PricingDocs
LoginStart building
← All legal documents

Data Processing Addendum

Version 2026-09-07 · Effective 2026-09-07

Volcano Data Processing Addendum

Last Updated:

This Data Processing Addendum (“Addendum”) forms part of and is subject to the Volcano Customer Agreement available at https://volcano.dev/legal/customer-agreement between Customer and Volcano Services, LLC covering Customer’s use of the Products (“Agreement”) and governs in connection with the Processing of Personal Data with respect to the applicable Product subscribed to by Customer. “Volcano,” and “We,” refers to Volcano Services, LLC and “Customer,” “You” and “Your” refers to the person, company or other legal entity entering into the Agreement with Volcano. Any capitalized term not defined in this Addendum will have the meaning provided in the Agreement.

We may update this Addendum from time to time. The date on which the Addendum was last updated will be reflected on the “Last Updated” date at the top of this Addendum. Any revised Addendum will become effective on such date. Your continued use of the Products or Your Account constitutes acceptance of the revised terms. If You do not agree to the revised terms, You must stop using the Products and Your Account.

1. Definitions

“Account Information” has the meaning given in the Agreement solely to the extent such Account Information contains Personal Data.

“Applicable Data Protection Law(s)” means all applicable state, federal, and foreign laws, rules, and regulations applicable to Processing of Personal Data under the Agreement, as amended from time to time.

“CCPA” means the California Consumer Privacy Act, as amended by the California Privacy Rights Act, as amended from time to time.

“Controller”, “Data Subject”, “Processor”, “Processing”, or “Process” shall have the same meanings given to them in Article 4 (Definitions) of the General Data Protection Regulation, as amended from time to time (“GDPR”).

“Personal Data” means any personally identifiable information relating to a natural person that is submitted to the Products by Customer. Specific categories of Personal Data are further described in the attached Schedule 1 (Details of Processing).

“Personal Data Breach” means a confirmed or reasonably suspected accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data attributable to Volcano.

“Sub-Processor” means any third-party Processor engaged by Volcano to Process Personal Data in order to provide the Products to Customer.

“Third-Party Request” means any request, correspondence, inquiry, or complaint from a Data Subject, regulatory authority, or third-party.

2. Relationship and Purpose

2.1 Roles of the Parties. Customer and Volcano agree that with regard to the Processing of Personal Data, Customer may act either as a Controller or Processor and Volcano is a Processor. With respect to the Processing of Usage Data and Account Information, Volcano is a Controller and the Privacy Policy will apply, available at https://volcano.dev/legal/privacy.

2.2 Purpose Limitation. Volcano will Process Personal Data in order to provide the Products. Schedule 1 (Details of Processing) of this Addendum further specifies the nature and purpose of the Processing, the Processing activities, the duration of the Processing, the types of Personal Data, and categories of Data Subjects.

2.3 Compliance. Customer is responsible for ensuring that (i) it has complied, and will continue to comply, with Applicable Data Protection Law in its use of the Products; and (ii) it has, and will continue to have, the right to transfer, or provide access to, Personal Data to Volcano for Processing in accordance with the terms of the Agreement and this Addendum.

3. Processing Personal Data

3.1 Customer Instructions. Customer appoints Volcano as a Processor to Process Personal Data on behalf of, and in accordance with: (i) Customer’s instructions, as set forth in the Agreement, this Addendum, and as otherwise necessary for Volcano to provide the Products to Customer, and which includes investigating security incidents and detecting and preventing network exploits or abuse; (ii) as necessary to comply with Applicable Data Protection Law; and (iii) as otherwise agreed in writing between Customer and Volcano (collectively, the “Permitted Purposes”). Volcano will process such Personal Data in accordance with Customer’s instructions as set forth in this Sub-Section 3.1 (Customer Instructions).

3.2 Lawfulness of Instructions. Customer will ensure that its instructions comply with Applicable Data Protection Law. Customer acknowledges that Volcano is neither responsible for determining which laws or regulations are applicable to Customer’s business nor whether Volcano’s provision of the Products meets or will meet the requirements of such laws or regulations. Customer will ensure that Volcano’s Processing of Personal Data, when done in accordance with Customer’s instructions, will not cause Volcano to violate any Applicable Data Protection Law. Volcano will inform Customer if it becomes aware, or reasonably believes, that Customer’s instructions violate any Applicable Data Protection Law.

3.3 Customer Obligations. Customer represents and warrants that (i) it will comply with Applicable Data Protection Laws; (ii) it has obtained, or will obtain, and will maintain all necessary consents, rights, lawful bases, and authorizations necessary for Volcano to perform its obligations herein; and (iii) it has provided its end users or Data Subjects who Personal Data will be Processed with all privacy notices applicable and necessary in connection with any Processing.

