Paradraw
Supabase/The availability commitment is stated 2 times, in 2 different figures
Data Processing Addendum · p111
Part of the agreement

Data Processing Addendum

5,497 words, 185 clausesno date on the pageread 08/10/2026source

·Data Processing Addendum

·Version 1 - August 1, 2026

·This Data Processing Addendum (the "DPA") supplements and forms part of the Supabase Terms of Service available at https://supabase.com/terms, or such other agreement entered into between the Customer and Supabase Pte. Ltd ("Supabase") relevant to Customer's use of the Services (the "Agreement"), and in case of any conflict, supersedes the Agreement in relation to the transfer and processing of Covered Data in connection with the performance of the Services. This DPA is effective as of the Effective Date of the Agreement.

11. Definitions.#

·Capitalized terms used but not defined within this DPA will have the meaning set forth in the Agreement. The terms "controller", "processor", "business" and "service provider", whether capitalized or in the lower-case, have the meanings given to them under the Applicable Data Protection Laws. The following capitalized terms used in this DPA will be defined as follows:

·"Applicable Data Protection Laws" means all applicable laws, rules, regulations, and governmental requirements relating to the privacy, confidentiality, or security of Personal Data, as they may be amended or otherwise updated from time to time, including (without limitation): the GDPR, Swiss Data Protection Laws and the US Data Protection Laws.

·"Biometric Data" means Personal Data resulting from technical processing of physical, physiological or behavioral characteristics such as fingerprints, facial images, iris or voice recognition data, used to identify a natural person.

·"CCPA" means the California Consumer Privacy Act of 2018, Cal. Civ. Code § 1798.100 et seq., as amended, including its implementing regulations and the California Privacy Rights Act of 2020.

·"Covered Data" means: (a) Personal Data that is provided by or on behalf of Customer to Supabase in connection with Customer's use of the Services, as further described in Schedule 3 (Processing Details) of this DPA; (b) contact information and access credentials relating to, and support requests submitted by, Authorized Users; and (c) any other Personal Data that is otherwise collected, generated or Processed by Supabase in connection with the provision of the Services.

·"Customer's Controller" means, where the Customer acts as a processor or service provider (as identified in Schedule 3 (Processing Details)), the controller or business on whose behalf the Customer Processes Covered Data.

·"Data Subject" means a natural person whose Personal Data is Processed.

·"Deidentified Data" means data created using Covered Data that cannot reasonably be linked to such Covered Data, directly or indirectly.

·"GDPR" means Regulation (EU) 2016/679 (the "EU GDPR") or, where applicable, the "UK GDPR", as defined in section 3 of the Data Protection Act 2018.

·"Personal Data" means any data or information that: (a) is linked or reasonably linkable to an identified or identifiable natural person; or (b) is otherwise "personal data," "personal information," "personally identifiable information," or similarly defined data or information under Applicable Data Protection Laws.

·"Processing" means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means. "Process", "Processes" and "Processed" will be interpreted accordingly.

·"Security Incident" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to (including unauthorized internal access to) Covered Data. Security Incidents do not include unsuccessful incidents that are trivial in nature, such as pings and other broadcast service attacks that do not compromise the security of Covered Data.

·"Sensitive Data" means any Personal Data that reveals racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership; genetic data; Biometric Data used to uniquely identify a natural person; data concerning health or a person's sex life or sexual orientation; or data relating to criminal convictions and offenses.

·"Standard Contractual Clauses" or "SCCs" means the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914.

·"Sub-processor" means, with respect to any Processing performed by Supabase as a processor or service provider, an entity appointed by Supabase to Process Covered Data on its behalf.

·"Swiss Data Protection Laws" means the Swiss Federal Act on Data Protection of 19 June 1992 and the Swiss Ordinance to the Swiss Federal Act on Data Protection of 14 June 1993, and any new or revised version of these laws that may enter into force from time to time.

·"US Data Protection Laws" means all applicable federal and state laws, rules, regulations, and governmental requirements relating to data protection, the Processing of Personal Data, privacy and/or data protection in force from time to time in the United States, including (without limitation): the CCPA, the Virginia Consumer Data Protection Act, Code of Virginia Title 59.1 Chapter 52 § 59.1-571 et seq., the Colorado Privacy Act, Colorado Revised Statute Title 6 Article 1 Part 13 § 6-1-1301 et seq., the Utah Consumer Privacy Act, Utah Code § 13-6-101 et seq., and Connecticut Senate Bill 6, An Act Concerning Personal Data Privacy and Online Monitoring (as such law is chaptered and enrolled).

22. Role of the Parties.#

·The Parties acknowledge and agree that Supabase acts as a processor/service provider, and Customer as controller/business under the Agreement and this DPA. To the extent Customer Processes Covered Data on behalf of its own Controller, Supabase acts as a subprocessor.

33. Details of Data Processing.#

3.13.1 Nature, Purpose and Duration.#

·The nature, purpose, and duration of the Processing of Personal Data under the Agreement and this DPA are described in the Agreement and in Schedule 3 (Processing Details) to this DPA.

3.23.2 Instructions.#

·Supabase shall comply with its obligations under Applicable Data Protection Laws. Supabase shall only Process Covered Data on behalf of and under the instructions of Customer and in accordance with Applicable Data Protection Laws. The Agreement and this DPA shall constitute Customer's instructions for the Processing of Covered Data. Customer may issue further written instructions in accordance with this DPA. Supabase will: (a) provide reasonable assistance to Customer to enable Customer to conduct and document any data protection assessments required under Applicable Data Protection Laws; and (b) promptly inform Customer if, in its opinion, an instruction from Customer infringes the Applicable Data Protection Laws.

