This Data Processing Agreement (“DPA”) forms an integral part of, and is subject to the Terra Terms and Conditions located at https://www.terra.security/terms and the Order Form or similar purchase instruments governing the use of Terra’s services, entered into by and between the Customer and Terra Security Inc. or Terra Security Ltd., as applicable (“Terra”) (the DPA together with the Terms and Conditions are collectively referred to as the “Agreement"). Terra and Customer are hereinafter jointly referred to as “Parties” and individually as “Party.” Capitalized terms not otherwise defined herein shall have the meaning given to them in the Terms and Conditions or similar purchase instruments.
By using the Terra services, Customer accepts this DPA, and you represent and warrant that you have full authority to bind the Customer to this DPA. If you cannot, or do not agree to comply with and be bound by this DPA, or otherwise do not have the authority to bind the Customer or any other entity, kindly do not provide Personal Data (or any similar terms under applicable laws) to Terra.
Customer shall comply with all applicable laws in connection with the performance of this DPA. As between the Parties, Customer shall be solely responsible for compliance with applicable laws (including Data Protection Laws) regarding the collection and transfer of Customer Personal Data to Terra. Customer agrees not to provide Terra with any special categories of data, as defined in Article 9 of the GDPR.
Terra shall take reasonable steps to ensure that access to the Customer Personal Data is limited on a need to know/access basis, and that all Terra personnel receiving such access are subject to confidentiality undertakings or professional or statutory obligations of confidentiality in connection with their access/use of Customer Personal Data.
In relation to the Customer Personal Data, Terra shall implement appropriate technical and organizational measures (Technical and Organizational Measures) including to the extent appropriate and applicable the measures referred to in Article 32(1) of the GDPR, to establish an appropriate level of security for the Customer Personal Data. Such security has to be sustained throughout the entire duration of this DPA and must aim to (i) ensure the ongoing confidentiality and security of Processing systems and services in connection with the Processing of the Customer Personal Data; and (ii) restore the availability and access to Customer Personal Data in a timely manner in the event of a physical or technical incident. In assessing the appropriate level of security, Terra shall consider the risks presented by Processing, paying particular attention to risks arising from a Personal Data Breach.
At the written request of the Customer, Terra and each Terra Affiliate shall provide reasonable assistance to Customer, at Customer 's expense, with any data protection impact assessments or prior consultations with Supervising Authorities or other competent data privacy authorities, as required under any applicable Data Protection Laws. Such assistance shall be solely in relation to Processing of Customer Personal Data by Terra.
Terra acknowledges and confirms that it does not receive or process any Personal Information (as defined in the CCPA) as consideration for the services or other items it provides to Customer under the Agreement or this DPA. Terra shall refrain from selling or sharing (as those terms are defined under the CCPA) any Personal Information processed under this DPA without Customer’s prior written consent or instruction. Terra further agrees not to take any action that would cause any transfer of Personal Information under the Agreement or this DPA to qualify as “selling” or “sharing” such Personal Information under the CCPA.
Annex 1
Details of Processing of Customer Personal Data
This Annex 1 includes certain details of the Processing of Customer Personal Data as required by Article 28(3) or 28(4) GDPR.
Subject Matter of the Processing of Customer Personal Data. The subject matter of the Processing of the Customer Personal Data are set out in the Agreement.
The Nature and Purpose of the Processing of Customer Personal Data: Providing the Terra services, as detailed in the Agreement.
The Types of Customer Personal Data to be Processed are as follows: name, phone, organization email address, role, IP address and log-in credentials (e.g. Google sign-up or other account authentication methods made available through the Services)
The categories of Data Subjects to whom the Customer Personal Data relates to are as follows:
Customer’s authorized users accessing the Terra Services on its behalf (i.e. authorized Customer personnel).
Duration of Processing
Subject to any section of the DPA and/or the Agreement concerning the duration of the processing and the consequences of the expiration or termination thereof, Terra will process Customer Personal Data for the duration of the Agreement, unless otherwise agreed upon in writing.
Annex 2
List of authorized Sub Processors




© 2026 Terra. All rights reserved.