Satcove

Data Processing Agreement

Last updated: March 2026

Scope

This Data Processing Agreement (DPA) applies to the processing of personal data by Satcove (operated by Abyssal Group, the “Processor”) on behalf of the customer (the “Controller”) who subscribes to a Business or Enterprise plan.

Data processed

  • Account data: email address, full name, plan type.
  • Usage data: AI model used, token counts, request timestamps.
  • Transaction data: payment amounts, Stripe customer ID.
  • Content data: conversation content, stored according to configured history and retention controls.

Sub-processors

  • Supabase — database and authentication under the configured project region and contract.
  • Stripe — payment processing.
  • Vercel — application hosting and edge services; execution location can vary by deployment.
  • AWS SES — transactional email, under the configured region and contract.
  • AI Providers: Anthropic, Google, OpenAI, Mistral, xAI, Perplexity — model inference under the configured commercial API terms and data controls.

Security measures

Satcove uses encrypted transport, managed encryption-at-rest controls, hashed API credentials, database access policies and restricted production access. Specific controls can vary by subprocessor and contracted deployment.

Data breach notification

In the event of a personal data breach affecting customer data, we will notify the Controller without undue delay and provide the information reasonably available to support its assessment and notification duties. The Controller remains responsible for its applicable regulatory deadlines.

Request a signed DPA

Business and Enterprise customers can request a signed DPA — contact us.

Satcove — A product by Abyssal Group