3.33.3 Supabase Prohibitions.#

·Without limiting the foregoing, Supabase is prohibited from: (a) selling Covered Data or otherwise making Covered Data available to any third party for monetary or other valuable consideration; (b) sharing Covered Data with any third party for cross-context behavioral advertising; (c) retaining, using, or disclosing Covered Data for any purpose other than for the business purposes specified in the Agreement or as otherwise permitted by Applicable Data Protection Laws; (d) retaining, using, or disclosing Covered Data outside of the direct business relationship between the Parties; and (e) except as otherwise permitted by Applicable Data Protection Laws, combining Covered Data with Personal Data that Supabase receives from or on behalf of another person or persons, or collects from its own interaction with the Data Subject.

44. Compliance.#

·Customer shall comply with its obligations under Applicable Data Protection Laws and shall: (a) provide (or ensure that the Customer's Controller provides) such information to Data Subjects regarding the Processing of their Covered Data in connection with Customer's use of the Services as required under Applicable Data Protection Laws; (b) to the extent required for the lawful Processing of Covered Data under Applicable Data Protection Laws, obtain (or ensure that the Customer's Controller obtains) valid consents from Data Subjects for such Processing in the form required under Applicable Data Protection Laws; (c) implement appropriate technical and organizational measures to give effect to Data Subject rights under Applicable Data Protection Laws, and shall comply with requests from Data Subjects (or, where applicable, Customer's Controller) to exercise their rights under Applicable Data Protection Laws within the timeframe and subject to any exemptions prescribed in the Applicable Data Protection Laws; and (d) ensure it has provided notice and obtained all necessary explicit consents from Data Subjects for the collection and Processing of any Sensitive Data by the Processor on Controller's behalf. Customer certifies that it is in compliance with all laws applicable to the collection, use, and storage of Sensitive Data.

55. Supabase Personnel.#

·Supabase shall: (a) limit access to Covered Data to personnel who have a business need to have access to such Covered Data; and (b) ensure that such personnel are subject to obligations at least as protective of the Covered Data as the terms of this DPA and the Agreement, including duties of confidentiality with respect to any Covered Data to which they have access.

66. Sub-processors.#

6.16.1 Location.#

·Supabase may Process Covered Data anywhere that Supabase or its Sub-processors maintain facilities, subject to the remainder of this clause 6, its obligations with respect to data transfers as required by Applicable Data Protection Laws and clause 12 of this DPA. Where Customer directs Supabase to Process Covered Data in a specific geographical region, Supabase shall ensure that such Covered Data is stored and primarily Processed in that region unless otherwise required to comply with Customer's additional instructions, applicable law or as necessary to provide Services requested by Customer. Customer shall not direct Supabase to Process Covered Data in a specific region to the extent such instruction violates applicable law, and shall indemnify, defend and hold Supabase harmless with regard to any liability arising out of any such violation.

6.26.2 Authorization.#

·Customer grants Supabase general authorization (or, where applicable, has Customer's Controller's general authorization) to engage any of the Sub-processors provided in Supabase's Sub-processor list, available at https://supabase.com/legal/customer-resources/subprocessor-list ("Subprocessor List"), as amended from time to time in accordance with clause 6.3 (the "Authorized Sub-processors"), to Process Covered Data. Supabase shall: (a) enter into a written agreement with each Authorized Sub-processor imposing data protection obligations that, in substance, are no less protective of Covered Data than Supabase's obligations under this DPA; and (b) remain liable for each Authorized Sub-processor's compliance with the obligations under this DPA.

6.36.3 Updates to the Subprocessor List.#

·Supabase offers a mechanism for Customer to subscribe to notifications of changes to the Subprocessor List via https://supabase.com/legal/customer-resources/subprocessor-list. If Customer subscribes to receive such updates, Supabase will provide Customer with at least thirty (30) days' notice of any proposed changes to the Authorized Sub-processors. Customer shall notify Supabase if it objects to the proposed change to the Authorized Sub-processors (including, where applicable, when exercising its right to object under clause 9(a) of the SCCs) by providing Supabase with written notice of the objection within five (5) days after Supabase has provided notice to Customer of such proposed change (an "Objection"). In the event Customer submits an Objection to Supabase, Supabase and Customer shall work together in good faith to find a mutually acceptable resolution to address such Objection. If Supabase and Customer are unable to reach a mutually acceptable resolution within a reasonable timeframe, which shall not exceed thirty (30) days, Customer may terminate the portion of the Agreement relating to the Services affected by such change by providing written notice to Supabase.

77. Data Subject Rights Requests.#

·Supabase will promptly notify Customer of any request received by Supabase or any Authorized Sub-processor from a Data Subject which Supabase, given the nature of the Services, is able to associate with Customer or which identifies itself to Supabase as associated with Customer, to assert their rights in relation to Covered Data under Applicable Data Protection Laws (a "Data Subject Request"). As between the Parties, Customer will have sole discretion in responding to the Data Subject Request, and Supabase shall not respond to the Data Subject Request, except to advise the Data Subject that their request has been forwarded to Customer. Supabase will, taking into account the nature of the Services, provide Customer with reasonable assistance as necessary for Customer to fulfill its obligation under Applicable Data Protection Laws to respond to Data Subject Requests.

88. Security.#

·Supabase will implement and maintain appropriate technical and organizational data protection and security measures designed to ensure security of Covered Data, taking into account the nature, scope, context, and purpose of the Processing and its associated risks, including, without limitation, protection against unauthorized or unlawful Processing and against accidental loss, destruction, or damage of or to Covered Data. Such measures will meet the minimum standards set out in Schedule 1.

