GDPR
How we process personal data as a processor for our customers and as a controller for account data.
Last reviewed on 2026-09-19.
EU
What we do
- Processor role: for the code and evidence you submit we act as your processor under a Data Processing Agreement.
- Data minimisation: no source code is retained after a run; evidence contains hashes, metadata and outcomes only.
- Data subject rights: access, rectification, erasure and portability of account data are honoured through the app.
- Right to erasure honoured for personal data; execution evidence is not personal data and is retained under art. 17(3).
- Breach notification: personal-data breaches are notified to affected customers without undue delay and within 72 hours of becoming aware.
- Legal-claims retention: execution evidence (no personal data, no source code) is retained for 6 years for the establishment, exercise or defence of legal claims (art. 17(3)(e)), independently of account deletion.
- Sub-processors: listed publicly with their role and region; international transfers rely on Standard Contractual Clauses where applicable.
- Deletion requests are honoured within 30 days (reversible during that period); in complex cases we may extend up to two further months and will inform you.
This page describes our practices. It is not legal advice, not an audit report and not a statement of conformity with any framework.