Legal
Data Processing Agreement
Last updated: 2026-07-26
These Data Processing terms (the "DPA") form part of the agreement between O'Shea & Sons, LLC ("Processor", "we", "us") and the customer that uses ControlDrill ("Controller", "Customer", "you"). This DPA is the operative processor terms that apply to all customers of the Service unless a separately signed DPA expressly replaces it.
Together with the Terms of Service and Privacy Policy, this DPA governs processing of Customer Personal Data. Capitalized terms not defined here have the meaning in the Terms.
1. Roles
- Customer is the Controller of uploaded incident-response / BCDR plans and plan text, exercise decisions and transcripts, participant names/roles/emails Customer supplies, and related exercise configuration that constitutes personal data or Customer confidential content ("Customer Personal Data" and Customer content processed under this DPA).
- O'Shea & Sons, LLC is the Processor that processes that data only to provide the Service (tailor, run, and produce the evidence packet) and as instructed by Customer through the Service configuration and documented features.
Each party will comply with data protection laws applicable to its role. For Processor's own account and billing contact data about Customer, Processor may act as an independent controller as described in the Privacy Policy; that account data is not "Customer Personal Data" under this DPA.
2. Processing details
- Subject matter: hosting and operation of ControlDrill tabletop exercises, including optional document upload, AI-assisted tailoring on Cloudflare Workers AI, live session, and evidence packet generation.
- Duration: for the term of Customer's use of the Service for the relevant purchase(s), and until deletion or return as described below.
- Nature and purpose: store and process plan text; tailor scenarios; run exercises; record decisions and transcripts; produce evidence packets; support deletion and account requests. Processing is only to provide the Service.
- Data subjects: Customer's employees and contractors who are buyers or exercise participants, and any individuals identified in uploaded plans or free text.
- Categories of data: plan documents and extracted text; stack and company context; participant names, roles, and emails; exercise messages, decisions, timestamps, and related session artifacts; technical logs needed to operate the Service.
- Special categories: the Service is not designed for special-category data. Customer must not instruct processing of special-category data unless lawful and necessary, and Customer remains responsible for that decision.
3. Customer instructions
Processor will process Customer Personal Data only on documented instructions from Customer, including via the Service UI and features, and as required by law (in which case Processor will inform Customer unless legally prohibited). Customer is responsible for the lawfulness of its instructions, for notices to participants, and for the content of uploaded plans.
4. Confidentiality
Processor ensures that persons authorized to process Customer Personal Data are bound by confidentiality obligations.
5. Security measures
Processor implements reasonable technical and organizational measures appropriate to the nature of the Service, including: edge hosting on Cloudflare Workers with Durable Objects and D1; storage of uploaded plan originals in Cloudflare R2; inference for tailoring and moderation on Cloudflare Workers AI so plan content does not leave Cloudflare for an external LLM; encrypted transport (HTTPS); authenticated buyer sessions; magic-link access for participants; and access limited to operating the product. No security measure is perfect. Processor does not claim SOC 2, ISO 27001, or other certifications it does not hold, and does not promise absolute security.
6. Subprocessors
Customer authorizes Processor to use the following subprocessors (complete current disclosed list):
- Cloudflare - hosting and infrastructure (Workers, Durable Objects, D1, R2), DNS/CDN, and inference via Workers AI (no external LLM subprocessor; the uploaded plan does not leave Cloudflare for third-party model providers)
- Stripe - payment processing (primarily account and billing data; may process limited metadata tied to the purchase)
- WorkOS - buyer authentication and account sign-in (identity data for the purchasing account; not the uploaded plan or exercise content)
Processor will impose data-protection obligations on subprocessors no less protective than this DPA. Processor remains responsible for subprocessors' performance. Processor will update this page (or otherwise notify Customer) when the subprocessor list changes. Customer may object to a new subprocessor on reasonable data-protection grounds within thirty (30) days of notice; if the parties cannot resolve the objection, Customer may stop using the affected Service as its sole remedy for that objection.
7. No model training; no external LLM subprocessor
Processor does not use Customer Personal Data or uploaded plans to train models. Inference for the Service runs on Cloudflare Workers AI. There is no external LLM subprocessor: plan content is not sent to a third-party model API outside Cloudflare for tailoring or moderation.
8. International transfers
Where Customer Personal Data is transferred internationally, Processor relies on Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms provided via subprocessors as applicable, together with any supplementary measures those providers document.
9. Assistance with data-subject rights
Taking into account the nature of processing, Processor assists Customer in responding to data-subject requests by providing in-product deletion for uploaded documents where available and by handling written requests at hello@controldrill.com. Customer remains responsible for verifying requestors who are its participants or employees and for responding to those data subjects.
10. Breach notification
Processor will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to help Customer meet its own notification obligations.
11. Return and deletion
Upon termination of the Service, completion of the relevant purchase lifecycle under the stated retention policy, or on Customer's written request, Processor will delete or return Customer Personal Data in accordance with product tools and operational practice, except where retention is required by law. Uploaded plan originals and extracted corpus are deleted on request (including in-product delete where available) and otherwise under the stated 12-month retention window. Customer should export evidence packets before requesting deletion if a copy is needed.
12. Audits
Upon reasonable written request, and no more than once per twelve (12) months (unless a regulator or confirmed breach requires more), Processor will provide information reasonably necessary to demonstrate compliance with this DPA (for example up-to-date subprocessor list and high-level security description). On-site audits are not offered by default for a small multi-tenant SaaS; the parties will discuss good-faith alternatives if required by law.
13. Liability
Liability under this DPA is subject to the limitations in the Terms of Service, except where prohibited by applicable data-protection law.
14. Order of precedence
If there is a conflict between this DPA and the Terms regarding processing of Customer Personal Data, this DPA controls for that subject. A separately signed DPA between the parties controls over this page if it expressly says so.
15. Governing law
This DPA is governed by the laws of the State of Illinois, USA, without regard to conflict-of-law rules, except where mandatory data-protection law requires otherwise. Courts in Illinois have exclusive jurisdiction for disputes under this DPA, subject to those mandatory rules.
16. Contact
O'Shea & Sons, LLC
Email: hello@controldrill.com
Website: https://controldrill.com/