99. Information and Audits.#

9.19.1 Information.#

·Supabase shall notify Customer promptly if Supabase determines that it can no longer meet its obligations under Applicable Data Protection Laws. Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Covered Data upon reasonable notice.

9.29.2 Audit Reports.#

·Upon request, Supabase shall provide to Customer: (a) data protection compliance certifications issued by a commonly accepted certification issuer which has been audited by a data security expert, or by a publicly certified auditing company; or (b) such other documentation reasonably evidencing the implementation of the technical and organizational data security measures in accordance with industry standards (together (a) and (b) of this clause 9.2, the "Audit Reports"). If an audit requested by Customer is addressed in the Audit Reports, and the certification or documentation is dated within twelve (12) months of Customer's audit request; and Supabase confirms that there are no known material changes to the controls audited, then Customer agrees to accept that certification or documentation in lieu of conducting a physical audit of the controls pursuant to clause 9.3.

9.39.3 Customer Audit Rights.#

·To the extent Customer is unable to retrieve the information it needs to comply with its diligence requirements under Applicable Data Protection Laws via the Audit Reports, Customer may audit Supabase's compliance with this DPA no more than once per calendar year to the extent required by Applicable Data Protection Laws. The Parties agree that all such audits will be conducted: (a) upon at least thirty (30) days' written notice to Supabase; (b) only during Supabase's normal business hours; and (c) in a manner that does not materially disrupt Supabase's business or operations and at Customer's sole expense. With respect to any such audits, Customer may engage a third-party auditor to conduct the audit on its behalf. Supabase shall not be required to facilitate any such audit unless and until the Parties have agreed in writing the scope and timing of such audit.

9.49.4 Results.#

·Customer shall promptly notify Supabase of any non-compliance discovered during an audit. The results of the audit shall be Supabase's Confidential Information.

1010. Security Incidents.#

·Supabase shall notify Customer in writing without undue delay, and where feasible, within forty-eight (48) hours, after becoming aware of any Security Incident to the contact details for Customer associated with its Supabase account. Supabase shall take reasonable steps to contain, investigate, and mitigate any Security Incident, and shall send Customer timely information about the Security Incident, including, but not limited to, the nature of the Security Incident, the measures taken to mitigate or contain the Security Incident, and the status of the investigation. Supabase shall provide reasonable assistance with Customer's investigation of any Security Incidents and any of Customer's obligations in relation to the Security Incident under Applicable Data Protection Laws, including any notification to Data Subjects or supervisory authorities. Supabase's notification of or response to a Security Incident under this clause 10 shall not be construed as an acknowledgement by Supabase of any fault or liability with respect to the Security Incident.

1111. Term, Deletion and Return.#

11.111.1 Term.#

·This DPA shall commence on the Effective Date and, notwithstanding any termination of the Agreement, will remain in effect until, and automatically expire upon, Supabase's deletion of all Covered Data as described in this DPA.

11.211.2 Deletion and Return.#

·Supabase shall, if requested to do so by Customer within thirty (30) days of expiry of the Agreement (the "Retention Period"), provide a copy of all Covered Data in such commonly used format as requested by Customer, or provide a self-service functionality allowing Customer to download such Covered Data. On expiry of the Retention Period, Supabase shall delete all copies of Covered Data Processed by Supabase or any Authorized Sub-processors.

1212. Standard Contractual Clauses.#

12.112.1 Incorporation of the SCCs.#

·The Standard Contractual Clauses shall, as further set out in Schedule 2, apply to the transfer of any Covered Data from Customer to Supabase, and form part of this DPA, to the extent that:

·(a) the GDPR or Swiss Data Protection Laws apply to the Customer when making that transfer; or

·(b) the Applicable Data Protection Laws that apply to the Customer when making that transfer (the "Exporter Data Protection Laws") prohibit the transfer of Covered Data to Supabase under this DPA in the absence of a transfer mechanism implementing adequate safeguards in respect of the Processing of that Covered Data, and any one or more of the below (i) - (iii) applies; or

·(i) the relevant authority with jurisdiction over the Customer's transfer of Covered Data under this DPA has not formally adopted standard data protection clauses or another transfer mechanism under the Exporter Data Protection Laws; or

·(ii) such authority has issued guidance that entering into standard contractual clauses approved by the European Commission would satisfy any requirement under the Exporter Data Protection Laws to implement adequate safeguards in respect of that transfer; or

·(iii) established market practice in relation to transfers subject to the Exporter Data Protection Laws is to enter into standard contractual clauses approved by the European Commission to satisfy any requirement under the Exporter Data Protection Laws to implement adequate safeguards in respect of that transfer.

·(c) the transfer is an "onward transfer" (as defined in the applicable module of the SCCs).

12.212.2 Signature of the SCCs.#

·The Parties agree that acceptance of the Agreement shall have the same effect as signing the SCCs.

1313. Deidentified Data.#

·If Supabase receives Deidentified Data from or on behalf of Customer, Supabase shall: (a) take reasonable measures to ensure the information cannot be associated with a Data Subject; (b) publicly commit to Process the Deidentified Data solely in deidentified form and not to attempt to reidentify the information; and (c) contractually obligate any recipients of the Deidentified Data to comply with the foregoing requirements and Applicable Data Protection Laws.

1414. General.#

·The Parties hereby certify that they understand the requirements in this DPA and will comply with them. The Parties agree to negotiate in good faith any amendments to this DPA as may be required in connection with changes in Applicable Data Protection Laws. All notices to be provided by Supabase to Customer under this DPA shall be sent to the contact details for Customer associated with its Supabase account or as otherwise stated in the Agreement, unless the Parties agree otherwise in writing.

