Data processing terms for enterprise customers
Last updated: February 23, 2026
Version: 1.0
Last Updated: February 23, 2026
Effective Date: January 15, 2026
This Data Processing Agreement ("DPA") is entered into between:
Data Controller ("Customer"): The entity that has agreed to SnowCoder's Terms of Service and is identified in the account registration.
Data Processor ("SnowCoder," "Processor," "we," "us"): Kumoco Limited (trading as SnowCoder), the provider of the Services.
This DPA supplements and forms part of the Terms of Service ("Agreement") between Customer and SnowCoder.
1.1 "Applicable Data Protection Laws" means all laws and regulations applicable to the processing of Personal Data under this DPA, including:
1.2 "Controller" means the entity that determines the purposes and means of the processing of Personal Data.
1.3 "Data Subject" means an identified or identifiable natural person whose Personal Data is processed.
1.4 "Personal Data" means any information relating to an identified or identifiable natural person.
1.5 "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
1.6 "Processor" means an entity that processes Personal Data on behalf of the Controller.
1.7 "Security Incident" means any unauthorized access to, or acquisition, use, or disclosure of Personal Data.
1.8 "Services" means the SnowCoder platform and related services provided under the Agreement.
1.9 "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
1.10 "Standard Contractual Clauses" ("SCCs") means the standard contractual clauses for international data transfers approved by the European Commission.
This DPA applies to the processing of Personal Data by SnowCoder on behalf of Customer in connection with the Services.
This DPA remains in effect for as long as SnowCoder processes Personal Data on Customer's behalf.
Customer warrants that:
Customer agrees to:
Customer's instructions for data processing are documented in:
SnowCoder shall:
SnowCoder shall:
SnowCoder implements appropriate technical and organizational measures including:
Encryption:
Access Control:
Network Security:
Monitoring:
See our Security Assurance Pack for detailed security controls.
Current Sub-processors:
| Sub-processor | Location | Purpose | Data Processed |
|---|---|---|---|
| Amazon Web Services | UK (London – eu-west-2) | Infrastructure hosting, storage, secret management | All customer data |
| Anthropic (standard tier; via Cloudflare AI Gateway) | US | LLM inference | Prompt content: requirement text, conversation, ServiceNow metadata, file extracts (credentials excluded) |
| OpenAI | US | Text embeddings (retrieval) | Text to be embedded |
| Cloudflare | Global | CDN, security, AI Gateway | IP addresses, requests, LLM request traffic |
| Stripe | US | Payment processing | Billing information |
| Xero | Global (NZ/AU/US) | Accounting / invoicing | Invoice and contact details |
| Google (Gmail / Workspace SMTP) | US | Transactional email delivery | Email addresses, message content |
| Telegram | Global | Operational error alerting | Error messages / stack traces (may incidentally include an email) |
| UptimeRobot | US | Uptime monitoring | Endpoint URLs only (no customer data) |
| AWS Bedrock (in-region AI – Enterprise+ dedicated, per engagement) | Customer-nominated region (e.g. EU) | In-region LLM inference (dedicated deployments) | Prompt content (as above) |
Note: For Enterprise+ dedicated deployments, AI inference can be provisioned in-region via AWS Bedrock as part of the engagement; in that configuration the model is accessed through AWS under the existing AWS DPA rather than Anthropic’s US API. This is delivered per engagement and is not the standard-tier configuration.
Sub-processor Management:
SnowCoder shall assist Customer in responding to Data Subject requests for:
Process:
SnowCoder shall provide reasonable assistance to Customer for:
In the event of a Security Incident affecting Customer's Personal Data, SnowCoder shall:
SnowCoder shall:
Incident notifications will include (to the extent known):
Personal Data may be transferred outside the European Economic Area (EEA) to:
For transfers to third countries without adequacy decisions:
SCC Options Selected:
For transfers from the UK:
SnowCoder implements supplementary technical and organizational measures:
Customer has the right to:
Documentation Audits:
On-site Audits:
SnowCoder maintains the following (SnowCoder does not currently hold SOC 2 or ISO 27001 certification):
SnowCoder retains Personal Data:
Upon termination of the Agreement:
Upon request, SnowCoder will provide:
Liability under this DPA is subject to the limitations in the Terms of Service, except where Applicable Data Protection Laws prohibit such limitations.
Each party shall indemnify the other for damages arising from:
In case of conflict between this DPA and the Agreement:
This DPA may be amended:
If any provision is found invalid, the remaining provisions continue in effect.
This DPA is governed by:
A. List of Parties
Data Exporter: Customer (as identified in account registration)
Data Importer: SnowCoder
B. Description of Processing
| Element | Description |
|---|---|
| Categories of Data Subjects | Customer's employees, contractors, end users |
| Categories of Personal Data | Names, email addresses, user identifiers, usage data, ServiceNow credentials (encrypted) |
| Sensitive Data | None routinely processed; Customer may submit at own risk |
| Frequency of Transfer | Continuous during service usage |
| Nature of Processing | Collection, storage, organization, retrieval, use, transmission, deletion |
| Purpose | Providing AI-powered code generation for ServiceNow development |
| Retention Period | Duration of Agreement + 30 days |
C. Competent Supervisory Authority
The competent supervisory authority of the EEA member state in which the data exporter is established. SnowCoder's own supervisory authority is the UK Information Commissioner's Office (ICO).
See Security Assurance Pack for detailed technical and organizational measures.
Summary:
Current list maintained at: https://snowcoder.ai/sub-processors
Data Protection Inquiries:
Data Protection Officer (EU):
Security Incidents:
Registered Address: Kumoco Limited (trading as SnowCoder) 180 Strand London, WC2R 1EA United Kingdom
Document Status: Production Ready Classification: Customer-Facing (Enterprise) Review Cycle: Annual