Data Processing Agreement

Our processing commitments as your data processor.

Draft — review with counsel. This document is a plain-language working draft and is not yet legal advice or a final agreement.

In plain language

  • You are the controller; SchemaForce is the processor acting on your instructions.
  • We process Salesforce metadata only — never the contents of your records.
  • We apply encryption at rest, tenant isolation, and access controls.
  • We use a limited list of subprocessors and will notify you of changes.

Last updated: June 2026

Roles

For data processed through the service, you act as the data controller and SchemaForce acts as the data processor. We process data only on your documented instructions, which include your use of the product.

Scope of processing

We process Salesforce metadata — object and field definitions, picklists, relationships, descriptions, and configuration — together with the account data needed to operate the service. We do not process the contents of your Salesforce records.

Security measures

We encrypt Salesforce credentials at rest, isolate tenant data with row-level security, restrict access to authorized systems and personnel, and keep tokens and identifiers out of URLs.

Subprocessors

We engage a limited set of subprocessors to provide infrastructure (database, hosting, billing, and language-model services). None receive the contents of your records. We maintain the current list on our Security page and will provide notice of material changes.

Data subject requests & assistance

We will assist you, taking into account the nature of processing, in responding to data subject requests and in meeting your security, breach-notification, and impact-assessment obligations.

Return & deletion

On termination, you may export or request deletion of processed data, subject to legal retention requirements.