptance unless Customer terminates as permitted under the Agreement.
- Conflict with SCCs. If there is a conflict between this DPA body and the Standard Contractual Clauses, the SCCs prevail for the relevant transfer.
- Counterparts / acceptance. Electronic acceptance, Order incorporation by reference, or continued use of the Service after notice of this DPA constitutes execution.
Annex I — Details of processing
A. List of parties
- Controller: Customer (as identified in the account, Order, or signup records).
- Processor: Camper; contact hello@getcamper.io; security security@getcamper.io.
B. Description of processing
- Subject matter: Provision of the Camper Service—directory ingest, org modeling, membership/resource desired-state computation, observation of connected systems, provisioning tasks, and related audit and operator features.
- Duration: Term of the Agreement plus deletion/return period under Section 10.
- Nature and purpose: Hosting, storage, retrieval, structuring, combination, transmission to Customer-authorized systems, logging, support, security, and metering necessary to deliver the Service per Customer’s configuration and instructions.
- Types of Customer Personal Data: Work email; display name; IdP external identifiers; directory profile attributes Customer pushes (e.g. division, department, team); group memberships used for placement; employment/status flags as provided; role attributes used for operator elevation; membership in linked resources (as observed or desired); audit metadata (actor, action, timestamps); and technical identifiers necessary for processing. Credentials Customer supplies for integrations may be associated with administrators but are secrets rather than ordinary directory attributes.
- Special categories: The Service is not designed for special-category data (e.g. health, biometric templates for identification, precise religious beliefs). Customer will not instruct Camper to process such data unless the parties agree in writing and additional safeguards are implemented.
- Categories of data subjects: Customer’s employees, contractors, and other workforce members whose data is supplied via the IdP/SCIM or appears in membership of linked resources; Customer’s operators and invitees only insofar as their data is processed as Customer Personal Data within the tenant (account auth may also be Camper Account Data).
- Out of scope content: File contents, message bodies, and calendar event contents inside managed resources are not product storage targets.
C. Competent supervisory authority (for SCC purposes): as determined under the SCCs (typically the authority of the Customer’s EEA establishment or main establishment; UK ICO for UK transfers).
Annex II — Technical and organizational measures
Camper maintains measures that include, as of the effective date:
- Encryption at rest for secrets: OAuth tokens, API credentials, and SCIM bearer tokens sealed with per-tenant data keys (AES-256-GCM) and additional authenticated data binding ciphertext to tenant and connection context; master-key wrapping with rotation capability.
- Encryption in transit: TLS for public HTTPS endpoints.
- Tenant isolation: Domain queries scoped through explicit tenant context in the data access layer.
- Secret handling: Credentials excluded from asynchronous job payloads and designed not to appear in application logs; workers unseal at execution time.
- Access control: Authenticated operators; role-based authorization; session management with revocation; optional enterprise SSO (SAML/OIDC), passkeys, email OTP, and TOTP on password paths.
- Least privilege operations: Support access intended to be time-boxed and auditable; staff eligibility controlled.
- Integrity and change control: Dry-run / plan approval flows for resource-link go-live where product requires; provisioning task model with retries and dead-letter handling; audit/event trail of material actions.
- Availability and resilience: Hosted on managed cloud infrastructure (GCP) with managed database and cache services; operational monitoring appropriate to service stage.
- Vulnerability handling: Security contact at security@getcamper.io; coordinated disclosure preferred over unsolicited production scanning.
- Subprocessor diligence: Use of reputable infrastructure and payment/email providers under contractual terms.
Customer acknowledges Camper is in private preview and does not currently hold SOC 2, ISO 27001, or similar attestations. Measures are implemented in product and operations; independent certification may follow.
Annex III — Authorized Subprocessors
The following Subprocessors may process Customer Personal Data in connection with the Service. Locations indicate primary processing region as of the effective date.
| Subprocessor | Purpose | Location |
|---|---|---|
| Google Cloud Platform (Google LLC) | Application hosting, managed Postgres, Redis, secret storage, and related cloud infrastructure | us-central1 (United States) |
| Stripe, Inc. | Payment processing and subscription billing (customer, invoice, and payment metadata; card data handled by Stripe) | United States |
| Resend, Inc. | Transactional email delivery (e.g. sign-in codes, password reset, invitations) | United States |
Infrastructure build tooling (e.g. GitHub for source and CI) does not host production tenant databases; it is listed on the Trust Center for transparency and is not a runtime Subprocessor of Customer Personal Data unless Customer Personal Data is intentionally introduced into those systems (which is not the product path).
Live list: https://getcamper.io/trust/#subprocessors
Annex IV — International transfer mechanisms
A. EU Standard Contractual Clauses
Where required for restricted transfers from the EEA, the parties enter into the Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914 (“SCCs”), Module Two (controller to processor), which are incorporated by reference. For purposes of the SCCs:
- Clause 7 (Docking): optional docking clause applies.
- Clause 9 (Subprocessors): Option 2 (general written authorization) applies, with the notice period stated in Section 7 of this DPA (15 days).
- Clause 11 (Redress): optional language is not used unless required.
- Clause 17 (Governing law): law of Ireland, unless Customer’s establishment requires otherwise as permitted by the SCCs.
- Clause 18 (Forum): courts of Ireland, unless the SCCs require otherwise.
- Annex I–III of the SCCs: completed by Annexes I–III of this DPA.
B. United Kingdom
For restricted transfers subject to UK GDPR, the SCCs are read with the UK Information Commissioner’s International Data Transfer Addendum (or successor), completed with the same operational details as this DPA. Alternative: UK International Data Transfer Agreement where the parties elect it in writing.
C. Switzerland
For transfers subject to Swiss data-protection law, the SCCs apply with adaptations required under Swiss FDPIC guidance (including references to Swiss law and authorities where mandatory).
D. Execution
By accepting the Terms or an Order that incorporates this DPA, or by using the Service to submit Customer Personal Data, Customer and Camper are deemed to have executed the SCCs (and UK/Swiss addenda as applicable) as of the date of first restricted transfer. Upon request, Camper will provide a countersigned PDF copy for Customer’s records.
17. Contact
DPA and privacy: hello@getcamper.io
Security incidents and vulnerabilities: security@getcamper.io
Related: Terms of Service · Privacy Policy · Trust Center