Data Processing Agreement
Version 1.0.0 · last reviewed 2026-09-19. Structure fixed by legal review; wording subject to final review before launch.
1. Roles
The customer is the controller of the code and evidence it submits; the provider is its processor (GDPR art. 28).
2. Subject matter, duration, nature and purpose
Execution of published audit scripts on releases designated by the customer, for the duration of the service agreement, for the purpose of producing execution attestations.
3. Instructions
The provider processes only on documented instructions: the run requests issued by the customer through the product or its CI token.
4. Confidentiality and security
Ephemeral sandboxes with egress allow-list; no source code retention; findings encrypted at rest with a per-organisation key; signed, hash-chained evidence ledger under write-once retention; access logging.
5. Sub-processors
Listed publicly at /compliance/subprocessors. Changes are announced in advance; the customer may object.
6. Data subject rights and assistance
The provider assists the customer with data subject requests and with security and impact assessments as reasonably required.
7. Breach notification
Personal-data breaches are notified to the customer without undue delay and within 72 hours of the provider becoming aware.
8. Deletion and return
At the end of the service, account data is deleted after the grace period; execution evidence (no personal data) is retained 6 years as set out in the Terms.
9. Audits
The customer may verify compliance through the evidence published with each attestation and through reasonable written enquiries.
10. International transfers
Standard Contractual Clauses (Decision 2021/914) apply to transfers to sub-processors outside the EEA.
Annex — Service Provider Terms (11 CCR §7051(a))
- The personal information is disclosed by the business only for the limited and specified business purposes set out in the agreement (providing the release attestation service).
- The service provider is prohibited from selling or sharing the personal information.
- The service provider is prohibited from retaining, using or disclosing the personal information for any purpose other than the business purposes specified in the agreement.
- The service provider is prohibited from retaining, using or disclosing the personal information for any commercial purpose other than the specified business purposes.
- The service provider is prohibited from retaining, using or disclosing the personal information outside the direct business relationship between the service provider and the business.
- The service provider is prohibited from combining the personal information received from the business with personal information received from another person or collected from its own interaction with the consumer, except as permitted by the regulations.
- The service provider shall comply with the CCPA and provide the same level of privacy protection as required of businesses.
- The business has the right to take reasonable and appropriate steps to ensure the service provider uses the personal information in a manner consistent with the business's obligations under the CCPA.
- The service provider shall notify the business if it determines it can no longer meet its obligations under the CCPA.
- The business has the right, upon notice, to take reasonable and appropriate steps to stop and remediate unauthorised use of personal information.