Schedule 1SCHEDULE 1 - TECHNICAL AND ORGANIZATIONAL MEASURES#

·Introduction#

·Supabase employs a combination of policies, procedures, guidelines and technical and physical controls to protect the personal data it processes from accidental loss and unauthorized access, disclosure or destruction.

·Governance and policies#

·Supabase:

  • ·assigns personnel with responsibility for the determination, review and implementation of security policies and measures;
  • ·reviews its security measures and policies on a regular basis to ensure they continue to be appropriate for the data being protected; and
  • ·establishes and follows secure configurations for systems and software, and ensures that security measures are considered during project initiation and the development of new IT systems.

·Breach response#

·Supabase maintains internal monitoring systems that can alert its operational teams regarding any service outages, in some cases even in advance of the outage thresholds being breached.

·Supabase has a breach response plan that has been developed to address data breach events. The plan is regularly tested and updated.

·Access controls#

·Supabase limits access to personal data by implementing appropriate access controls, including the following:

  • ·Access to infrastructure and internal resources is managed on the basis of the Principle of Least Privilege: individuals are granted only the privileges they require to execute their business duties, and said privilege is revoked when it is no longer needed.
  • ·Access management is centralized to identity providers, and wherever feasible, internal services delegate both authentication and authorization to these providers. This ensures that off-boarding and privilege revocation can be handled in a timely fashion.
  • ·Supabase infrastructure requires approvals from at least one additional authorized person before any changes can be made. Authorized persons are designated based on the relevance of the system in question to their business roles.
  • ·User authentication for Supabase internal resources is protected with both a strong password policy and mandatory 2FA that disallows the use of SMS-based 2FA.
  • ·Supabase never knowingly stores plaintext passwords; if necessary, Supabase stores hashed, salted results of authentication material, as appropriate for the use case.
  • ·Supabase devices that are used for accessing internal resources enforce strong security measures, including strong passwords, use of anti-virus software, and full-disk encryption.
  • ·Audit trails are retained of user actions performed within Supabase infrastructure. Supabase retains audit logs of all interactions with its internal services and all interactions with Customer projects.
  • ·Traffic flow logs are retained that enable retroactive analysis of all connections to Supabase infrastructure if needed.
  • ·Only pre-approved and secure means of communicating with Supabase services are exposed by Supabase's firewalls.
  • ·All communication-including transmission of credentials-is conducted over connections protected by TLS configured with a set of modern cipher suites.

·Segmentation#

·Customer projects and Supabase internal Control Plane services are deployed in separate networks with firewalls enforcing that only the expected traffic across the two is allowed. Additionally, logs are retained of metadata about the traffic flowing across the two.

·Logs and metrics used for observability and debugging are automatically extracted and sent to systems that are segregated from Customer projects that contain Customer's data.

·Encryption#

·Stored data is encrypted where appropriate, including any backup copies of the data.

  • ·All hard disks are encrypted-at-rest using the industry-standard AES-256 algorithm. Similarly, the regularly scheduled backups are also encrypted-at-rest using AES-256.
  • ·The encryption keys are protected by keys stored using FIPS 140-2 compliant HSMs.

·All network communication is conducted over encrypted links protected by modern security standards (TLS 1.2, modern cipher suites) to preserve confidentiality and integrity of the data.

·Availability and backup#

·Supabase takes daily backups of Customer projects by default. Additional backups can be scheduled based on Customer requirements and service agreements.

·All backups are encrypted in-transit and at-rest.

·Backups are stored on a storage system independent of the Customer's project resources, and aim for 99.99% availability.

·Supabase has employees strategically placed around the world, which allows it to utilize a follow-the-sun model for supporting and monitoring its operations, and to expedite the response to any service incidents.

·Testing#

·Supabase uses reasonable and appropriate security and compliance monitoring systems across its infrastructure, in order to detect any violations of its security policies.

·Supabase regularly conducts penetration testing of its systems by hiring reputable third-party security firms, and remediates any findings as appropriate.

Schedule 2SCHEDULE 2 - STANDARD CONTRACTUAL CLAUSES#

11. EU SCCs#

·With respect to any transfers referred to in clause 12, the Standard Contractual Clauses shall be completed as follows:

1.11.1 The following modules of the SCCs will apply:

·(a) where the Customer acts as a controller and Supabase acts as a processor, Module Two (controller to processor) shall apply; and

·(b) to the extent that Customer acts as a processor and Supabase acts as a subprocessor, Module Three (processor to processor) shall apply.

1.21.2 Clause 7 of the Standard Contractual Clauses (Docking Clause) does not apply.

1.31.3 Option 2 of Clause 9(a) (General written authorization) shall apply, and the time period to be specified is determined in clause 6.3 of the DPA.

1.41.4 The option in Clause 11(a) of the Standard Contractual Clauses (Independent dispute resolution body) does not apply.

1.51.5 With regard to Clause 17 of the Standard Contractual Clauses (Governing law), the Parties agree that option 1 will apply and the governing law will be Irish law.

1.61.6 In Clause 18 of the Standard Contractual Clauses (Choice of forum and jurisdiction), the Parties submit themselves to the jurisdiction of the courts of Ireland.

1.71.7 For the purpose of Annex I of the Standard Contractual Clauses:

·(a) Schedule 3 (Processing Details) of this DPA sets out the details of the Customer and the competent supervisory authority;

·(b) the description of the transfer is set out in Schedule 3 (Processing Details) and includes the processing of contact information and access credentials relating to, and support requests submitted by, Authorized Users for the purposes of granting Authorized Users access to the Services and providing support in relation to the Services; and

·(c) the data importer is Supabase Pte. Ltd whose offices are located at 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513 and whose contact details are privacy@supabase.io.