4. Third-Party Requests and Confidentiality

4.1 Responding to Third-Party Requests. If any Third-Party Request is made directly to Volcano in connection with Volcano’s Processing of Personal Data, Volcano will promptly inform Customer and provide details of the same, to the extent legally permitted. Volcano will not respond to any Third-Party Request without Customer’s prior consent, except as legally required to do so or to confirm that such Third-Party Request relates to Customer.

4.2 Confidentiality Obligations of Volcano Personnel. Volcano will ensure that any person it authorizes to Process Personal Data has agreed to protect Personal Data in a manner substantially similar to Volcano's confidentiality obligations in the Agreement.

5. Sub-Processors

5.1 Authorization for Sub-Processing. Customer provides a general authorization to Volcano to engage the third-party Sub-Processors listed at the following link https://volcano.dev/sub-processor-list, which may be updated from time to time, (“Sub-Processor List”) to Process Personal Data in connection with the Products for the Permitted Purposes. Volcano agrees: (i) to impose contractual data protection obligations, including appropriate technical and organizational measures to protect Personal Data, on any Sub-Processor it appoints that require such Sub-Processor to protect Personal Data to the standard required by Applicable Data Protection Law and this Addendum; and (ii) it will remain liable for any breach of this Addendum that is caused by an act, error, or omission of its Sub-Processors.

5.2 Notification of Sub-Processor Changes. Volcano will provide notice to the Customer of any changes or additions to the Sub-Processor List by posting updated Sub-Processor List online or via Customer’s email. In the event the Customer rejects the Sub-Processor, the Parties will work together in good faith to reach a resolution, which may include Customer no longer having access to the Products.

6. Data Subject Rights. Volcano will provide reasonable assistance to Customer in complying with Customer's data protection obligations with respect to Data Subject rights under Applicable Data Protection Law.

7. Impact Assessments and Consultations. Volcano will provide reasonable cooperation to Customer in connection with any data protection impact assessment or consultations with regulatory authorities that may be required in accordance with Applicable Data Protection Law, at Customer’s expense if the reasonable consultations with regulatory authorities will require Volcano to assign significant resources to that effort.

8. Access to and Deletion of Personal Data. Customer may access its Personal Data during the Subscription Term. Volcano will, in accordance with Section 3 (Retention Period) of Schedule 1 (Details of Processing) of this Addendum, delete any Personal Data under its custody or control in accordance with the Agreement. However, Volcano may retain Personal Data, or any portion of it, if required by applicable law or regulation, including Applicable Data Protection Law, provided such Personal Data remains protected in accordance with the terms of the Agreement, this Addendum, and Applicable Data Protection Law.

9. Security and Audit

9.1 Volcano Security Measures. Volcano will maintain the technical and organizational security measures as set forth in the Agreement and Schedule 2 (Technical and Organizational Security Measures) of this Addendum (“Security Measures”). Customer acknowledges that Volcano’s Security Measures are subject to technical progress and development and that Volcano may update or modify its Security Measures from time to time, provided that such updates and modifications do not materially degrade or diminish the overall security of the Products or Personal Data.

9.2 Customer Security Obligations. Customer acknowledges the Products include certain features and functionalities that Customer may elect to use which may impact the security of Personal Data processed by the Products, such as, but not limited to, use of Third-Party Technologies. Customer is responsible for properly configuring the Products and using features and functionalities made available by Volcano to maintain appropriate security in light of the nature of Personal Data processed through the Products.

9.3 Personal Data Breach Notification. Volcano will provide notification of a Personal Data Breach in the following manner:

(i) Volcano will, to the extent permitted by Applicable Data Protection Law, notify Customer without undue delay, but in no event later than seventy-two (72) hours after Volcano’s confirmation of a Personal Data Breach affecting Customer’s Personal Data;

(ii) Volcano will notify Customer of any Personal Data Breach via email to the email address(es) designated by Customer in Customer’s Account; and

(iii) Volcano will provide reasonable assistance to Customer in the event that Customer is required under Applicable Data Protection Law to notify a regulatory authority or any Data Subjects impacted by a Personal Data Breach.

9.4 Audit. Upon Customer’s written request and no more than once per year, Volcano will provide written responses on a confidential basis to Customer’s reasonable requests outlining how Volcano complies with this Addendum.

10. Cross-Border Transfers and the CCPA

10.1 Cross-Border Data Transfer Mechanisms. Customer authorizes Volcano and its Sub- Processors to transfer Customer Personal Data across international borders, including from the European Economic Area, Switzerland, and/or the United Kingdom to the United States.

