SuperFile Data Processing & Subprocessors

Legal Information & Notices · Updated July 2026

This page describes how Superfile (“Superfile,” “we,” “our,” or “us”) processes personal data on behalf of its customers and lists the subprocessors we rely on. It supplements our Privacy Policy. A signed Data Processing Agreement is available to business and institution customers on request.

1. Roles

When a customer uses the Superfile product to process personal data, the customer is the Controller (or business) and Superfile acts as the Processor (or service provider). We process such data only on the customer’s documented instructions and for the purpose of providing the service, except where law requires otherwise.

2. Nature of Processing

We process the categories of data, data subjects, and purposes necessary to operate the registry and the services a customer has chosen — typically account and contact details, reserved names and their status, and usage and security metadata. We do not sell personal data and do not use customer data to train unrelated models or for advertising.

3. Subprocessors

We engage the following subprocessors to provide the service. Each is bound by contractual obligations consistent with applicable data-protection law.

We will provide reasonable prior notice of any intended addition or replacement of a subprocessor so that customers may object on legitimate grounds.

4. Security

We maintain technical and organizational measures designed to protect personal data, including access controls, encryption in transit, vendor due diligence, and incident-response procedures. In the event of a personal-data breach affecting customer data, we will notify affected customers without undue delay.

5. Data Subject Requests

Where Superfile acts as Processor, we will assist the Controller, taking into account the nature of the processing, in responding to requests from individuals to exercise their rights. Individuals should ordinarily direct such requests to the Controller. You may also contact privacy@superfile.com.

6. International Transfers

Superfile is based in the United States. Where personal data is transferred from the EEA or UK, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and the UK Addendum, together with additional measures where appropriate.

7. Retention and Return

On termination of the service, we will delete or return customer personal data in accordance with the Data Processing Agreement and applicable law, except where retention is legally required.

8. Requesting a Signed DPA

Business and institution customers who require a countersigned Data Processing Agreement may request one at legal@superfile.com.

9. Contact

Email: privacy@superfile.com
Address:
9663 Santa Monica Blvd, Unit 121
Beverly Hills, CA 90210