1.81.8 For the purpose of Annex II of the Standard Contractual Clauses, Schedule 1 of the DPA contains the technical and organizational measures.

22. UK Addendum#

2.12.1 This paragraph 2 (UK Addendum) shall apply to any transfer of Covered Data from Customer (as data exporter) to Supabase (as data importer), to the extent that:

·(a) the UK Data Protection Laws apply to Customer when making that transfer; or

·(b) the transfer is an "onward transfer" as defined in the Approved Addendum.

2.22.2 As used in this paragraph 2:

·"Approved Addendum" means the template addendum, version B.1.0 issued by the UK Information Commissioner under S119A(1) Data Protection Act 2018 and laid before the UK Parliament on 2 February 2022, as it may be revised according to Section 18 of the Approved Addendum.

·"UK Data Protection Laws" means all laws relating to data protection, the processing of personal data, privacy and/or electronic communications in force from time to time in the UK, including the UK GDPR and the Data Protection Act 2018.

2.32.3 The Approved Addendum will form part of this DPA with respect to any transfers referred to in paragraph 2.1, and execution of this DPA shall have the same effect as signing the Approved Addendum.

2.42.4 The Approved Addendum shall be deemed completed as follows:

·(a) the "Addendum EU SCCs" shall refer to the SCCs as they are incorporated into this DPA in accordance with clause 12 and this Schedule 2;

·(b) Table 1 of the Approved Addendum shall be completed as set out in paragraph 1.7 of this Schedule 2;

·(c) the "Appendix Information" shall refer to the information referred to in paragraph 1.7 of this Schedule 2 and set out in Schedule 1;

·(d) for the purposes of Table 4 of the Approved Addendum, neither party may terminate the Approved Addendum in accordance with Section 19 of the Approved Addendum; and

·(e) Section 16 of the Approved Addendum does not apply.

33. Swiss Addendum#

3.13.1 This paragraph 3 (Swiss Addendum) shall apply to any transfer of Covered Data from Customer (as data exporter) to Supabase (as data importer), to the extent that the Swiss Data Protection Laws apply to Customer when making that transfer.

3.23.2 The Standard Contractual Clauses will apply to such transfers, subject to the modifications described in paragraph 3.3.

3.33.3 The following modifications shall be made to the SCCs:

·(a) references to "Regulation (EU) 2016/679" shall be interpreted as references to the Swiss Data Protection Laws, and references to specific Articles of "Regulation (EU) 2016/679" shall be replaced with the equivalent Article or Section of the Swiss Data Protection Laws;

·(b) references to "EU", "Union" and "Member State" shall be interpreted as references to Switzerland;

·(c) the term "member state" shall not be interpreted in such a way as to exclude data subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (Switzerland) in accordance with Clause 18(c) of the SCCs;

·(d) references to personal data in the SCCs also refer to data about identifiable legal entities until the entry into force of revisions to the Swiss Data Protection Laws that eliminate this broader scope;

·(e) under Annex I.C of the SCCs (Competent supervisory authority): the supervisory authority is the Swiss Federal Data Protection and Information Commissioner ("FDPIC") insofar as the data transfer is governed by the Swiss Data Protection Laws; and the supervisory authority is the supervisory authority designated in accordance with paragraph 1.7 of this Schedule 2 insofar as the data transfer is governed by the EU GDPR.

44. Transfers of personal data from Other Jurisdictions#

4.14.1 If the SCCs apply pursuant to clause 12.1(b) of the DPA, then:

·(a) Module One (controller to controller) of the SCCs will apply where Customer is acting as a controller of Covered Data and Supabase is acting as a controller of Covered Data;

·(b) Module Two (controller to processor) of the SCCs will apply where Customer is acting as a controller of Covered Data and Supabase is acting as a processor of Covered Data;

·(c) Module Three (processor to processor) of the SCCs will apply where Customer is acting as a processor of Covered Data and Supabase is acting as a sub-processor of Covered Data; and

·(d) Module Four (processor to controller) of the SCCs will apply where Customer is acting as a processor of Covered Data and Supabase is acting as a controller of Covered Data.

4.24.2 If, under the Exporter Data Protection Laws, the SCCs require modifications when used for the purpose of transferring data from a non-EU jurisdiction (the data exporter's jurisdiction) to another country, the Parties shall be deemed to have incorporated the SCCs into this Schedule 2 with such modifications, and shall comply with such modified SCCs in connection with such transfers.

4.34.3 If clause 12.1(b) of the DPA applies, the SCCs shall apply with the following modifications:

·(a) references to "Regulation (EU) 2016/679" and any specific articles of "Regulation (EU) 2016/679" shall be replaced with the equivalent references to the Exporter Data Protection Laws;

·(b) references to the "Union", "EU" and "EU Member State" are all replaced with reference to the jurisdiction in which the Exporter Data Protection Laws were issued (the "Exporter Jurisdiction");

·(c) the "competent supervisory authority" shall be the applicable supervisory in the Exporter Jurisdiction; and

·(d) Clauses 17 and 18 of the SCCs shall refer to the laws and courts of the Exporter Jurisdiction respectively.

4.44.4 Where, at any time during the Supabase's Processing of Covered Data under this DPA, a transfer mechanism other than the SCCs is approved under the Exporter Data Protection Laws with respect to transfers of Covered Data by Customer to Supabase, the Parties shall promptly enter into a supplementary agreement that:

·(a) incorporates any standard data protection clauses or another transfer mechanism formally adopted by the relevant authority in the Exporter Jurisdiction;

·(b) incorporates the details of Processing set out in Schedule 3 (Processing Details) of this DPA;

·(c) shall, with respect to the transfer of Personal Data subject to the Exporter Data Protection Laws, take precedence over this DPA in the event of any conflict.