10.2. Jurisdiction Specific Terms. To the extent Volcano processes Personal Data originating from and protected by Applicable Data Protection Law in one of following jurisdictions: Australia, Canada, European Economic Area (“EEA”), Mexico, Singapore, Switzerland, United Kingdom (“UK”), or United States of America, the terms with respect to the applicable jurisdiction(s) apply in addition to the terms of this Addendum.

10.3 EEA, Swiss, and UK Standard. If Customer Personal Data originating in the EEA, Switzerland, and/or the UK is transferred by Customer to Volcano in a country that has not been found to provide an adequate level of protection under Applicable Data Protection Laws, the parties agree that the transfer shall be governed by Module Two’s obligations in the Annex to the Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (“Standard Contractual Clauses”), the terms of which are incorporated herein by reference.

10.4 California Residents. This Section will apply to the extent the CCPA applies to the parties performance of the Agreement and Volcano is a service provider as defined in the CCPA. The terms “service provider”, “sell”, and “personal information”, as used in this Section 10.4, will have the meaning provided in the CCPA.

10.4.1 Customer is responsible for ensuring that it has complied, and will continue to comply, with the requirements of the CCPA in its use of the Products and its own Processing of personal information. Upon written notice to Volcano, Customer will have the right to take reasonable and appropriate steps in accordance with this Addendum to stop and remediate unauthorized use of personal information.

10.4.2 As a service provider:

(i) Volcano will Process personal information only for the Permitted Purpose;

(ii) Volcano will not sell or share personal information (a) for any purpose other than the Permitted Purpose or as otherwise permitted by the CCPA; or (b) outside of the direct business relationship between Customer and Volcano;

(iii) Volcano will (a) comply with obligations applicable to it as a service provider under the CCPA and (b) protect personal information with the at least the minimum level of privacy protection as is required by the CCPA;

(v) Volcano will notify Customer if it makes a determination that it can no longer meet its obligations as a service provider under the CCPA;

(vi) Volcano will provide reasonable additional and timely assistance to assist Customer in complying with its obligations with respect to consumer requests as set forth in this Addendum;

(vii) For any Sub-Processor used by Volcano to Process personal information subject to the CCPA, Volcano will ensure that Volcano’s agreement with such Sub-Processor materially complies with the CCPA;

(viii) Volcano will not combine personal information that it receives from, or on behalf of, Customer, with personal information that it receives from, or on behalf of, another person or persons, or collects from its own interaction with the consumer, unless such combination is required to perform any business purpose as permitted by the CCPA, including any regulations thereto, or by regulations adopted by the California Privacy Protection Agency; and

(ix) Volcano certifies that it understands and will comply with its obligations under the CCPA.

10.5 Geofencing. Where Customer directs Volcano to Process Personal Data in a specific geographic region in its Account, Volcano shall ensure that such data is primarily processed in that region unless otherwise required to comply with Customer's additional instructions, as necessary to provide the Products to Customer, or as required by applicable Data Protections Laws. Customer agrees Volcano shall not be responsible for Processing in a specific geographic region in accordance with Customer’s instructions. Customer acknowledges that, as of the Effective Date, Volcano primary processing facilities are in the United States. Notwithstanding the foregoing, Customer acknowledges that Volcano may in connection with the provision of Products, need to transfer and process Personal Data to and in the United States and anywhere else in the world where Volcano or its Sub-Processors maintain data processing operations. Volcano will ensure such transfers are made in compliance with the requirements of Applicable Data Protection Laws and this Addendum.

11. Miscellaneous

11.1. Conflict. In the event of any conflict or inconsistency among the following documents, the order of precedence will be: (1) the applicable terms set forth in Section 10 (Cross-Border Transfers and the CCPA) of this Addendum; (2) the terms of this Addendum outside of Section 10 (Cross-Border Transfers and the CCPA); and (3) the Agreement. Any claims brought in connection with this Addendum will be subject to the terms and conditions, including, without limitation, the exclusions and limitations of liability set forth in the Agreement.

11.2. Updates. Volcano may update the terms of this Addendum from time to time. Customer’s continued use of the Products constitutes acceptance of the revised terms. If Customer does not agree to the revised terms, Customer must stop using the Products.

11.3. Term. This Addendum becomes effective on the Effective Date of the Agreement and remains effective so long as Volcano processes Customer’s Personal Data.

11.4. Governing Law. This Addendum will be governed by the laws of California (without regard to the conflicts of law provisions of any jurisdiction), and claims arising out of or in connection with this Agreement will be subject to the exclusive jurisdiction of San Francisco, California.

