Provision record
Windsurf · Windsurf Terms of Service · View original document ↗

Customer Breach Notification Obligation

High severity Medium confidence Explicit document language Unique · 0 of 352 platforms
Stay ahead of the changes
Track Windsurf and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

The agreement assigns to the customer the obligation to notify employees and end users in the event of a security breach, to file with data protection authorities, and to fulfill access, rectification, and deletion requests from Authorized Users or authorities. The customer also indemnifies Cognition against third-party claims arising from these notification and compliance obligations.

This analysis describes what Windsurf's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision shifts standard data breach notification and data subject rights fulfillment obligations to the customer, including regulatory filing obligations with data protection authorities. The accompanying indemnification clause requires the customer to hold Cognition harmless from claims arising out of these obligations, including claims from Authorized Users or regulators.

Interpretive note: The enforceability of this contractual allocation of breach notification obligations may be constrained by independent statutory obligations under GDPR, CCPA, and state breach notification laws that cannot be contracted away.

Recent Activity

This document changed recently

Medium Jul 1, 2026

The updated terms indicate that Windsurf is now operating as the Cognition Platform under Cognition AI, Inc., replacing the prior Exafunction, Inc. structure. The revised terms state that prior terms continue to govern use for 30 days from the posting date (July 1, 2026), and that continued access after that period constitutes acceptance of the updated terms. Users who do not agree with the new terms are instructed to stop using or accessing the Services. The specific substantive changes to user rights, data collection, fees, or service functionality are not detailed in the provided change summary.

View change record →

Consumer impact (what this means for users)

Under this clause, the customer bears responsibility for issuing breach notifications to their own personnel, filing with data protection authorities, and responding to data subject rights requests, even where the breach originates from Cognition's systems. Cognition's liability for security breaches is limited to instances of gross negligence under these terms.

Cross-platform context

See how other platforms handle Customer Breach Notification Obligation and similar clauses.

Compare across platforms →
▸ View Original Clause Language DOCUMENT RECORD
"
Cognition will not be responsible for any breach in security except to the extent the breach is due to Cognition's gross negligence. You will be responsible for routinely backing up Customer Data, and Cognition has no obligation or liability for any loss, alteration, destruction, damage, corruption, or recovery of Customer Data. ... In the event of a security breach, you will be responsible for notifying your employees and customers of such breach. You will convey information notices as required by applicable law, gain any necessary consents from Authorized Users, make any necessary filings with data protection authorities, and enforce and comply with any request from Authorized Users or authorities to access, rectify, and/or delete any Customer Data of Authorized Users. You agree to indemnify us against any suits, actions, claims, or proceedings arising from an Authorized User, data protection authority, or other third party with regard to these obligations.

Excerpt from Windsurf's Terms of Service

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision engages GDPR Articles 33 and 34, which assign breach notification obligations to data controllers and, in some cases, processors.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →
  • State Attorney General
    State AGs in California, New York, Texas, and other states can investigate violations of state consumer protection and privacy laws, including CCPA (California), SHIELD Act (New York), and equivalents.
    Who can file: Residents of states with comprehensive privacy laws — primarily California, Virginia, Colorado, Connecticut, and Utah
    What you need: Evidence of the violation, explanation of how your state rights were affected, and your account or contact information with the company
    What to expect: Outcomes vary by state. May result in investigation, enforcement action, or requirement for the company to change practices. No direct individual compensation in most cases.

    Search "[your state] attorney general consumer complaint" to find your state's direct complaint form

Provision details

Document information
Document
Windsurf Terms of Service
Entity
Windsurf
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014092
Document ID
CA-D-00487
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
f6e8d9d0bd5f9547549794c5f7e89d7dbd456e727e5d9c631d8366f1a48c326f
Analysis generated
July 9, 2026 04:42 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Windsurf
Document: Windsurf Terms of Service
Record ID: CA-P-014092
Captured: 2026-07-09 04:42:52 UTC
SHA-256: f6e8d9d0bd5f9547…
URL: https://conductatlas.com/platform/windsurf/windsurf-terms-of-service/provision/CA-P-014092/customer-breach-notification-obligation/
Accessed: Sept. 15, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Windsurf's Customer Breach Notification Obligation clause do?

This provision shifts standard data breach notification and data subject rights fulfillment obligations to the customer, including regulatory filing obligations with data protection authorities. The accompanying indemnification clause requires the customer to hold Cognition harmless from claims arising out of these obligations, including claims from Authorized Users or regulators.

How does this clause affect you?

Under this clause, the customer bears responsibility for issuing breach notifications to their own personnel, filing with data protection authorities, and responding to data subject rights requests, even where the breach originates from Cognition's systems. Cognition's liability for security breaches is limited to instances of gross negligence under these terms.

Is ConductAtlas affiliated with Windsurf?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Windsurf.