Legal and privacy
Data Processing Addendum (draft)
Draft for review · August 2026
This is a discussion draft, not an executed DPA or a representation that a particular legal, security, residency, or compliance arrangement is available by default. The signed tenant agreement and its schedules control the processing details for an approved engagement.
Roles
The customer and Falcon Cortex identify the applicable controller, processor, or other roles in the signed agreement. A candidate sub-processor list is available on the sub-processors page and is subject to contract confirmation.
Processing scope
Processing is limited to the personal data and approved workflows documented for the tenant. This draft does not promise a selectable region, a particular transfer mechanism, or a universal retention period; those terms are agreed and recorded before tenant access.
Security measures
- Tenant-bound authorization and database-policy controls evaluated for the approved deployment.
- Access, change, and security evidence controls documented for the tenant-specific environment.
- Step-up authentication and separation-of-duties workflows where enabled by the approved scope.
- Identity integrations and MFA requirements recorded in the tenant implementation plan where applicable.
Sub-processing
The final DPA identifies authorised sub-processors and the applicable notice, objection, and change process. The public draft and list are not a substitute for that contractual notice.
Sign-off
To request the current tenant-specific DPA for review, contact Falcon Cortex Support.