11.5. Illegality. Should any term of this Addendum be declared invalid, void or unenforceable by any court of competent jurisdiction, that provision will be modified, limited or eliminated to the minimum extent necessary to effectuate the original intent and such declaration will have no effect on the remaining terms of this Addendum, which will continue in full force and effect.

Schedule 1

Details of Processing

1. Nature and Purpose of the Processing.

1.1 Personal Data. Volcano will process Personal Data as a Processor to provide the Products in accordance with the Agreement and this Addendum.

1.2 Account Information. Volcano will process Account Information as a Controller in order to (i) manage the relationship with Customer; (ii) carry out Volcano’s core business operations, such as accounting and filing taxes; (iii) detect, prevent, or investigate security incidents, fraud, and other abuse or misuse of the Products; (iv) perform identity verification; and (v) as otherwise permitted under Applicable Data Protection Law or the Agreement, and in accordance with this Addendum and the Agreement.

2. Processing Activities

2.1 Personal Data. The Processing activities may include collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, destruction or other operations.

2.2 Account Information. The Processing activities may include collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, destruction or other operations.

3. Retention Period. The period for which Personal Data will be retained and the criteria used to determine that period is as follows:

3.1 Personal Data. Until the earliest of (i) the deletion date set out in the Agreement, or (ii) the date upon which Processing is no longer necessary for the purposes of either party performing its obligations under the Agreement (to the extent applicable). Notwithstanding the foregoing, Volcano may retain and use deidentified and aggregated Personal Data after termination or expiration of the Agreement or this Addendum.

3.2 Account Information. Volcano will process Account Information as long as required (i) to provide the Products to Customer; (ii) for Volcano’s legitimate business needs; (iii) as permitted and in accordance with Volcano’s Privacy Policy; or (iv) by Applicable Data Protection Law. Account Information will be stored in accordance with Volcano’s Privacy Policy.

4. Categories of Data Subjects

4.1 Personal Data. Natural persons that access or use Customer’s domains, networks, websites, APIs, and applications. Such natural persons may include end users that Customer registers or authenticates through Volcano’s authentication features. The extent of any Personal Data processed is determined by the Customer in its sole discretion.

4.2 Account Information. Customer’s contact and billing information submitted to Customer’s Account.

5. Categories of Personal Data. Volcano Processes the following categories of Personal Data:

  • User Identification and Account Data: Customer name, email, organization/tenant ID, support interaction history, billing account IDs, and project/account configuration data.
  • Device, Browser, and Analytics Data: IP address (and derived location data), user agent, device identifiers, session IDs, analytics events (e.g., page views, clicks, session replay interaction data), and referrer/UTM tracking information.
  • Customer Content and Application Data: Function source code, uploaded storage files, database schema and contents, project environment variables (including any embedded third-party credentials), and custom domain/TLS configurations.
  • Operational, Billing, and Usage Data: Deployment and resource identifiers (ARNs, IDs), usage metrics/counters, Stripe subscription data (customer/payment-method IDs, billing events), and operational logs/traces (including error data and audit logs).
  • Security and Credential Data: Password hashes, platform API tokens, service/anonymous keys, OAuth provider metadata (e.g., tokens, identifiers), and Git-connection credentials.
  • Customer’s End User Data: Emails, profile data, password hashes, session IP/user agent, and OAuth provider data (from Google, GitHub, Microsoft, and Apple providers).
  • AI Information: Customer inputs and AI outputs (excluding data processed specifically by AI Builder, such as Builder prompts, generated content, model-provider processing, Builder files, conversation or debug data, retention, deletion, or subprocessors).

6. Sensitive Data or Special Categories of Data. Customer and its end users should not submit any highly sensitive or special categories of Personal Data to the Products without the express written consent of Volcano.

Schedule 2

Technical and Organizational Security Measures

Where applicable, this Schedule 2 will serve as Annex II to the EU Standard Contractual Clauses.

Volcano’s security measures include: (a) Customer source archives, build artifacts, and uploaded files are encrypted at rest; (b) account passwords and end-user passwords are stored as one-way hashes; (c) end-user OAuth refresh tokens and import-provider credentials are encrypted at rest; and (d) command-line debug logging redacts authorization, token, cookie, secret, and API-key headers and does not log request or response bodies.

Product

HomePricing

Features

Functions & AgentsNext.js FrontendsDatabases & VectorFile StorageAuthenticationRealtime

Resources

Getting startedDocumentation

Legal

Customer AgreementPrivacy PolicyCookie PolicySubprocessorsAll legal documents

Created by Kong to bring production readiness to the AI world