4.54.5 Where required under the Exporter Data Protection Laws, the relevant data exporter shall file a copy of the agreement entered into in accordance with paragraph 4.4 with the relevant national authority.

Schedule 3SCHEDULE 3 - PROCESSING DETAILS#

·Customer Name: Customer.

·Customer Address: The address for Customer associated with its Supabase account or as otherwise stated in the Agreement.

·Contact: The contact details for Customer associated with its Supabase account or as otherwise stated in the Agreement.

·Customer Role: Controller/business (or processor/service provider for Customer's controller, as applicable).

·Categories of Personal Data stored or processed through the Services: The specific categories of Personal Data depend on the nature of Customer's use of the Services, but may include for example: Contact information, first name, last name, email address, Usage information, Registration/account information, name, email address, password, and any other information as determined by the Customer in accordance with the Agreement.

·Categories of Data Subjects to whom the personal data mentioned above relates: The specific categories of data subjects depend on the nature of Customer's use of the Services but may include for example: Authorized Users and Customer's end users, as submitted by Customer.

·Special categories of Personal Data: The specific categories of Sensitive Data depend on the nature of Customer's use of the Services, but may include for example: personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation. Notwithstanding the foregoing, Customer is not permitted to submit and shall not submit personal data to the Services which would be defined as Personal Health Information under the Health Insurance Portability and Accountability Act of 1996 without first agreeing to sign a separate business associate agreement with Supabase.

·Frequency of the transfer: continuous.

·Nature of the processing: Storage, deletion, rectification, analysis, transfer, aggregation.

·Purpose of the processing: The performance of the Services, namely the provision of database and tooling services for the development and operation of web and mobile applications.

·Retention period: The duration of the Agreement, unless earlier deletion is requested by the Customer in accordance with the functionality of the Services.

·Subprocessors: As found in the Subprocessor List.

·Supervisory Authority: The competent supervisory authority determined in accordance with Applicable Data Protection Laws.

Service Level Agreement | Supabase · p30
Part of the agreement

Service Level Agreement | Supabase

2,375 words, 192 clausesno date on the pageread 08/10/2026source

·Service Level Agreement

·Enterprise Platform Uptime SLA#

·The following Service Level Agreement, which is incorporated into and forms part of the Subscription Agreement between Supabase, Inc. ("Supabase") and Customer (the "Agreement"), will apply to the Services for Enterprise Customers specified in an Order Form during the applicable Subscription Term.

11. Definitions#

·All capitalized terms used but not defined in this SLA have the meaning set forth in the Agreement.

·Availability Metrics:

·Defines the measurements used to calculate service uptime under this SLA.

  • Schedule DScheduled Availability: The total time (in minutes) that the applicable service is generally accessible and available to permitted users.

Schedule DScheduled Availability:

·The total time (in minutes) that the applicable service is generally accessible and available to permitted users.

  • Schedule DScheduled Downtime/Maintenance Windows: Periods of time that Supabase has communicated in advance, during which the service may be temporarily unavailable due to planned maintenance, upgrades, or other scheduled activities. These windows are not counted as Unscheduled Downtime for SLA purposes.

Schedule DScheduled Downtime/Maintenance Windows:

·Periods of time that Supabase has communicated in advance, during which the service may be temporarily unavailable due to planned maintenance, upgrades, or other scheduled activities. These windows are not counted as Unscheduled Downtime for SLA purposes.

  • ·Unscheduled Downtime: The total time (in minutes) that the service is not accessible or available, excluding periods attributable to any causes listed under SLA Exclusions.

·Unscheduled Downtime:

·The total time (in minutes) that the service is not accessible or available, excluding periods attributable to any causes listed under SLA Exclusions.

  • ·Actual Availability: The result of subtracting Unscheduled Downtime from Scheduled Availability.

·Actual Availability:

·The result of subtracting Unscheduled Downtime from Scheduled Availability.

·Release Maturity Levels: Indicates the stage of release for a given product or feature and whether it is covered by the SLA.

  • ·GA (General Availability): The product is fully released and covered by the SLA.
  • ·Beta: The product or feature is in limited release. Beta products are not covered by the SLA.
  • ·Alpha: The product or feature is in early release. Alpha products are not covered by the SLA.

·For the current release stage of each Supabase product and feature see Supabase features.

·SLA Scope: The level at which service availability is measured and the impact required to constitute an SLA breach.

  • ·Global: The service is deployed from a centralized global infrastructure; SLA is breached if more than 1% of projects worldwide are affected during a downtime event.
  • ·Regional: The service is deployed within individual geographic regions; SLA is breached if more than 1% of projects in a single region are affected.
  • ·Project: The service is deployed on a dedicated, per-project basis; SLA applies individually to each project.

22. Uptime Commitment#

·Supabase will provide Actual Availability for at least ninety-nine and nine tenths percent (99.9%) of the total time in each calendar month during the Subscription Term, as measured by Supabase (the "Uptime Commitment"). Each product is individually covered by a 99.9% uptime commitment for customers with an Enterprise tier subscription.

33. SLA Definition & Exclusions#

·This Service Level Agreement applies only to the services and products specifically listed as covered, and is subject to the definitions, scopes, and exclusions outlined in this document.

·Supabase is not responsible for outages or service interruptions caused by factors outside of its reasonable control. The following categories of events are excluded from this SLA:

  • ·Third-Party Vendors: Issues attributable to external vendors or cloud providers, including AWS, Cloudflare, GCP, Azure, GitHub, or other similar providers.

·Third-Party Vendors:

·Issues attributable to external vendors or cloud providers, including AWS, Cloudflare, GCP, Azure, GitHub, or other similar providers.

