The agreement assigns to the customer the obligation to notify employees and end users in the event of a security breach, to file with data protection authorities, and to fulfill access, rectification, and deletion requests from Authorized Users or authorities. The customer also indemnifies Cognition against third-party claims arising from these notification and compliance obligations.
This analysis describes what Windsurf's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision shifts standard data breach notification and data subject rights fulfillment obligations to the customer, including regulatory filing obligations with data protection authorities. The accompanying indemnification clause requires the customer to hold Cognition harmless from claims arising out of these obligations, including claims from Authorized Users or regulators.
Interpretive note: The enforceability of this contractual allocation of breach notification obligations may be constrained by independent statutory obligations under GDPR, CCPA, and state breach notification laws that cannot be contracted away.
The updated terms indicate that Windsurf is now operating as the Cognition Platform under Cognition AI, Inc., replacing the prior Exafunction, Inc. structure. The revised terms state that prior terms continue to govern use for 30 days from the posting date (July 1, 2026), and that continued access after that period constitutes acceptance of the updated terms. Users who do not agree with the new terms are instructed to stop using or accessing the Services. The specific substantive changes to user rights, data collection, fees, or service functionality are not detailed in the provided change summary.
View change record →Under this clause, the customer bears responsibility for issuing breach notifications to their own personnel, filing with data protection authorities, and responding to data subject rights requests, even where the breach originates from Cognition's systems. Cognition's liability for security breaches is limited to instances of gross negligence under these terms.
Cross-platform context
See how other platforms handle Customer Breach Notification Obligation and similar clauses.
Compare across platforms →"Cognition will not be responsible for any breach in security except to the extent the breach is due to Cognition's gross negligence. You will be responsible for routinely backing up Customer Data, and Cognition has no obligation or liability for any loss, alteration, destruction, damage, corruption, or recovery of Customer Data. ... In the event of a security breach, you will be responsible for notifying your employees and customers of such breach. You will convey information notices as required by applicable law, gain any necessary consents from Authorized Users, make any necessary filings with data protection authorities, and enforce and comply with any request from Authorized Users or authorities to access, rectify, and/or delete any Customer Data of Authorized Users. You agree to indemnify us against any suits, actions, claims, or proceedings arising from an Authorized User, data protection authority, or other third party with regard to these obligations.Excerpt from Windsurf's Terms of Service
(1) REGULATORY LANDSCAPE: This provision engages GDPR Articles 33 and 34, which assign breach notification obligations to data controllers and, in some cases, processors.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision shifts standard data breach notification and data subject rights fulfillment obligations to the customer, including regulatory filing obligations with data protection authorities. The accompanying indemnification clause requires the customer to hold Cognition harmless from claims arising out of these obligations, including claims from Authorized Users or regulators.
Under this clause, the customer bears responsibility for issuing breach notifications to their own personnel, filing with data protection authorities, and responding to data subject rights requests, even where the breach originates from Cognition's systems. Cognition's liability for security breaches is limited to instances of gross negligence under these terms.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Windsurf.