Data Processing Agreement
Last updated 23 July 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Sonder Labs ("Processor") and the customer ("Controller") for use of the Service, and applies where Sonder processes personal data on the Controller's behalf under UK/EU GDPR or equivalent data protection law.
1. Roles
The customer is the data controller for account and workspace data it submits to the Service. Sonder is the data processor and processes that data only on documented instructions from the customer, except where required by law.
2. Sub-processors
Sonder uses the sub-processors listed on our Sub-processors page, which is incorporated into this DPA by reference. We will notify customers of material changes to this list per the notice period stated there.
3. Confidentiality
Sonder ensures personnel authorised to process personal data are bound by confidentiality obligations.
4. Security measures
- Encryption of data in transit
- Access controls scoped to workspace
- Least-privilege access for internal systems
- Logging and monitoring of production systems
5. Assistance with data subject rights
Sonder will reasonably assist the customer in responding to data subject access, correction, deletion, and portability requests relating to data processed under this DPA.
6. Breach notification
Sonder will notify the customer without undue delay after becoming aware of a personal data breach affecting the customer's data.
7. International transfers
Where personal data is transferred outside the UK/EEA, Sonder relies on Standard Contractual Clauses or an equivalent adequacy mechanism.
8. Deletion on termination
On termination of the agreement, Sonder will delete or return customer data within a reasonable period, subject to legal retention requirements.
9. Requesting a signed copy
For an executed, entity-specific version of this DPA (including Standard Contractual Clauses annexes where applicable), contact hello@sonderlabs.co.uk.