  • ·Integration Partners: Failures or downtime related to third-party integration partners, such as Resend for email delivery, or other external service failures.

·Integration Partners:

·Failures or downtime related to third-party integration partners, such as Resend for email delivery, or other external service failures.

  • ·General Factors Outside Our Control: Events such as force majeure, internet service provider (ISP) outages, or other issues outside Supabase's reasonable control.

·General Factors Outside Our Control:

·Events such as force majeure, internet service provider (ISP) outages, or other issues outside Supabase's reasonable control.

  • ·Customer Actions or Inactions: Resource limitations, misconfigurations, or failures to follow operational guidelines provided in Supabase documentation; delays in recovery due to insufficient I/O capacity; issues caused by customer's equipment or software; or account suspension or termination in accordance with Supabase Terms.

·Customer Actions or Inactions:

·Resource limitations, misconfigurations, or failures to follow operational guidelines provided in Supabase documentation; delays in recovery due to insufficient I/O capacity; issues caused by customer's equipment or software; or account suspension or termination in accordance with Supabase Terms.

·Product-specific exclusions and further detail are provided in the following sections.

·Product-Specific#

·Postgres#

  • ·SLA Scope: Project Dependencies: None

·Downtime Definition:

·Any period during which the managed Postgres database for a given project is not generally accessible for permitted users to perform read or write operations.

·Exclusions:

  • ·Use of user-defined, unofficial, or unsupported Postgres extensions.
  • ·Use of Postgres versions older than the two most recent major releases officially supported by Supabase.
  • ·Use of outdated database extension versions; customers must be running the most recent version of database extensions for those to be included in SLA coverage.
  • ·Customer's failure to provision sufficient CPU, memory, or storage resources for expected workloads.
  • ·Excessively large numbers of tables or objects that significantly impact recovery times.
  • ·Insufficient I/O capacity for the database workload as provisioned by the customer.
  • ·Outages caused by customer-initiated schema changes or migrations that impact database integrity or operability.
  • ·Issues caused by customer's equipment, networks, or software.
  • ·Downtime related to suspension or termination of account per Supabase Terms.

·Auth#

  • ·SLA Scope: Project Dependencies: Postgres

·Downtime Definition:

·Any period during which the Auth service is unavailable for performing authentication or authorization operations for permitted users of a production system.

·Exclusions:

  • ·Unavailability caused by upstream service outages listed in Dependencies.
  • ·Inappropriately provisioned compute resources for anticipated auth workloads.
  • ·Customer-initiated modifications to database objects, roles, or relationships in the auth schema.
  • ·Outages resulting from integration with third-party providers (OAuth, OpenID, email, SMS, CAPTCHA, password strength checking, geolocation, etc.).
  • ·Outages due to overly permissive rate-limiting configurations set by the customer.
  • ·Email sending issues when using the default (provisional) configuration not intended for production use.
  • ·Issues caused by using retracted or unofficial Supabase libraries, frameworks, or proxies.
  • ·Issues that would have been resolved by upgrading to a newer minor or patch version of official Supabase libraries or tools.

·Data APIs (PostgREST)#

  • ·SLA Scope: Project Dependencies: Postgres, Auth

·Downtime Definition:

·Any period during which the Data APIs (including PostgREST endpoints) are unavailable for permitted users to perform API calls against the database.

·Exclusions:

  • ·Unavailability caused by upstream service outages listed in Dependencies.
  • ·Customer misconfiguration of API permissions, security policies, or database schema.
  • ·Use of unofficial or unsupported client libraries, API versions, or modifications.
  • ·Failures resulting from customer's network, application, or API client errors.
  • ·Outages that could have been resolved by upgrading to the latest supported version of Supabase Data API components.

·Storage#

  • ·SLA Scope: Regional Dependencies: Postgres, Pooler

·Downtime Definition:

·Any period during which the Storage service is unavailable for permitted users to upload, download, or manage files and buckets in a region.

·Exclusions:

  • ·Unavailability caused by upstream service outages listed in Dependencies.
  • ·Customer misconfiguration of storage settings or connection pools (e.g., low max_clients or pool_size).
  • ·Use of unofficial or unsupported client libraries or modifications.
  • ·Customer-initiated schema changes in the storage schema or cross-schema relationships impacting availability.
  • ·Deletion of objects or buckets by the customer via the Storage API.
  • ·Outages that could have been resolved by upgrading to the latest supported version of Supabase Storage components.

·Pooler (PgBouncer & Supavisor)#

  • ·SLA Scope: Regional Dependencies: Postgres

·Downtime Definition:

·Any period during which the database connection pooling layer is unavailable for permitted users, resulting in inability to connect to Postgres.

·Exclusions:

  • ·Unavailability caused by upstream service outages listed in Dependencies.
  • ·Customer's failure to provision sufficient pooler capacity (e.g., max_clients, pool_size) for actual workload.
  • ·Custom changes to connection pooling settings outside recommended operational guidelines.
  • ·Issues arising from customer's network or database client configuration.
  • ·Failures resolvable by updating to a supported version of official Supabase pooling components.

·Management API#

  • ·SLA Scope: Regional Dependencies: None

·Downtime Definition:

·Any period during which the Supabase Management API is unavailable for permitted users to perform management, provisioning, or configuration actions in a region.

·Exclusions:

  • ·Customer loss or compromise of personal access tokens or confidential information.
  • ·Use of the Management API in violation of Supabase fair-use policy.
  • ·Failures that could have been resolved by upgrading to a newer version of official Supabase management tooling.

·Branching#

  • ·SLA Scope: Regional Dependencies: Postgres, Management API

·Downtime Definition:

·Any period during which the branching functionality (including creation, deletion, or promotion of branches) is unavailable for permitted users within a given region.

