Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The agreement assigns to the customer the obligation to notify employees and end users in the event of a security breach, to file with data protection authorities, and to fulfill access, rectification, and deletion requests from Authorized Users or authorities. The customer also indemnifies Cognition against third-party claims arising from these notification and compliance obligations.
This analysis describes what Windsurf's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision shifts standard data breach notification and data subject rights fulfillment obligations to the customer, including regulatory filing obligations with data protection authorities. The accompanying indemnification clause requires the customer to hold Cognition harmless from claims arising out of these obligations, including claims from Authorized Users or regulators.
Interpretive note: The enforceability of this contractual allocation of breach notification obligations may be constrained by independent statutory obligations under GDPR, CCPA, and state breach notification laws that cannot be contracted away.
The updated terms indicate that Windsurf is now operating as the Cognition Platform under Cognition AI, Inc., replacing the prior Exafunction, Inc. structure. The revised terms state that prior terms continue to govern use for 30 days from the posting date (July 1, 2026), and that continued access after that period constitutes acceptance of the updated terms. Users who do not agree with the new terms are instructed to stop using or accessing the Services. The specific substantive changes to user rights, data collection, fees, or service functionality are not detailed in the provided change summary.
View change record →Under this clause, the customer bears responsibility for issuing breach notifications to their own personnel, filing with data protection authorities, and responding to data subject rights requests, even where the breach originates from Cognition's systems. Cognition's liability for security breaches is limited to instances of gross negligence under these terms.
Cross-platform context
See how other platforms handle Customer Breach Notification Obligation and similar clauses.
Compare across platforms →Monitoring
Windsurf has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Cognition will not be responsible for any breach in security except to the extent the breach is due to Cognition's gross negligence. You will be responsible for routinely backing up Customer Data, and Cognition has no obligation or liability for any loss, alteration, destruction, damage, corruption, or recovery of Customer Data. ... In the event of a security breach, you will be responsible for notifying your employees and customers of such breach. You will convey information notices as required by applicable law, gain any necessary consents from Authorized Users, make any necessary filings with data protection authorities, and enforce and comply with any request from Authorized Users or authorities to access, rectify, and/or delete any Customer Data of Authorized Users. You agree to indemnify us against any suits, actions, claims, or proceedings arising from an Authorized User, data protection authority, or other third party with regard to these obligations.Excerpt from Windsurf's Terms of Service
(1) REGULATORY LANDSCAPE: This provision engages GDPR Articles 33 and 34, which assign breach notification obligations to data controllers and, in some cases, processors. CCPA and state breach notification statutes (including California Civil Code Section 1798.82) impose notification obligations that may conflict with or supplement this contractual allocation. The FTC Act applies to unfair or deceptive security practices. EU and state data protection authorities are the primary enforcement bodies. Where the customer is acting as a data controller and Cognition as a processor, applicable law may independently impose processor-side notification obligations regardless of contractual allocation. (2) GOVERNANCE EXPOSURE: High. The combination of a gross-negligence-only liability carve-out for Cognition on security breaches and a customer-side indemnification obligation for regulatory claims creates a significant operational exposure for enterprise customers. If a breach originates from Cognition's infrastructure but does not meet the gross negligence threshold, the customer bears notification costs and potential regulatory penalties without a corresponding right of recovery from Cognition under these terms. (3) JURISDICTION FLAGS: EU and EEA customers face heightened exposure because GDPR processor obligations may independently require Cognition to notify the controller without undue delay, creating a potential tension between this contractual allocation and statutory requirements. California, New York SHIELD Act, and other state breach notification laws impose independent obligations that the customer must fulfill regardless of this contractual structure. Healthcare and financial services customers face additional sector-specific notification requirements under HIPAA and GLBA. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement teams should assess whether this breach notification allocation is acceptable relative to standard vendor security agreements, which more commonly require the vendor to provide timely breach notification to the customer. The Data Processing Addendum at cognition.ai/dpa should be reviewed to determine whether it modifies these notification obligations. Cyber insurance policies should be reviewed to confirm coverage for regulatory filing costs and third-party claims arising from breach notification obligations assumed under this agreement. (5) COMPLIANCE CONSIDERATIONS: Customers should implement internal incident response procedures that account for the contractual obligation to self-file with data protection authorities and notify Authorized Users. Data mapping should identify all personal data processed through the platform to ensure notification scope can be rapidly determined. The indemnification obligation warrants review by legal counsel to confirm it does not create unacceptable risk transfer relative to the customer's actual control over Cognition's systems.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision shifts standard data breach notification and data subject rights fulfillment obligations to the customer, including regulatory filing obligations with data protection authorities. The accompanying indemnification clause requires the customer to hold Cognition harmless from claims arising out of these obligations, including claims from Authorized Users or regulators.
Under this clause, the customer bears responsibility for issuing breach notifications to their own personnel, filing with data protection authorities, and responding to data subject rights requests, even where the breach originates from Cognition's systems. Cognition's liability for security breaches is limited to instances of gross negligence under these terms.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Windsurf.