Windsurf · Windsurf Terms of Service · View original document ↗

Customer Breach Notification Obligation

High severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Windsurf changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Windsurf recorded 4 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Windsurf Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The agreement assigns to the customer the obligation to notify employees and end users in the event of a security breach, to file with data protection authorities, and to fulfill access, rectification, and deletion requests from Authorized Users or authorities. The customer also indemnifies Cognition against third-party claims arising from these notification and compliance obligations.

This analysis describes what Windsurf's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision shifts standard data breach notification and data subject rights fulfillment obligations to the customer, including regulatory filing obligations with data protection authorities. The accompanying indemnification clause requires the customer to hold Cognition harmless from claims arising out of these obligations, including claims from Authorized Users or regulators.

Interpretive note: The enforceability of this contractual allocation of breach notification obligations may be constrained by independent statutory obligations under GDPR, CCPA, and state breach notification laws that cannot be contracted away.

Recent Activity

This document changed recently

Medium Jul 1, 2026

The updated terms indicate that Windsurf is now operating as the Cognition Platform under Cognition AI, Inc., replacing the prior Exafunction, Inc. structure. The revised terms state that prior terms continue to govern use for 30 days from the posting date (July 1, 2026), and that continued access after that period constitutes acceptance of the updated terms. Users who do not agree with the new terms are instructed to stop using or accessing the Services. The specific substantive changes to user rights, data collection, fees, or service functionality are not detailed in the provided change summary.

View change record →

Consumer impact (what this means for users)

Under this clause, the customer bears responsibility for issuing breach notifications to their own personnel, filing with data protection authorities, and responding to data subject rights requests, even where the breach originates from Cognition's systems. Cognition's liability for security breaches is limited to instances of gross negligence under these terms.

Cross-platform context

See how other platforms handle Customer Breach Notification Obligation and similar clauses.

Compare across platforms →

Monitoring

Windsurf has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Cognition will not be responsible for any breach in security except to the extent the breach is due to Cognition's gross negligence. You will be responsible for routinely backing up Customer Data, and Cognition has no obligation or liability for any loss, alteration, destruction, damage, corruption, or recovery of Customer Data. ... In the event of a security breach, you will be responsible for notifying your employees and customers of such breach. You will convey information notices as required by applicable law, gain any necessary consents from Authorized Users, make any necessary filings with data protection authorities, and enforce and comply with any request from Authorized Users or authorities to access, rectify, and/or delete any Customer Data of Authorized Users. You agree to indemnify us against any suits, actions, claims, or proceedings arising from an Authorized User, data protection authority, or other third party with regard to these obligations.

Excerpt from Windsurf's Terms of Service

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision engages GDPR Articles 33 and 34, which assign breach notification obligations to data controllers and, in some cases, processors. CCPA and state breach notification statutes (including California Civil Code Section 1798.82) impose notification obligations that may conflict with or supplement this contractual allocation. The FTC Act applies to unfair or deceptive security practices. EU and state data protection authorities are the primary enforcement bodies. Where the customer is acting as a data controller and Cognition as a processor, applicable law may independently impose processor-side notification obligations regardless of contractual allocation. (2) GOVERNANCE EXPOSURE: High. The combination of a gross-negligence-only liability carve-out for Cognition on security breaches and a customer-side indemnification obligation for regulatory claims creates a significant operational exposure for enterprise customers. If a breach originates from Cognition's infrastructure but does not meet the gross negligence threshold, the customer bears notification costs and potential regulatory penalties without a corresponding right of recovery from Cognition under these terms. (3) JURISDICTION FLAGS: EU and EEA customers face heightened exposure because GDPR processor obligations may independently require Cognition to notify the controller without undue delay, creating a potential tension between this contractual allocation and statutory requirements. California, New York SHIELD Act, and other state breach notification laws impose independent obligations that the customer must fulfill regardless of this contractual structure. Healthcare and financial services customers face additional sector-specific notification requirements under HIPAA and GLBA. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement teams should assess whether this breach notification allocation is acceptable relative to standard vendor security agreements, which more commonly require the vendor to provide timely breach notification to the customer. The Data Processing Addendum at cognition.ai/dpa should be reviewed to determine whether it modifies these notification obligations. Cyber insurance policies should be reviewed to confirm coverage for regulatory filing costs and third-party claims arising from breach notification obligations assumed under this agreement. (5) COMPLIANCE CONSIDERATIONS: Customers should implement internal incident response procedures that account for the contractual obligation to self-file with data protection authorities and notify Authorized Users. Data mapping should identify all personal data processed through the platform to ensure notification scope can be rapidly determined. The indemnification obligation warrants review by legal counsel to confirm it does not create unacceptable risk transfer relative to the customer's actual control over Cognition's systems.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has jurisdiction over data security practices and breach notification obligations under the FTC Act and the Safeguards Rule.
    File a complaint →
  • State AG
    State attorneys general enforce state breach notification statutes including California Civil Code Section 1798.82 and the New York SHIELD Act.
    File a complaint →

Provision details

Document information
Document
Windsurf Terms of Service
Entity
Windsurf
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014092
Document ID
CA-D-00487
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
f6e8d9d0bd5f9547549794c5f7e89d7dbd456e727e5d9c631d8366f1a48c326f
Analysis generated
July 9, 2026 04:42 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Windsurf
Document: Windsurf Terms of Service
Record ID: CA-P-014092
Captured: 2026-07-09 04:42:52 UTC
SHA-256: f6e8d9d0bd5f9547…
URL: https://conductatlas.com/platform/windsurf/windsurf-terms-of-service/provision/CA-P-014092/customer-breach-notification-obligation/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Windsurf's Customer Breach Notification Obligation clause do?

This provision shifts standard data breach notification and data subject rights fulfillment obligations to the customer, including regulatory filing obligations with data protection authorities. The accompanying indemnification clause requires the customer to hold Cognition harmless from claims arising out of these obligations, including claims from Authorized Users or regulators.

How does this clause affect you?

Under this clause, the customer bears responsibility for issuing breach notifications to their own personnel, filing with data protection authorities, and responding to data subject rights requests, even where the breach originates from Cognition's systems. Cognition's liability for security breaches is limited to instances of gross negligence under these terms.

Is ConductAtlas affiliated with Windsurf?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Windsurf.