·Exclusions:

  • ·Unavailability caused by upstream service outages listed under Dependencies.
  • ·Failures due to unsupported schema or configurations within branches.
  • ·Customer misuse or unsupported use of branching features, including but not limited to version pinning, manual overrides, or undocumented patterns.
  • ·Issues resulting from user-initiated migrations that introduce data loss or instability, including those merged into production environments.
  • ·Failures in applying configuration or updates older than 90 days.
  • ·Failures in applying configuration or service updates (e.g., Auth settings) to branches with stale or diverged states.

·Realtime#

  • ·SLA Scope: Regional Dependencies: Postgres, Auth

·Downtime Definition:

·Any period during which the Realtime service is unavailable for permitted users to send and receive event notifications or subscribe to database changes in a region.

·Exclusions:

  • ·Unavailability caused by upstream service outages listed in Dependencies.
  • ·Customer's failure to provision sufficient compute resources for Realtime workloads.
  • ·The Realtime service does not guarantee delivery of messages (at-least-once, exactly-once, or at-most-once delivery).
  • ·Issues resulting from the use of unofficial, outdated, or unsupported client libraries or event-handling frameworks.

·Functions#

  • ·SLA Scope: Regional Dependencies: None

·Downtime Definition:

·Any period during which Supabase Edge Functions are unavailable to be executed, created, updated, or deleted by permitted users in a region.

·Exclusions:

  • ·Outages caused by user code errors, infinite loops, or unsupported packages.
  • ·Failures due to integration with external dependencies or services.
  • ·Failures resulting from downstream dependencies explicitly invoked by the user within their function logic (e.g., Postgres queries, HTTP requests to PostgREST, Auth, Storage, or third-party services). These are considered outside the scope of the Functions SLA.

·Studio#

  • ·SLA Scope: Global
  • ·Dependencies: Postgres, Management API, Logging, Auth, Realtime, Functions, Storage

·Downtime Definition:

·Any period during which Supabase Studio is unavailable for permitted users to manage projects, view logs, or interact with platform resources globally.

·Exclusions:

  • ·Unavailability caused by upstream service outages listed in Dependencies.
  • ·Failures caused by unsupported browser versions or extensions.

·Logging#

  • ·SLA Scope: Global Dependencies: None

·Downtime Definition:

·Any period during which the Logging service is unavailable for permitted users to collect, query, or retrieve log data globally.

·Exclusions:

  • ·Integration failures with external log ingestion partners or third-party tools.
  • ·Outages resulting from customer misconfiguration of log collection or retention policies.

44. Service Credits#

·If the Uptime Commitment is not met during any particular calendar month, Customer is eligible for a service credit ("Service Credit") upon request. The amount will be:

·<Total Monthly Fees for Affected Service> * <Credit Percentage>

·where Credit Percentage is derived from the table below: Actual Availability | Credit Percentage

Less than 99.9% but greater than or equal to 99.0%10%
Less than 99.0% but greater than or equal to 98.0%15%
Less than 98.0% but greater than or equal to 96.0% | 20% Less than 96.0% | 30%

55. Credit Requests and Payment#

·To request a Service Credit, Customer must send an email to Supabase at support@supabase.io within thirty (30) days of the end of the month in which the Uptime Commitment was not met. The request must include:

·(a) the affected organization, service(s), region(s), and project(s);

·(b) the specific dates and times (in 5-minute intervals) during which the service was unavailable; and

·(c) supporting logs or monitoring data showing failed requests or clear unavailability.

·Supabase reserves the right to validate any claim using its own internal monitoring systems and may deny claims that are unsupported, inaccurate, or inconsistent with internal metrics.

·If Supabase confirms that Customer is eligible for a Service Credit, Supabase will issue a credit to Customer's account within thirty (30) days. Service Credits are not refunds, cannot be exchanged into cash, and may only be applied to future billing charges. Except as set forth in Section 6 below, the Service Credits constitute Customer's sole and exclusive remedy, and Supabase's sole and exclusive liability, for any failure to meet the Uptime Commitment.

·Notwithstanding anything to the contrary in this SLA, the total amount of Service Credits issued to Customer under this SLA shall not exceed twenty percent (20%) of the total fees paid by Customer for the affected services under the applicable Order Form during the preceding twelve (12) month period. Any Service Credits calculated in excess of this cap will be forfeited and shall have no cash or credit value.

77. Support#

·Supabase provides Support Service Level Agreements for Team and Enterprise customers.

·Urgent#

·Critical Issue

·Defect resulting in full or partial system outage or a condition that makes Supabase unusable or unavailable in production for all of Customer's Users.

·High#

·Significant Business Disruption

·Issue resulting in a situation meaning major functionality is impacted and significant performance degradation is experienced. Issue impacts significant proportion of user base and / or major Supabase functionality.

·Normal#

·Minor Feature or Functional Issue / General Question

·Issue results in a component of Supabase not performing as expected or documented. An inquiry by a Customer representative regarding a general technical issue or general question.

·Low#

·Minor Issue / Feature Request

·An Information request about Supabase or feature request.

·Severity and Target Initial Response Times#

Severity LevelTeamEnterprise StandardPriority Plus
1. Urgent24 hours24/7 × 3651 hour24/7 × 3651 hour24/7 × 365
2. High1 business dayMonday - Friday2 business hoursMonday - Friday2 hours24/7 × 365
3. Normal1 business dayMonday - Friday1 business dayMonday - Friday12 hours24/7 x 365
4. Low2 business daysMonday - Friday2 business daysMonday - Friday24 hours24/7 x 365

·Business hours are 6am to 6pm local time unless stated otherwise.