The standard Data Processing Addendum is available to sign at turgo.ai/legal and covers GDPR/CCPA processing. A Business Associate Agreement (BAA) for HIPAA-regulated data is available on Enterprise plans — request it through your account team.
Data Processing Addendum (DPA)
The DPA governs turgo's processing of personal data on your behalf, including sub-processors, international transfer mechanisms (SCCs), and security commitments. Most customers can accept the standard DPA at turgo.ai/legal; Enterprise customers can request a countersigned copy or negotiate specific terms.
Business Associate Agreement (BAA)
If you process protected health information, turgo is HIPAA-eligible and a BAA is available on Enterprise. The BAA defines permitted uses, safeguards, and breach obligations. Certain configurations (e.g. restricting where PHI can appear) are required once a BAA is in place — your account team walks you through them.
Sub-processors
The current sub-processor list, with each vendor's purpose and region, is published at turgo.ai/legal. You can subscribe to be notified of changes before new sub-processors are engaged, which the DPA requires.
How to request
Standard DPA: self-serve at turgo.ai/legal. BAA, countersigned DPA, or custom terms: email legal@turgo.ai or ask your account team. Have your legal entity name and the regulated data types ready to speed review.