BrowserStack Software
Last Reviewed: 03 Jun 2026
At a Glance
BrowserStack's DPA contains core GDPR processor obligations and incorporates SCCs, but does not include explicit audit rights for customers or any provision for DPIA assistance. BrowserStack's main terms (clause 4.3.2) expressly prohibit the inclusion of personal data within the "Customer Content". We recommend this contract is manually reviewed to ensure the terms are acceptable to you.
Company & Product Details
HQ
India, Ireland
Products
BrowserStack testing platform
Product description
Cloud software testing platform for websites and mobile applications across browsers, devices and operating systems.
What data is being processed?
Primarily account-related information and limited service data. Public terms say the services are not designed for customer content containing personal information, other than account-related information.
Document Details
Date of DPA
13 Feb 2026
Additional date information
Terms of Service effective 13 February 2026; data protection addendum contained in Exhibit A
What jurisdictions are covered?
The DPA defines "Data Protection Legislation" broadly to include GDPR (EU 2016/679), the Irish Data Protection Acts 1988–2018, the E-Privacy Directive 2002/58/EC, and related Irish E-Privacy Regulations, as supplemented or amended from time to time. The DPA addresses Restricted Transfers outside the EEA with SCCs as the primary mechanism. (Exhibit A, clause 1(j))
Is the DPA incorporated into service or customer agreements?
Link
Location & Transfers
Where is data held or processed?
Not explicitly stated The DPA does not specify particular storage locations. BrowserStack publishes a list of sub-processors at https://www.browserstack.com/sub-processors indicating where processing may occur. Restricted Transfers outside the EEA require Appropriate Safeguards under Article 46 GDPR, with SCCs as the primary mechanism. (Exhibit A, clauses 10.1, 11.1)
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
BrowserStack must implement Appropriate Technical and Organisational Measures to safeguard Account-Related Information from unauthorised or unlawful processing or accidental loss, alteration, disclosure, destruction or damage. Measures must be proportionate to the risk, having regard to the state of technological development and implementation costs. BrowserStack must also maintain administrative, physical and technical safeguards ensuring access only by authorised persons and systems. (Exhibit A, clauses 7.1, 7.2)
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
BrowserStack will notify Customer without undue delay if Account-Related Information is lost, destroyed, damaged, corrupted or unusable, or if there is any accidental, unauthorised or unlawful disclosure or access. BrowserStack must also assist Customer with its 72-hour supervisory authority notification obligation and with communicating breaches to data subjects where there is a high risk to their rights. (Exhibit A, clauses 8.1, 8.2)
What happens to the data on termination?
Account-Related Information is retained for such period as BrowserStack determines to be reasonably necessary, including maintaining the account while active and for a reasonable period after termination in case of reactivation. BrowserStack may also retain data to comply with legal obligations, resolve disputes, enforce agreements, support business operations, or develop or improve the Services. No specific deletion timeline is stated. (Exhibit A, clause 13)